in

German Teen Hacks Tesla’s and Gains Control of Key Features

German Teen Hacks Tesla’s and Gains Control of Key Features

The autonomous car manufacturer has 25 vehicles hacked by a 19-year old security researcher through a third-party software provider.

His name is David Columbo, and he is a German teen that has exploited 25 Tesla autonomous vehicles in 13 countries around the world. The 19-year-old security researcher and coding professional recently declared that he exposed significant vulnerabilities in Tesla’s connected keyless entry and driving systems. He stated that he could remotely unlock doors and windows, control the cars’ stereos, flash car headlights, and even start their engines to begin navigation.

According to a Bloomberg report, the teen hacked a third-party software that Tesla uses, a method that hackers have had a lot of success within many of the most notable breaches worldwide. The real issue with the third-party software is the information that the car owners share with the provider. Columbo was unwilling to provide additional information as he is a whitehat hacker and tests security flaws to bolster security.

Are Tesla’s More Prone to Cyber Breaches?

Almost all modern cars are basically computers on wheels, making them prone to hacks at a software and a hardware level. Hardware attacks are often more challenging to detect than software attacks. Unlike software attacks, which come with anomalous behavior, a hardware attack means that the malicious chip(s) or device will have to be physically found. This can make the lifecycle of a hardware attack significantly longer. In the case of hardware attacks against a Tesla, it could be devastating, as the hardware opens up a backdoor for further software attacks – and the vicious cycle continues.

Data can be in three states depending on its movements: data at rest, data in use, and data in motion. All data kept on devices that are not transmitted from device to device or network to network is referred to as data at rest. It includes data saved directly on hard disks and data stored in databases, file systems, and storage infrastructure. Data in use is data that is being updated, processed, erased, accessed, or read by a system right now and is kept in IT infrastructures like RAM, databases, or CPUs. This form of data is not stored passively but rather in a very active manner. Data in motion, also known as data in transit, is information going from one location to another.

As a result, data in transit is regarded as less secure. It is vulnerable to Man-in-the-Middle (MITM) cyberattacks that target data as it travels, not only because it is exposed to transfer across potentially unsecured routes but also because it leaves the security of enterprise networks going to potentially less secure locations.

Data at rest is deemed less dangerous than data in motion since it is not exchanged over the internet and remains inside the constraints of enterprise networks and security frameworks.

On the other hand, data at rest is more appealing to cybercriminals because it ensures a larger payout than tiny data packets in transit. Malicious insiders attempting to harm a company’s reputation or steal data before moving on to a new job frequently target data at rest.

Even while data at rest isn’t sent via the internet, it nevertheless travels. Data at rest is put in a particularly vulnerable position during the COVID-19 pandemic, as more and more work computers are taken out of the security of office settings and into the limited security capabilities of home environments.

Enterprises and even small and medium-size organizations spend billions of dollars annually at attempts to protect their “crown jewels.” However, no matter how hard they try, we still read about record-breaking data breaches, hacks of millions of IoT devices (connected devices), and more.

How to Safeguard Data in Transit vs. Data at Rest

Both data at rest and data in motion have their own set of concerns in terms of security. While data in motion is inescapable, many businesses have attempted to limit the local storage of sensitive company data by establishing Virtual Desktop Infrastructures (VDIs) and Desktop-as-a-Service (DaaS) platforms. These solutions, however, come with their own set of data security problems.

To protect data at rest from external threats, basic cybersecurity measures such as firewalls and antivirus software are necessary. Until now, many car manufacturers have been using similar security solutions, which is not a good thing as threat actors can reverse engineer and implement techniques faster than many of these solutions can patch vulnerabilities.

Solutions like Upstream Security and its Cybersecurity & Data Management Platform for Connected Vehicles are backed by BMW, Volvo, Hyundai, Renault, Nissan, Mitshubishi, etc. Still, many of these companies have reported hacks over the last few years.

Another popular defense solution is IBM’s Cloud Pak for Data Systems, which uses SSD disks as the primary storage medium. Together with a range of other costly solutions, it may have effectively protected the Teslas from hacks such as Columbo’s.

Still, both of these solutions require regular maintenance and, in many cases, an entire team of cybersecurity professionals to operate them correctly.

There is, however, another option.

Hub Security has developed the ultimate holistic security solution to encrypt data-at-rest and data-in-motion. Its proprietary Hardware encryption solutions and Data-in-use encryption are military-grade products implemented across major enterprises. Advanced attacks against Lo4j utility are useless with the Hub Security solution. Hub Security would have made Columbo’s attempts at breaching Tesla ineffective.

A dual application will end the need for the myriad of cybersecurity solutions that, until today, have not lived up to their promises. As threat actors implement innovative ways to hack and reverse engineer products and software, so too must be the solutions chosen to protect the crown jewels, which is why Hub Security has approached things completely different from existing cybersecurity companies.

Source: www.techtimes.com

Report

What do you think?

486 Points
Upvote Downvote

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

GIPHY App Key not set. Please check settings

Aurora partners with U.S. Xpress to refine driver-as-a-service product

Aurora partners with U.S. Xpress to refine driver-as-a-service product

(video) German expat family discoverying Robotaxi in Shenzhen