Archive for Cars

How Safe Is Your Connected Car?

How Safe Is Your Connected Car?There will be 250 million wirelessly connected cars on the road by 2020 according to Gartner (IT). The technical prognosticators believe that 60% – 75% of them will be capable of consuming, creating, and sharing Web-based data. In light of predictions like these and highly publicized car network attack demonstrations car need more security. Intel (INTC) has established the Automotive Security Review Board (ASRB) to help mitigate cyber-security risks associated with connected automobiles.

Intel logoAn Intel presser says ASRB researchers will do ongoing security tests and audits. They will codify best practices and design recommendations for advanced cyber-security solutions and products. Intel will publish automotive cyber-security best practices white papers, which the company will update based on ASRB findings. Chris Young, senior vice president, and general manager of Intel Security said in the presser.

We can, and must, raise the bar against cyberattacks in automobiles … Few things are more personal than our safety while on the road, making the ASRB the right idea at the right time.

Secure car networks

It is the right time to secure the networks in cars. A study released by Atlanta-based PT&C|LWG Forensic Consulting Services looked at what made cars vulnerable to attacks.
Robert Gragg, a forensic analyst with PT&C|LWG told CSO cars with the highest risk of cyber threat tended to have the most features networked together, especially where radio or Wi-Fi networks are connected to physical components of vehicles.

radio or Wi-Fi networks are connected to physical components of vehiclesToday’s modern automobile uses between 20 and 70 computers, each with its own specialized use. The article explains that engine control units oversee a wide array of electronic sensors and actuators that regulate the engine and maintain optimal performance. Vehicle manufacturers use the generic term “electronic control units” (ECUs) to describe the myriad of computers that manage various vehicle functions.

For example, the author says ECUs control vehicle safety functions, such as antilock brakes and proximity alerts. The ECU which governs climate control systems receives temperature data from sensors inside the cabin and uses that to adjust airflow, heating, and cooling.

modern automobile uses between 20 and 70 computers

What is a controller area network

Typically, all of a vehicle’s computer systems can be accessed over a vehicle’s controller area network (CAN) via the radio head unit, a computerized system that runs a car’s or truck’s communications and entertainment system.

firmware can be used to compromise the vehicleMany of today’s modern vehicles can be accessed via cellular, Bluetooth, or even WiFi connectivity. While no easy task, the CSO article says, once a hacker gains access to the vehicle’s head unit, its firmware can be used to compromise the vehicle’s CAN, which speaks to all the ECUs. Then it’s just a matter of discovering which CAN messages can control various vehicle functions.

Car attacks

These attacks can happen at a distance. PT&C|LWG study estimated minimum distances from which a vehicle could be hacked according to the wireless communication protocol it is using. For example, a passive anti-theft system could be access from 10 meters, a radio data system (or radio head unit) could be hacked from 100 meters, a Bluetooth system could be accessed from 10 meters, a smart key from five to 20 meters, and a vehicle equipped with Wi-Fi… well, it could be hacked from anywhere there’s Internet access (rb- I wrote about this vulnerability in 2011).

That may be a problem. Increasingly, carmakers are coming out with vehicles that include Wi-Fi routers for Internet connectivity. PT&C|LWG’s Gragg said.

In more advanced vehicles — the ones that have infotainment systems — wireless security and wireless access points are all connected into the navigation system. So those are more susceptible to hacking because there are just more wireless access points … Anything open to wireless capabilities is susceptible to the hacking.

rb-

In May, both General Motors (of ignition switch cover-up infamy) and the Auto Alliance, the car maker’s lobbyist, testified against a proposed exemption in copyright law that would allow third-party researchers to get access to vehicle software. A decision in that matter could come any day from the U.S. Copyright Office.

Ralph NaderThe Auto Alliance has also threatened to run to Congress should the Copyright Office rule in favor of the researchers to cover up threats to the consumer, like Volkswagen and GM. The lobbying group calls legitimate researchers attackers in a letter to a Congressional subcommittee investigating the auto industry’s ability to thwart cyber attackers; “Automakers are facing pressure from the organized efforts of technology pirates and anti-copyright groups to allow the circumvention of protected onboard networks, and to give hackers with the right to attack vehicles carte blanche under the auspices of research”.

This would set a dangerous precedent for devices connected to the Internet of Things (IoT) to be unregulated. If the automakers are successful in their DMCA claims, it would be deadly for everyone on the road too. 

Who remembers “Unsafe At Any Speed“?

 PT&C|LWG infographicRelated articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Run Your DC with a Chevy

Run Your DC with a ChevyGeneral Motors (GM) is using Chevy Volt batteries to power a data center. MLive reports that expired lithium-ion batteries retrieved from Chevrolet Volt’s help power the General Motors Enterprise Data Center at the Milford Proving Grounds in Milford, MI.

GM logoGM recently announced that five batteries from first-generation Volts are working in parallel with a 74-kilowatt solar array and two 2-kilowatt wind turbines to green up the data center. The batteries have the capacity to provide backup power for four hours in the event of an outage, GM said. According to the article, the set-up has given the Enterprise Data Center a net-zero energy use on an annual basis, and extra power will be sent back to the grid used by the Milford Proving Ground.

First-gen Chevy Volts still have a lot of juice

As it readies to sell its all-new, second-generation Volt, GM said first-gen cars still have a lot of leftover juice in their battery packs for stationary use. Pablo Valencia, GM’s senior manager of battery life cycle management, said in a presser that the batteries still have value after they come out of the car.

Chevy Volt batteries to power a data center.Even after the battery has reached the end of its useful life in a Chevrolet Volt, up to 80 percent of its storage capacity remains … This secondary use application extends its life, while delivering waste reduction and economic benefits on an industrial scale.

The first-generation plug-in hybrid Volt went on sale in 2010 for the 2011 model year. It uses battery power to get an electric range of about 35-38 miles, before switching to gasoline.

Battery powered carThe 2016 Volt, unveiled last January in Detroit, will have about a 31% greater electric range than its predecessor. The second-gen Volt has about a 50-mile, all-electric range, and a total driving range of about 400 miles when combined with a gasoline engine.

Rb-
According to the Detroit News, GM is working with unidentified partners to validate and test systems for other commercial and non-commercial uses. 

Elon Musk‘s Tesla (TSLA) is also leveraging its car-based battery systems to develop a line of storage batteries designed for homes and SMB’s called Powerwall. Powerwall is designed to store electricity for home use, to be used during peak consumption times when utilities charge the most. The device comes in several colors including white, charcoal, red, and blue. There are two options — a 7-kilowatt-hour package using nickel-manganese-cobalt batteries and a 10 kilowatt-hour unit with a nickel-cobalt-aluminum battery.

 

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Privacy for Drivers

Privacy for DriversFord Motor Company (F) Global Marketing Director Jim Farley touched off a privacy storm when he told an audience at the Consumer Electronics Show that the automaker is tracking their travels thanks to their in-car navigation systems. He told the crowd in Las Vegas that the automaker tracks driver behavior, “We know everyone who breaks the law, we know when you’re doing it.

automaker are tracking travelsThe auto manufacturers have installed “black boxes” on most modern cars. The black boxes are capable of tracking, gathering, and storing vehicle information. In fact, the Fed has proposed that such tracking technology become standard equipment on all cars.

Privacy firestorm

Even though Ford quickly backed down from Mr. Farley’s claims, the comments created a privacy firestorm. As a result, TheDetroitBureau.com reports that privacy advocates accelerated increased pressure on manufacturers to reveal what info that collects on “black box’s” they’re doing with the personal data they do collect – and put limits on how it can be used.

black-boxes are capable of tracking, gathering and storing vehicle information.

In response, a group of 19 automakers has gotten together to lay down some ground rules, which they hope will assuage fears about the accessibility and use of the material. According to the article, the makers say the information won’t be given to government officials or law enforcement agencies without a court order, sold to insurance companies or other companies without their permission.

The automakers agreeing to the “rules,” which they submitted to the Federal Trade Commission, include Aston Martin, BMW, Chrysler (STLA),  Ferrari, Ford, General Motors (GM), Honda (HMC) Hyundai, Kia, Maserati, Mazda, Mercedes-Benz, Mitsubishi, Nissan, Porsche, Subaru, Toyota, Volkswagen, and Volvo.

Self-imposed data collection “rules”

Future carThe author speculates that the automakers are willing to abide by the self-imposed “rules” because they believe actual laws could become onerous. Sen. Edward Markey, D-MA is skeptical of the impact of the “rules.” He called them “an important first step,” but said it remains unclear “how auto companies will make their data collection practices transparent beyond including the information in vehicle manuals.”

Senator Markey noted that the automakers did not offer consumers an opt-out option for whether sensitive information is collected in the first place. He plans to legislate an answer. He said in a statement, “I will call for clear rules — not voluntary commitments — to ensure the privacy and safety of American drivers is protected,” Markey said in a statement.

The automakers also committed to “implement reasonable measures” to protect personal information from unauthorized access. Privacy experts are concerned that in recent years many vehicles have had a variety of GPS and mobile communications technology built into them.

Cloud securityThe TheDetroitBureau explains these devices record and sends all types of information which privacy advocates are afraid the data could be used by the government against the owners of vehicles. Some worry that many three-letter agencies and law enforcement will use data from the device to track citizens. Marc Rotenberg, executive director of the Electronic Privacy Information Center said that legislation is needed to ensure automakers don’t back off their self-imposed “rules” when they become inconvenient. He said,

You just don’t want your car spying on you. That’s the practical consequence of a lot of the new technologies that are being built into cars.

Pop-up ads on in-car touch screens

The black boxes now installed in new vehicles could also be a safety issue for drivers. The article speculates that the rising level of interactivity of cars could open the door for pop-up ads in cars. These automakers’ “rules” do not end the possibility that Pop-up ads could appear on the touch screens of cars, trucks, and SUVs as folks are motoring down the road.

One loophole in the guidelines identified in the blog, if customers agree at the time they buy the car, they could receive messages from advertisers who want to target motorists based on their location and other personal data according to the author. Some safety advocates are concerned about pop-up ads possibly popping up on in-car touch screens while drivers are behind the wheel. Henry Jasny of Advocates for Highway and Auto Safety warned the Associated Press.

There is going to be a huge amount of metadata that companies would like to mine to send advertisements to you in your vehicle … We don’t want pop-up ads to become a distraction.

rb-

Who is listeningThe road to hell is paved with good intentions and full of pot-holes. I covered Cisco’s try at monetizing driver data here. Industry officials say they want to assure their customers that the information that their cars stream from the vehicle’s computers to automakers (or Feds) via OnStar. Sync, Automatic, In-Drive, or Car-Net won’t be handed over to authorities without a court order, sold to insurance companies, or used to bombard them with ads for pizza, gas stations, or other businesses they drive past, without their permission.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Ford Rolls Out A Hot Wheels Transit

Ford Rolls Out A Hot Wheels TransitTheDetroitBureau.com reports from SEMA 2013 in Las Vegas that Ford Motor Company (F) has rolled out some very hot wheels. Ford is the latest carmaker to honor Hot Wheels the popular Mattel (MAT) toy line with a running, life-size model. This one based on the latest Ford Transit Connect van.

Hotwheels logoThe Hot Wheels Ford Transit Connect van is dark blue with bright orange accents. It has a flaming “Hot Wheels” logo, fins, and fender details one might expect on a toy car.

Hot Wheels Ford Transit Connect van

The Hot Wheels design team jumped at the chance to hot rod a Transit Connect van. The idea was to create a race-inspired support vehicle for the average guy to spend a weekend at the track testing his Hot Wheels race car,” said Felix Holst, vice president of creative for the Mattel Wheels Division.

Ford’s 2014 Transit Connect Sizzles for SEMA Courtesy of Hot Wheels®

It’s no surprise Ford came up with the flashy version of its all-new 2014 Transit Connect. The Hot Wheels brand has been around since 1968. Kids – as well as many adult fans – have snapped up 4 billion of the line’s model cars since then.

Hotwheels Ford Transit Connect

The Hot Wheels Transit Connect is more than just a van with a flashy paint job and decals.  It is powered by Ford’s 2.5-liter 2.5-liter Ti-VCT four-pot. The sliding side doors are replaced by gull-wing doors. The rear wheels are widened with the body panels flared out to accommodate the larger wheels.  There are three shark fins on the back of the roof and scoops on the hood. To complete the package, there are three widescreen TV sets inside the author reports.

Ford’s 2014 Transit Connect Sizzles for SEMA Courtesy of Hot Wheels®
It has everything you need to spend a weekend at the track,” suggested Mr. Holst. The blog says he didn’t say whether that meant the race track or the little orange plastic tracks that Hot Wheels cars run on.

Ford’s 2014 Transit Connect Sizzles for SEMA Courtesy of Hot Wheels®

There’s no word on whether Ford plans to offer any of the modifications made for the Hot Wheels Transit Connect concept, though the use of gullwing doors in a production vehicle seems unlikely speculates TheDetroitBureau.com.

That said, Chevrolet debuted its homage to Hot Wheels at the 2012 SEMA Show. last year. Chevy displayed the Hot Wheels Camaro at the 2013 Woodward Dream Cruise and sold it as a limited-edition Hot Wheels Camaro.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Is Connected Car Data Worth $1,400 Annually?

Is Connected Car Data Worth $1,400 Annually?Michael Strong at TheDetroitBureau.com reports that Continental AG and Cisco (CSCO) recently demoed a highly connected car using the internet to improve vehicle safety and infotainment options at the recent Center for Automotive Research Management Briefing Seminars in Traverse City, MI.

Cisco logoThe firms believe they’ve produced a connected car that provides a balance between giving consumers a safe, connected driving experience while providing companies with a chance to offer services that enhance the driving experience: for a price.

According to the article, the companies involved in bringing the Internet to cars collect an enormous amount of information about drivers. This presents a variety of challenges when it comes to privacy, who owns the information, how can or should it be used and what’s it worth?

data generated by a connected car is worth about $1,400 a year.While privacy and data ownership issues are still up in the air thanks to the U.S. government. Andreas Mai, director of product management at Cisco, believes data generated by a connected car is worth about $1,400 a year.  He breaks it down this way:

  • Drivers can save $550 through better fuel economy, less time stuck in traffic, lower insurance rates, etc.
  • Society can save $420 by employing car platoons to speed up traffic and increase a road’s capacity.
  • Service providers can earn $150 by providing traffic guidance, navigation, parking, emergency services, etc.
  • Automakers can save $300 in lower warranty costs, profitable apps, etc.

The key, according to the article, is to maximize the information that can be collected (and re-sold) is convincing drivers that they get a tangible benefit from releasing the data, such as shorter commutes or lower insurance rates (thanks Flo). According to a survey by Cisco, 74% of drivers were willing to share vehicle information. However, who or what owns that information still needs to be sorted out, he said. They must balance all of those things against the driver’s wants and needs: connectivity, infotainment, and cutting-edge safety features.

Cars switch between 3G, 4G, WiFi, and DSRC on the goThe firms believe they’ve produced a connected car that provides a balance between giving consumers a safe, connected driving experience while providing companies with a chance to offer services that enhance the driving experience: for a price.

Continental and Cisco teamed up to keep the bits flying. As a vehicle moves it needs to prioritize the critical needs of drivers and passengers for network connectivity, according to the article. Digital Trends explains that Continental will supply the hardware and Cisco will provide the software. The car can switch between 3G, 4G, WiFi, and Dedicated Short Range Communication (DSRC) on the go, depending on service quality and cost to the customer. DSRC system is part of the emerging vehicle-to-vehicle (V2V) technology system that allows cars to communicate with each other directly – and autonomously.

A Cisco software router loaded in Continental hardware performs the network switching. The router sends signals first to a Cisco-managed “Connected Car Cloud,” which then relays information to whatever network appears optimal at the moment.

 Connected Car Concept

The Cisco on-board software system can seamlessly switch between available 3G, 4G, and other wireless networks based on cost and quality of service preferences. “Connected vehicles are opening up a vast field of opportunities for services to make driving safer, more efficient, and more comfortable,” said Ralf Lenninger, head of innovation and strategy, Continental’s Interior Division. “This is why we are looking at ways to connect the moving vehicle in a highly secure, fast, and reliable way.

the same amount of network security that is available at homeThe Cisco and Continental proof-of-concept connected car show how auto manufactures can provide the same amount of network security that is available at home (oh NO!) or in the office. Cisco provides one highly secure software gateway that delivers Cisco’s core networking capabilities and optimizes multiple communication links and mobility services to and from the vehicle. Security against cyber attacks will become more important as more vehicles include connected functions.

rb-

I recently covered Ford’s efforts to understand connected cars by studying the commlinks of space-based robots here.

The savings claims seem suspicious to me. The “lower insurance costs” are just cash savings. Oh, yeah Walmart is still in business. What is going to be the costs to the drivers after the insurance companies get their Hadoop big data analytics on the data from the magic boxes they are installing? Will they use the data you provided them to change the rules on your policy to raise your rates? It only takes a small leap to think about what the NSA could do with the data.

Just in case someone at Cisco or Ford or anybody else is reading this, here are some suggestions from Veracode to secure connected cars.. 

Versacode Connected Car infographic

Infographic by Veracode Application Security

 

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.