Here is the podcast about this investigation.

Archived version

On a narrow country road outside Canberra, I’m driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.

But while I’m at the wheel, I’m not the only one in control; a hacker has access to the car.

As the 2.6 tonne ute rounds a bend, he gets to work.

With the stroke of a key, he kills the headlights, plunging me into darkness.

The attack is not a total surprise. The Shark has spent the past two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars.

His task was to hack the vehicle and find out what could be seen and done remotely by the Shark’s Chinese manufacturer.

“It was easier than we were expecting,” Hreszczuk says.

EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country’s national security laws to co-operate with authorities.

Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark’s lack of cybersecurity.

“The access we took advantage of didn’t even have a password,” he says.

“It’s a little bit scary how open … the BYD Shark is to a hacker.”

While sabotage is one worry, the concern most often cited is surveillance due to the array of cameras and microphones on an EV.

Last year, the UK military banned Chinese EVs, even those made with Chinese components, from parking within 3 kilometres of some of its most sensitive locations.

China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.

In Australia, there’s no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.

When I pull into a service station and leave my phone unlocked in the car, Hreszczuk seizes his opportunity.

He’s done a simple audio edit, stitching together me saying “Hey Siri” and his voice asking a few questions to get the personal details he needs.

Using the car’s speaker system, Hreszczuk plays the voice command from his computer into the car.

“Hey, Siri, what is my home address?” the edited audio asks.

Siri replies, without questioning why I don’t know where I live.

Hreszczuk repeats this process and quickly extracts my date of birth and age.

Within minutes, he’s obtained the internet banking password.

Alastair MacGibbon, Australia’s former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.

MacGibbon says a cabinet minister should not be able to own a Chinese EV.

“China has always shown its strong desire to steal things, to surveil,” he says.

"No-one should be in any doubt that [Chinese EVs] are used in the same manner.

  • deeprlyeh@lemmus.org
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 days ago

    They are purposely building surveillance into all vehicles. I’m not sure the Chinese vehicles are going to be much worse.

    • pasdechance@jlai.lu
      link
      fedilink
      arrow-up
      3
      ·
      2 days ago

      Agreed. I seem to remember security researchers hacking moving cars on a highway many years ago. Every part has some sort of wireless access, it only takes one weak link.

  • Atelopus-zeteki@fedia.io
    link
    fedilink
    arrow-up
    5
    ·
    2 days ago

    Ok, yes, not surprised. How can I learn to hack my own car? I have a number of changes I’m interested in making, e.g. I would like the music controls on the left 1/3 of the screen, and the map on the right 2/3s. It’s currently the reverse. Simple stuff like that, to start.

    • Mikina@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      14 hours ago

      There was one defcon talk about it. It’s a lot of pretty complex reverse engineering, so getting really good at reading and understanding assembly and working with debuggers /disassemblers without symbols is a start.

      The talk I remember, where they were able to steer and break any car of the model in the world remotely, they got in by finding a unauth vulnerability in a remote call, and then used the firmware update process to bridge the almost airgapped vehicle controls system from the frontend car control (the screen, etc) system.

      They boasted how secure it is because it’s airgaoped and compromised frontend can’t touch the critical vehicle controls. It almost was, save for a single function used for updating both at once. It was months of reverse engineering and several bricked cars.

      But if you just want to change the frontend a little bit, it’s not going to be as complex, probably. Still really difficult.

      • Atelopus-zeteki@fedia.io
        link
        fedilink
        arrow-up
        1
        ·
        7 hours ago

        I’ll have to give that talk a listen. Might be something on 2600. Thing is the next pricier level up on my vehicle unlocks a number of features that would be pleasant to add. And I’m the sort of person that feels like making changes in the vehicle I own is my right and privilege. Mod is Life. Thanks for your input!!

  • refalo@programming.dev
    link
    fedilink
    arrow-up
    2
    ·
    2 days ago

    Is this the reason they want to/are banning Chinese EVs in the US? Or is it just to protect profits? Or is it both?

    • moth@anarchist.nexus
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 hours ago

      that’s just to protect profits. and this is just propaganda, because American cars are also laughably insecure. it made the national news several years ago.

      cars these days are built to be surveillance machines on wheels, with almost no thought to security or protecting them from people trying to hack them. it’s only a matter of time until we start seeing deaths related to this.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      Both, I bet. Internet-connected cars in general aren’t very secure, so this isn’t really very surprising.