Ruminations

Blog dedicated primarily to randomly selected news items; comments reflecting personal perceptions

Thursday, September 05, 2013

Heading Off Hackers

"The more technology they add to the vehicle, the more opportunities there are for that to be abused for nefarious purposes. Anything with a computer chip in it is vulnerable, history keeps showing us."
Rich Mogull, Securosis, Phoenix

"We could control steering, braking, acceleration to a certain extent, seat belts, lights, horn, speedometer, gas gauge."
Chris Valasek, Pittsburgh computer security consulting company

If anything could go wrong in mechanical systems, it may do just that. Sometimes spontaneously, sometimes from fatigue of use, and sometimes as a result of skilled computer hackers entering a system and corrupting it to reflect their orders not the designed and inputted orders programmed to operate all the systems of a motor vehicle. What was once purely mechanical in design and function has been replaced with far more advanced computer-designed software in the control of mechanical functions.

Driving has become much more effortless, more pragmatically simplified for the driver and in some ways perhaps safer. But with less to be preoccupied with in the maintenance of one's driving skills attention can so easily become diverted because the driver is bored, and looks to other mind-absorbing things to round out his attention. Like, for example a cellphone; Bluetooth making even that more accessible

Our vehicles now resemble in function if not yet form, personal-computers-on-wheels. And since they're so profoundly computer-driven now, what makes them any less vulnerable than desk-top or laptop computers to the frustrating malicious intervention of hackers? The thing is, who might it even have occurred to, that what could be done with an ordinary computer could also be done with function-computerized vehicles?

There appears not yet to have been any reports of criminal hackers actually managing to manipulate the internal network of a car. But it has been done, and quite effectively, by computer security experts who have deliberately set out to test the access-vulnerability of vehicle-based computer networks. Their success didn't come easily. It took concentration and time, lots of it, for them to succeed, but succeed they did.

Demonstrating that high-tech hijackings could be just around the corner. Even, perhaps, demonstrations of road rage embarked upon by the skilled sociopath. And experts claim that these intrusions will become even easier as auto manufacturers give their products full Internet access, adding computer-controlled safety devices taking over more and more driving functions.
In pics: Top 10 ultra-luxury cars
A technically skilled thief might discover how relatively easy it may be to unlock the doors of your vehicle and jauntily drive off with it. The last twenty-five years has seen automakers gradually embrace computerized functions like steering, braking, accelerating and shifting. There is greater performance reliability in electronic gas pedal position sensors than in the old throttle cables.

In the advances toward using less fuel in cars, electronic parts reduce the weight of the finished product as an additional bonus. Hackers have been able to convincingly demonstrate their capability of slamming a car's brakes at freeway speeds, pull the steering wheel one way or the other, shut down the engine ... from the vantage of their laptop computers. All cars and trucks possess from 20 to 70 computers.
In pics: Top 10 ultra-luxury cars
In one instance a pair of hackers manipulated two vehicles by plugging a laptop into a port beneath the dashboard. The very place where mechanics connect their computers in an effort to electronically search out operating problems in vehicles. Yet another group of hackers took control of a car's computers through cellular telephone and Bluetooth connections, the compact disc player, even the tire-pressure monitoring system.

The idea behind all of this effort, taken up by security experts was to make vehicle manufacturers fully aware of just how potentially vulnerable their products are to malevolent intrusion. Ford Motor Co. defensively said it takes the issue seriously indeed. Toyota responded by assuring it has added security and tests regularly to ensure its products advance safety beyond the reach of hackers.
In pics: Top 10 ultra-luxury cars
Its computers, they stated, are programmed to recognize rogue commands and to reject them. Reassuring, isn't it?

Labels: , , , ,

Thursday, August 15, 2013

Cyber-Vulnerable Insecurity

"Even though the current priority in Canada is international terrorism, there are growing concerns about the cyber-instrumented attacks attributed to government-backed hackers from China and Russia.
"Various state players have developed cyber resources that pose a significant threat to systems and programs deemed important to national security and economic stability. Once largely confined to government and military targets, malicious malware programs now threaten all forms of critical infrastructure including electric grid and telecommunications networks.
"Given the ever-growing relevance of ICT (information and communications technologies) for the economy and society as a whole, and the growing incidence and diversity of threats to which Canada is being subjected, a more aggressive approach and dynamic leadership are warranted if loss of public confidence in ICT and the government itself is to be avoided."
Angela Gendron, Carleton University, Canadian Centre of Intelligence and Security Studies
Professor Gendron's assessment of risks and dangers facing Canada through digital technologies, published in the Canadian Foreign Policy Journal, brings home in a very obvious way the country's vulnerabilities to foreign meddling, and much worse; malicious corruption of the many areas of infrastructure upon which we rely. From government itself, to public utilities, communication grids, transportation networks, energy transmission and finance.

Where once for those civil sectors and systems to work, human ingenuity, physical manoeuvring and hands-on dedication were relied upon, computer/Internet technology has intervened. Physical defences and geography itself could be relied upon for defence, once. Now that countries, including Canada are so committed and heavily interconnected, cyber-dependent, networked, we are increasingly vulnerable in an entirely different and far more dangerously involved manner. The consequences are greater, and difficult to predict, let alone protect against.

Just-in-time supply chains that have become so wide-spread, instead of stocking and warehousing for maximum profit and reliance even effect all of our distribution capabilities, inclusive of our water supplies, energy and finances. All vulnerable to malicious cyber-attacks. Such 'enemies' could be represented by other, foreign nations with whom relations are less than compatible, to criminal hackers and even cyber-jihadists.

We do have a fairly good idea of what it is like to be without electricity for a prolonged period. When nothing works without power. When, for example, a decade ago, a random event occurred when a power line touched foliage causing a generating station in Ohio to trip and shut down. A mechanical alarm meant to alert operators to the need to shut down power malfunctioned, and electricity surged through interconnected transmission lines among states and provinces between the U.S. and Canada.

It took sixty seconds for power to fail, cascading across 24,000 square kilometres, leaving over 50-million people without electricity as over one hundred power plants, including 22 nuclear plants and 300 transmission lines to shut down in a massive outage. It was the largest, most prolonged blackout experienced to date, and not a very welcome occurrence, disrupting countless lives, sending people into panic mode, and discommoding communities and governments alike.

The issue of cyber-security is complex and vexing: 90% of Canada's critical infrastructure is privately owned. No common, never mind mandatory security standards are in place. Global interconnectedness and interdependence relating to a myriad of sectors place just about everyone at potential risk. A global solution is called for; at the very minimum, vast international co-operation, to face the growing problem.

In Canada no department or agency in the intelligence and security community has been assigned - or acknowledges such an assignment - for a cyber-warfare research program, according to Professor Gendron. In the United states a new U.S. Cyber Command responsible for defence of cyberspace has been launched as an operational domain, capable of military retaliation in cyberspace.

The dimensions and consequences of the issue are overpoweringly difficult to comprehend.

Labels: , , ,

 
()() Follow @rheytah Tweet