Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations

3/7/2016
04:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Automakers In The Hotseat For Vehicle Cybersecurity

Car cybersecurity one to three years behind threats, as drivers look to automakers to secure vehicles from hacking.

As new-model vehicles increasingly come equipped with third-party applications and Internet connectivity, the majority of consumers say the car manufacturers are liable for the safety and security of their cars.

A pair of separate studies released last week at the RSA Conference in San Francisco shed light on the escalating pressures on automakers to address cybesecurity of their vehicles – even though many of the new software and connectivity features come from their third-party suppliers and cellular providers.

Nearly 90% of drivers in an IDC and Veracode study said car manufacturers should be responsible for locking down the cybersecurity and related safety issues of the vehicles, even if the car’s apps were created by a separate software company.

Kelley Blue Book found in its survey that more than 55% of drivers consider carmakers responsible for providing security software to protect cars from being hacked, and 44% say carmakers hold the most responsibility for securing a car, while two-thirds believe carmakers are partially responsible for car hacks. Half of consumers say carmakers should provide insurance for car-hacking losses.

“Whenever you have a supply chain and the more complicated it is, and the more individual pieces it has, the more difficult it is to do security,” says Chris Wysopal, CTO and co-founder of Veracode. “There are so many different parties involved: infotainment, connectivity, and they’re going with someone else to do the OS, like Apple Car Play, for example. Ford and Toyota are going with their own OSes. Who’s building the apps? [Likely] a third party.”

Wyospal says the software security issues with a traditional complex enterprise supply chain is challenging enough. This model for car comes with physical safety ramifications as well.

“Why the stakes are higher, and we should not replicate all [that was] done with enterprise security,” he says.

IDC and Veracode also surveyed and interviewed Bosh, Delphi, Fiat-Chrysler, Scania, Seat, and ADAC, Germany’s automotive industry association. The European carmakers say it will take one to three years for them to catch up with cybersecurity threats, and they all say they are concerned about the security of their “critical systems” amid the emergence of third-party apps in the car. Their worry is that vehicle safety would be out of the manufacturer’s control with these apps in play.

Veracode’s Wysopal thinks one year may be too optimistic, given the complicated mesh of suppliers for connected cars. And even the conventional wisdom calling for the car’s features to run on a different and air gapped network from the infotainment system and apps isn’t realistic today. “The software is intermingled” via the same user interface as car features, he says. “An airgap isn’t going to work. So you have to think: is there a certain class of app that gets more rigorous testing, is certified” and can’t communicate directly with the car’s performance systems. This needs to be thought through.”

The IDC-Veracode report points to how Tesla allows Internet-based software updates to its performance elements of the vehicle rather than updating software when the driver takes his vehicle in for maintenance.

Traditional automakers also are starting to beef up their cybersecurity profiles. General Motors now has a bug bounty program underway as well as a product security officer position. “Those all seem like steps in the right direction, that they get it: they are becoming a software company,” Wysopal says. “Security and software are coming to their business and they have to organize that way.”

“For at least three years they are going to have to deal with in-bound vulns at a rate higher than today and have to respond to them,” says Wysopal.

“Manufacturers cannot afford to be complacent when it comes to application and overall system security within vehicles,” said Duncan Brown, research director at IDC’s European Security Practice. “Manufacturers should increase their focus on how to secure applications that enhance car functionality, such as the many driving aids currently being developed.”

Millennials, meanwhile, are less likely to consider car hacking a big problem: about half say it will be a frequent issue in the next three years, while 70% of all respondents say so.

 

Related Content:

Interop 2016 Las VegasFind out more about security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-22861
PUBLISHED: 2021-03-03
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of the instance to gain write access to unauthorized repositories via specifically crafted pull requests and REST API requests. An attacker would need to be able to fork the targeted ...
CVE-2021-22862
PUBLISHED: 2021-03-03
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with the ability to fork a repository to disclose Actions secrets for the parent repository of the fork. This vulnerability existed due to a flaw that allowed the base reference of ...
CVE-2021-22863
PUBLISHED: 2021-03-03
An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authenticated users of the instance to modify the maintainer collaboration permission of a pull request without proper authorization. By exploiting this vulnerability, an attacker would b...
CVE-2020-10519
PUBLISHED: 2021-03-03
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the Gi...
CVE-2021-21353
PUBLISHED: 2021-03-03
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was p...