Experience trumps content in apps monetization http://t.co/iaCY5ebX
5 minutes ago by monetize_me on twitterZDNet is available in the following editions:
A group of researchers discover that, just like PCs, cars can be hacked. However, they say the risk is fairly low--for now.
stefan savage, technology, software, science and technology, computer technology, university of washington, university of california-san diego, cnet networks, oakland, california
In the near future, you may be more worried about a hacker attack on your car than on your PC.
A group of researchers from two universities tested their hacking skills on two cars and found that they could remotely lock the brakes, the engine, and windows on a car; turn on the radio, heat, and windshield wipers; honk the horn; and change the speedometer display.
They were able to do all of that in tests on two cars of unnamed make and model by connecting a laptop to the electronic control system and controlling that computer wirelessly using a second laptop in a separate car.
The paper (PDF) will be presented by researchers at the University of Washington and the University of California at San Diego at the IEEE Symposium on Security and Privacy in Oakland, Calif., last week.
"Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input," the paper says.
In an interview with CNET last week, two of the researchers--Stefan Savage of UCSD and Tadayoshi Kohno of the University of Washington--talked about the tests and what their findings mean for drivers today.
Q: I'd like to know more about what you did for the research. Did you have to have physical access to the car, or is there a way this could be done remotely?
Savage: In the paper we didn't focus on the different ways that one could do it. The paper focuses on the question of if someone were able to gain access to the car, how resilient would it be in our scenario? We connected our computer to the on-board diagnostics port--it's standard and is located under the dashboard on the driver's side.
Kohno: This paper is not focusing on the specific threats. We are focusing on understanding the evolution of cars in the hopes that the industry can protect against adverse things happening in the future.
Savage: If you look at PCs in the early 1990s, they had all kinds of latent software vulnerabilities. It didn't matter so much because PCs were at home and not connected to everything else. Then they were connected to the Internet and the latent vulnerabilities were exposed to outside attack. We see cars moving in much the same direction. There is a strong trend to provide pervasive connectivity in cars going forward. It would be good to start working on hardening these systems and providing defenses before it becomes a real problem.
Can you give me a scenario where a car would be compromised?
Savage: You could have an adversarial mechanic or a jealous boyfriend or girlfriend who temporarily has access to the car. They could connect to this component, download onto the car, disconnect, and the code could do their bidding. I think at this point these attacks are much more fantastical than a real thing people need to be concerned about today.
Kohno: Today everyone is focusing on Web security and botnets. We want to make sure that in 5 or 10 years we don't add cars to that list.
You have written a tool that enables this type of attack, called CarShark, right?
Kohno: The tool captures a lot of what we did. It's a software tool we wrote. It runs on a computer that plugs into the OBD-II (On-Board Diagnostics II) port and it can sniff (and inject) packets on the network.
Couldn't someone use that tool to compromise a car?
Savage: We're not releasing it.
But there are ways to do this remotely, right?
Savage: We're trying to find a balance in the research. We're not interested in taking an alarmist tone. We purposely are not focusing on that aspect here. Can I imagine it's doable? Yes. In the end it's all software, and software on your car is not fundamentally different from software on your PC.
Do you think anyone is actually doing anything like this, other than for legitimate research purposes?
Kohno: We have no reason to believe this is an issue today. One of our goals is to stay ahead of the bad guys before the threats really do manifest.
Have you talked to the car manufacturers about this?
Savage: We talked with the appropriate parties, which we can't name.
Did they take this seriously or dismiss it?
Savage: Everyone we've talked to has taken it seriously and been very positive.
Anything else you would like to add?
Kohno: It's a changing world of technology. Often when people hear the word "computer" they associate it with the meaning of laptop or desktop. And one of the things we'll see in the future is computer devices integrating themselves both literally and figuratively into our world. There will be computers integrated into cars, medical devices, homes, and the smart grid. And I think that we need to be proactively thinking about security issues, not just on the desktops with botnets and Web browsing, but think about where our computers will be in the future and what we can do today to protect them. This research on cars is part of that.
This article was first published as a blog post on CNET News.
Experience trumps content in apps monetization http://t.co/iaCY5ebX
5 minutes ago by monetize_me on twitterMalaysia offers some manufacturing benefits over China http://t.co/bMquIFiX
5 minutes ago by AsianFashionLaw on twitterRT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi
5 minutes ago by GarnieBolling on twitterThats it.Im digging up an old bus plan i wrote around acquisition of #bigdata talent. http://t.co/gpkha5A1 Any investors want2 read/discuss?
20 minutes ago by BigDataInsights on twitterIntegration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 mins ag... http://t.co/aaa0Cb73
35 minutes ago by jamstrit on twitterHomegrown smartphone OSes gaining favor in China http://t.co/lOBVp1T6
35 minutes ago by smartfone on twitterHomegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/gHypbdIY
35 minutes ago by androidnewshome on twitterIntegration, focused investments to propel Windows Phone - ZDNet Asia http://t.co/7sZi6Dhb
50 minutes ago by sonuise on twitterRT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW
1 hour ago by AsiaBites on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi
1 hour ago by MDMGeek on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia: Big data acquisition... http://t.co/r6taCmG1 #ITNews #BigData
1 hour ago by BigDataNetwork on twitterBig data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/d9k21ro5: David G... http://t.co/4JgaOz8g #bigdata #sna
1 hour ago by BigDataSocial on twitterBig data acquisitions pave way to fast, effective innovation - Zd Net http://t.co/fbori8UQ: Incr... http://t.co/nuEeUbj7 #ITNews #BigData
1 hour ago by BigDataNetwork on twitterBig data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/iFQ74xYI #Bigdata #analytics
1 hour ago by ciropuglisi on twitter@ChemarieMonica : Integration, focused investments to propel Windows Phone - ZDNet As... http://t.co/ZVPDpbxH http://t.co/1QrdIsaV #tech
1 hour ago by mcjimmm on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoidI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
5 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
5 days ago by wykoong on Drop the egos, copy ideas, then innovateThreats and malware know no boundaries. Neither should your web security. See how far Blue Coat Unified Web Security goes to protect your network.
Echelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.