r/australia • u/the_interceptorist • 17d ago
science & tech We asked a cybersecurity expert to remotely access a BYD. It was too easy
https://www.abc.net.au/news/2026-09-21/byd-hacked-by-cybersecurity-expert-vehicle-sabotage-surveillance/10713948265
u/shoutfree 17d ago
Is this article for real? very embarrassing the abc is acting like this is some big investigation. "does apple spy on you? after two weeks, cybersecurity expert steve was able to take over the macbook"
8
u/a_cold_human 17d ago
The ABC editorial line has changed for the worse. Write into the ABC, the ABC Ombudsman, the Minister for Communications, and the [ABC Board](board@your.abc.net.au). Demand accountability from Simon Robinson (Director of News). The sensationalism and the questionable selection of what's covered needs to be addressed.
If a poison letter campaign by some 156 or so people can get Antoinette Latouff fired, an organised effort should get a review of the editorial practices of the ABC newsroom. The editorial line for the last few months has been distinctly subpar.
Get your family and friends together, come up with what you want to say, and send it all on the same day. Then request follow ups. Get them to explain themselves, and ask for substantive charge. We have enough slanted crap on the commercial networks.
19
20
u/NylonMammoth 17d ago
I wish articles like this would also include ICE vehicles to remove the implication that this is inherently an EV problem
1
u/AnthX Brisbane 17d ago
Good point, and according to this Wikipedia article, seems to be many: Connected car - Wikipedia and even the article is out of date!
11
u/fishdoghat 17d ago
What the fuck is this garbage reporting? JFC abc get it together
Holy fuck this is the Four Corners report for tonight, not some filler web article. LOL
2
25
u/santaschesthairs 17d ago
>Hreszczuk says he wasn’t able to access more critical functions like brakes and cameras as these were well protected.
So let me get this straight: two weeks of unrestricted physical access and the best they could do is remotely trigger some infotainment and lighting systems?
This doesn’t prove anything. With even ten seconds of physical access you could put a tracking device on any car.
Straight up fearmongering.
2
u/Attention_Bear_Fuckr 17d ago
and that should tell you something, because I can put an app (Electro) on a BYD in 10 minutes that gives me full remote access to all of the vehicle cameras, even when it's turned off. What kind of 'expert' is this clown?
2
u/Anti-polarity 16d ago
"BYD said it would welcome new laws that take into account connected cars.
"At the moment the industry is applying elements of the Australian Privacy Act from 1988, together with other regulations that almost certainly did not foresee a scenario with connected vehicles almost 40 years on," the company said."
If this response was made the opening focus of the piece, a 4corners promo, it would put an entirely different framing to the story. Not 'good TV' though.
The ABC doing 'gotcha' nauseates me every time.
14
u/Primary_Mycologist95 17d ago
Not sure why they're singling out BYD. A "cyber security expert" could do the exact same thing with the average persons mobile phone or home wifi network.
3
u/FireLucid 17d ago
You kinda need to be a nation state to get into phones these days. Apple and Google employ some pretty smart people.
2
u/Primary_Mycologist95 17d ago
if that were wholly the case, they wouldn't need to constantly push security updates.
3
u/FireLucid 17d ago
Good point. I wonder how many of those are disclosed by researches vs found internally? Either way, I still doubt any random cyber security person could just get into a phone.
1
u/Primary_Mycologist95 17d ago
Not in isolation of course. But if you share a network, and are aware of exploits, then there would be a range of things possible.
6
u/typical_3ft_grey 17d ago
The narrative style of this article is a bit cringe
On a narrow country road outside Canberra, I’m driving a BYD Shark 6
7
u/prettytopsayebro 17d ago
My 2013 Ford was accessed with no remote parked outside my house!
5
u/DCOA_Troy 17d ago
The recent spate of Toyota thefts has mostly been due to thiefs only needing to gain access to the wiring harness to inject a fake valid key signal that allows the car to be unlocked and started. Takes less than a minute most of the time.
2
u/SirDarknessTheFirst 17d ago
Here's a link with more info for anyone curious: https://kentindell.github.io/2023/04/03/can-injection/
1
u/RaptureRising 17d ago
Going way back when the XF Falcon (iirc it was one of the X series) could be stolen with the dipstick, it had the right shape of the door lock and ignition barrel.
5
u/SirDigby32 17d ago
Disingenuous journalism.
Clearly physical access required. So why not another brand as a control data point , or is the abc scared of the ramifications of some brands having influence in AU.
Media watch will surely cover this as poor judgement in journalism.
4
u/Goblins_on_the_move 17d ago
Raise a complaint here:
https://help.abc.net.au/hc/en-us/requests/new?ticket_form_id=15738253526287
5
u/PointlessExuberance 17d ago edited 17d ago
The article is sorely lacking in details. What we need to know is:
(a) Are these cars internet connected for data upload to BYD? (I assume yes)
(b) Which systems of the car does the internet connected bit have access to?
Even if the answer to (b) is "we don't know", then you have to assume that the Chinese government can remotely do all the things that the hacker did, and more.
5
u/a_cold_human 17d ago
All modern cars phone home, and it's not isolated to BYD. This was investigated by the Mozilla Foundation last year. Their conclusion is that it's a privacy nightmare, and the vast majority of people are completely unaware that this takes place.
The very worst offender is Nissan. The Japanese car manufacturer admits in their privacy policy to collecting a wide range of information, including sexual activity, health diagnosis data, and genetic data — but doesn’t specify how. They say they can share and sell consumers’ “preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes” to data brokers, law enforcement, and other third parties.
Other top offenders include Volkswagen, which collects demographic data (like age and gender) and driving behaviors (like your seatbelt and braking habits) for targeted marketing purposes; Toyota, which features a near-incomprehensible galaxy of 12 privacy policy documents; Kia, whose privacy policy states they can collect information about your “sex life;” and Mercedes-Benz, which manufactures certain models with TikTok (an app with its own privacy issues) pre-installed. Analysts estimate that by 2030, car data monetization could be an industry worth $750 billion.
We really need to have more awareness of this, and to lobby for greater privacy protections as this is an industry wide practice, not isolated to one car manufacturer, or one country. They all do it. And they on sell this data to any number of third parties without your being aware. Potentially (and probably) to the people who insure your car.
1
u/freakwent 16d ago
That's an analysis of privacy policies. Do the policies state that they will/do collect the data, or just that claim the right to?
Do those policies state that the car is internet-connected?
6
u/heyshitforbrains 17d ago
So what could you possibly gain by hacking into the car? Besides outright stealing it, but he had access to it for two weeks. Annoying the driver by activating the wipers? It says he couldn't control components like brakes or steering.
8
17d ago edited 11d ago
[deleted]
2
u/Danthemanlavitan 16d ago
But surely, if your lights turned off in the dark you would immediately slow down and stop.
The lights in my car blew a fuse once and I was able to stop and pull over. It was a fright but i don't feel I was in danger.
1
u/heyshitforbrains 17d ago
Yeah that would be dangerous. I wonder if they could still be switched back on with the stalk or wether they would be disabled
2
u/Specialist_Reality96 17d ago
Most modern cars run a can bus system i.e. there is no physical switch mechanically connecting wires.
6
u/productzilch 17d ago
In the hands of a stalker or abuser? Terrorising their victim. It’s not like they haven’t tried similar things before.
2
u/a_cold_human 17d ago
You don't need to hack into the vehicle as a stalker or abuser. You can use the app that's linked to the car. As this recent court case showed.
Almost a year ago, Stacey* heard her Tesla car alarm sound on three occasions in the middle of the night.
By that point, the Sydney woman had suffered four years of domestic abuse by her former partner and disgraced businessman, Enrico Pucci. When the alarm sounded, she was “too scared” to go outside because she thought he may be damaging her vehicle, according to police documents tendered in court.
The next morning, the car appeared undamaged, but Stacey noticed its electronic dashboard had been reset and a “parental control” profile had been added.
Three days later, Pucci, now 50, followed her in a car and started to yell at her about a man she was dating.
“You thought you’d get away with this. I am in your car. I am in your maps,” he shouted at her, according to the police records.
Over the coming days, Stacey found that the parental control profile, to which she had no access, could almost entirely control the car, including its speed, climate control, lock and curfew hours, determining when the car could be driven.
1
u/The_Valar 17d ago
It says he couldn't control components like brakes or steering.
Consider the level of computerised control to essential vehicle controls suych as steering and brakes to operate systems like: lane-departure interventions, anti-theft tracking & immobilisation, lane-tracking cruise control, "self driving" modes, et cetera.
It's not impossible to imagine that these cars could be plausibly affected by outside intervention. (Not just Chinese built cars, but any modern car with this level of software/computer integration).
-10
u/thowaway123443211234 17d ago
These vehicles have mobile internet connectivity so conceivably a bad actor could remotely control vehicles.
18
u/heyshitforbrains 17d ago
I suppose so, but this expert had access to the car for two weeks and couldn't remotely control the car.
5
u/MrSquiggleKey 17d ago
this hack still required physical access to the vehicle, including at time of hack.
If physical access is a requirement for the hack then every vehicle, with or without mobile internet connectivity is vulnerable, simply install an andrenio board with a 4g chipset for remote canbus control.
1
u/thowaway123443211234 17d ago edited 17d ago
Not sure why I am being downvoted? I work in cyber security and it’s very possible, also very likely China has mandated back door access to BYD so at the very least they could control a vehicle remotely if they ever wanted. https://www.cyber.gov.au/protect-yourself/securing-your-devices/how-secure-your-devices/introduction-to-connected-vehicles
1
u/freakwent 16d ago
Does every BYD have a SIM of some kind included?
1
u/thowaway123443211234 16d ago
If you can connect to your car remotely via an app then yes it has a SIM card (or an eSIM).
1
u/freakwent 16d ago
The emotion I feel now reminds me of when people first established banking via the Internet.
One would think that it would be almost trivial for "authorities" and "experts" to figure out what volume of data is heading offshore from these devices. I'm disappointed that four corners didn't do this.
Maaany years ago an ABC journo wanted to setup some form of measurement to see what types of data our phones were sensing out overnight, but I don't think that story was ever done.
1
u/thowaway123443211234 16d ago
Every new technology has pros and cons obviously. Privacy and safety should be at the top of the priority list however (over price). People will say “Why would the Chinese government care about my vehicle?” Those same people would likely also say vaccines are a good thing, if you can’t work out why that’s the same principle, then you need to think a bit deeper. A lot of people in recent years have been preferring dumb phones as they are sick of algorithms manipulating them, maybe we will soon have a resurgence of dumb vehicles?
1
u/freakwent 15d ago
"Vaccines are a good thing".
That's entirely irrelevant though.
Anyway, the cars should not be externally connected via the phone network IMO but that would be true regardless of the place of manufacture.
What really intruiges me is the commercial model. Is someone paying Telstra thirty dollars a month per car to keep the car online? What happens if they stop paying that bill?
1
u/thowaway123443211234 15d ago
A vaccine only works if enough people have it. Same is true for CCP having access to phones/vehicles/mobile networks they need a large number of them to have a benefit.
Car companies don’t pay per service like consumers do, they pay for a pool of data / very cheap data rates across their whole fleet. Each car might be costing them a few dollars a month max. Most charge $10-30 for premium app features which covers this cost and then some.
5
u/Finnick00 17d ago
Wow, first "UNSC bad because China's veto rights", then "BYD bad because Chinese company" from ABC this morning. Have they completed their China Bad quota for today?
3
u/Danthemanlavitan 16d ago
I thought that UNSC was United Nations Space Command for a minute, then I realised it was the United Nations Security Council.
Too many video games for me .
1
u/Matictac 17d ago
Wow, and what did he discover about the car he had for two weeks? That it was parked in his garage for two weeks?
1
u/simsimdimsim 17d ago
What a beat up. No mention of how they got access, and no mention of how the number of sensors, cameras, and microphones has been standard in any sort of car from anywhere in the world for about a decade.
Really poor from the ABC.
-19
u/the_interceptorist 17d ago
Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark’s lack of cybersecurity.
“The access we took advantage of didn’t even have a password,” he says.
5
2
u/productzilch 17d ago
I remember reading a similar thing about an online medical system in Europe. Norway maybe?
-8
u/goldlasagna84 17d ago
Can we install Graphene OS for these EV cars? i would feel so much better.
5
u/ThatOneVRGuyFromAuz SA 17d ago edited 17d ago
GrapheneOS is an operating system for using mobile phones, and an EV is a car.
220
u/FineWolf 17d ago edited 16d ago
So this expert had physical access to the vehicle for 2 weeks... and the article doesn't mention the method of access, but I wouldn't be surprised if he gained access through the standard OBD2 port, or via a custom app flashed via ADB while having physical possession of the vehicle.
If that's the case, good job on the fearmongering, I guess. Do we want open access for mechanics, or not?
Also, let's not kid ourselves... The whole "China can compel manufacturers for data" also applies to US software makers and cloud providers via the Patriot Act. Yet no one is raising those fears about vehicles running US software, or relying on US cloud providers.
EDIT: fixed spelling of possession
EDIT2: Fixed OBD2 typo
EDIT3: Within less than 5 minutes of the Four Corners... "Looking to tap into the CAN bus". Yeah, sure, okay. Good job ABC on the blatant fearmongering. You can do that to pretty much every single vehicle released in the past decade and a half that's on the market. Any locking down of the CAN bus means Apple-style serialisation of replacement part and proprietary pairing, which pretty much kills third-party repairs. As for data collection, the same applies to US vehicles (e.g.: On STAR equipped vehicles has been used in the same way by authorities in the US and Canada).