Skip to main content

OnStar hacking issue resolved, General Motors says

onstar hacking issue resolved general motors says remotelink03 medium
Image used with permission by copyright holder
About two weeks ago, a hacker exposed a vulnerability in General Motors’ OnStar telematics system that could allow ne’er-do-wells to remotely seize control of vehicles. GM has been implementing a fix to the problem, is now certain it is under control.

“We’re confident the issue is closed,” Terry Inch, GM’s OnStar chief, said in an interview with WardsAuto at a recent OnStar press event. GM began deploying its software fix almost immediately after the issue became public, and now believes the vulnerability has been completely eradicated.

Recommended Videos

Uncovered by researcher Sammy Kamkar, the vulnerability allowed hackers to break into a car’s onboard systems using the OnStar RemoteLink smartphone app. Chamber used a device positioned on the victim car to harvest credentials, and then use those credentials to mimic the app.

Since the app allows drivers to do things like remotely lock and unlock doors, or start the engine, those powers would be conferred to the hacker. GM has since added a patch that allows the OnStar system to check for fake access certificates, something it wasn’t programmed to do before.

“We feel the vulnerability is taken care of by downloading the new RemoteLink app,” GM’s Inch said. However, he cautioned that future hacking episodes are still possible, saying that “we can’t say something like this will never happen again.”

Inch said GM is always looking into ways to improve the system, including working with universities and government agencies to identify additional possible weak points, and to pre-empt any future hacker attacks.

The OnStar hack came hot on the heels of a vulnerability in Chrysler’s Connect infotainment system that allowed researchers Charlie Miller and Chris Valasek to remotely take control of a Jeep Cherokee. Fiat Chrysler Automobiles is recalling 1.4 million vehicles to implement a software fix.

Perhaps the most tech-heavy car on the market, the Tesla Model S, also became a victim recently. At the recent DefCon convention in Las Vegas, hackers Kevin Mahaffey and Marc Rogers claimed they were able to break into a Model S and control certain functions, including remotely shutting the car down.

As cars become increasingly connected and computerized, it seems the same vulnerabilities that plague smaller-scale electronic devices are creeping into dashboards. Consumers may soon have to decide if connectivity is worth the price of safety.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
Tesla and Elon Musk sued over use of AI image at Cybercab event
tesla and spacex CEO elon musk stylized image

Tesla’s recent We, Robot presentation has run into trouble, with one of the production companies behind Blade Runner 2049 suing Tesla and its CEO, Elon Musk, for alleged copyright infringement.

Tesla used the glitzy October 10 event to unveil its Cybercab and Robovan, and also to showcase the latest version of its Optimus humanoid robot.

Read more
Qualcomm wants to power your next car with the Snapdragon Cockpit and Ride Elite platforms
Qualcomm Snapdragon Cockpit Elite and Ride Elite automotive platforms

It’s been a big year for Qualcomm. Alongside its massive launch into laptop chips through the Snapdragon X Elite series, Qualcomm is now entering the automotive space. The company has announced the new Qualcomm Snapdragon Cockpit Elite and Snapdragon Ride Elite platforms at its annual Snapdragon Summit, which it flew me out to attend.

The two platforms are designed for different purposes, and can be used togetheror separately. The Snapdragon Cockpit Elite is built for in-vehicle infotainment systems and services, while the Snapdragon Ride Elite is built to power autonomous vehicle systems, including all the cameras and sensors that go into those systems.

Read more
Scout Traveler and Scout Terra forge a new path for EVs
Scout Traveler and Scout Terra.

Electric vehicles are inseparable from newness, whether it’s new tech, new designs, or new companies like Rivian, Lucid, and Tesla. But the Volkswagen Group’s new EV-only brand also relies heavily on the past.

Unveiled Thursday, the Scout Traveler electric SUV and Scout Terra electric pickup truck are modern interpretations of the classic International Harvester Scout. Manufactured from 1961 to 1980, the original Scout helped popularize the idea of the rugged, off-road-capable utility vehicle, setting the stage for modern SUVs.

Read more