- As it turns out, the documentary gave a “hacker” two weeks to work on a Shark 6.
- BYD says he installed an untrusted third-party application into the infotainment system.
- The documentary failed to acknowledge the security concerns about all new cars, not just BYDs.
BYD has quickly responded to cybersecurity concerns about the popular Shark 6 pickup truck following the release of an Australian documentary, which revealed how easily it could be hacked. The Chinese brand has also clarified how a hacker gained control of the plug-in hybrid’s headlights and windshield wipers.
As part of the ABC’s Four Corners program, cybersecurity expert Dan Hreszczuk was given a Shark 6 for two weeks and was able to listen in to the interior microphones, take control of the door locks, and mess with the Shark 6’s audio. To avoid giving any other hackers any bad ideas, details about how Hreszczuk hacked into the BYD weren’t disclosed.
Read: A Hacker Took Control Of A BYD For TV, But Should You Be Worried?
BYD says it’s found out how he did it. To hack into the truck’s infotainment system, it says he breached the Android Debug Bridge (ADB) with a special tool and installed an untrusted third-party application. BYD was able to replicate this vulnerability in its own testing but says for a hacker to gain access to a vehicle’s location data and microphone, the driver must accept a permission prompt that will be displayed on the screen, something the documentary didn’t disclose.
To address this vulnerability, BYD says it’s working on an over-the-air software update that will remove the pathway used to enable the ADB, which is ordinarily disabled. It hasn’t said when this update will be ready, but says if similar vulnerabilities are found in its other models, they too will get the new software.
What The Documentary Didn’t Tell You
Then there’s the matter of the headlights and windshield wipers. In the Four Corners program, the hacker was shown remotely turning on the wipers and then turning off the headlights as the Shark 6 was being driven at night. According to BYD, gaining control of these functions required far more than installing some third-party software.
It says the hacker tapped into the vehicle’s wiring and accessed the internal CAN bus, which obviously isn’t something a hacker sitting behind a computer screen can do. Hreszczuk confirmed in a blog post that he spliced into the Shark 6’s wiring and installed a low-cost Raspberry Pi computer, something that could be replicated on plenty of other new cars.
To minimize the chance of any would-be hackers using an OBD device to gain access to critical vehicle functions, BYD says it has implemented new security measures for the OBD interface. Now, it will require physical isolation and device authentication.
