Mitsubishi Outlander Just The Latest 'Smart' Car That's Trivial To Hack And Control

from the not-so-smart dept

Yet another vehicle heavily advertised as being "smart" has proven to be notably less secure than its older, dumber counterparts. This week, researchers discovered that flaws in the Mitsubishi Outlander leave the vehicle's on-board network vulnerable to all manner of hacker attack, allowing an intruder to disable the alarm system, drain the car's battery, control multiple vehicle functions, and worse.

The app for most "smart" vehicles connects to a web-based service hosted by the manufacturer. This service in turn connects to a GSM module inside of the automobile, letting a user control the vehicle from anywhere. While convenient, this has proven to be problematic when poorly implemented -- something Nissan recently discovered after the company failed to implement any real authentication, letting an attacker use the Leaf app to track a driver's driving behavior, physically control the Leaf's heating and cooling systems, and drain the car's battery.

Analysis of the Mitsubishi Outlander's security flaw found that Mitsubishi did things differently, requiring users connect to an on-board Wi-Fi hotspot before controlling the vehicle using the associated app (presumably to save money on an online hosting service). But the researchers found that the Wi-Fi key was relatively trivial to hack:
"The Wi-Fi pre shared key is written on a piece of paper included in the owners’ manual. The format is too simple and too short. We cracked it on a 4 x GPU cracking rig at less than 4 days. A much faster crack could be achieved with a cloud hosted service, or by buying more GPUs."
Given the embedded access point has a unique SSID, an attacker can use public resources like Wigle.net to easily geolocate any Outlander PHEVs they might like to target. With the PSK and the SSID, the security firm was able to compromise the remainder of the car's rudimentary security using a man-in-the-middle attack to sniff the traffic flowing between the car and the app. Once inside, researchers noted that like the Leaf hack they could drain the car's battery, turn various vehicle functions on and off, and turn off the alarm. But they also note the vulnerability goes much deeper than with the Leaf:
"Once unlocked, there is potential for many more attacks. The on board diagnostics port is accessible once the door is unlocked. Whilst we haven’t looked in detail at this, you may recall from a hack of some BMW vehicles which suggested that the OBD port could be used to code new keys for the car. We also haven’t looked at connections between the Wi-Fi module and the Wi-Fi module and the Controller Area Network (CAN). There is certainly access to the infotainment system from the Wi-Fi module. Whether this extends to the CAN is something we need more time to investigate."
Like with so many vulnerabilities, the researchers say that when they brought the problem to the attention of Mitsubishi, the company showed "disinterest" in a dialogue. At least until they contacted the BBC, at which point Mitsubishi got chatty:
"Initial attempts by us to disclose privately to Mitsubishi were greeted with disinterest. We were a bit stumped at this point: As so often happens, the vendor takes no interest and public disclosure becomes an ethical dilemma. So, we involved the BBC who helped us get their attention. Mitsubishi have since been very responsive to us! They are taking the issue very seriously at the highest levels."
We've noted for a few years now that in-car security -- as with most products on board the "internet of things" hype train -- is aggressively atrocious. And it's not really clear it's getting any better despite several government warnings and bad press. Many car manufacturers still aren't quick to respond to disclosures, and even if they can, they often take far too long to patch problems when found. That's of great benefit to government, private or criminal entities that surely appreciate the easy new way to spy on, stall or even potentially kill via methods most police departments likely don't have the chops to adequately investigate.


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • identicon
    Anonymous Coward, 9 Jun 2016 @ 5:02pm

    Four days of cracking to get the key may not be "trivial", but it's still a huge problem.

    reply to this | link to this | view in chronology ]

    • identicon
      Anonymous Coward, 9 Jun 2016 @ 11:01pm

      Re:

      consider those 4 days as "advance preparation" for stealing a car. You don't even need to be near the car to find it out.

      Since the key is computed from the WiFi SSID, you can use publicly accessible wireless SSID databases (e.g. https://wigle.net/ or similar) to look for car-specific WiFi SSIDs, compute the wireless key in advance, even from halfway around the world, then just send a goon squad armed with that pre-computed key and steal the car in less than 2 minutes.

      reply to this | link to this | view in chronology ]

    • icon
      Karl Bode (profile), 10 Jun 2016 @ 9:00am

      Re:

      Well, they also proceed to note "a much faster crack could be achieved with a cloud hosted service, or by buying more GPUs."

      reply to this | link to this | view in chronology ]

  • identicon
    Anonymous Coward, 9 Jun 2016 @ 5:14pm

    It's no surprise that Mitsubishi wasn't interested until the press got involved, like most of the internet of things auto makers have shown little interest in actually securing their products and would rather push heavily for legislation that makes it illegal for people to work on their own vehicles or to tinker with the onboard computers. They feel that is good enough and of course then they won't have to spend money for security. Which is insane and short sighted but unfortunately that's their mindset now and I think it's going end up taking some bad guys hacking into vehicles and causing a few large accidents before they are finally forced into dealing with it and putting in real security.

    reply to this | link to this | view in chronology ]

  • identicon
    Anonymous Coward, 9 Jun 2016 @ 7:09pm

    Just give me a plain old vehicle with no smarts to it at all. Seems they are the most secure.

    While I'm at it, forget the IoT since none of the makers have time for security during the programming to create these toys. I want something that when I buy it, like a thermostat for instance, continues to work until it is worn out. Not when the maker decides it will no longer support the product and force you to purchase a new replacement. As far as I am concerned, I want something that just works and not connected to the internet or wifi is a plus when it comes to features.

    reply to this | link to this | view in chronology ]

    • icon
      nasch (profile), 10 Jun 2016 @ 9:29am

      Re:

      Just give me a plain old vehicle with no smarts to it at all. Seems they are the most secure.

      I'd say OBD-II counts as smarts, and that's been mandatory since 1996, so you can't have anything newer than that.

      reply to this | link to this | view in chronology ]

    • icon
      John Fenderson (profile), 13 Jun 2016 @ 6:47am

      Re:

      "Just give me a plain old vehicle with no smarts to it at all."

      It's not the smarts that are the problem -- it's the connectivity.

      reply to this | link to this | view in chronology ]

  • icon
    Spaceman Spiff (profile), 9 Jun 2016 @ 8:48pm

    It's all cost and time to market

    Security is hard. Good security is really hard. Just ask Bruce Schneier. It costs money, and takes a lot of time and development resources to get it right. Car companies, and others, are pressured to get these products to market quickly, so security is given short shrift, to the detriment to their customers. At the least, they could provide an OFF switch to disable all remote internet or other wireless access other than the hardware key that the driver has to have on their person in order to get into or lock the vehicle. I think I will keep my '99 Camry until it falls apart. 250,000 miles and it still runs like a Swiss watch, burns no oil, and gets 25 city and 30+ mpg on the highway.

    reply to this | link to this | view in chronology ]

  • icon
    lazbo (profile), 10 Jun 2016 @ 5:32am

    Don't give them more ideas

    "That's of great benefit to government, private or criminal entities that surely appreciate the easy new way to spy on, stall or even potentially kill via methods most police departments likely don't have the chops to adequately investigate."


    Chops? The police are undoubtedly champing at the bit to *use* the exploit. Imagine, no more high speed chases; just hack into the fleeing car and take control.

    reply to this | link to this | view in chronology ]

  • identicon
    Skeeter, 10 Jun 2016 @ 7:39am

    Smart Car Oxymoron

    From '24/7 connected' cars that offer you almost all the computing convenience of home, to self-driving cars that (apparently) most politicians want to license sight-unseen, because some billionaire promised them a few campaign dollars; it's easy to see this deep 'profit-pool' of low-hanging criminal fodder, combined with the opportunity to indiscriminately kill thousands through unproven tech.

    The next time someone wants a 'self-driving' car, ask them 'and when's the last time you found an error on your GPS, because that's what 'drives' a self-driving car?'

    reply to this | link to this | view in chronology ]

    • icon
      nasch (profile), 10 Jun 2016 @ 10:04am

      Re: Smart Car Oxymoron

      The next time someone wants a 'self-driving' car, ask them 'and when's the last time you found an error on your GPS, because that's what 'drives' a self-driving car?'

      You know they have cameras and others sensors, and don't just rely on GPS, right? Your self driving car might take you to the wrong place because of a GPS error, but it's not going to drive you into a lake because of one.

      reply to this | link to this | view in chronology ]

  • identicon
    Anonymous Coward, 10 Jun 2016 @ 12:54pm

    It's done on purpose. They want the "authorities" to control every car. They don't car if "bad guys" do the same.

    reply to this | link to this | view in chronology ]


Add Your Comment

Have a Techdirt Account? Sign in now. Want one? Register here
Get Techdirt’s Daily Email
Use markdown for basic formatting. HTML is no longer supported.
  Save me a cookie
Follow Techdirt
Special Affiliate Offer

Advertisement
Report this ad  |  Hide Techdirt ads
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Chat
Advertisement
Report this ad  |  Hide Techdirt ads
Recent Stories
Advertisement
Report this ad  |  Hide Techdirt ads

Close

Email This

This feature is only available to registered users. Register or sign in to use it.