Showing posts with label cars. Show all posts
Showing posts with label cars. Show all posts

Wednesday, January 27, 2016

Backseat Drivers, Your Wish Has Come True

Excuse for speeding 10 years from now: ‘Officer, it was the software.’

When I was in college, I would drive the 1040 miles from Marquette Univ. in Milwaukee to my parent’s house in Rhode Island for things like summer vacation and semester break. It seemed to take forever, especially through Pennsylvania where the state speed limit at the time was 55mph. I always tried to complete it straight through yet would inevitably start the head drop and would fall asleep at some rest stop in Connecticut, about 3 hours from my goal. This is back when they still had toll booths on the Connecticut turnpike.

As an adult, my family has driven the 2000 miles from California to Minnesota to visit family. In both instances, I wished I could simply doze off, take a little nap, stay on the road and awake a couple hundred miles closer to the destination. Yes, we alternated drivers but that also meant I wasn’t driving. For some reason, I had a much easier time falling asleep while holding the steering wheel than in shotgun position.

Soon, you just might be able to notch that seat in recline or even stretch out in the back – do I hear third row - while your car continues on its merry way. Deutsche Telekom and Nokia conducted the first demonstration of car-to-car communication over a high speed cellular connection with close to 5G performance. And they did it on the recently inaugurated Digital A9 Motorway Test bed - Germany’s Autobahn. The cars connected over a regular LTE service optimized for rapidly moving vehicles. They used a cellular network since it is already in place and didn’t need to negotiate a digital handshake to connect.

Nokia says that its technology cut the transmission lag time to under 20 milliseconds, versus today’s limit of 100+ milliseconds, give or take. And it is counting the relay time from one car to another, via a central cloud. This was simply a test to see how self-driving cars could communicate while travelling at high speeds. These connected cars will have a lot of data chatter but outside our earshot.
There is also growing attention to automobile vulnerabilities as more of these driverless cars start to appear on our roads. Recorded Future has a great graphic showing some of the attacks and exploits against automakers, vehicles and components since 2010.


Just like our applications, there is a growing list of the types of connected vehicle focused hackers. From researchers to criminals to insiders to competitors and even nation states are all trying to target these vehicles for their own purposes. And they all have their own motives as you can imagine. TechCrunch has an excellent article Connected Car Security: Separating Fear From Fact which digs into the short history of car vulnerability research along with the various players and what they are digging for.

Meanwhile, Ford Motors announced that they will begin testing self-driving cars at a Michigan facility called Mcity. A fake town with stores, crosswalks, street lights and other scale structures to test the software and sensors controlling the car. They’ve also announced that whatever driver data is generated (which can be up to 25GB and hour) is the customer’s data. Ford says they will only share it with the customer’s informed consent and permission.

And lastly, a Google self-driving car was lit-up by a CHiP in Mountain View for going too slow – 24mph in a 35 zone. Too bad no one was at the wheel to sign for the ticket. The officer quickly realized that he pulled over an autonomous car and asked the human passenger about the speed settings while reminding him of the CA Vehicle Code. This model tops out at 25mph for safety reasons and no ticket was issued.

And in the future, remember this: ‘Officer, it was the software.’

ps

Related:



This article originally appeared 11.19.15 on F5.com


Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Friday, October 2, 2015

IoT: Tabs to be Read Later

I've been traveling a bit over the last month and my tabs-to-read-later pile is growing. We'll be at AWS re:Invent next week so I thought I'd unload some of the IoT stories that caught my eye recently, that I'm finally getting to read. Apologies if this is old news to you.

tabs

One I've been holding on to almost the longest is an interesting INC article Our Future Will be Analog, Not Digital. Geoffrey James talks about the Internet of Things and how people think the convenience of connectivity is more important than the risks involved. He talks about how snail mail, cash and unplugging are tending up along with how analog objects are becoming status symbols. This is a good one if you think all this connectivity will become so hackable and fragile that no one will want to use it.

Next from The Economist, saying on the IoT theme, is Their own Devices. From Barbie's to cars to televisions, compromised computers are all over the place and few companies have the incentive to take security seriously within their widgets. There needs to be a change in corporate culture especially within non-computer companies. From the early days of the boiler explosions and crashes on railways to the safety of cars in the 70's to the hacks of medical devices today, we all need to recognize that connected devices need protection. And so do we.

To that, from Mashable, is how Major automakers are forming an alliance to tackle cybersecurity.With the growing concerns and actual demonstrations of cars getting breached, the Alliance of Automobile Manufacturers and the Association of Global Automakers are forming an Information Sharing and Analysis Center, according to Automotive News. Chris Perkins says, the creation of the Information Sharing and Analysis Center (ISAC) represents an important proactive step from the industry to address these hacks before they happen.

The last couple years during the NFL season, I've written some stories about technology in sports including Are You Ready For Some...Technology!! and more recently with Will Deflate-Gate Lead to Micro-Chipped Footballs? On Ars Technica, David Kravets goes deeper into the sensor technology being used by the NFL this year with How the NFL—not the NSA—is impacting data gathering well beyond the gridiron. He talks about how RFID is being used to track all the player's movements and how they will use the 2 to 3 gigs of data generated each game. Also how teams can use the data for training and coaching along with how console gaming might use it and how it could affect fantasy bets. Very interesting article on how all this connectivity plays into the games we watch, play and enjoy.

OK, that's it for now and thanks for the chance to clean up some of my browser tabs. Now I got room for the next bunch.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, August 23, 2012

From Car Jacking to Car Hacking

With the promise of self-driving cars just around the corner of the next decade and with researchers already able to remotely apply the brakes and listen to conversations, a new security threat vector is emerging.  Computers in cars have been around for a while and today with as many as 50 microprocessors, it controls engine emissions, fuel injectors, spark plugs, anti-lock brakes, cruise control, idle speed, air bags and more recently, navigation systems, satellite radio, climate control, keyless entry, and much more. 

In 2010, a former employee of Texas Auto Center hacked into the dealer’s computer system and remotely activated the vehicle-immobilization system which engaged the horn and disabled the ignition system of around 100 cars.  In many cases, the only way to stop the horns (going off in the middle of the night) was to disconnect the battery.  Initially, the organization dismissed it as a mechanical failure but when they started getting calls from customers, they knew something was wrong.  This particular web based system was used to get the attention of those who were late on payments but obviously, it was used for something completely different.  After a quick investigation, police were able to arrest the man and charge him with unauthorized use of a computer system.

University of California - San Diego researchers, in 2011, published a report (pdf) identifying numerous attack vectors like CD radios, Bluetooth (we already knew that) and cellular radio as potential targets.  In addition, there are concerns that, in theory, a malicious individual could disable the vehicle or re-route GPS signals putting transportation (fleet, delivery, rental, law enforcement) employees and customers at risk.  Many of these electronic control units (ECUs) can connect to each other and the internet and so they are vulnerable to the same internet dangers like malware, trojans and even DoS attacks.  Those with physical access to your vehicle like mechanics, valets or others can access the On-Board Diagnostic System (OBD-II) usually located right under the dash.  Plug in, and upload your favorite car virus.  Tests have shown that if you can infect the diagnostics tools at a dealership, when cars were connected to the system, they were also infected.  Once infected, the car would contact the researcher’s servers asking for more instructions.  At that point, they could activate the brakes, disable the car and even listen to conversations in the car.  Imagine driving down a highway, hearing a voice over the speakers and then someone remotely explodes your airbags.  They’ve also been able to insert a CD with a malicious file to compromise a radio vulnerability.

Most experts agree that right now, it is not something to overly worry about since many of the previously compromised systems are after-market equipment, it  takes a lot of time/money and car manufactures are already looking into protection mechanisms.  But as I’m thinking about current trends like BYOD, it is not far fetched to imagine a time when your car is VPN’d to the corporate network and you are able to access sensitive info right from the navigation/entertainment/climate control/etc screen.  Many new cars today have USB ports that recognize your mobile device as an AUX and allow you to talk, play music and other mobile activities right through the car’s system.  I’m sure within the next 5 years (or sooner), someone will distribute a malicious mobile app that will infect the vehicle as soon as you connect the USB. 

Suddenly, buying that ‘84 rust bucket of a Corvette that my neighbor is selling doesn’t seem like that bad of an idea even with all the C4 issues.

ps

Related:

Technorati Tags: F5, integration, cloud computing, Pete Silva, security, business, education, technology, television, threats,appliances, context-aware, set top devices, web, internet, cybercrime, security, entertainment, identity theft, scam, email, data breach

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]