Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 15 submissions in the queue.
posted by Fnord666 on Wednesday May 02 2018, @12:43PM   Printer-friendly
from the all-your-golf-are-belong-to-us dept.

Submitted via IRC for SoyCow4408

A Dutch cyber-security firm has discovered that in-vehicle infotainment (IVI) systems deployed with some car models from the Volkswagen Group are vulnerable to remote hacking. Daan Keuper and Thijs Alkemade, security researchers with Computest, said they successfully tested their findings and exploit chains on Volkswagen Golf GTE and Audi A3 Sportback e-tron models (Audi is a brand part of the Volkswagen Group).

The two researchers said used a car's WiFi connection to exploit an exposed port and gain access to the car's IVI, manufactured by electronics vendor Harman. Researchers also gained access to the IVI system's root account, which they say allowed them access to other car data.

"Under certain conditions attackers could listen in to conversations the driver is conducting via a car kit, turn the microphone on and off, as well as gaining access to the complete address book and the conversation history," Computest researchers said. "Furthermore, due to the vulnerability, there is the possibility of discovering through the navigation system precisely where the driver has been, and to follow the car live wherever it is at any given time," researchers added.

Source: https://www.bleepingcomputer.com/news/security/volkswagen-and-audi-cars-vulnerable-to-remote-hacking/

Original Paper: The Connected Car Ways to get unauthorized access and potential implications


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by Justin Case on Wednesday May 02 2018, @08:58PM

    by Justin Case (4239) on Wednesday May 02 2018, @08:58PM (#674760) Journal

    I'm not saying the safety feature should not exist. I'm saying you should not be required to bet your life (or your undamaged car) on it, merely so you can check the odometer.

    Belt and suspenders. Defense in depth, especially where life, injury, or large financial damage are on the line.

    But for FSM's sake do not train people to start the car without pressing the brake, because the safety feature will probably save your ass.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2