A recent investigation by Australian program Four Corners has shone a harsh spotlight on the growing cybersecurity risks inherent in modern vehicles, particularly those with extensive connectivity features. Security expert Chris Hreszczuk demonstrated just how easily a four-wheel-drive ute, a Chinese-manufactured truck, could be compromised, proving that the task was surprisingly straightforward.

Hreszczuk’s initial point of entry was the vehicle’s CAN bus, the internal network that facilitates communication between all of the car’s control units. He gained access through an unprotected access point, a critical flaw that then allowed him to delve into the software controlling various vehicle functions. The real-world demonstration, conducted on a rural road outside Canberra with reporter Angus Grigg at the wheel, showcased the alarming extent of his control.

At a modest 30 kilometers per hour (approximately 19 mph), Hreszczuk remotely activated the wipers at full blast, caused the windshield washers to spray, made the headlights flash erratically, and even had the speakers blare instructions to use low beams. The most dramatic action, however, was the complete disabling of the headlights, leaving the vehicle in darkness.

While Hreszczuk was unable to gain control over the brakes, steering, or camera systems – functions that Four Corners reported were robustly protected – his access to peripheral systems still presented a significant threat. In today’s connected automotive landscape, the list of these peripheral systems is extensive.

Adding another layer to the cybersecurity concerns, Hreszczuk was able to exploit a vulnerability involving the vehicle’s microphone and speakers. After reporter Angus Grigg left his unlocked phone in the car, Hreszczuk used his laptop to craft voice commands. These commands, relayed through the car’s speakers, prompted Siri on Grigg’s phone to read out sensitive information. While the phone itself wasn’t breached, the ability to remotely activate listening devices and audio output systems creates a tangible security risk.

Manufacturer BYD has responded to the investigation, stating that it is currently looking into the claims and emphasizing its commitment to customer safety and security. The company does have a point, however, in that remote exploitation typically requires some form of initial physical access to the vehicle. The Four Corners investigation, however, raised broader questions about data handling and privacy.

When questioned about its Australian privacy policy, BYD provided a link to a document that had been uploaded just 76 minutes prior. Notably, this revised policy omitted any mention of China or surveillance. BYD asserts that Australian data is stored locally and is not shared with Chinese authorities. Despite these assurances, the timing and content of the policy change have understandably raised skepticism.

Adding to the urgency of the situation, Australia currently lacks any minimum cybersecurity standards for automobiles. This is a stark contrast to regulations in place for connected household devices, where a smart washing machine may undergo more rigorous cybersecurity scrutiny than a mid-size pickup truck. While discussions about vehicle-specific regulations have commenced in Australia, widespread enforcement is still several years away.