Drawing Lessons From July’s Jeep Hack

Comment

Image Credits: Matt Swaim (opens in a new window) / Flickr (opens in a new window) under a CC BY-ND 2.0 (opens in a new window) license.

Jessy Irwin

Contributor

Jessy Irwin is a security advocate and communications professional specializing in information security, privacy and trust.

If you were anywhere near the internet in late July, you probably read the news: Charlie Miller and Chris Valasek, two security researchers who specialize in hacking cars, figured out how to remotely take control of a Jeep.

They didn’t just take control of the vehicle from ten miles away— the hacking duo exploited a software flaw that shut down the Jeep’s engine while Wired’s Andy Greenberg was driving it. On a busy stretch of public highway where cars whizzed by at 60+ miles per hour. Without a shoulder or emergency pull off lane.

“THEY DID WHAAAAAAAAT?” most of the internet asked, mouths agape while watching the video proof that this was all possible.

Though the piece was masterful, the experiment was an entirely insane trust exercise in which two hackers promised not to put Greenberg’s life in danger while exploiting a security hole in the car’s uConnect system. Weeks later most of the internet was still discussing their shenanigans, and Chrysler announced a recall for 1.4 million vehicles, almost three times the number originally estimated by Miller, a Twitter employee, and Valasek, head of vehicle research at security firm IOActive.

Automakers and technology companies have worked together to connect cars to the internet left and right— there is no shortage of solutions for the connected car on the market, some of which can even unlock your home for you. How is it that major car companies across the world are just now beginning to hire security teams?

Security by Design

If one thing is certain about security, it’s this: security is a fundamental that has to be built in from the very beginning of the product creation process— it cannot be effectively reverse-engineered in at the end. When we design houses, we don’t put the toilet in the middle of the kitchen next to the sink— and when dealing with critical and non-critical systems, isolation is key for strong security.

To prevent an attacker from using a non-critical network to gain access to a highly critical network, security professionals often implement an air gap between the two. In the case of the systems powering the hacked Jeep, however, an air gap didn’t exist: after combining a few different security vulnerabilities, the hackers discovered a link between the system driving the car and the uConnect system powering the dashboard entertainment unit. One SIM card vulnerability and a few hacks later, the potentially fatal remote takeover flaw went from being a theoretical attack to a plausible threat.

Ultimately, this raises many questions about Chrysler’s security, design and review processes— someone (or multiple someones) within Chrysler had the opportunity to spot and correct this flaw, and did no such thing. How could something so glaringly obvious have been missed in something as critical and powerful as an automobile? Who could have thought that connecting these systems was a sound choice in the first place?!

Disclosure is hard

According to cybersecurity advocate Keren Elezari, “Hackers are the immune system of the internet.” As part of that immune system, white hat hackers and security researchers search for vulnerabilities in the critical infrastructures that connect our world, and disclose them as a means to protect vital systems from malicious attack. For this coordinated or responsible disclosure to work, vendors and security researchers must collaborate to find a fix and improve software or device security together.

More often than not, however, disclosure is a risky process for security researchers, and many are threatened with legal action for simply pointing out a flaw to a vendor. Since the 1990s, countless researchers have been threatened with prosecution for attempting to report software holes that are equally accessible by criminals, and more often than not, their findings are downplayed when vulnerabilities are released in the wild.

 

Though this is slowly beginning to change as large technology companies embrace disclosure and adopt platforms like Bugcrowd and HackerOne for vulnerability management, it is still common for researchers to face threats, or to have to approach the media and raise awareness of a security issue for it to be appropriately fixed.

While some consider this to be a dangerous act of stunt hacking, this particular case of car hacking is an example of public vulnerability disclosure at its absolute best. Instead of releasing the vulnerability into the wild,  Miller and Valasek coordinated with the vendor once they found the exploit, and then waited to make their findings public until a fix was available.

Without a video to illustrate the severity and implications of their car hack, their findings might have never been heard outside of the security community in attendance at BlackHat: a patch for the flaw may have never been developed. This summer, there are many more car hacks on the horizon at the world’s largest gathering of hackers and infosec pros BlackHat and DEF CON. (No word yet on whether any of the researchers behind this summer’s round of car hacks are working with reporters on videos of their vulnerability exploits, too!)

Bridging the Last Mile

After sharing their severe vulnerability with Chrysler, Miller and Valasek committed to the time consuming task of collaborating with the car manufacturer to develop a patch for the issue. Using an algorithm for tagging and tracking wild animals, Miller and Valasek estimated that 471k cars were affected— but after the recall from Chrysler, we now know that Chrysler will attempt to ship 1.4 million USB drives preloaded with software updates to consumers. If we know anything about consumers, though, it’s this: consumers don’t regularly update software for their computers, much less their cars.

Updating car software (which can be downloaded here) isn’t a simple process— it requires that the driver take the car to the dealership, or download the software from the web, upload it onto a thumb drive, connect the thumb drive to a USB port in the car’s dashboard, and then go through the installation process in the vehicle.

While this task might be reasonable for a certain subset of tech-savvy drivers, the vast majority of people will not go through this process, meaning many of the vehicles vulnerable to remote hacking may never see this upgrade. (Since the breach, Sprint has implemented upgrades that prevent the attack from being launched on their network, too.)

What good is a security update if it can’t make its way from a manufacturer to the device with a highly critical security issue? If Chrysler knew about this issue for nine months, why did it take three days from the initial public disclosure to announce a recall? And why is the burden of updating being left on the end-user when it the system could have been designed from the outset to automatically deliver important updates directly to affected vehicles?

Mo’ connectivity, mo’ problems

When their structures fail or their designs are found to be faulty, architects and civil engineers are frequently deemed negligent and held liable for decisions that lead to loss of life and limb. The Internet of Things is expected to grow to 30 billion devices by 2020, and as technology begins to power more and more of the things we use in our daily lives, we are quickly approaching world where technologists will be held liable for the loss of life and limb, too.

Whether you agree or not with how Charlie, Chris and Andy worked together to demonstrate a vulnerability affecting 1.5 million cars on the road does not change the severity of the issue or its widespread implications for consumers. By adding connectivity to devices, we greatly expand the potential for security vulnerabilities— with more connectivity comes more security problems.

Make room for it at the beginning of your product development process and embrace the security researchers who step in and share insights that will harden your product against abuse and malicious attack. In the end, it could do more than just save your company’s reputation from massive heartache— it could save life and limb.

Though no technology will ever be unhackable or 100% secure, security and security researchers serve to protect end users and empower the innovation we love so much in the Silicon Valley. To prevent the future from becoming a fully connected Internet of Terrors, it is time for those of us building an always-on, omni-connected future to be more proactive about the choices we make for the consumers that trust us to protect their safety.

More TechCrunch

Tags

One 97 Communications, the parent company of India’s leading digital payments platform Paytm, widened its consolidated net loss to $66.1 million in the quarter ending March, compared to a loss…

Paytm counts costs of regulatory clampdown as losses swell

Government officials and AI industry executives agreed on Tuesday to apply elementary safety measures in the fast-moving field and establish an international safety research network. Nearly six months after the…

In Seoul summit, heads of states and companies commit to AI safety

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Some startups choose to bootstrap from the beginning while others find themselves forced into self funding by a lack of investor interest or a business model that doesn’t fit traditional…

VCs wanted FarmboxRx to become a meal kit, the company bootstrapped instead

Uber and Lyft drivers in Minnesota will see higher pay thanks to a deal between the state and the country’s two largest ride-hailing companies. The upshot: a new law that…

Uber’s and Lyft’s ride-hailing deal with Minnesota comes at a cost

Andreessen Horowitz’s American Dynamism fund has established a new fellowship program aimed at introducing top engineers and technologists to venture investing, a move that could help the firm identify less…

a16z’s American Dynamism team launches program to introduce technical minds to VC

Another fintech startup, and its customers, has been gravely impacted by the implosion of banking-as-a-service startup Synapse. Copper Banking, a digital banking service aimed at teens, notified its customers on…

Teen fintech Copper had to abruptly discontinue its banking, debit products

Autodesk — the 3D tools behemoth — has acquired Wonder Dynamics, a startup that lets creators quickly and easily make complex characters and visual effects using AI-powered image analysis. The…

Autodesk acquires AI-powered VFX startup Wonder Dynamics

Farcaster, a blockchain-based social protocol founded by two Coinbase alumni, announced on Tuesday that it closed a $150 million fundraise. Led by Paradigm, the platform also raised money from a16z…

Farcaster, a crypto-based social network, raised $150M with just 80K daily users

Microsoft announced on Tuesday during its annual Build conference that it’s bringing “Windows Volumetric Apps” to Meta Quest headsets. The partnership will allow Microsoft to bring Windows 365 and local…

Microsoft’s new ‘Volumetric Apps’ for Quest headsets extend Windows apps into the 3D space

The spam reached Bluesky by first crossing over two other decentralized networks: Mastodon and Nostr.

The ‘vote Trump’ spam that hit Bluesky in May came from decentralized rival Nostr

Welcome to TechCrunch Fintech! This week, we’re looking at the continued fallout from Synapse’s bankruptcy, how Layer wants to disrupt SMB accounting, and much more! To get a roundup of…

There’s a real appetite for a fintech alternative to QuickBooks

The company is hoping to produce electricity at $13 per megawatt hour, which would be more than 50% cheaper than traditional onshore wind.

Bill Gates-backed wind startup AirLoom is raising $12M, filings reveal

Generative AI makes stuff up. It can be biased. Sometimes it spits out toxic text. So can it be “safe”? Rick Caccia, the CEO of WitnessAI, believes it can. “Securing…

WitnessAI is building guardrails for generative AI models

It’s not often that you hear about a seed round above $10 million. H, a startup based in Paris and previously known as Holistic AI, has announced a $220 million…

French AI startup H raises $220M seed round

Hey there, Series A to B startups with $35 million or less in funding — we’ve got an exciting opportunity that’s tailor-made for your growth journey! If you’re looking to…

Boost your startup’s growth with a ScaleUp package at TC Disrupt 2024

TikTok is pulling out all the stops to prevent its impending ban in the United States. Aside from initiating legal action against the U.S. government, that means shaping up its…

As a US ban looms, TikTok announces a $1M program for socially driven creators

Microsoft wants to put its Copilot everywhere. It’s only a matter of time before Microsoft renames its annual Build developer conference to Microsoft Copilot. Hopefully, some of those upcoming events…

Microsoft’s Power Automate no-code platform adds AI flows

Build is Microsoft’s largest developer conference and of course, it’s all about AI this year. So it’s no surprise that GitHub’s Copilot, GitHub’s “AI pair programming tool,” is taking center…

GitHub Copilot gets extensions

Microsoft wants to make its brand of generative AI more useful for teams — specifically teams across corporations and large enterprise organizations. This morning at its annual Build dev conference,…

Microsoft intros a Copilot for teams

Microsoft’s big focus at this year’s Build conference is generative AI. And to that end, the tech giant announced a series of updates to its platforms for building generative AI-powered…

Microsoft upgrades its AI app-building platforms

The U.K.’s data protection watchdog has closed an almost year-long investigation of Snap’s AI chatbot, My AI — saying it’s satisfied the social media firm has addressed concerns about risks…

UK data protection watchdog ends privacy probe of Snap’s GenAI chatbot, but warns industry

U.S. cell carrier Patriot Mobile experienced a data breach that included subscribers’ personal information, including full names, email addresses, home ZIP codes and account PINs, TechCrunch has learned. Patriot Mobile,…

Conservative cell carrier Patriot Mobile hit by data breach

It’s been three years since Spotify acquired live audio startup Betty Labs, and yet the music streaming service isn’t leveraging the technology to its fullest potential — at least not…

Spotify’s ‘Listening Party’ feature falls short of expectations

Alchemist Accelerator has a new pile of AI-forward companies demoing their wares today, if you care to watch, and the program itself is making some international moves into Tokyo and…

Alchemist’s latest batch puts AI to work as accelerator expands to Tokyo, Doha

“Late Pledge” allows campaign creators to continue collecting money even after the campaign has closed.

Kickstarter now lets you pledge after a campaign closes

Stack AI’s co-founders, Antoni Rosinol and Bernardo Aceituno, were PhD students at MIT wrapping up their degrees in 2022 just as large language models were becoming more mainstream. ChatGPT would…

Stack AI wants to make it easier to build AI-fueled workflows

Pinecone, the vector database startup founded by Edo Liberty, the former head of Amazon’s AI Labs, has long been at the forefront of helping businesses augment large language models (LLMs)…

Pinecone launches its serverless vector database out of preview

Young geothermal energy wells can be like budding prodigies, each brimming with potential to outshine their peers. But like people, most decline with age. In California, for example, the amount…

Special mud helps XGS Energy get more power out of geothermal wells

Featured Article

Sonos finally made some headphones

The market play is clear from the outset: The $449 headphones are firmly targeted at an audience that would otherwise be purchasing the Bose QC Ultra or Apple AirPods Max.

16 hours ago
Sonos finally made some headphones