May 8, 2019

Remote kill switches meant to secure cars could create new risks

Illustration: Rebecca Zisser/Axios

Recent reports have revealed that two remote GPS tracker and immobilizer products for vehicles, known as remote kill switches, are vulnerable to attack due to guessable default passwords.

The big picture: Remote kill switches were designed to prevent theft, but can be compromised and used to steal or hijack cars, target high-profile individuals in their private vehicles, or shut down roadways through mass immobilization. The more complex a connected car’s systems are, the more potential points of vulnerability it has, making the stakes especially high for AVs.

How it works: Remote immobilizers allow an owner to shut off a car's engine by using an app to access the car's CAN bus, the central communication network that controls everything from vehicles cameras to the accelerator.

  • Security researchers have examined only a few GPS trackers and security systems, but most on the market share the same design, and the same potential to give adversaries virtually unfettered access to the engine, brakes and steering.

Between the lines: Vulnerabilities can exacerbate the problems these systems were designed to solve, exposing vehicle owners, passengers and others on the road to new dangers.

  • While the increased capabilities of AVs promise enormous benefits, adversaries could also benefit if vehicles — and the technologies that remotely support them — are not secured.
  • Attackers could target not just a single car but potentially all vehicles in a defined area, according to research from Georgia Tech. Simultaneously activating kill switches on millions of cars could trigger chaos, shutting down traffic and choking off deliveries of food, gas and other essential resources.

What's needed: Among the most promising solutions are adversarial resilience modeling, which helps avoid foreseeable issues such as weak default passwords, and secure software updates that fix issues as companies detect them.

  • I Am The Cavalry, a global grassroots initiative of cybersecurity researchers, advocates for both approaches in a cyber safety framework that could inform future car designs.

What to watch: The U.S. government has taken only baby steps on AV cybersecurity, but could accelerate its leadership by helping to standardize privacy-preserving “black box” data recorders and updating laws whose requirements may inadvertently deter automakers from adopting more securable technologies.

Beau Woods is a cyber safety innovation fellow at the Atlantic Council's Scowcroft Center for Strategy and Security.

Go deeper

Coronavirus dashboard

Illustration: Sarah Grillo/Axios

  1. Global: Total confirmed cases as of 12 p.m. ET: 1,450,343 — Total deaths: 83,568 — Total recoveries: 308,617Map.
  2. U.S.: Total confirmed cases as of 12 p.m. ET: 399,979 — Total deaths: 12,912 — Total recoveries: 22,539Map.
  3. Business updates: Roughly one-third of U.S. apartment renters didn't make April payments.
  4. Federal government latest: The U.S. has begun to see "glimmers of hope" despite its highest recorded number of deaths in 24 hours, Anthony Fauci said.
  5. Public health latest: Surgeon General Jerome Adams highlighted the disproportionate impact the illness is having on African-American communities.
  6. World latest: Indians look to Taiwan amid China's coronavirus missteps
  7. 🚌 Public transit: Systems across the country are experiencing ridership collapse, squeezed funding streams and slow recovery from the pandemic.
  8. What should I do? Pets, moving and personal healthAnswers about the virus from Axios expertsWhat to know about social distancingQ&A: Minimizing your coronavirus risk.
  9. Other resources: CDC on how to avoid the virus, what to do if you get it.

Subscribe to Mike Allen's Axios AM to follow our coronavirus coverage each morning from your inbox.

Bernie Sanders suspends presidential campaign

Photo: ANDEL NGAN/AFP via Getty Images

Sen. Bernie Sanders announced Wednesday that he is suspending his presidential campaign.

The big picture: It's an end to the campaign of the leading progressive in the race — and the candidate who seemed to be the clear front-runner for the Democratic nomination just a few months ago. It also makes Biden the presumptive Democratic nominee four months before the party's convention in Milwaukee.

Indians look to Taiwan amid China's coronavirus missteps

Illustration: Sarah Grillo/Axios

Many Indians are angry at China and the World Health Organization for their perceived mishandling of the coronavirus. The efficiency and transparency of Taiwan's response to the epidemic, in contrast, has made it a topic of renewed sympathy and interest in India.

Why it matters: The coronavirus crisis is showcasing Taiwan's democratic system of governance on an international stage, the biggest soft power win for the country in years.

Go deeperArrow1 hour ago - World