Here is the podcast about this investigation.

Archived version

On a narrow country road outside Canberra, I’m driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.

But while I’m at the wheel, I’m not the only one in control; a hacker has access to the car.

As the 2.6 tonne ute rounds a bend, he gets to work.

…

With the stroke of a key, he kills the headlights, plunging me into darkness.

The attack is not a total surprise. The Shark has spent the past two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars.

His task was to hack the vehicle and find out what could be seen and done remotely by the Shark’s Chinese manufacturer.

“It was easier than we were expecting,” Hreszczuk says.

…

EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country’s national security laws to co-operate with authorities.

…

Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark’s lack of cybersecurity.

“The access we took advantage of didn’t even have a password,” he says.

“It’s a little bit scary how open … the BYD Shark is to a hacker.”

…

While sabotage is one worry, the concern most often cited is surveillance due to the array of cameras and microphones on an EV.

Last year, the UK military banned Chinese EVs, even those made with Chinese components, from parking within 3 kilometres of some of its most sensitive locations.

China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.

…

In Australia, there’s no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.

…

When I pull into a service station and leave my phone unlocked in the car, Hreszczuk seizes his opportunity.

He’s done a simple audio edit, stitching together me saying “Hey Siri” and his voice asking a few questions to get the personal details he needs.

…

Using the car’s speaker system, Hreszczuk plays the voice command from his computer into the car.

“Hey, Siri, what is my home address?” the edited audio asks.

Siri replies, without questioning why I don’t know where I live.

Hreszczuk repeats this process and quickly extracts my date of birth and age.

Within minutes, he’s obtained the internet banking password.

…

Alastair MacGibbon, Australia’s former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.

MacGibbon says a cabinet minister should not be able to own a Chinese EV.

“China has always shown its strong desire to steal things, to surveil,” he says.

"No-one should be in any doubt that [Chinese EVs] are used in the same manner.

…

  • randomname@scribe.disroot.orgOP
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    1
    ·
    4 days ago

    As an addition: Remote ‘kill switches’ in Chinese buses have been found last year in the Netherlands, UK, Denmark, Norway, …

    Here are some articles:

    Kill switches: a new way of waging war

    There is already evidence found of Chinese kill switches in devices like wind turbines, solar panels, and buses. These are pieces of hardware that allow the manufacturer to disable or disrupt the device. Are we surrounded by ticking time bombs?

    Neighboring Norway’s discovery that buses could be controlled from China now has Denmark on high alert

      • nilloc@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 days ago

        It needs to be very well tested, but we need it if we’re going to keep these things in the road and repairable in the long term too. Just can’t have any kernel panics at 100kph

  • Calirath@sh.itjust.works
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    3 days ago

    Sensationalist title and article for clicks with body necessarily vague in detail designed to rouse emotions over thought works amongst the general populace lacking critical thinking is a tale as old as time.

    The Shark has spent the past two weeks with Dan Hreszczuk

    “Security expert shocked at how easily hackable your phone/computer is!*
    *(Only after unrestricted physical access for 2 weeks).”

    • PointlessLifePersonified@slrpnk.net
      link
      fedilink
      arrow-up
      3
      ·
      3 days ago

      Once the research is done & they know how to get in, I imagine it’s quite possible to get it done remotely, or at the very least with only a few minutes of physical access - for which there are a wide variety of possibilities to force into occurring.

      • No_Eponym@lemmy.ca
        link
        fedilink
        arrow-up
        1
        ·
        2 days ago

        Do they? You assume, but the article doesn’t make that clear. This article isn’t made to inform you, its made to incite you.

        At minimum the jurnos should:

        • show how the hack was done, or clarify if it can be done remotely on other vehicles once the flaws are known.
        • compare this to other EVs and ICEs from the same/other manufacturers. Is this an issue with this one EV or does it apply more broadly? This would help avoid conflating issues in the article (this EV is hackable, all EVs are banned from military bases in the UK, therefore all EVs are hackable).

        Likely there is an issue with all connected cars. No one/company/government is on your side. The need for laws regulating all connected cars to prevent these issues (or allow you to disconnect the car) should be your takeaway.