We have seen it in dozens of movies: someone explodes the glass of a car door or opens its lock using a long piece of metal, creates a bridge, and drives off with the vehicle in a matter of seconds. However, in the era of "smart cars", the modern thief knows that they only need a couple of minutes and a laptop to take a relatively recent model. How do they do it? The answer is simple: software vulnerabilities, design mistakes, and manufacturers that do not respond with the appropriate speed.

Car Theft and Connectivity: Two Worlds Starting to Clash
Jeep

The idea of replacing old security solutions with high-tech alternatives seems like a good idea until proven otherwise. The success or failure of such alternatives depends on how good their implementation is, but if we go by recent examples, the scale tends to tip toward the second option. Most systems that are considered mission critical probably have errors due to the lack of updates and audits on their code. The so-called air gap is becoming less effective at protecting a device because human contact does not disappear, and we must not forget the ever-present feature creep, which translates into software with more entry points for an attack.

Now, imagine these problems transferred to a car. In recent months, technology-assisted vehicle thefts have increased, and across the pond they indicate that Jeep has become the preferred brand for thieves. In early August, the Houston Police Department reported the capture of two hackers responsible for stealing more than thirty Jeeps in a period of six months. According to available reports, the detainees used a laptop to access Fiat Chrysler's DealerCONNECT platform (Jeep is one of its subsidiaries), and after entering the vehicle verification number, they enabled reprogramming of the security system in order to associate a generic key. Obviously, the hack requires access to the inside of the car, but it is clear that thieves have additional resources to achieve that without major inconvenience.

The Houston police also announced that the vehicles were taken out of the United States through the border with Mexico. Although the two detainees are linked to about thirty thefts, authorities speak of about a hundred similar incidents, which has already attracted the attention of the Department of Homeland Security. A Fiat Chrysler spokesperson suggested that thieves might be using stolen official tools that were given to "dealers", so the company modified the terms of use in DealerCONNECT to initiate "civil and/or criminal actions" against all those who provide unauthorized access to keys, codes, integrated anti-theft systems, and other security measures in their vehicles.

Source:

Source: