U.S. debates how to protect cars from hackers
Full article730 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The U.S. government’s latest efforts to protect internet-connected cars and their passengers from hackers is being criticized by two senators who say the new voluntary guidelines don’t go nearly far enough.
The U.S. government’s latest efforts to protect internet-connected cars and their passengers from hackers is being criticized by two senators who say the new voluntary guidelines don’t go nearly far enough.
The National Highway Traffic Safety Administration (NHTSA) released voluntary best practices on cybersecurity for automakers on Monday, pressing manufacturers to make the issue a top priority so that drivers are not at risk from hackers. The guidelines encourage well-documented penetration testing, encryption on all communication between the car and manufacturer, and limited access to Engine Control Units. Several major American automakers have already signed on in support.
However, the new guidelines are far too loose, according to Sens. Edward J. Markey, D-Mass, and Richard Blumenthal, D-Conn., who first released a study criticizing flawed automobile cybersecurity in 2015.
The new debate flared up just days after massive denial-of-service attacks hit American targets on Friday, focusing an intense new spotlight on cybersecurity issues surrounding the Internet of Things (IoT). Like televisions and refrigerators, cars are relatively newly connected devices that have exhibited significant vulnerabilities to hackers. The difference, of course, is that a hacked car is a bit more dangerous than a hacked fridge.
Markey and Blumenthal are behind the Security and Privacy in Your Car (SPY Car) Act designed to establish firm federal standards for security and privacy in vehicles.
“This new cybersecurity guidance from the Department of Transportation is like giving a take-home exam on the honor code to failing students,” Senators Markey and Blumenthal wrote in a joint statement.
“If modern day cars are computers on wheels, we need mandatory standards, not voluntary guidance, to ensure that our vehicles cannot be hacked and lives and information put in danger. In this new Internet of Things era, we cannot let safety, cybersecurity, and privacy be an afterthought. We must pass our legislation, the SPY Car Act, that puts the protections in place to ensure auto safety and security in the 21st century.”
In addition to security against hackers, the SPY Car Act aims to protect consumer privacy from data trackers. The proposed legislation mandates transparency on how car owners’ data is collected, transmitted, kept and used. The bill demands the ability for consumers to opt out of such data tracking and prohibits the use of personal driving information in advertising unless the consumer opts in.
The bill also establishes a “cyber dashboard” showing consumers how their cars perform on security and privacy beyond minimum standards.
The NHTSA’s voluntary guidelines are the result of a nearly year-long process that began in Jan. 2016 with a 300-person “cybersecurity roundtable” including manufacturers, government entities and industry associations.
The NHTSA has pushed for automaker cybersecurity standards since they published a 2015 report for Congress on the subject.
Car hacking has become a high-profile affair in recent years. Hackers exposed flaws Jeep Cherokees and Tesla vehicles in 2015, resulting in new attention on the topic. Chrysler recalled 1.4 million vehicles as a result.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/car-hacking-nhtsa-cybersecurity-markey-blumenthal/