Car Hack Reveals Peril on the Road to Internet of Things

Advertisement
By Agence France-Presse | Updated: 6 August 2015 10:54 IST

A software glitch that allows hackers to commandeer a Jeep Cherokee while on the move is just a glimpse of dangers on the road ahead for the Internet of Things.

The ability to seize data from and take control of once-dumb devices that are now deemed "smart" with wireless Internet connections was a hot topic at the premier Black Hat cyber-security conference in Las Vegas Wednesday.

Researchers described how they remotely took control of a moving car or re-aimed high-tech sniper rifles, and many at the gathering warned the ramifications could be far more serious and wide-reaching.

Advertisement

For starters, many companies don't even have teams tasked with making sure their smart devices are secure.

Advertisement

"Almost none of the Internet of Things device-makers have any real security teams, it is sort of a gold rush to market," Black Hat founder Jeff Moss told AFP.

He expects the problem to grow, with skilled hackers eager to push the boundaries.

Advertisement

"The Jeep hack is the beginning," said Moss, who also founded the annual Def Con hacking conference that takes place later this week in Sin City.

"Criminals are geniuses at figuring out how to misuse this stuff."

Advertisement

He theorized a scenario in which a connected home appliance, a toaster for example, is hacked and becomes an entry point for an attack that hops wirelessly to other online devices, such as entertainment systems. A hacker could then jump next door via wireless Internet to take over a neighbor's home devices.

The possibilities for hackers are numerous and chilling.

Data from smart appliances or other devices can be used to learn about people's lifestyles or daily routines. Cameras in smart gadgets could be activated to spy on intimate moments people would prefer to keep private.

Adding to the problem is the fact that smart appliances, such as ovens or washing machines, are designed to last but do not typically get software updates. With time, hackers find vulnerabilities, and companies do not protect devices against attacks with new security software.

"You can see us racing toward a future where everything is connected, nothing is updatable, and it is going to last 10 years," Moss said.

"Then, it is a numbers game. A million of anything is trouble, a hundred million is a disaster."

Massive car recall
Fiat Chrysler Automobiles issued a safety recall for 1.4 million US cars and trucks in July after hackers demonstrated that they could remotely control their systems while the vehicles are in operation.

The recall came after cyber-security experts Charlie Miller and Chris Valasek remotely commandeered a Jeep Cherokee, made by Chrysler, to demonstrate the vulnerability of the vehicles' electronic systems.

Working from laptop computers at home, the two men were able to enter the Jeep's electronics via its online entertainment system, changing its speed and braking capability and manipulating the radio and windshield wipers.

The pair said it was a fairly easy job.

"We might be good at what we do, but this was a weekend project," Miller said.

"What if we did this full time, or got paid to do it?"

Miller is a security researcher at Twitter and Valasek works at cyber-security firm IOActive.

Miller and Valasek said they dug into automobile security because they wanted to make a point.

"Car companies spend millions of dollars on safety, and now this is a part of safety, whether they like it or not," Valasek said.

After the report, Chrysler offered a free software patch for vulnerable vehicles, but said it had no first-hand knowledge of hacking incidents.

The recall involves a broad range of Dodge, Jeep, Ram and Chrysler automobiles produced between 2013 and 2015 that have radios vulnerable to hacking.

The hack involved Harman hardware and the Sprint mobile network, but fixes have been put in place to block the tactic, according to Miller and Valasek.

Moss said the potential for hacking Internet-connected power meters was especially troubling. Hackers could not only target individual homes but could cause trouble on city grids, perhaps by toying with electric power in entire neighborhoods.

The Internet of Things promises to thrust into the spotlight an issue of liability that software makers have managed to avoid, according to Jennifer Granick, director of civil liberties at the Center of Internet and Society at Stanford University law school.

Most people might not think to sue a software maker when a computer crashes, but the odds are high they will when a smart car crashes, Granick said.

"Something that now has software in it but didn't before is going to blow up," added Granick, who gave a keynote presentation at Black Hat.

"Software liability is unavoidable, and it is necessary."

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. WhatsApp Rolls Out New Year 2026 Features Ahead of Its Busiest Day
  2. Redmi Pad 2 Pro 5G Price Range, Chipset Revealed Ahead of Launch in India
  3. iQOO 15 Ultra Could Have Its China Debut in Q1 2026, Claims Tipster
  4. Members Only: Palm Beach Season 1 Streaming on Netflix: Everything You Need to Know
  5. Amazon Get Fit Days Sale 2026 Announced in India: See Top Deals, Discounts
  6. Here are the Top 5 Gaming TWS Under Rs 2,000 in India
  1. NASA to Preview Upcoming ISS Spacewalks Focused on Solar Array Upgrades in January 2026
  2. New Study Explains Why Earth’s Poles Are Heating Up at an Alarming Rate
  3. Kumki 2 OTT Release Date: When and Where to Watch This Tamil Movie Online?
  4. The Demon Hunter OTT Release Date: When and Where to Watch it Online?
  5. A Legacy of Mettle: The Bharat Benz Story Now Streaming Online: Know Where to Watch it Online
  6. Members Only: Palm Beach Season 1 Streaming on Netflix: Everything You Need to Know About This Show
  7. Samsung Galaxy S26, Galaxy S26 Ultra Design Spotted in Leaked Hands-On Images
  8. Hotels Shift Focus to Loyalty Programmes to Challenge AI Agents, Booking Platforms: Report
  9. AI Impact Summit 2026: MeitY Says AI Should Not Be Controlled by Small Set of Companies
  10. Moto X70 Air Pro to Launch in China Soon; Could Feature Periscope Telephoto Camera, Snapdragon Chipset
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.