Connected-car software updates draw cyber warnings from analysts
Analysts say over-the-air vehicle updates cut maintenance costs but may open cars, buses and transport networks to cyberattacks.
By Theo Nakamura · Staff Writer
· 3 min read
Automakers’ growing reliance on wireless software updates is drawing warnings from cybersecurity analysts, who say the same feature that can fix a car remotely can also create a new attack path. For everyday investors watching the auto sector, the issue adds a security and regulatory risk to the connected-car push.
Over-the-air, or OTA, technology sends software, firmware, fixes and data to internet-connected devices without a shop visit. Firmware is the low-level software built into hardware, and in vehicles it can help manage systems through a mobile network rather than through a recall or scheduled service visit.
Tesla began sending OTA updates to its Model S vehicles in 2012, a move that helped make the practice more common across the industry, according to Jason Van der Schyff, a fellow in cyber, technology and security at the Australian Strategic Policy Institute.
Siraj Ahmed Shaikh, a professor in systems security at Swansea University in the U.K., told CNBC that automakers have embraced OTA systems because they can be faster and cheaper than older maintenance methods. That convenience is the core trade-off: internet-connected vehicles can receive improvements more easily, while also creating more points that need to be secured.
Security concerns move beyond data privacy
Gabriel Lim, a senior analyst at the S. Rajaratnam School of International Studies in Singapore, told CNBC that OTA use in transport creates “a unique national security concern.” Lim said worries extend past personal data, because a hostile foreign actor could in theory interfere with the controls of a vehicle while it is operating, a risk he said Norway, Denmark and Britain have raised.
The American Enterprise Institute made a similar point in a May report focused on connected and autonomous vehicles. The think tank said the U.S. should consider more security reviews, limits on some foreign-made hardware and software in vehicles, and broader disclosures about data collection to reduce espionage risks tied to foreign governments.
Real-world testing has added weight to those concerns. Late last year, Norwegian bus operator Ruter tested two buses and identified potential OTA-related risks in one of them. Ruter said the bus had access to its battery and power-supply control system through a mobile network using a Romanian SIM card.
“In theory, therefore, this bus can be stopped or rendered inoperable by the manufacturer,” Ruter said in its findings.
CNBC reported that Ruter’s work was followed by investigations in the U.K. and Denmark. The U.K. Department for Transport said it was examining the issue and working closely with the National Cyber Security Centre.
The issue is wider than one bus maker
The Ruter tests involved buses made by Chinese manufacturer Yutong, but Shaikh told CNBC that the risk should not be viewed as tied only to one company or one country. He said OTA technology is spreading into other transport and industrial fields, including maritime, rail, drones, industrial machinery and robotics.
Lim said governments and companies should be held accountable for how OTA systems are used, especially when the software runs quietly inside technologies people use every day. For automakers, suppliers and investors, the debate shows how connected vehicles are becoming as much a cybersecurity question as a transportation story.
This story draws on original reporting from CNBC.