My Car Is Too Dumb to Get Hacked

My Car Is Too Dumb to Get Hacked

Personal car-security jeep-hack personal windows 10

I've spent way too much of this week reading about Jeep Cherokees. Not because I'm car shopping - my Civic is eleven years old, has a tape deck adapter jammed in for my phone, and I intend to drive it until the wheels fall off - but because of that Wired story from last week where two security researchers, Charlie Miller and Chris Valasek, remotely took over a Jeep on the highway while a reporter was driving it. They killed the transmission. From ten miles away. Using a laptop and a cell connection into the entertainment system.

Chrysler ended up recalling something like 1.4 million vehicles over it this week, and if you'd told me five years ago that a car company would issue a security patch the way Microsoft issues a security patch, Id have assumed you were describing some future decades off, not next Tuesday.

Heres the thing that actually gets me though. Its not really about Jeeps specifically. Its that every car company right now is racing to cram a tablet into the dashboard and call it innovation, and almost none of them seem to be asking the boring question of who else might be able to get into that tablet besides the driver. Im not a security guy. I dont even really understand the CAN bus stuff Ive been reading about, except in the vaguest sense that its the internal nervous system of the car, and apparently talking to the entertainment unit gets you further into that nervous system than it should. But you dont need to understand the mechanism to understand the headline, and the headline is: a stranger stopped a car on a highway from his living room, on purpose, as a demonstration.

And my own car has none of this. No cellular connection, no app, no way for anyone to remotely do anything to it short of physically breaking in and hotwiring it like its 1994. For the first time in my life this feels like a feature instead of just cheapness. Ive been mildly embarrassed for years that I dont have a car with Bluetooth. Now Im sort of smug about it, which is a strange thing to be smug about, honestly.

Separate tangent, and this has nothing to do with cars: Windows 10 launches tomorrow and I still havent decided if Im doing the free upgrade the day it drops or waiting a week to see what breaks. Every time Ive done a day-one OS upgrade it has cost me an evening I didnt plan on losing, usually to some printer driver or audio thing nobody else seems to have a problem with. But I also kind of want to see the new Start menu for myself instead of reading about it secondhand, so Ill probably cave around 9pm tomorrow and regret it by midnight. Thats just how this always goes with me.

Back to the cars for a second, because I keep circling back to it. What strikes me most is how fast the recall happened once the story went public. Chrysler had apparently known about some version of this vulnerability for months before the Wired piece ran - there was already a patch available, sitting on a website, that you had to manually download and install yourself via USB stick, which nobody was ever going to do - but it took an actual demonstrated highway hack with a journalist behind the wheel to get 1.4 million cars called in for a fix. That tells you something about how these things actually get prioritized inside a company that size. It wasnt the vulnerability itself that moved anyone. It was the story about the vulnerability, told in a way normal people could feel in their stomach.

Im not trying to be a doomer about connected cars generally. Ill probably own one eventually, whenever the Civic finally gives out on me, and Ill probably end up liking the backup camera and the phone integration and all of it more than I expect to. But Im going to be the annoying person at dinner parties for a while asking dealership guys pointed questions about how the infotainment system talks to the rest of the vehicle, and Im not going to feel bad about that one bit.