Sat nav systems at risk from hackers
By Guy Matthews,
The satellite navigation systems in many cars are wide open to potentially dangerous abuse by hackers, warns a security expert.
Andrea Barisani, chief security engineer with Italian consultancy Inverse Path, says systems based on Radio Data System-Traffic Message Channel (RDS-TMC) technology are particularly vulnerable.
He says his own tests show how a hacker could get into such systems and send drivers wrong messages about where to go, and other misleading information.
RDS-TMC is used widely in vehicles across the UK, Europe and the US, typically to provide data on traffic conditions, accidents and detours. Because it does not authenticate the source of data sent to it, says Barisani, the system is open to senders of bogus information, or large amounts of data aimed at swamping it and causing a denial of service.
"I recently bought a new car with an RDS-TMC sat nav feature, which made me wonder how easy it would be for someone to detect it and then inject it with false data," Barisani said. "A colleague and I tested it and discovered it was relatively easy."
He believes there are a number of ways that navigation systems could be abused: "You could divert someone to a secondary road that you know of, and ambush them there. You could create a traffic jam by sending everyone down a narrow street. You could use it to send false terror alerts and spread alarm."
He says company car drivers could be especially at risk from competitors making them divert, or springing a denial of service attack. "A lot of professional people no doubt depend on this technology," he says.
"The trouble is that people trust sat nav," he points out. "It's not like your PC which everyone knows is vulnerable to hackers and viruses, so are wary of. Sat nav naturally inspires blind faith."
Barisani says he is amazed that there is no authentication on RDS-TMC systems: "I know some manufacturers are working on new and more secure standards, primarily for billing purposes though," he says. "These new standards will solve most of the issues but it's going to take quite some time before wide implementation and adoption."
He says he'd like to see more awareness of this, 'so at least the good guys know what the risks are before the bad guys get to work'.
Barisani and colleague Daniele Bianco plan to present their full research at next month's CanSecWest security conference in Vancouver.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Mobile Analysis & Insight
Welcome to the stay-at-home Olympics
Inside the Enterprise: The Government has warned of disruption, and the Civil Service is practising working from home. Could IT yet save businesses from chaos on an Olympian scale?
- What should RIM do to recapture the attention of businesses?
- What can Intel bring to the smartphone market?
- OK, computer
- A data shock warning for Orange customers
- Is there such a thing as a secure tablet?
- Top 10 tech winners and losers of 2011
- 2011: The year in news
- BYOD: Old or new, good or bad?
- If retailers build it, will the shoppers come?
Latest Mobile Reviews
BlackBerry Bold 9790 review
Rating: ![]()
The Bold 9790 is the latest BlackBerry to run RIM’s new BlackBerry 7 OS, but does this budget offering for business users cut too many corners to compete? Julian Prokaza finds out.
advertisement
Most popular
- Google releases Chrome for Android beta
- Will someone rid me of these troublesome Macs?
- OneNote hits Google?s Android
- BlackBerry Bold 9790 review
- Google sends in Bouncer to sort out malicious apps
- Ubuntu vs. Windows 7 on the business desktop
- Who to trust after the VeriSign hack?
- Head to Head: Mac OS X 10.7 Lion vs Windows 7
- ACTA: the basics, the controversies, and the future
- BT considering Ofcom price cap appeal
Latest News Videos in Mobile
IT PRO Podcast: CES 2011
In the first podcast of 2011, we talk with Adam Griffin of Dell and Barry Collins of PCPro about tablets, the cloud and all the other exciting...
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





