Time for car makers to face new challenges, says Ptolemus Consulting following Jeep ‘hackjack’

Alexandra Willard of PTOLEMUS Consulting Group

You may have seen the article and video in Wired about hackers gaining remote access to an SUV’s Controller Area Network (CAN)  through the Bluetooth interface of the Uconnect entertainment system. Here Alexandra Willard, director of Global Technology Practice at PTOLEMUS Consulting Group responds:

“I think we can safely say that this is a problem that the automakers have and THEY should be the ones to develop the solution. Knee-jerk reactions by governments, no matter how well intentioned, often result in very poor solutions being devised.

We in the connected car software world have been aware of the possibility of vehicle cyber attacks for many years but it has not been possible to get the automakers to collaborate in making their vehicles more cyber-secure. Car manufacturers operate in silos.

Culture of metal and plastic

It’s time for the automakers to put aside their culture of metal and plastic, and to realise that their biggest challenges now come in bits and bootloaders.

They need to agree a set of short terms actions which will make their vehicles safe even if this means a limitation in functionality – and then develop a joint road map to ensure that the digital systems on the car are as safe and secure as the mechanical systems. This test and validation approach is what they know and what they do well – time to ‘go-do it’.

Let’s not be naive

We should not be naive about this Jeep incident though. A Ford Pinto-type episode (where the fuel tank placement was proven deadly and Ford was aware of this flaw during the design stage of the Pinto but went ahead with the production regardless) would put the connected car industry back 10 years – and we will all be the losers.

In terms of short terms actions, without implementing a stop to the over-the-air update boot loader it’s going to be incredibly tricky. A medium-term solution would be to have a grid server on the car which would handle external requests (as is done with web services for all sorts of secure system on the internet already).

We’re going to need a working group of cyber security, automotive engineers and software engineers to sort this out and agree a future standard.

Finally, we should remember to keep a sense of realism. The easier a digital system is to upgrade, maintain and to connect with, the easier it is to hack. That’s a fact of digital life.

Note: Chrysler has issued a recall for 1.4 million vehicles as a result of Miller and Valasek’s research. The company has also blocked their wireless attack on Sprint’s network to protect vehicles with the vulnerable software.

This blog was first posted by Alexandra Willard.

It is reproduced here by kind permission.

You can comment on this article below
or via Twitter:     @m2mnow



How will OEMs manufacture the smart factories of the future?

Posted on: September 23, 2022

“By 2025, there will be approximately 27 billion connected IoT devices. Someone is going to have to manufacture these, and OEMs are gearing up to enable as many functions as possible to be integrated into the devices they build.”REGISTER NOW TO READIoT relies on manufacturing efficiency to get massive volumes of devices out into the

Read more

IoT meets the property sector to combat rising energy costs and climate change while increasing property value

Posted on: September 23, 2022

Ericsson released a Connected Buildings Energy Management report in partnership with Nordic property technology company Kiona and Arthur D. Little.

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way you work, play, and live. But is it just another buzzword, or is it the as-promised technological holy grail? The truth is that Internet of

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT Platform 2021? authors Robin Duke-Woolley, the CEO and Bill Ingle, a senior analyst, at Beecham Research. Figure 1 shows these parts and, although not all

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for smart home automation will reach $40 billion by 2020.

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into a more switched-on place to live.

Read more

What is IoT?

Posted on: July 7, 2019

What is IoT Data as a new oil IoT connectivity What is IoT video So what’s IoT? The phrase ‘Internet of Things’ (IoT) is officially everywhere. It constantly shows up in my Google news feed, the weekend tech supplements are waxing lyrical about it and the volume of marketing emails I receive advertising ‘smart, connected

Read more
IoT Newsletter

Join the IoT Now online community for FREE, to receive: Exclusive offers for entry to all the IoT events that matter, round the world

Free access to a huge selection of the latest IoT analyst reports and industry whitepapers

The latest IoT news, as it breaks, to your inbox