It's not really a surprise that your vehicle is tracking you. Connected cars collect your exact location, your driving speeds, and plenty of other data about you. But once that data is sent to the manufacturer via the cloud, it's safe from prying hands, right? A new teardown of a vehicle's computer shows that's not the case. Your car stores that data, in some cases forever. Santa Claus Has Nothing On Your Car's Tracking Connected cars have been controversial since they first launched. If the car knows where you are, then the company knows where you are. If the company knows, then both good and bad actors can find it. Because of that danger, some countries have regulations that cover how it should be secured. The EU even has rules that demand updates over-the-air to try and help fix any security vulnerabilities that get uncovered. But it's not enough. Romain Marchand with cybersecurity consultants Quarkslab wanted to find out if they could get location data directly from a vehicle. Marchand then used that data along with open source intelligence to find shocking amounts of information. Marchand started with a Telematics Control Unit (TCU) from a BYD Seal. He picked the BYD because "some Chinese vehicles have raised security concerns; for instance, Poland has banned certain models from its military bases." The US has also implemented a ban on Chinese connected vehicle tech, though we don't have any reason to think cars from any other country are better in this way. He got a TCU from a scrapped BYD Seal and then tore it down to the bare chips. Using a custom-made adapter, Marchand and team were able to dump the contents of the TCU's memory chip. We would have expected this to be encrypted, but the paper describes it as
Modern GPS-Equipped <b>Cars</b> Track Your Every Move, And The Data Can't Be Erased
Read the original article
carbuzz.com →