Does Putting Tech in Cars Make It Easier for Hackers to Start Your Car?

Does Putting Tech in Cars Make It Easier for Hackers to Start Your Car? Featured Image

There’s a trend that has taken shape through the 2010s. Everything is now connected. Your washing machine? It has an app! Your doorbell? There are several options available that let you see who’s in front of your door from your smartphone. This app frenzy gives us the possibility of making our lives immeasurably more convenient, but what role does security play in all of this?

And when we’re talking about something as valuable and crucial as a vehicle, the question is no longer casual. You can start, locate, and even summon your car using your phone, which raises a question very few people ask when blinded by the glare of instant satisfaction and convenience: just how safe is this?!

A Little Background

carapp-keys

Back in 2013 we discussed built-in mobile software installed in vehicles. At that point we could only conceive of dangers to the driver while texting and driving and how this evolution would affect the trend. Since then the possibilities have expanded, raising many more concerns.

We live in a world that allows someone the ability to perform many functions otherwise done with a physical key using a phone. The shift from ignition key to mobile device puts even more of a burden on our phones, making them responsible for yet another crucial function of our daily lives. We must begin to ask ourselves whether this reliance is healthy and whether it is safer than the previous way of doing things.

The reality is that hackers can and do present challenges to the implementation of remote vehicle access technology.

How Hackers Ruin the Party

carapp-garage

A recent piece published on Wired shows us that researchers at Kaspersky have discovered some ways that hackers can definitely compromise remote ignition applications installed on smartphones. They’ve concluded that this can be done in one of three ways:

  1. A hacker can simply grab the authentication data from the phone. In most cases the app doesn’t even bother to encrypt it.
  2. A hacker could install a fake version of the app that would grab the user’s login credentials when they try entering.
  3. A hacker could infect the phone with malware that hooks onto the real app and stores whatever input the user types in.

The first method is the easiest (and the one I am most concerned about) since it doesn’t require a hacker to manipulate his victim into downloading anything. Installing malware on a phone with its default settings is much more cumbersome. One of the first rules of hacking is to find the path of least resistance!

Prevention

I’m going to go out on a limb here and say that using a key in your car isn’t the most inconvenient thing in the world. Your best method of prevention is just to use your car the same way people have been using theirs since before we ever had computers in our homes. Other than that, your best bet is to exercise as much prudence as possible with what you download and ensure that your phone’s screen cannot be unlocked with a simple slide of the finger.

Nothing will keep you one-hundred percent safe from a hacker siphoning your data. For example, aside from the three methods stated above, a hacker can also compromise your data by sniffing your WiFi traffic. Unlocking your car through your phone might just prove more of a hurdle than it’s worth.

It’s time to tell us what you think. Are we going too far by connecting literally everything we own to our smartphones? Let us know your opinion in a comment!

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Miguel Leiva-Gomez Avatar

Read next

French scientist Michel Siffre spent two months alone in a cave with no clock, no calendar, and no sunlight — and when his team finally told him the experiment was over, he thought he still had nearly a month left underground
When Cingular chief Stan Sigman backed the original iPhone before its 2007 unveiling, he accepted terms American carriers usually refused: no logo on the device, no control over its software, no preloaded apps, and a share of monthly subscriber revenue flowing back to Apple, after signing on without seeing a prototype
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When Edme Mariotte stared at marks on a wall in the 1660s, one mark vanished inside a six-degree hole where the optic nerve leaves the eye and the brain has been filling in wallpaper, sky, and faces ever since
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.