In Letter To 20 Automakers, Senator Demands Answers On Cybersecurity
chicksdaddy writes "Cyber attacks on 'connected vehicles' are still in the proof of concept stage. But those proofs of concept are close enough to the real thing to prompt an inquiry from U.S. Senator Ed Markey, who sent a letter to 20 major auto manufacturers (PDF) asking for information about consumer privacy protections and safeguards against cyber attacks in their vehicles. Markey's letter, dated December 2, cites recent reports of 'commands...sent through a car's computer system that could cause it to suddenly accelerate, turn or kill the breaks,' and references research conducted by Charlie Miller and Chris Valasek (PDF) on the Toyota Prius and Ford Escape. 'Today's cars and light trucks contain more than 50 separate electronic control units (ECUs), connected through a controller area network (CAN) ... Vehicle functionality, safety and privacy all depend on the functions of these small computers, as well as their ability to communicate with one another,' Markey wrote. Among the questions Markey wants answers to: What percentage of cars sold in model years 2013 and 2014 do not have any wireless entry points? What are automakers' methods for testing for vulnerabilities in technologies it deploys — including third pressure technologies? Markey asks specifically about tire pressure monitors, bluetooth and other wireless technologies and GPS (like Onstar). What third party penetration testing is conducted on vehicles (and any results)? What intrusion detection features exist for critical components like controller area network (CAN) buses on connected vehicles?"
There, get your ... campaign contribution... and stop asking questions.
Just trust us, we know how to build cars and we know how to keep them safe. We're Totally and Extremely Professional and Competent Organizations, you can trust us with stuff that goes boom.
If you don't know the difference between "breaks" and "brakes", will you really understand the answers to your questions?
After all, there are factions within government and if one doesn't agree with another, you may find yourself the victim of an unfortunate accident. Only a tiny minority of government gets the secret service and paramilitary police protecting them you know.
Perhaps we are seeing some government players waking up to the reality that even THEY have good reason to fear the government they are participating in.
Out do nothing congress is finally doing something useful. These are the kinds of questions we should be asking before problems start to occur and while there are chances to try to introduce standards. It's like the Toyota sudden acceleration thing, everyone assumed it was careless people until someone did a proper audit and discovered a complete lack of industry best practices that everyone assumed had been in place.
I'd tell him to pound sand until he can provide some answers about privacy protections and safeguards preventing the government from illegally spying on its citizens.
Follow the links to the actual letter on Markey's site. It really does say "kill the breaks".
Now, here's a spoon.
-- Tigger warning: This post may contain tiggers! --
To prove their earnestness about cyber security.
why not pass the buck and make the uses pay for the dealer to do the updates and lock out DIY'er and 3rd party shops.
Sir, our vehicles are just as secure as healthcare.gov.
Just lie. There are no repercussions.
Politics; n. : A religion whereby man is god.
...showed as much interest in the security of Healthcare.gov, we might actually get somewhere. But of course, why worry about the security of a Big Government project, when you have some evil corporations to kick around.
I like manual brakes.
If they were good enough for the Flintstones they're good enough for a Senator!
Yeah, but it takes weeks to build up the callouses necessary for one trip to the quarry and home. You don't see all of Fred's down-time while he grows those callouses back.
For my money, throwing a rock on a rope out the window is the last word in brake technology.
A feeling of having made the same mistake before: Deja Foobar
Tesla wasn't on the list?! What is the Senator trying to say?
Thanks for fact-checking that. I'm not sure I could drive more than 8 hours or so without breaks, so I'm glad the senator has my interests in mind.
Stop calling everything computer related "cyber".
"A plan fiendishly clever in its intricacies"- Homer Simpson
What the (bleep) third pressure technologies are? (car analogies welcomed)
(don't blame the /. editors on this, one of TFA has used it
Questions raise, answers kill. Raise questions to stay alive.
If the senator thinks that "break" = "brake", we should send him the "Gimme a brake" email to remind him that as a role model (albeit a very crummy one) to the young people, at the very least he should be able to discern "break" from "brake".
Now ... can someone gimme that senator's email address ?
Muchas Gracias, Señor Edward Snowden !
Tesla wasn't on the list?! What is the Senator trying to say?
+500 insightful!
Seriously, a senator wants to know about high-tech exploits, and doesn't ask the single highest tech auto manufacturer in the US today about it? That just screams "Agenda!".
there wasn't a car analogy for healthcare.gov security. i'm guessing someone made a car analogy about his car.
Anons need not reply. Questions end with a question mark.
Sure you could. Heck, an astronaut has even proven the technology works great for long road trips.
Write failed: Broken pipe
Tesla MIGHT be the single highest tech auto manufacturer in the US, but they are insignificant [and will be for years] in terms of cars on the road [past, present and future].
Sleep your way to a whiter smile...date a dentist!
Most car manufacturers dimension their batteries such, that a car parked with a full battery should be able to start after 2 months under normal circumstances. If your car only lasts ten days, either your battery or charging circuit isn't working properly, or you indeed have devices in the car that consume too much electricity in standby mode. If your radio is the culprit, it really needs to be replaced. Fortunately, car stereos follow an industry standard form factor and plugs, so replacing that should be easy. Oh wait, they all stopped using that because they wanted to integrate all the car computers with that thing.....
You are forgetting that your engine ECU requires power too. They have quite a few dynamic parameters stored in RAM that you really don't want to store in flash because they are updated every few seconds if the engine is running and you need a quick and easy way to erase them. Maybe modern cars would be able to store them in flash, but the older generations didn't have that luxury and would need to relearn their ignition timing and fuel mixture every time you pulled the plug on them.
I was promised a flying car. Where is my flying car?
I suspect - just like most industries providing consumer goods - the automotive engineers knew about and pointed out the potential of such vulnerabilities, only to be ignored by their PHBs and their R&D budgets for said issues zeroed-out by the true bosses: Bean Counters.
let's see.. According to Forbes... In order of sales here's the largest 11 in the world.
VW
Toyota
Daimler
Ford
BMW
GM
Nissan
Honda
Hyndai
SAIC (Chinese)
The top 10 up there represent the major manufacturers that sell cars in the US other than Tesla and Fisker is about dead anyway.. SAIC doesn't sell anything in the US, so really what's the other 8 on his list? Some guy in a garage building kit cars?
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Electrically heated seats are underrated. Now you can get cooling seats. All the rest, GPS, complicated, vendor-locked in car entertainment, OnStar (which I ripped out of my car) are all wastes of money. It's getting so that you can't find cars (except very small, low-end models) that have hand crank windows.
Harrison's Postulate - "For every action there is an equal and opposite criticism"
Among the questions Markey wants answers to: What percentage of cars sold in model years 2013 and 2014 do not have any wireless entry points?
Zero, all cars have wireless entry points. They are called windows, doors and vents and probably a few others.
Uh, guys, the GP AC was making fun of the semiliterate summary: a car's computer system that could cause it to suddenly accelerate, turn or kill the breaks
What is it with you guys and homophones? If you write code like you write English, no wonder software is so buggy.
That said, though, don't blame the slashdot editor or submitter -- it was cut and pasted from the fucking article. Remind me that "the security ledger," being run by aliterates who obviously never finished high school, is NOT a good source of information about anything more important than lolcats. That kind of mistake is forgivable in a slashdot comment or summary, but it is certainly unforgivable by a so-called "professional" writer. I would expect a professional to at least have a BA in English, and what kind of institution will give an English degree to someone who doesn't know the difference between brake and break?
What, are they outsourcing writing, editing, and proofreading now? Or are those professions now obsolete, since nobody reads any more?
Free Martian Whores!