Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Wednesday May 02 2018, @12:43PM   Printer-friendly
from the all-your-golf-are-belong-to-us dept.

Submitted via IRC for SoyCow4408

A Dutch cyber-security firm has discovered that in-vehicle infotainment (IVI) systems deployed with some car models from the Volkswagen Group are vulnerable to remote hacking. Daan Keuper and Thijs Alkemade, security researchers with Computest, said they successfully tested their findings and exploit chains on Volkswagen Golf GTE and Audi A3 Sportback e-tron models (Audi is a brand part of the Volkswagen Group).

The two researchers said used a car's WiFi connection to exploit an exposed port and gain access to the car's IVI, manufactured by electronics vendor Harman. Researchers also gained access to the IVI system's root account, which they say allowed them access to other car data.

"Under certain conditions attackers could listen in to conversations the driver is conducting via a car kit, turn the microphone on and off, as well as gaining access to the complete address book and the conversation history," Computest researchers said. "Furthermore, due to the vulnerability, there is the possibility of discovering through the navigation system precisely where the driver has been, and to follow the car live wherever it is at any given time," researchers added.

Source: https://www.bleepingcomputer.com/news/security/volkswagen-and-audi-cars-vulnerable-to-remote-hacking/

Original Paper: The Connected Car Ways to get unauthorized access and potential implications


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 1, Insightful) by Anonymous Coward on Wednesday May 02 2018, @06:36PM

    by Anonymous Coward on Wednesday May 02 2018, @06:36PM (#674698)

    The question is whether the infotainment system is isolated from the car's driving control system.

    I don't think this distinction makes much difference with the public.
    IMO, a hacker messing with the infotainment controls will end up being(possibly) more dangerous, due to the distracted driving while trying to 'fix' the misbehaving controls.

    From a purely technical POV, I'd agree with your comment, but when you add in humans...

    Starting Score:    0  points
    Moderation   +1  
       Insightful=1, Total=1
    Extra 'Insightful' Modifier   0  

    Total Score:   1