news.volyx.in

Hacking Kia: Remotely controlling cars with just a license plate (samcurry.net)

630 points by speckx · 681 days ago · 367 comments on HN

Article summary

Researchers discovered vulnerabilities in Kia vehicles that allowed remote control over key functions using only a license plate. The vulnerabilities, which have since been fixed, could be exploited to unlock, start, and locate vehicles, as well as access personal information of the vehicle's owner. The researchers created a proof-of-concept tool to demonstrate the impact of the vulnerabilities. The issue was reported to Kia, and a fix was implemented before the tool was released.

Main themes

  • Vehicle security
  • Remote control vulnerabilities
  • Connected cars
  • Bug bounty programs
  • Internet of Things risks

What commenters say

  • Connecting cars to the internet introduces significant security risks and unnecessary complexity, making them vulnerable to remote attacks and data breaches.
  • Some people find features like remote start and app unlock to be useful and convenient, and are willing to accept the associated risks.
  • The benefits of connected cars, such as over-the-air updates and remote diagnostics, do not outweigh the potential risks and costs, and cars should be kept disconnected from the internet.
  • Vehicle manufacturers should prioritize security and transparency in their connected car systems, and provide clear guidelines for responsible disclosure of vulnerabilities.
  • The market will self-sort, with some consumers opting for connected cars and others preferring non-connected vehicles, and regulatory oversight may be necessary to ensure safety and security standards.
  • The use of cellular connectivity and internet-connected systems in cars is not necessary for features like remote start, and can be achieved through simpler, more secure means.