Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Black Hat: Cars can be hacked with simple exploits due to technology advances

by The Gurus
August 6, 2014
in Editor's News
Share on FacebookShare on Twitter

Advances in automobile technology are enabling attacks, but that industry is not ready for security and updates.
 
Speaking in a well-publicised presentation at the Black Hat conference in Las Vegas, Charlie Miller and Chris Valasek claimed that this time they were able to present at this conference after completing more of a study of automotive technology, and identifying common flaws. Last year’s proposed talk was rejected and presented at the Def Con conference instead.
 
Miller, a security analyst at Twitter, claimed that of the 15 cars they looked at, most were done visually and were from 2014. He said: “Each car is hardened in its own way. You can send messages to the Electronic Control Unit (ECU) and get the ECU to do something.”
 
The cars they looked at were: Audi A8; Honda Accord LX; Infiniti Q37 and G35; Jeep Cherokee; Dodge Ram 3500; Chrysler 300; Dodge Viper; Cadillac Escalade (2015); Ford Fusion; BMW 3-Series and i12; Range Rover Evoque and Sport; and the Toyota Prius.
 
Valasek, director of vehicle security researchat IOActive, said that all cars do not have computers, and their research was not the first, as the University of Washington had done a similar compromise of the ECU to send diagnostic messages to lock the brakes.
 
Miller said that last year it only focused on “plugging into a car”, but this year it looked at wider features. He said: “We were looking at steps and before we looked at the car, we used public information to determine how hard it was to hack a car. We saw how big the attack surface was – Bluetooth communications, app stores and cellular communications. With a bigger attack surface it is easier.”
 
Valasek said: “Cars are the same as software; we don’t see people writing exploits for them and they may be something of a soft target. Bluetooth has a viable attack surface, but no one is writing perfect Bluetooth stacks any time soon.”
 
He also described cellular telematics as the “holy grail”, while an expansion of “infotainment” modules and app stores will open cars up to attacks, as they are using simple web browsers and applications.
 
Valasek said: “There are great features which make you safer, as the Q50 feature can brake, accelerate and keep you in your lane. But why can we as a security industry not promote change within organisations? Security considerations are hard to do.”
 
Miller said: “Some cars have remote things on the same network and some do not. Car hacking is hard, but with more ECUs, there is more complexity in the network.”
 
Valasek added that with more technology, there are more problems. “In car apps need to get on as people know how to exploit these things, don’t know if it is engineering but the biggest take away is patching problems but for cars it is really hard and manufacturers usually just send a letter in the mail,” he sai
d,

 
“If release an exploit for in-car Bluetooth, it is costly to send letters in and tell the owner to bring the car to the dealership for an update. If an exploit comes out it will be hard to get it fixed, and next will be to do over-the-air updates.”
 
To protect cars, Miller said that they need to be considered as a “secure remote endpoint” and think about making it hard for an attacker. “Software for automobile should be safe and if you pop the ECU, you have got the keys so it is a losing battle.”
 

ShareTweet
Previous Post

BSides Las Vegas – Incidents happen, react and learn from them

Next Post

Black Hat: Get software security right, as we are in a Civil Cold War

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol