Posted in

Cyber Security of the Connected Car in the Age of the Internet of Things

The Revolutionary Design and Features of Connected Cars

In this age of the Internet of Things, virtual technology affects just about every aspect of our lives. From the way that we watch movies and television to the manner in which we shop and order food from our favorite restaurants, we have become increasingly dependent on wireless and virtual inventions that are designed to make our lives easier.

This technology now extends to the very cars that we drive every day to school, work, or anywhere else we need to go. Our new wireless Internet vehicles, dubbed connected cars, are designed to help us with ordinary driving tasks like backing out of a driveway, parallel parking, and even making a phone call or sending a text without having to dial or type on our cell phones. 

Our cars can tell us what directions to take and what the weather will be like once we arrive at our destination. They play movies, connect to global satellite radio stations, and keep us entertained at the touch of a button. All of their technological features center on maximizing our driving pleasure, improving our safety and handling, and relieving us of much of the thought and effort that used to come with driving a car.

Their innovative capabilities come directly from more than 300 million lines of code found within each connected car. In fact, they possess more lines of code than a Boeing 747 jet and have more powerful computing capabilities than 20 personal computers combined! 

Indeed, connected cars have forever changed the way that people today and in the future will drive their personal vehicles. More importantly, they have revolutionized the global automobile industry and the manner in which cars will be designed and marketed.

Connected Car Cybersecurity

As innovative and fun as these connected cars are to drive, they are not without flaws (mainly caused by poorly written software), which could compromise drivers’ physical and personal safety. Automobile industry insiders are becoming increasingly aware of the security risks found with owning and driving a connected car today.

Their awareness stems in part from a cybersecurity flaw in Jeep Cherokee that was discovered in 2015 by Charlie Miller and Chris Valasek. These two security experts demonstrated that they could easily manipulate this connected vehicle. By accessing Jeep’s infotainment system, they were capable of compromising its basic functions and stopping it from miles away, or specifically their basement. This hack subsequently forced Fiat Chrysler Automobiles NV to recall 1.4 million vehicles. Many other cases of car hacking occurred since, which has caused FBI and the Department of Transportation to issue an announcement recently saying that car hacking is a real risk.

A hack into one of these technologically innovative vehicles proves to be more of a threat than a hacker simply being able to unlock the vehicle. Hackers could overtake the car’s handling features and cause the driver to wreck. They can shut down the engine and inflict irreversible damage to the vehicle and to the person driving it. 

A cyber security hack into one of these cars can also expose the owner’s personal banking and financial information. Makers of connected cars retain owners’ information like their Social Security numbers, bank routing and account numbers, and the holder of their licens for customers‘ convenience. 

This information can be accessed by unauthorized parties if hackers succeed in compromising the cars’ virtual security. Victims of such a hack could be left to deal with having their identities stolen, their bank accounts drained, and new credit accounts opened in their names. They may have to cope with the consequences of the hack for years. 

Connected Car Manufacturer Obligation toward Cybersecurity

So what role do connected car makers actually play in improving cybersecurity in their vehicles? If one were to formulate an answer by these companies’ attitude toward connected car cybersecurity today, it would be easy to assume that they are not taking this matter seriously enough.

That is not to say, however, that all connected car makers are blas about their customers safety and privacy. Industry observers have seen some improvement in manufacturers’ attitudes if not their attempts to make these cars more secure. Some of their attempts at addressing this problem include launching bug bounties for hackers and establishing what is known as Auto-ISAC, which is a central information hub that gathers and analyzes information about cyber hacks on connected cars. Many of these industry observers also argue that connected carmakers today undoubtedly have a legal and moral responsibility to minimize cyber hacks on their vehicles. 

A recent study from International Data Corporation (IDC) concluded that although auto manufacturers acknowledge the need for securing their connected systems, they could be overlooking the privacy concerns that come with storing driver information. They fail to understand that connected cars are in essence personal computers on wheels that need the same form of protection against cyber security risks that most people afford their laptops and desktop computers at home and work. Cyber hackers typically aim for big targets, such as government or corporate databases, so they are more likely to exploit IoT devices of the connected car to gain entry to corporate and government networks and databases instead of crashing a compromised car.

It is arguably unfortunate that it took the cyber hacks of car models like Jeep Cherokee and another recent incident involving Volkswagen to awaken carmakers to this potentially devastating risk. Further, while car manufacturing engineers say right now that improved connected car security could still be one to three years down the proverbial road, industry observers question whether this is realistically feasible given the challenges ahead and the rate at which applications are being developed today. In any case, manufacturers are going to need to pay attention to security at the initial production stages, instead of regarding it as something they are forced to deal with later.

Proactive Security Measures for Connected Car Owners

Until connected car makers take significant and meaningful strides in improving connected car cyber security, owners of these vehicles are veritably left to their own devices when it comes to preventing their cars and their personal data from being hacked. What can you do to safeguard your own vehicle and information from being taken over by a hacker? One of the most important steps you can take right now involves researching what apps exist that could allow someone to overtake your connected car. 

These driver-downloaded applications are plentiful in today’s virtual world and can pose a real and serious threat to your security. They not only allow a hacker to overtake your car but also access your personal and financial data as well as threaten your consumer safety. 

In a bid to help consumers protect themselves, connected car manufacturers continue to urge owners to pay attention to any apps that they purchase and download for their cars. These apps ideally should come through approved app stores like the iStore or Google Play. Any third-party apps should also go through a preprocessor that can evaluate them for security risks.

Another important step the drivers can take involves simply being aware of the possibility of a cyber hack on the connected car. A recent Kelley Blue Book survey noted that nearly 70 percent of U.S. car consumers believe that connected cars will be hacked at some point. 42 percent of them also believe that cars should be more connected and capable of offering more virtual technology. Surprisingly, only around 13 percent of those surveyed said they would not use an app if it meant that their cars could be compromised by hackers. This study shows that automakers would not be able to rely on customers to keep their cars protected from cyber hacking.


Conclusion

Connected cars seem like the ideal answer to enhanced safety, improved handling, efficient navigation, and even better entertainment while driving. Despite their now commonplace existence in the age of the IoT, these vehicles are not without their fair share of cyber risks. 

In fact, they have demonstrated how challenging it can be to design cyber security measures to protect consumers in a technological ecosystem that is becoming more and more complex. Even so, this complexity should be a call for improved security rather than a disinterested approach to protecting consumers or the assumption that people will figure out their own way of safeguarding their cars and personal information.

It is not up to the consumers to protect themselves from cybersecurity risks while owning and driving a connected car. Everyone in the chain of making, marketing, and owning these vehicles bears some responsibility that they should take very seriously today. Key role players in improved connected car security include parts manufacturers and suppliers, OEMs, connected car dealerships, service providers, government regulators, and even the consumers themselves. 

The NHTSA also has demonstrated its role in improving cybersecurity for connected cars. It put pressure on Chrysler to address cyber risks regarding its vehicles last year. However, industry insiders note that the NHTSA must do more than demand fixes for bugs. It must insist that car manufacturers close the gap on security risks that could leave customers vulnerable to being hacked. The strategies for addressing these issues are still being formulated but it is important that all involved parties take this matter seriously since car hacking can become the next big security threat.

David has been obsessed with cars since he was little. When he realized he could combine his love of writing with his passion for cars, his fate was sealed. When he is not writing about the latest auto technology, he spends his time hiking. 

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.