back to article Israeli ex-spies want to help you defend your car from cybercrooks

Security shortcomings in new cars could nurture a new branch of the infosec industry in much the same way that Windows' security failings gave rise to the antivirus industry 20 or so years ago, auto-security pioneers hope. Former members of Unit 8200, the signals intelligence unit of the Israel Defense Forces, have banded …

  1. Anonymous Coward
    Anonymous Coward

    > He said that a car IPS doesn't do away with the need for secure vehicle design,

    But a secure vehicle design does away with the need for an IPS.

    1. Robert Helpmann??
      Childcatcher

      @AC Security Design

      But a secure vehicle design does away with the need for an IPS.

      That's like saying, "A secure house design does away with the need for a household security system." Vehicles literally have a lot of moving parts. Because of this, the complexity makes eliminating all problems highly unlikely. To illustrate this, I invite you to do a search for "recall" paired with the make of the vehicle you drive. Having a layered approach to security would seem to be important in the automotive world, too.

      1. Anonymous Coward
        Anonymous Coward

        Re: @AC Security Design

        "secure" is a boolean state.

        You are talking about the probability of security. They are two different things entirely.

  2. Charles Smith

    Zapper

    So I can have a Zapper to set a speed limit on the car behind that is tailgating me on the motorway/freeway?

  3. M7S

    Cue "let them try and hack my Series 3 Landrover" comments

    Yes. I have one.

    But I also have (and expect in future to have) a modern car.

    Maybe we should look at changing manufacturer perceptions regarding security in ALL areas where IT is becoming an issue. TVs, Fridges, electricity meters, home security systems etc etc

    Whilst generally legislation applied to tech tends, even if done with the best of intentions, to fail as laws stagnate and tech (usually) doesn't, this might be one area where some broad principles could perhaps be laid down, with manufacturers being subject to penalties if they dont secure things so that joe bloggs buying on the street doesnt have to be an IT expert.

  4. Anomalous Cowshed

    In other news...

    Ex. GCHQ and NSA spies want to help defend your personal data from the pitfalls of anonymity...

  5. xyz Silver badge

    Ah the high pitched screech of the software salesman

    You will all die unless you buy our warez! Oh the Israeli salesman always lobs in "ex-spy" or "ex-military" because everyone does national service, so it's really true ;)

  6. Anonymous Coward
    Anonymous Coward

    The next Symantec?

    Keys are currently the weak-point in vehicle security, which is why they are either being cloned or stolen from your house.

    The advent of always connected vehicles will change that. Some vehicle manufacturers are already testing delivering software upgrades over the air remotely, without the need for the car to be switched on, it just needs the battery connected. Next time you start the car you'll get an egg-timer with 'Please wait, installing upgrades....60 minutes to go...'

    So there will definitely be a route in for remote hackers. I can't see why a hacker would want to attack one car (other than a terrorist wanting to take control of the Prime Minister's car and drive it into the Thames, for instance) but if they can infect tens of thousands in one go, then there is a definite incentive for them to start trying, and probably some money in being the next Symantec and try to stop them.

    1. Anonymous Coward
      Anonymous Coward

      "Keys are currently the weak-point in vehicle security"

      Is that why keyless Range Rovers are car thieves favourite target?

      My car keys haven't been cloned or stolen thanks!

  7. Anonymous Coward
    Anonymous Coward

    Some of them have it sorted

    When I needed a couple of new keys for my 2003 Hyundai Terracan even the franchise dealer was totally unable to get the immobiliser to accept the new keys - security against theft (or even use by the legal owner) doesn't get any better than that!

    In the end a locksmith had to install duplicate responders in the new keys to match the one existing key.

  8. JaitcH
    FAIL

    Mass produced anything precludes security

    Mass produced devices of any type have a weakness - MASS.

    All to takes is a criminal sharpy to hack a mass anything and the device is often defenceless.

    A language student of mine is a car electronics technician and we use the service manuals, carefully presented in English, for an American designed automobile that is manufactured in China.

    We ploughed through the boring suspension, engine and body manual sections and then we hit the electronics! In this manual were all the details needed to bypass, eliminate, all manner of electronic security ... for maintenance purposes only.

    If I, albeit an electronics technician, can fathom the devices what can a dedicated, thieving, hacker do?

    Even the good old cylinder locks are open book since there is a device you insert into a lock and, using induced frequency testing, can determine the lock characteristics in seconds. What hope is there?

    My high-end TaiWan made motorcycle has a convenient multi-pin connector behind the rear number plate. This is used in production test and circumvents all the security provisions. Naturally I inserted switches in the power pin lines and the test connector is ineffective unless switched on - after removing the seat mounting storage box.

    I also installed a 15 second timer in the fuel pump line which, unless a concealed contact is touched, stops fuel delivery to the engine. I also have a very noisy alarm which is triggered by motion and is loud enough to awaken any sleeping parking lot attendant.

    Neither of these devices would have value except for the fact they are unique. THIS is what is missing from mass produced security devices.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like