• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

2

Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45

3

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military

1

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer

2

Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45

3

Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Commentary

The Latest Security Threat Could Be Hiding in Your Car

By
David Barzilai
David Barzilai
and
Bethany Cianciolo
Bethany Cianciolo
Down Arrow Button Icon
By
David Barzilai
David Barzilai
and
Bethany Cianciolo
Bethany Cianciolo
Down Arrow Button Icon
June 4, 2016, 1:00 PM ET
on board a driving car - hood in foreground
Long exposure photograph captured with a front-mounted camera from outside the car. Streaking reflections in the car's surface and streaking background.Photograph by Emanuel M Schwermer via Getty Images

Have you ever watched a thrilling movie scene, where fear grips a driver who realizes he’s no longer in control of his car, but rather in the clutches of some far-off villain who has taken over? Ever wonder if it could actually happen? It turns out that with today’s connected cars, it’s not just a far-fetched plot dreamed up by an imaginative screenwriter, but a real possibility.

In mid-April, the U.S. assistant attorney general for national security warned that connected cars can be attacked, making them a potential target for hackers and terrorists. That warning came after a recent joint statement made by the FBI, the Department of Transportation, and the National Highway Traffic Safety Administration that warned “motor vehicles [are] increasingly vulnerable to remote exploits.”

Automotive companies and car systems providers have been taking notice, particularly after white-hat hackers demonstrated they can get into the connected cars on the road today and do almost anything, from turning on the radio and windshield wipers to killing the engine as the car flies down the freeway.

Many of today’s cars are made up of more than 100 small computers called controllers, which are responsible for running many of the car’s operations. They control the windshield wipers, move the driver’s seat, activate the airbags, run the engine, apply the brakes, etc. All of the controllers are connected to a network within the car, called a CAN (controller area network) bus.

A few controllers are available to the external world, enabling the car to connect to the Internet and external networks, such as GPS systems, cellular, Bluetooth and Wi-Fi networks. This connectivity, which is common in many of today’s automobiles, has given rise to the term “connected cars.” And it appears the connected car is here to stay: Gartner estimates there will be 250 million connected vehicles on the road by 2020.

Because the car is now connected to the Internet, Wi-Fi, etc., hackers can take advantage of those external connections to penetrate the car’s network and target its safety systems, just as they’ve done in enterprise and government data centers. In the enterprise, we continuously see attackers hack into externally connected devices, drop malware onto those devices, and then use that malware to move around the network to access and manipulate the data center’s critical resources. Using that same approach, hackers can penetrate connected cars—via the externally connected controllers—to gain access and control over all of the controllers in that car’s network. This means they can manipulate the car’s safety systems and drive or stop the car, leaving the driver helpless.

What concerns the FBI and the assistant to the attorney general the most is the potential grand scale of hacks on automobiles. For example, hackers could theoretically penetrate a single car make/model and then stop the engine of all of the cars of that make/model during rush hour. This type of coordinated hack could be used by criminal organizations or terrorists to create havoc or hold states ransom.

 

The good news is there are relatively effective solutions that can be used to protect automobiles. Unlike enterprise networks and data centers, which have many different devices connected to the Internet, cars are generally closed systems, with only a limited number of externally connected controllers. By protecting those externally connected controllers, car manufacturers can significantly minimize the risk of attackers being able to penetrate the car and disrupt its safe operations.

The industry is starting to take action, with car manufacturers and system providers strengthening their software security practices and hiring security teams. In addition, legislators proposed the Spy Car Act 2015, which is designed to ensure vehicle manufacturers in the U.S. take “reasonable measures to protect against hacking attacks” on all of a car’s “entry points,” i.e. the externally connected controllers.

The best way to protect those externally connected controllers is to ensure that nothing except factory settings is allowed to run on them. There are now open-source and commercial technologies that can be used by car manufacturers and system providers to allow only the code and applications that were approved in the factory to run on the controller. It is fairly easy to add this security software to the controller as a software update. By hardening the externally connected controller, the car cannot be infiltrated. There is no ambiguity; no false alarms; no threats.

Using this approach, connected cars on the road today can also be easily retrofitted. When cars are brought into the dealership for their annual service checks, the dealer occasionally upgrades some of the controllers’ software according to the system provider’s guidance. Vendors can take advantage of this annual cycle to add the hardening capabilities as part of a regular upgrade to the software of the car’s controllers, effectively protecting the cars from hackers.

David Barzilai is the executive chairman of Karamba Security.

About the Authors
By David Barzilai
See full bioRight Arrow Button Icon
By Bethany Cianciolo
See full bioRight Arrow Button Icon

Latest in Commentary

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Commentary

Three ways that Asia’s enterprises are adopting AI—and where they are falling behind
CommentaryOracle
Three ways that Asia’s enterprises are adopting AI—and where they are falling behind
By Garrett IlgJune 11, 2026
6 hours ago
gordon
CommentaryVenture Capital
Gordon Ritter: I predicted AI’s learning loop a decade ago. The doomers are still measuring the wrong thing
By Gordon RitterJune 11, 2026
15 hours ago
bessent
CommentarySocial Security
Social Security and Medicare are heading toward insolvency. Congress has 6 years to act
By Steve H. Hanke and David M. WalkerJune 11, 2026
17 hours ago
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
Commentarydata sovereignty
Digital sovereignty isn’t the same thing as digital isolation. Asia’s governments should be careful
By Leonard LimJune 10, 2026
1 day ago
tim
CommentaryAirline industry
Merlin CTO: autonomy can rebuild the foundation of aviation — and national security
By Tim BurnsJune 9, 2026
3 days ago
dewar
CommentaryLeadership
I founded McKinsey’s CEO practice: Here’s why operational excellence is a liability right now
By Carolyn DewarJune 9, 2026
3 days ago

Most Popular

Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
Energy
Analysts expected oil to surge above $200 but China has quietly kept prices half of that—and can’t for much longer
By Sasha RogelbergJune 10, 2026
1 day ago
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
Innovation
Marc Lore’s robots make 500 burrito bowls an hour. A human can make 45
By Amanda GerutJune 9, 2026
2 days ago
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
Asia
Pentagon accuses Alibaba, Baidu and BYD, three of China's biggest companies, of supporting the Chinese military
By Kate O'Keeffe and BloombergJune 8, 2026
3 days ago
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
Environment
Corporate America has been draining the world's water. Matt Damon's new campaign calls on Gap, Starbucks, and Amazon to help give it back
By Catherina GioinoJune 9, 2026
3 days ago
Current price of oil as of June 11, 2026
Personal Finance
Current price of oil as of June 11, 2026
By Joseph HostetlerJune 11, 2026
14 hours ago
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
Success
Costco CEO Ron Vachris rose from forklift driver to the C-suite without a college degree: ‘Don’t chase a title’ is the career advice that got him there
By Preston ForeJune 8, 2026
4 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.