Wikileaks shines a light on car hacking
Recent Wikileaks documents reveal that the CIA considered a “mission” against vehicle computer systems is a warning sign for consumers and carmakers.
Security experts cite the hypothetical example of a remote attack on a fully autonomous vehicle with no steering wheel or brakes, in which the passenger would have no recourse to regain manual control of the car.
“You have a lot of car companies trying to design cars to be better suited to automation, which means they’re more attractive to hackers,” says auto consultant Roger Lanctot of Strategy Analytics.

A major strategy for automakers is to reduce the number of communications gateways to crucial systems and to require services offered by third parties to go through a single secure path.
A modern car has dozens of computers with as much as 100 million lines of code — and for every 1000 lines there are as many as 15 bugs that are potential doors for would-be hackers, according to Navigant Research.
Wikileaks and the CIA
WikiLeaks documents show the CIA citing “vehicle systems” and a car operating system from QNX, owned by Blackberry Ltd, as “potential mission areas” for the CIA’s “Embedded Devices Branch” to consider.
The QNX operating system, which is used by most global automakers, provides a “comprehensive, multi-level, policy-driven security model … to mitigate attacks,” the company said in a statement to Reuters.
“But given the collection of software, hardware and network components that make up a connected car, “security is only as strong as its weakest link,” it adds.
Carmakers have been increasingly adopting QNX. In 2016, for example, Ford announced it was dropping Microsoft as the platform for its SYNC infotainment system and adopting QNX instead.
Ford’s new SYNC 3, using QNX, was rolled out in new vehicles last year.
Automakers have also been enabling over-the-air software updates for vehicles that could allow malicious code to be uploaded to on-board computer systems.
A key example surfaced in September 2016 when Chinese cyber security researchers hacked a Tesla Model S sedan, remotely tapping the brakes and popping the boot.
The electric carmaker subsequently patched the bugs using an over-the-air fix.
In 2015 researchers used a wireless connection to turn off a Jeep Cherokee’s engine, prompting a recall of 1.4 million vehicles.
Hacks could also expose private information shared between car and third parties – credit card numbers, account numbers or passwords – to theft.
A January 2017 survey by the University of Michigan’s Transportation Research Institute found that 33% of respondents said they were “extremely concerned” over hacking of full self-driving cars to cause crashes.



Join the conversation