Volkswagen spent years hiding this huge security flaw

August 14, 2015, 6:12 PM UTC
Volkswagen Group Delivers Over 9 Million Vehicles In 2012
BERLIN, GERMANY - JANUARY 14: Visitors look at VW cars at a Volkswagen Group showroom on January 14, 2013 in Berlin, Germany. (Photo by Sean Gallup/Getty Images)
Photograph by Sean Gallup — Getty Images

2015 may go down as the year when we all realized that our cars are vulnerable to hackers.

First we had a report from a U.S. Senator on the security risks facing new car owners, and then the news that Fiat had recalled 1.4 million cars to address security flaws. And this week a paper is being presented at the USENIX security conference in Washington, D.C., on a security flaw affecting “thousands of cars from a host of manufacturers,” according to a Bloomberg News report.

We could have known about these risks for some time, as the paper was actually written two years ago, but car makers like Volkswagen fought in court to keep the information private. According to Bloomberg:

“Keyless” car theft, which sees hackers target vulnerabilities in electronic locks and immobilizers, now accounts for 42 percent of stolen vehicles in London. BMWs and Range Rovers are particularly at-risk, police say, and can be in the hands of a technically minded criminal within 60 seconds.

Security researchers have now discovered a similar vulnerability in keyless vehicles made by several carmakers. The weakness – which affects the Radio-Frequency Identification (RFID) transponder chip used in immobilizers – was discovered in 2012, but carmakers sued the researchers to prevent them from publishing their findings.