news.volyx.in

Hacking Subaru: Tracking and controlling cars via the admin panel (samcurry.net)

548 points by ramimac · 558 days ago · 320 comments on HN

Article summary

A security vulnerability was discovered in Subaru's STARLINK connected vehicle service, allowing unauthorized access to customer accounts and vehicle control. The vulnerability was reported and patched within 24 hours, and it was not exploited maliciously. The vulnerability allowed attackers to remotely start, stop, lock, and unlock vehicles, as well as access customer location history and personal data. The issue was found in the STARLINK admin panel, which is used by Subaru employees to manage customer accounts.

Main themes

  • Vehicle security
  • Connected car vulnerabilities
  • Data collection and privacy
  • Automotive industry security
  • Remote vehicle control

What commenters say

  • The ability of companies to collect and sell customer data, including location history, is a concern for privacy and security.
  • Some car manufacturers' systems are vulnerable to battery drain issues due to constant attempts to connect to the cloud, even when the car is not in use.
  • The complexity of opting out of data collection and connected services in modern vehicles can be overly complicated and frustrating for consumers.
  • There is a risk that companies may sell access to vehicle control and data to third parties, including those that repossess vehicles, which could lead to abuse.
  • The automotive industry's reliance on trust and broad access to customer data and vehicle control systems makes it difficult to secure these systems.
  • Some commenters believe that companies will exploit any opportunity to make money, including selling access to vehicle control and data, if they are not explicitly prohibited from doing so.