Hacking Group Wants to Play Nice With Automakers

Advertisement
By Reuters | Updated: 9 August 2014 10:39 IST

A group of well-known hackers and security professionals are trying to build better ties with the auto industry in an effort to enlist their help in improving vehicle security, one of the hottest areas of cyber research.

The non-profit group, known as "I am the Cavalry," is asking attendees at this weekend's Def Con hacking conference in Las Vegas to sign an open letter to "Automotive CEOs" to ask them to implement basic guidelines to defend cars from cyber attacks.

"The once distinct worlds of automobiles and cyber security have collided," said the letter. "Now is the time for the automotive industry and the security community to connect and collaborate."

Advertisement

Vehicles rely on tiny computers to manage everything form engines and brakes to navigation, air conditioning and windshield wipers. Security experts say it is only a matter of time before malicious hackers are able to exploit software glitches and other vulnerabilities to try to harm drivers.

Advertisement

The Cavalry group is scheduled to make a presentation at Def Con on Saturday about efforts to improve auto security. They will not disclose any specific problems that might embarrass carmakers, said Josh Corman, a security industry professional who co-founded the group a year ago.

(Also See: LG Joins Google-Led Open Automotive Alliance for Android Auto)

That sensitivity contrasts with much of the hacking research presented these days at Def Con, which attracts more than 10,000 attendees. For instance, one high-profile paper being released this year reviewed 20 vehicle models to find the three "most hackable" cars.

Advertisement

The Cavalry group has been trying to smooth relations between researchers and industry by promoting responsible disclosure. That means they approach carmakers to discuss bugs before going public, giving them time to fix them.

"The goal is build trust," said Corman, chief technology officer of software firm Sonatype. "In the past, these hacking talks were 'Look at me. Look at what I did.' There wasn't much care for what happens next and how it affects the industries."

Advertisement

Leaders of the Cavalry - which has several hundred active members who also study medical devices, consumer electronics and critical infrastructure - have spent the past year meeting with other security experts, manufacturers, regulators and lawmakers.

On Tuesday, the group talked about hacking cars and medical devices with industry representatives in a private meeting in Las Vegas. They agreed not to publicly discuss those sessions.

Katie Moussouris, a Cavalry leader who is an executive at a startup known as HackerOne, said she encourages hackers to show empathy when approaching companies.

"It is important to show that you are not just trying to show their weakness and make them look stupid, but that you are trying to help," said Moussouris, who until recently ran outreach to security researchers for Microsoft Corp.

Wade Newton, a spokesman for the Auto Alliance, which represents 12 car makers, declined to comment on Cavalry's efforts to reach out to the industry. "Our record shows that we typically welcome the opportunity to work with a broad array of stakeholders when we have a common goal," he said.

The U.S. National Highway Traffic Safety Administration said in a statement that it is not aware of any incidents of consumer vehicle control systems that have been hacked.

(Also See: US Homeland Security Contractor Reports Computer Breach)

Not all researchers believe in Cavalry's conciliatory approach. Charlie Miller, who co-authored the study on "most hackable" cars, said he does not think automakers will take serious action to improve security until they are shamed into doing so by someone who demonstrates code capable of remotely attacking a car and causing it to crash.

"They say they know what they are doing. But all the evidence points to the contrary," said Miller.

Jeff Moss, who founded Def Con 22 years ago and is now an advisor to the U.S. Department of Homeland Security, said there are merits to both approaches.

"Either side has a valid argument," Moss said. "It's almost like a carrot and stick approach."

© Thomson Reuters 2014

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  2. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  3. Flipkart Buy Buy 2025 Sale With Discounts on iPhone 16 Begins on This Date
  4. Airtel Discontinues These Prepaid Recharge Packs in India
  5. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  6. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  7. Flipkart Buy Buy 2025 Sale: Nothing Phone 3, Phone 3a Deals Revealed
  8. Samsung May Limit Exynos 2600 to South Korea's Galaxy S26 Units
  9. Realme Watch 5 Launched in India With Up to 16-Day Battery Life: See Price
  10. Apple Announces App Store Awards 2025 Winners: Check List
  1. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  2. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
  3. NotebookLM App Gets an In-Built Camera, Lets Users Upload Images as a Source
  4. HMD 101 Launched in India With 1,000mAh Battery, Auto Call Recording Alongside HMD 100: Price, Features
  5. Crypto Traders Await US Fed Signals as Bitcoin Price Drops to $91,900
  6. Nothing Phone 3a Lite Goes on Sale in India: See Price, Offers, Availability
  7. Realme Narzo Phones Confirmed to Launch in India Soon via Amazon
  8. Samsung Galaxy Watch Ultra 2 Launch Timeline Leaked; Could Debut Alongside Samsung Galaxy Watch 9
  9. Samsung Galaxy S26 Series May Get Exynos 2600 Chipset Exclusively in South Korea: Report
  10. Apple’s FaceTime Reportedly Blocked in Russia Alongside Snapchat’s Video Calling Feature
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.