Subaru Software Hacked, Allowing Remote Control And Access To The Location Histories Of Millions Of Drivers

from the remote-control dept

Last year Mozilla released a report showcasing how the auto industry has some of the worst privacy practices of any tech industry in America (no small feat). Massive amounts of driver behavior is collected by your car, and even more is hoovered up from your smartphone every time you connect. This data isn’t secured, often isn’t encrypted, and is sold to a long list of dodgy, unregulated middlemen.

Given the fact the U.S. is simply too corrupt to pass even a baseline privacy law, automakers and executives are never incentivized to really try very hard.

The latest case in point: hackers recently discovered that vulnerabilities in a Subaru web portal allowed them to hijack most remote car features, including the locks, the horn, and remote ignition. But they also discovered that the vulnerabilities made it possible to not only track the location of millions of Subaru drivers in real time, but a database of anywhere the car had traveled in the last year:

“…they found they could also track the Subaru’s location—not merely where it was at the moment but also where it had been for the entire year that his mother had owned it. The map of the car’s whereabouts was so accurate and detailed, Curry says, that he was able to see her doctor visits, the homes of the friends she visited, even which exact parking space his mother parked in every time she went to church.”

Great stuff! To their credit, Subaru was quick to patch the security flaws last November, but the flaws are increasingly common across an industry that simply doesn’t prioritize consumer security and privacy. The same industry also routinely lobbies against right to repair reforms (which would lower consumer costs and bring greater transparency to car privacy systems) under the pretense they’re just really super duper concerned about consumer security and privacy.

Subaru wasn’t the worst on privacy and security of all the automakers Mozilla tracked, but it was still bad. Not only do automakers fail to secure your sensitive data, they routinely monetize it in misleading and nontransparent ways, selling access to a vast array of barely regulated and extremely dodgy data brokers. Some of whom turn around and sell it to no limit of bad actors.

Congress is too corrupt to function, automakers see no incentive to really change, and consumers usually aren’t aware the problem exists in the first place, so the problem continues.

Filed Under: , , , , ,
Companies: subaru

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Subaru Software Hacked, Allowing Remote Control And Access To The Location Histories Of Millions Of Drivers”

Subscribe: RSS Leave a comment
5 Comments
Anonymous Coward says:

Given the fact the U.S. is simply too corrupt to pass even a baseline privacy law, automakers and executives are never incentivized to really try very hard.

I really don’t understand this — most auto manufacturers operate globally. Most technical issues are of the “fix once, globally” type, and can be implemented in all regions at close to zero cost.

All these auto manufacturers, including Subaru, have to deal with the GDPR.

Which means, even with privacy legislation with teeth staring them in the face, they’re STILL the worst at data security — AND they aren’t being called to account for it, despite legislation in non-US countries that suggests they should be.

Mamba (profile) says:

The manual transmission is once again proving to be the best theft deterrent.

But seriously, I haven’t applied that patch that’s been sitting inbox for months….and I’m in this industry. It’s just getting out of hand.

Software need 3rd party testing as fit for service, including cybersecurity.
Or it needs PEs to sign off on the codebase for custom items.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a BestNetTech Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

BestNetTech community members with BestNetTech Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the BestNetTech Insider Shop »

Follow BestNetTech

BestNetTech Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the BestNetTech Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
BestNetTech Deals
BestNetTech Insider Discord
The latest chatter on the BestNetTech Insider Discord channel...
Loading...