cross-posted from: https://scribe.disroot.org/post/11438860
Here is the podcast about this investigation.
On a narrow country road outside Canberra, I’m driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.
But while I’m at the wheel, I’m not the only one in control; a hacker has access to the car.
As the 2.6 tonne ute rounds a bend, he gets to work.
…
With the stroke of a key, he kills the headlights, plunging me into darkness.
The attack is not a total surprise. The Shark has spent the past two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars.
His task was to hack the vehicle and find out what could be seen and done remotely by the Shark’s Chinese manufacturer.
“It was easier than we were expecting,” Hreszczuk says.
…
EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country’s national security laws to co-operate with authorities.
…
Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark’s lack of cybersecurity.
“The access we took advantage of didn’t even have a password,” he says.
“It’s a little bit scary how open … the BYD Shark is to a hacker.”
…
While sabotage is one worry, the concern most often cited is surveillance due to the array of cameras and microphones on an EV.
Last year, the UK military banned Chinese EVs, even those made with Chinese components, from parking within 3 kilometres of some of its most sensitive locations.
China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.
…
In Australia, there’s no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.
…
When I pull into a service station and leave my phone unlocked in the car, Hreszczuk seizes his opportunity.
He’s done a simple audio edit, stitching together me saying “Hey Siri” and his voice asking a few questions to get the personal details he needs.
…
Using the car’s speaker system, Hreszczuk plays the voice command from his computer into the car.
“Hey, Siri, what is my home address?” the edited audio asks.
Siri replies, without questioning why I don’t know where I live.
Hreszczuk repeats this process and quickly extracts my date of birth and age.
Within minutes, he’s obtained the internet banking password.
…
Alastair MacGibbon, Australia’s former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.
MacGibbon says a cabinet minister should not be able to own a Chinese EV.
“China has always shown its strong desire to steal things, to surveil,” he says.
"No-one should be in any doubt that [Chinese EVs] are used in the same manner.
…
Not going to read the article yet, as it will spoil the associated Four Corners episode which airs tonight. This is one of my biggest problems with modern cars, though. They have all this technology built into them that can be connected to the internet (in some cases they are permanently connected because they are checking for OTA updates) which massively increases their attack surface. There’s also a concern with some of the smaller companies that they’ll go out of business and leave customers with a very expensive brick.
My biggest problem with modern cars is that the ADAS systems are all rubbish.
I can deal with my car radio spying on what I say and monitoring where I drive, but I don’t like that it can suddenly decide that I should drive off a cliff or the wrong way onto a freeway on-ramp.
Number one rule of driving is to not occupy the same space as someone else. ADAS like Park Sensors and Autonomous braking can help with that, when they function correctly, but when they are using an Optical Object Recognition Chip from Cheapest Bidder electronics company, they become a liability. And don’t get me started on “self driving” cars.
The only ADAS system I’ve tried that didn’t immediately infuriate me was on a newer VW Golf I rented last year. This was actually good and felt safe to use. It worked reliability on country roads with erased lane markings. I actually enjoyed using it. I’ve tried over the years, Peugeot, Opel, Fiat, Mercedes, Volvo,
GMMG. All terrible.GMMG I also tried last year, brand new car, it was the absolute worst! Volvo’s was tolerable.Edit: MG, not GM
We are finding that the Korean ones are the least-bad.
Japanese are the least functional but also the least intrusive. I think that this is because Japanese marques are preferred by people who enjoy driving.
Some Chinese ones are very Temu (say you have them but they are completely useless) and some are very AliBaba (say you have them and they function as well as the low end European).
Speaking of European, the Volume brands have something to mark off the ENCAP checklist, despite the fact that they are useless, while the real Luxury marques have fully functional systems that try to do everything for you but just end up annoying you. Prestige marques are generally more selective and tailored to their owners requirements.
The US is funny; you have Tesla and then you have everyone else. Tesla used to have the best units (that were used in higher end Mercedes a decade ago), while new Teslas, Ford and GM have cheapest bidder units to pretend to be Tesla, but are completely useless.
I must correct my previous comment. I didn’t mean GM, but MG
As an addition: Remote ‘kill switches’ in Chinese buses have been found last year in the Netherlands, UK, Denmark, Norway, …
Here are some articles:
Kill switches: a new way of waging war
There is already evidence found of Chinese kill switches in devices like wind turbines, solar panels, and buses. These are pieces of hardware that allow the manufacturer to disable or disrupt the device. Are we surrounded by ticking time bombs?




