{"id":78430,"date":"2015-10-27T18:08:38","date_gmt":"2015-10-27T22:08:38","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-08-01T12:06:23","modified_gmt":"2021-08-01T16:06:23","slug":"online-security-in-era-of-connected-cars","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/online-security-in-era-of-connected-cars\/","title":{"rendered":"Online Security in Era of Connected Cars"},"content":{"rendered":"<p><a href=\"https:\/\/web.archive.org\/web\/20160423224015\/https:\/\/gigaom.com\/2013\/02\/20\/your-next-kindle-could-be-embedded-in-your-car\/connectedcar-logo\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-105492\" title=\"Online Security in Era of Connected Cars\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/connectedcar-logo-2.png?resize=143%2C95&#038;ssl=1\" alt=\"Online Security in Era of Connected Cars\" width=\"143\" height=\"95\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/connectedcar-logo-2.png?resize=150%2C100&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/connectedcar-logo-2.png?resize=75%2C50&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/connectedcar-logo-2.png?w=600&amp;ssl=1 600w\" sizes=\"auto, (max-width: 143px) 100vw, 143px\" \/><\/a><a href=\"https:\/\/web.archive.org\/web\/20161224161602\/http:\/\/media.gm.com:80\/media\/intl\/en\/opel\/news.detail.html\/content\/Pages\/news\/opelcompany\/eu\/opel\/executives\/karl-thomas-neumann.html\" target=\"_blank\" rel=\"noopener noreferrer\">Karl-Thomas Neumann<\/a>, CEO of <a title=\"General Motors\" href=\"http:\/\/www.gm.com\/\" target=\"_blank\" rel=\"homepage noopener noreferrer\"><strong>General Motors<\/strong>&#8216;<\/a> (<a title=\"NYSE : GM\" href=\"https:\/\/www.tradingview.com\/symbols\/NYSE-GM\/\" target=\"_blank\" rel=\"nofollow noopener\">GM<\/a>) European <a href=\"http:\/\/www.opel.ch\/\" target=\"_blank\" rel=\"noopener noreferrer\">Opel brand<\/a> announced that GM would launch <a href=\"https:\/\/www.onstar.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>OnStar<\/strong><\/a> <a href=\"https:\/\/www.gartner.com\/it-glossary\/telematics\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>telematics<\/strong> service<\/a>\u00a0in vehicles sold in Europe in late 2015. The Opel CEO declared the new technology, \u201ctransforms the car into a true part of the<strong> <a href=\"http:\/\/whatis.techtarget.com\/definition\/Internet-of-Things\" target=\"_blank\" rel=\"noopener noreferrer\">Internet of things<\/a><\/strong>.\u201d <a href=\"http:\/\/www.thedetroitbureau.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>The Detroit Bureau<\/em><\/a> <a href=\"http:\/\/www.thedetroitbureau.com\/2015\/03\/automakers-struggle-to-address-privacy-issues-in-era-of-high-tech-cars\/\" target=\"_blank\" rel=\"noopener noreferrer\">says<\/a> it raises some of the same concerns consumers face on the Internet, including how to protect their privacy in highly connected cars.<\/p>\n<p><a href=\"https:\/\/connectedcarsworld.wordpress.com\/tag\/jupiter-research-connected-car-study\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105494\" title=\"App controlled car\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/app-connected-car.jpg?resize=122%2C100&#038;ssl=1\" alt=\"App controlled car\" width=\"122\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/app-connected-car.jpg?resize=150%2C123&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/app-connected-car.jpg?resize=75%2C61&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/app-connected-car.jpg?w=302&amp;ssl=1 302w\" sizes=\"auto, (max-width: 122px) 100vw, 122px\" \/><\/a>Even though a growing number of consumers have embraced the idea of having mobile access to smartphone apps, <strong>built-in Wi-Fi,<\/strong> and the safety and security promised by systems like OnStar issues loom that consumers, manufacturers, and regulators need to address. At the 2014 <a href=\"https:\/\/www.facebook.com\/CES\" target=\"_blank\" rel=\"noopener noreferrer\">Consumer Electronics Show<\/a>, <a href=\"https:\/\/web.archive.org\/web\/20211117063343\/https:\/\/media.ford.com\/content\/fordmedia\/fna\/us\/en\/people\/james-d--farley--jr-.html\" target=\"_blank\" rel=\"noopener noreferrer\">Jim Farley<\/a>,\u00a0 then the top marketing executive at <a title=\"Ford\" href=\"https:\/\/www.ford.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ford Motor Company<\/a> (<a title=\"NYSE : F\" href=\"https:\/\/www.google.com\/finance?q=NYSE:F\" target=\"_blank\" rel=\"noopener noreferrer\">F<\/a>),\u00a0 told an audience that the automaker \u201c<strong>know(s) everyone who breaks the law, we know when you\u2019re doing it<\/strong>,\u201d thanks to the data collected by its OnBoard Sync technology system.<\/p>\n<p>Despite a quick <a href=\"http:\/\/www.thedetroitbureau.com\/2014\/01\/fords-farley-apologizes-over-spying-flap\/\" target=\"_blank\" rel=\"noopener noreferrer\">backtrack<\/a> by Mr. Farley, the article says he was being truthful. The fact is, the onboard black boxes in most <strong>cars are now equipped with two-way capabilities<\/strong>. Privacy has become \u201ca big issue,\u201d according to <a href=\"https:\/\/www.linkedin.com\/pub\/jonathan-allen\/2\/80b\/757\" target=\"_blank\" rel=\"noopener noreferrer\">Jon Allen<\/a>, a principal with consulting firm <a href=\"https:\/\/www.boozallen.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Booz Allen Hamilton<\/a> who focuses on security issues. Precisely what makes such technology so compelling is why it is also so worrisome. Mr. Allen told <em>The Detroit Bureau<\/em>,<\/p>\n<p style=\"padding-left: 30px; text-align: justify;\"><em>Connected products provide customization and convenience because of the data they track. Part of the great opportunity to improve the customer experience is producing a vehicle that \u2018learns\u2019 your habits and preferences. But that information must be protected.<\/em><\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20210517230623\/http:\/\/www.thehackersamachar.com\/2016\/06\/woman-charged-with-stealing-computer.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105497\" title=\"Data privacy\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-3.jpg?resize=122%2C100&#038;ssl=1\" alt=\"Data privacy\" width=\"122\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-3.jpg?resize=150%2C122&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-3.jpg?resize=75%2C61&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_theft2-3.jpg?w=550&amp;ssl=1 550w\" sizes=\"auto, (max-width: 122px) 100vw, 122px\" \/><\/a>The <a href=\"http:\/\/europa.eu\/index_en.htm\" target=\"_blank\" rel=\"noopener noreferrer\">EU<\/a> takes privacy seriously and these types of <strong>tracking technology have drawn the attention of regulators in Europe<\/strong> and to a lesser extent, in the U.S. The article describes a measure of just how strongly Europeans feel about the issue that came during Opel chief Neumann\u2019s news conference. <strong>Unlike the U.S.<\/strong> version of OnStar, the European system will include a \u201cPrivacy\u201d button to let a user \u201cchoose whether they want to provide location information or not.\u201d<\/p>\n<p>That choice would only be over-ridden after a crash severe enough to trigger OnStar\u2019s emergency call system, CEO Neumann explained. It\u2019s designed to call rescue crews in the event of an accident severe enough passengers might be disabled.<\/p>\n<p><a href=\"http:\/\/techliberation.com\/2015\/02\/10\/dont-hit-the-techno-panic-button-on-connected-car-hacking-iot-security\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105499 size-thumbnail\" title=\"Don't panic\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/do-not-panic.jpg?resize=75%2C56&#038;ssl=1\" alt=\"Don't panic\" width=\"75\" height=\"56\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/do-not-panic.jpg?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/do-not-panic.jpg?resize=150%2C113&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/do-not-panic.jpg?w=200&amp;ssl=1 200w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>There have been experiments with marketing that could target motorists much as Google today can toss ads at a web viewer based on information revealed by hidden \u201ccookies.\u201d Imagine, they suggest, being able to send a McDonald\u2019s ad and virtual coupon to a car driving near one of its restaurants around lunchtime.<\/p>\n<p>While some drivers might embrace that possibility, others are appalled. <em>The Detroit Bureau<\/em> reports the potential to <strong>reveal more detailed personal information,<\/strong> as well as allowing a vehicle to be tracked, is raising flags on both sides of the Atlantic.<\/p>\n<p><a href=\"http:\/\/teachingprivacy.org\/youre-leaving-footprints\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-105501 size-medium\" title=\"Digtal tracking\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/footprints-e1569113683211-150x91.png?resize=150%2C91&#038;ssl=1\" alt=\"Digtal tracking\" width=\"150\" height=\"91\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/footprints-e1569113683211.png?resize=150%2C91&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/footprints-e1569113683211.png?resize=75%2C45&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/footprints-e1569113683211.png?w=230&amp;ssl=1 230w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>In the U.S., an auto industry alliance recently agreed on an approach called \u201c<a href=\"http:\/\/www.autoalliance.org\/?objectid=865F3AC0-68FD-11E4-866D000C296BA163\" target=\"_blank\" rel=\"noopener noreferrer\">Privacy Principles for Vehicle Technologies and Services<\/a>.\u201d (<em><strong>rb-<\/strong> Which I covered <a href=\"https:\/\/wp.me\/p2wgaW-jeT\" target=\"_blank\" rel=\"noopener\">here<\/a><\/em>) Meanwhile, both the <a href=\"https:\/\/www.ftc.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">U.S. Federal Trade Commission<\/a> and the <a href=\"http:\/\/www.nhtsa.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">National Highway Traffic Safety Administration<\/a> are exploring the issues \u2013 though in some cases, they are actually encouraging greater access, noted analyst Allen.<\/p>\n<p>The issue is further complicated by the threat of <strong>cyber-criminals exploiting vulnerabilities<\/strong> in-vehicle communications systems.<\/p>\n<p><em><strong>rb-<\/strong> <\/em><\/p>\n<p><em>I first covered this threat in 2011 <a href=\"https:\/\/wp.me\/p2wgaW-CA\" target=\"_blank\" rel=\"noopener\">here<\/a> and <a href=\"https:\/\/wp.me\/p2wgaW-S5\" target=\"_blank\" rel=\"noopener\">here<\/a><\/em>. And the theoretical became real in 2015 when researchers <a href=\"https:\/\/web.archive.org\/web\/20210820084249\/https:\/\/www.wired.com\/2015\/07\/hackers-remotely-kill-jeep-highway\/\" target=\"_blank\" rel=\"noopener noreferrer\">demonstrated<\/a> they could use online systems to take over a Jeep Grand Cherokee.<\/p>\n<p><em> The threat to personal freedom and privacy in your car has accelerated as <a title=\"Apple Computers\" href=\"http:\/\/www.apple.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Apple<\/a> (<a title=\"NASDAQ : AAPL\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-AAPL\/\" target=\"_blank\" rel=\"noopener noreferrer\">AAPL<\/a>) and <a title=\"Google\" href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Google<\/a> (<a title=\"NASDAQ : GOOG\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-GOOG\/\" target=\"_blank\" rel=\"noopener noreferrer\">GOOG<\/a>) join <a title=\"Microsoft\" href=\"http:\/\/www.microsoft.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft<\/a> (<a title=\"NASDAQ | MSFT\" href=\"https:\/\/www.tradingview.com\/symbols\/NASDAQ-MSFT\/\" target=\"_blank\" rel=\"nofollow noopener\">MSFT<\/a>) in the battle to rule the car. Apple\u2019s automotive ambition does not stop at <a href=\"http:\/\/www.apple.com\/ios\/carplay\/\" target=\"_blank\" rel=\"noopener noreferrer\">CarPlay<\/a>, they are also focused on developing an <a href=\"http:\/\/money.cnn.com\/2015\/09\/30\/technology\/apple-car-clues\/\" target=\"_blank\" rel=\"noopener noreferrer\">iCar<\/a>. Google&#8217;s <a href=\"https:\/\/www.google.com\/selfdrivingcar\/\" target=\"_blank\" rel=\"noopener noreferrer\">Autonomous Cars<\/a> ambitions are well known, but their efforts to take over the car cockpit are also taking off with <a href=\"http:\/\/www.cnet.com\/news\/google-unveils-android-auto-at-io-2014\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"color: #777777;\">Android<\/span>\u00a0Auto<\/a>.<\/em><\/p>\n<p><em>The government is contributing to the connected car\u00a0conundrum. The Feds are\u00a0abetting the Autos by trying to prevent security researchers from doing testing and reverse engineering that could improve security and safety for all of us according to <a href=\"https:\/\/nakedsecurity.sophos.com\/2015\/10\/23\/how-a-law-making-car-hacking-illegal-could-make-us-all-less-safe\/\" target=\"_blank\" rel=\"noopener noreferrer\">Naked Security<\/a>.<\/em><\/p>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Connected cars are security and privacy risks with more connections like Wi-Fi, 4G, 5G, Bluetooth Apple, Google, GM and Ford<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24],"tags":[3277,310,2571,420,202,101,1189,2546,1035,2021,2310,241,536,92,944,82,421,2570,2569,185],"class_list":["post-78430","post","type-post","status-publish","format-standard","hentry","category-cars","tag-3277","tag-4g","tag-5g","tag-aapl","tag-android","tag-apple","tag-bluetooth","tag-dmca","tag-f","tag-ford","tag-ftc","tag-gm","tag-goog","tag-google","tag-iot","tag-microsoft","tag-msft","tag-ntsc","tag-opel","tag-privacy"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78430","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=78430"}],"version-history":[{"count":9,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78430\/revisions"}],"predecessor-version":[{"id":130018,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/78430\/revisions\/130018"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=78430"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=78430"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=78430"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}