Hacker News new | ask | show | jobs
by slt2021 1267 days ago
There is a risk of automobile security. Nowadays cars have vast attack surface and uplink accesses directly into internal car's CAN/Ethernet bus: OBD-II port, bluetooth, GSM/5G, WiFI, NFC, access via OEM's web portal (these are big piles of unsecure code), via mobile app API, dealer network applications.

Plus OEMs have a vast parts and software supply chain that can be compromised.

I suspect that in couple years timeframe we can see massive incident, like ransomware, that will disable entire fleet of a single OEM globally. Like imagine all Mercedes around the world to just stop operating - these kind of incidents

1 comments

This is the correct take. Also just found yet another problem puiblished a few weeks ago: https://medium.com/@doctoreww/day-2-your-car-is-trackable-by...

This stuff falls completely within any infosec person's expectations. Privacy leaks are expected, as are interference from remote signals.