Dumb and dumber or fast and
furious?
Credit : Thinkstock
Is the car industry is going to repeat the same
mistakes the software industry made decades ago?
It’s like a scenario out of a fiction book. Two forces join together and create a much worse
universe than on their own alone. This is exactly what seems to happen to the car industry
respectively to the car’s own IT services like connecting to the internet, control car functions
and any other software based applications or system inside your car. These systems or
applications the car industry offers or imposes on its clients fail to safeguard the most simple
attacks.
Just recently a teenager hacked with a 15$ dollar software kit into a car manufactures software
and manipulated actors in the system like the horn and lights. You may say these are non-
essential services but losing the lights at wrong time or your horn goes off at the wrong place
could lead to fines or worse.
The car industry is now at the exact same point the IT industry was decades ago. The problem
is security has not been built into those system rather is has been bolted on. It is saddening to
see all the past failures of the software industry have to be repeated by the car industry.
Let’s go there for a minute if history repeats itself we will have the first viruses soon, then we
will have targeted attacks on specific car systems or manufacturers some will be more easy to
hack others less. Some manufactures will state hidden or non-public source code is safer and
other state public software and open source code is safer. As we all know this is far from the
truth both models created a mess in the security landscape. All known software and applications
had their fair share of vulnerabilities and mishaps.
Next we will see system breakdowns formerly known as blue screens. Then maybe we will
have car theft by ransomware meaning your car software will be encrypted and locked until you
pay for the release of the encryption key.
And lastly what about privacy? Do I really want to have my car sensory data hosted in the US?
What influence do I have over my data? Can I ask for a deletion of my data? Will my data about
speed, gear used, GPS coordinates shared with anybody or sold? Some location based ads when
passing by a fast food place on your car display. Can the car industry resist the temptations of
mobile advertising?
I haven’t seen very reassuring signs form the car industry on how to tackle the most basic
security scenarios. How is the car industry going to respond to country based privacy
guidelines?
Car companies’ lack fundamental understanding of how their own systems work and have little
clue how to defend them, according to the report, which was released Monday by U.S. Senator
Ed Markey (D-Mass).
Only two automobile manufacturers of the 16 surveyed could describe how they would respond
to a real-time infiltration of a vehicle, the report said. Six manufacturers avoided answering the
question on their response time entirely, and six more answered with "vague mentions" of
"appropriate actions."
"Drivers have come to rely on these new technologies, but unfortunately the automakers haven't
done their part to protect us from cyber-attacks or privacy invasions," Markey said in a written
statement.
I advise everyone with an interest in cars, security and IT to read this comprehensive report.
Here is the link to the full version:http://www.markey.senate.gov/imo/media/doc/2015-02-
06_MarkeyReport-Tracking_Hacking_CarSecurity%202.pdf
For your next car buy you should ask the car dealership for an option to switch off these systems
so you can have control over how and when your data is being exchanged and shared. Like the
airbag for the passenger side.
It would be encouraging to get signals from the car industry about taking security and ultimately
privacy seriously. Maybe the appointment of some heavy weights from the security and privacy
industry by the leading car manufactures could express commitment and highlight the
seriousness of the topic.
I wish you a good trip in your car on the commute from or to work!
What are your observations? Do you trust your car
manufacturer of choice with your data?

More Related Content

PPTX
CASE STUDY ANALYSIS ON PROGRESSIVE
PDF
Sbwire 531215
PDF
Within 10-years-autonomous-vehicles-will-change-every-ciso s-job
PPT
Progressive Case Study.Scm
PPTX
Progressive Insurance By Aditya Patni - IIT Dhanbad
PPT
Progressive Corp..Ashky
PDF
Promopremi
PPT
Progressive Corporation.Sssg
CASE STUDY ANALYSIS ON PROGRESSIVE
Sbwire 531215
Within 10-years-autonomous-vehicles-will-change-every-ciso s-job
Progressive Case Study.Scm
Progressive Insurance By Aditya Patni - IIT Dhanbad
Progressive Corp..Ashky
Promopremi
Progressive Corporation.Sssg

What's hot (13)

DOCX
Fine New Year resolution 2013 for drivers
PPT
Huge And Smart Progressive Case
PDF
Distracted driving white paper for fleets - Cell Control
PDF
2014 Card and Payments Fraud Forecast
 
PPTX
Auto insurance in United States
PDF
State insurance agency ridesharing warnings: California insurance release
PPTX
Progressive: Pay-As-You-Go Insurance
PDF
Innovation Stories: Self-Driving Cars
PDF
Sbwire 532387
PPTX
Alexa and the Connected Car
PDF
PassengerRights
PPTX
Society30. Is it all about sharing, robots and technology?
PDF
MWC Americas 2018 - HARMAN Sandip Ranjhan Automotive Cybersecurity
Fine New Year resolution 2013 for drivers
Huge And Smart Progressive Case
Distracted driving white paper for fleets - Cell Control
2014 Card and Payments Fraud Forecast
 
Auto insurance in United States
State insurance agency ridesharing warnings: California insurance release
Progressive: Pay-As-You-Go Insurance
Innovation Stories: Self-Driving Cars
Sbwire 532387
Alexa and the Connected Car
PassengerRights
Society30. Is it all about sharing, robots and technology?
MWC Americas 2018 - HARMAN Sandip Ranjhan Automotive Cybersecurity
Ad

Viewers also liked (20)

PDF
Get your own black van in the front yard series electronic dysoning- be the ...
PDF
Hack back series data is an asset - registration strategies v0.1
PPTX
Seef ebook promotion 18 dez-2015 dcb
PDF
Social Engineering public administration 2020
PDF
Hack back series how to spot fake linked in profiles - a way to figure out f...
PDF
Reputelligence lifecycle v3 Volkswagen "defeat device"
PPT
Ethical coffee machine ethical code or ethics into code v0.2
PDF
Clinton article
PDF
Sgs cloud 5 mar-2015 bsl dominique c. brack csach - public version
PDF
Social Media In Project Management Swiss PM Magazine Pm@CH 8th Edition
PDF
Management wisdom series leader and team
PDF
Security Zone 2013 DCBrack cloud computing
PDF
Artikel Dominique C Brack January February 2011 Issue Of It Professional
PDF
Greening IT
PDF
Green I.T. Awareness Week Speaker Dominique C. Brack Slideset
PDF
Whats The Role Of Social Media In Bcm Dominique C Brack, SBCI
PDF
Reputelligence power point template lifecycle v3
PDF
V4 Security Zone 2010 Speaker Dominique C. Brack Presentation, Handout
PDF
Security agility- dynamic policy creation and rollout
PDF
Sustainable IT KPMG Publication D. Brack Co-Author
Get your own black van in the front yard series electronic dysoning- be the ...
Hack back series data is an asset - registration strategies v0.1
Seef ebook promotion 18 dez-2015 dcb
Social Engineering public administration 2020
Hack back series how to spot fake linked in profiles - a way to figure out f...
Reputelligence lifecycle v3 Volkswagen "defeat device"
Ethical coffee machine ethical code or ethics into code v0.2
Clinton article
Sgs cloud 5 mar-2015 bsl dominique c. brack csach - public version
Social Media In Project Management Swiss PM Magazine Pm@CH 8th Edition
Management wisdom series leader and team
Security Zone 2013 DCBrack cloud computing
Artikel Dominique C Brack January February 2011 Issue Of It Professional
Greening IT
Green I.T. Awareness Week Speaker Dominique C. Brack Slideset
Whats The Role Of Social Media In Bcm Dominique C Brack, SBCI
Reputelligence power point template lifecycle v3
V4 Security Zone 2010 Speaker Dominique C. Brack Presentation, Handout
Security agility- dynamic policy creation and rollout
Sustainable IT KPMG Publication D. Brack Co-Author
Ad

Similar to Dumb and dumber or fast and furious (20)

PDF
WHITE PAPER▶ Building Comprehensive Security Into Cars
PDF
Addressing Security in the Automotive Industry
PPTX
Car Cybersecurity: What do Automakers Really Think?
PDF
Car cybersecurity: What do automakers really think?
PDF
The New Assembly Line: 3 Best Practices for Building (Secure) Connected Cars
PDF
SANS - Developments car hacking - 36607
PDF
How much "tech" is too much tech?
PDF
CONNECTED CARS: LIFE IN THE SMART LANE
PPTX
Digital Transformation and Data Protection in Automotive Industry
PPTX
Automotive Cybersecurity: The Gap Still Exists
PDF
Connected Car Security
PPTX
Automotive Cyber-Security Insights learned from IT and ICS/SCADA
PDF
Braking the Connected Car: The Future of Vehicle Vulnerabilities
PDF
Braking the Connected Car: The Future of Vehicle Vulnerabilities
PDF
Car Cybersecurity: The Gap Still Exists
PDF
Advancements and Hurdles in the Evolution of Automotive Wireless Interfaces: ...
PDF
FASTR_Overview2017
PDF
Why Cars Need Free Software
PPTX
Strategy Analytics - Automotive Cyber Security - Oct 2020.pptx
PPTX
Case study 4
WHITE PAPER▶ Building Comprehensive Security Into Cars
Addressing Security in the Automotive Industry
Car Cybersecurity: What do Automakers Really Think?
Car cybersecurity: What do automakers really think?
The New Assembly Line: 3 Best Practices for Building (Secure) Connected Cars
SANS - Developments car hacking - 36607
How much "tech" is too much tech?
CONNECTED CARS: LIFE IN THE SMART LANE
Digital Transformation and Data Protection in Automotive Industry
Automotive Cybersecurity: The Gap Still Exists
Connected Car Security
Automotive Cyber-Security Insights learned from IT and ICS/SCADA
Braking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle Vulnerabilities
Car Cybersecurity: The Gap Still Exists
Advancements and Hurdles in the Evolution of Automotive Wireless Interfaces: ...
FASTR_Overview2017
Why Cars Need Free Software
Strategy Analytics - Automotive Cyber Security - Oct 2020.pptx
Case study 4

More from Reputelligence (20)

PDF
Sicherheit welche gefahren durch drohnen drohen golem.de
PDF
Intensity levels social engineering engagement framework (seef) first cut d...
PDF
Artikel About Drones and Swisscom Innovation Startup Process
PDF
DRONES THE NEW WEAPON OF CHOICE - ALSO FOR HACKERS
PDF
The real- wolfpack story 2
PDF
Quantum Computing Shor algorithm crypto grafic IoT risk management
PDF
Press release 01_september_2016_social_engineering_engagement_framework_seef_...
PDF
Business shoes looking inconspicuous but still enough power to climb a wall o...
PDF
Press release social engineering engagement framework seef social engineering...
PDF
Press release social engineering engagement framework seef social engineering...
PPTX
Video integrated teaser awareness campaign seef
PDF
Teaser SEEF hack in Paris presentation
PDF
Sneak peek preview area 41 conference Zürich 10. - 11- June 2016
PDF
Reputelligence Lifecycle v3 Volkswagen example
PDF
«Se Klaud Brojäkt bräiks daun – wot is se först sing yu du?» Hä?
PDF
SEEF Framework Intensity Levels (English)
PPTX
New microsoft power point präsentation
PDF
Annoying practices series stupid math quiz etc v0.2
PDF
Genuis quizzle 6
PDF
Genuis quizzle 5
Sicherheit welche gefahren durch drohnen drohen golem.de
Intensity levels social engineering engagement framework (seef) first cut d...
Artikel About Drones and Swisscom Innovation Startup Process
DRONES THE NEW WEAPON OF CHOICE - ALSO FOR HACKERS
The real- wolfpack story 2
Quantum Computing Shor algorithm crypto grafic IoT risk management
Press release 01_september_2016_social_engineering_engagement_framework_seef_...
Business shoes looking inconspicuous but still enough power to climb a wall o...
Press release social engineering engagement framework seef social engineering...
Press release social engineering engagement framework seef social engineering...
Video integrated teaser awareness campaign seef
Teaser SEEF hack in Paris presentation
Sneak peek preview area 41 conference Zürich 10. - 11- June 2016
Reputelligence Lifecycle v3 Volkswagen example
«Se Klaud Brojäkt bräiks daun – wot is se först sing yu du?» Hä?
SEEF Framework Intensity Levels (English)
New microsoft power point präsentation
Annoying practices series stupid math quiz etc v0.2
Genuis quizzle 6
Genuis quizzle 5

Recently uploaded (20)

PDF
Life Cycle Analysis of Electric and Internal Combustion Engine Vehicles
PDF
Lubrication system for Automotive technologies
PDF
150 caterpillar motor grader service repair manual EB4
PPTX
internal combustion engine renewable new
PDF
Pharmacy is a goood college yvucc7t7tvy7tv7t
PDF
Cylinder head Volvo EC55 Service Repair Manual.pdf
PPTX
Moral Theology (PREhhhhhhhhhhhhhhhhhhhhhLIMS) (1).pptx
PDF
Transmission John Deere 370E 410E 460E Technical Manual.pdf
PPTX
IOT-UNIT 3.pptxaaaasasasasasasaasasasasas
PPTX
Money and credit.pptx from economice class IX
PPT
Main/Core Business Application User Manual
PPTX
Cloud_Computing_ppt[1].pptx132EQ342RRRRR1
PPTX
Victory precisions_Die casting foundry_.pptx
PPTX
Constitutional Design PPT.pptxl from social science class IX
PDF
Dongguan Sunnew ESS Profile for the year of 2023
PPTX
description of motor equipments and its process.pptx
PPTX
Quarter-1-Lesson-5-sdf wgwefwgwefgwgwgwewgwewgwewwedgfwrwtudents-copy.pptx
DOC
EAU-960 COMBINED INJECTION AND IGNITION SYSTEM WITH ELECTRONIC REGULATION.doc
PDF
MES Chapter 3 Combined UNIVERSITY OF VISVESHWARAYA
PDF
Fuel injection pump Volvo EC55 Repair Manual.pdf
Life Cycle Analysis of Electric and Internal Combustion Engine Vehicles
Lubrication system for Automotive technologies
150 caterpillar motor grader service repair manual EB4
internal combustion engine renewable new
Pharmacy is a goood college yvucc7t7tvy7tv7t
Cylinder head Volvo EC55 Service Repair Manual.pdf
Moral Theology (PREhhhhhhhhhhhhhhhhhhhhhLIMS) (1).pptx
Transmission John Deere 370E 410E 460E Technical Manual.pdf
IOT-UNIT 3.pptxaaaasasasasasasaasasasasas
Money and credit.pptx from economice class IX
Main/Core Business Application User Manual
Cloud_Computing_ppt[1].pptx132EQ342RRRRR1
Victory precisions_Die casting foundry_.pptx
Constitutional Design PPT.pptxl from social science class IX
Dongguan Sunnew ESS Profile for the year of 2023
description of motor equipments and its process.pptx
Quarter-1-Lesson-5-sdf wgwefwgwefgwgwgwewgwewgwewwedgfwrwtudents-copy.pptx
EAU-960 COMBINED INJECTION AND IGNITION SYSTEM WITH ELECTRONIC REGULATION.doc
MES Chapter 3 Combined UNIVERSITY OF VISVESHWARAYA
Fuel injection pump Volvo EC55 Repair Manual.pdf

Dumb and dumber or fast and furious

  • 1. Dumb and dumber or fast and furious? Credit : Thinkstock Is the car industry is going to repeat the same mistakes the software industry made decades ago? It’s like a scenario out of a fiction book. Two forces join together and create a much worse universe than on their own alone. This is exactly what seems to happen to the car industry respectively to the car’s own IT services like connecting to the internet, control car functions and any other software based applications or system inside your car. These systems or applications the car industry offers or imposes on its clients fail to safeguard the most simple attacks. Just recently a teenager hacked with a 15$ dollar software kit into a car manufactures software and manipulated actors in the system like the horn and lights. You may say these are non- essential services but losing the lights at wrong time or your horn goes off at the wrong place could lead to fines or worse.
  • 2. The car industry is now at the exact same point the IT industry was decades ago. The problem is security has not been built into those system rather is has been bolted on. It is saddening to see all the past failures of the software industry have to be repeated by the car industry. Let’s go there for a minute if history repeats itself we will have the first viruses soon, then we will have targeted attacks on specific car systems or manufacturers some will be more easy to hack others less. Some manufactures will state hidden or non-public source code is safer and other state public software and open source code is safer. As we all know this is far from the truth both models created a mess in the security landscape. All known software and applications had their fair share of vulnerabilities and mishaps. Next we will see system breakdowns formerly known as blue screens. Then maybe we will have car theft by ransomware meaning your car software will be encrypted and locked until you pay for the release of the encryption key. And lastly what about privacy? Do I really want to have my car sensory data hosted in the US? What influence do I have over my data? Can I ask for a deletion of my data? Will my data about speed, gear used, GPS coordinates shared with anybody or sold? Some location based ads when passing by a fast food place on your car display. Can the car industry resist the temptations of mobile advertising? I haven’t seen very reassuring signs form the car industry on how to tackle the most basic security scenarios. How is the car industry going to respond to country based privacy guidelines? Car companies’ lack fundamental understanding of how their own systems work and have little clue how to defend them, according to the report, which was released Monday by U.S. Senator Ed Markey (D-Mass). Only two automobile manufacturers of the 16 surveyed could describe how they would respond to a real-time infiltration of a vehicle, the report said. Six manufacturers avoided answering the question on their response time entirely, and six more answered with "vague mentions" of "appropriate actions." "Drivers have come to rely on these new technologies, but unfortunately the automakers haven't done their part to protect us from cyber-attacks or privacy invasions," Markey said in a written statement.
  • 3. I advise everyone with an interest in cars, security and IT to read this comprehensive report. Here is the link to the full version:http://www.markey.senate.gov/imo/media/doc/2015-02- 06_MarkeyReport-Tracking_Hacking_CarSecurity%202.pdf For your next car buy you should ask the car dealership for an option to switch off these systems so you can have control over how and when your data is being exchanged and shared. Like the airbag for the passenger side. It would be encouraging to get signals from the car industry about taking security and ultimately privacy seriously. Maybe the appointment of some heavy weights from the security and privacy industry by the leading car manufactures could express commitment and highlight the seriousness of the topic. I wish you a good trip in your car on the commute from or to work! What are your observations? Do you trust your car manufacturer of choice with your data?