BMW has released a patch to fix a security flaw in the ConnectedDrive system which is available in 2.2 million cars including Rolls-Royce and Mini.
The problem was discovered by ADAC in 2014, but wasn’t publicised until BMW had a fix in place. It would have potentially allowed hackers to be able to open car doors, but your car security will be updated as soon as your vehicle next connects to BMW servers. The improvements include the addition of HTTPS – the secure transfer protocol used for banks and eCommerce sites etc, to protect data being transmitted via ConnectedDrive.
There were no recorded cases of any hacking attempts before the new encryption was put in place, and no driving functions were in any way impacted.
But it highlights the increasing risks of connected vehicles with regards to security. Given that Tesla can adjust the acceleration of their vehicles via an automatic update, and BMW was sending data without HTTPS, it seems that you’ll need to be as much of a software security geek as a mechanic in future. Will the convenience of connected electric vehicles be outweighed by having to download anti-virus updates every time you stop?

Leave a Reply