Close Menu
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

What's On

Efforts to Ground Physics in Math Are Opening the Secrets of Time

3 August 2025

What Happens to Your Data If You Stop Paying for Cloud Storage?

3 August 2025

How to Clean Your Mattress

3 August 2025
Facebook X (Twitter) Instagram
Just In
  • Efforts to Ground Physics in Math Are Opening the Secrets of Time
  • What Happens to Your Data If You Stop Paying for Cloud Storage?
  • How to Clean Your Mattress
  • Gear News of the Week: Insta360 Debuts a Drone Company, and DJI Surprises With an 8K 360 Camera
  • Peacock Feathers Are Stunning. They Can Also Emit Laser Beams
  • Security News This Week: Google Will Use AI to Guess People’s Ages Based on Search History
  • Trump Promised to ‘Drill, Baby, Drill.’ The New Rigs Are Nowhere to Be Found
  • The 11 Best Coolers We’ve Tested for Every Kind of Adventure
Facebook X (Twitter) Instagram Pinterest Vimeo
Best in TechnologyBest in Technology
  • News
  • Phones
  • Laptops
  • Gadgets
  • Gaming
  • AI
  • Tips
  • More
    • Web Stories
    • Global
    • Press Release
Subscribe
Best in TechnologyBest in Technology
Home » Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug
News

Millions of Vehicles Could Be Hacked and Tracked Thanks to a Simple Website Bug

News RoomBy News Room27 September 20244 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email

In January 2023, they published the initial results of their work, an enormous collection of web vulnerabilities affecting Kia, Honda, Infiniti, Nissan, Acura, Mercedes-Benz, Hyundai, Genesis, BMW, Rolls Royce, and Ferrari—all of which they had reported to the automakers. For at least half a dozen of those companies, the web bugs the group found offered at least some level of control of cars’ connected features, they wrote, just as in their latest Kia hack. Others, they say, allowed unauthorized access to data or the companies’ internal applications. Still others targeted fleet management software for emergency vehicles and could have even prevented those vehicles from starting, they believe—though they didn’t have the means to safely test out that potentially dangerous trick.

In June of this year, Curry says, he discovered that Toyota appeared to still have a similar flaw in its web portal that, in combination with a leaked dealer credential he found online, would have allowed remote control of Toyota and Lexus vehicles’ features like tracking, unlocking, honking, and ignition. He reported that vulnerability to Toyota and showed WIRED a confirmation email seeming to demonstrate that he’d been able to reassign himself control of a target Toyota’s connected features over the web. Curry didn’t film a video of that Toyota hacking technique before reporting it to Toyota, however, and the company quickly patched the bug he’d disclosed, even temporarily taking its web portal offline to prevent its exploitation.

“As a result of this investigation, Toyota promptly disabled the compromised credentials and is accelerating security enhancements of the portal, as well as temporarily disabling the portal until enhancements are complete,” a Toyota spokesperson wrote to WIRED in June.

More Smart Features, More Dumb Bugs

The extraordinary number of vulnerabilities in carmakers’ websites that allow remote control of vehicles is a direct result of companies’ push to appeal to consumers—particularly young ones—with smartphone-enabled features, says Stefan Savage, a professor of computer science at UC San Diego whose research team was the first to hack a car’s steering and brakes over the internet in 2010. “Once you have these user features tied into the phone, this cloud-connected thing, you create all this attack surface you didn’t have to worry about before,” Savage says.

Still, he says, even he is surprised at the insecurity of all the web-based code that manages those features. “It’s a little disappointing that it’s as easy to exploit as it has been,” he says.

Rivera says he’s observed firsthand in his time working in automotive cybersecurity that car companies often put more focus on “embedded” devices—digital components in non-traditional computing environments like cars—rather than web security, in part because updating those embedded devices can be far more difficult and lead to recalls. “It was clear ever since I started that there was a glaring gap between embedded security and web security in the auto industry,” Rivera says. “These two things mix together very often, but people only have experience in one or the other.”

UCSD’s Savage hopes that the Kia-hacking researchers’ work might help shift that focus. Many of the early, high-profile hacking experiments that affected cars’ embedded systems, like the 2015 Jeep takeover and the 2010 Impala hack pulled off by Savage’s team at UCSD, persuaded automakers that they needed to better prioritize embedded cybersecurity, he says. Now car companies need to focus on web security too—even, he says, if it means making sacrifices or changes to their process.

“How do you decide, ‘We’re not going to ship the car for six months because we didn’t go through the web code?’ That’s a a tough sell,” he says. “I would like to think this kind of event causes people to look at that decision more fully.”

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow to cancel your Max subscription
Next Article How to turn off subtitles in Max

Related Articles

News

Efforts to Ground Physics in Math Are Opening the Secrets of Time

3 August 2025
News

What Happens to Your Data If You Stop Paying for Cloud Storage?

3 August 2025
News

How to Clean Your Mattress

3 August 2025
News

Gear News of the Week: Insta360 Debuts a Drone Company, and DJI Surprises With an 8K 360 Camera

2 August 2025
News

Peacock Feathers Are Stunning. They Can Also Emit Laser Beams

2 August 2025
News

Security News This Week: Google Will Use AI to Guess People’s Ages Based on Search History

2 August 2025
Demo
Top Articles

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024104 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views

Oppo Reno 14, Reno 14 Pro India Launch Timeline and Colourways Leaked

27 May 202582 Views

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Latest News
News

Security News This Week: Google Will Use AI to Guess People’s Ages Based on Search History

News Room2 August 2025
News

Trump Promised to ‘Drill, Baby, Drill.’ The New Rigs Are Nowhere to Be Found

News Room2 August 2025
News

The 11 Best Coolers We’ve Tested for Every Kind of Adventure

News Room2 August 2025
Most Popular

The Spectacular Burnout of a Solar Panel Salesman

13 January 2025128 Views

ChatGPT o1 vs. o1-mini vs. 4o: Which should you use?

15 December 2024104 Views

Costco partners with Electric Era to bring back EV charging in the U.S.

28 October 202495 Views
Our Picks

Gear News of the Week: Insta360 Debuts a Drone Company, and DJI Surprises With an 8K 360 Camera

2 August 2025

Peacock Feathers Are Stunning. They Can Also Emit Laser Beams

2 August 2025

Security News This Week: Google Will Use AI to Guess People’s Ages Based on Search History

2 August 2025

Subscribe to Updates

Get the latest tech news and updates directly to your inbox.

Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us
© 2025 Best in Technology. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.