What made the remote compromise of a car's driving systems possible, and why is it the reference case for IoT safety risk?
The vehicle's internet-facing entertainment system could reach the internal CAN bus, so crafted messages to the electronic control units disabled brakes, turned the steering and altered cruise control — on a car being driven.
* A compromised connected front end and a direct local connection are distinct routes to the CAN network; safety functions need protection from both. *
Chrysler recalled 1.4 million vehicles after researchers hijacked a Jeep's digital systems both locally and over the internet. Once they could speak to the internal network, they could:
- Disable the brakes at low speed, by sending crafted messages on the vehicle's internal network (the CAN bus, the shared serial bus that carries messages between a car's control units), causing unintended acceleration and slamming the brakes.
- Affect steering under the conditions of the demonstrated attack. Speed and gear restrictions differ between the original remote attack and later local CAN-bus experiments; these are not one unrestricted remote capability.
- Turn on and alter the cruise control settings.
How it worked: attacks arrived either over the internet or from a laptop plugged directly into the CAN network. From there they targeted the electronic control units (ECUs) — the small computers that run individual vehicle functions — sending them malicious commands and overwriting contradicting signals, for example the signal telling the parking brake not to activate.
The structural flaw is one that recurs across IoT: a flat internal network behind a connected front end. The CAN bus was designed in an era when everything attached to it was trusted and physically inaccessible; it has essentially no authentication, because it did not need any when nothing on it could reach the outside world. Adding a cellular-connected infotainment unit to that bus, without a hard boundary between them, exposed a trusted-by-design network to the internet.
This is the case that makes "danger to health and safety" concrete. A compromised database leaks records; a compromised brake controller does not.
Tip: the transferable question for any connected product is "what does the internet-facing component get to talk to?" Segmentation between the connected part and the safety-critical part is the control that was missing here.
Go deeper:
Wikipedia — CAN bus — why the internal bus was defenceless: a broadcast protocol with no intrinsic security features and no encryption in standard implementations.
Wikipedia — Automotive hacking — this case in its wider field, alongside the other attack paths into a modern vehicle.