Software updates, the next step in security

actualizaciones-software-seguridad-20162

Update of software of a Tesla Model S – Image: @TeslaPittsburgh

The electronics came to about 80 for the car, and is currently implementing the information technology. Several functions of the vehicles begin to be delegated to computers in the classical sense of the term: have operating system, a hardware (physical components), software (programming)… and errors that will affect the user experience.

Some models are beginning to be connected to the Internet constantly, to be able to control some functions remotely. They are primarily plug-in hybrids and electric, and the owners can control the air conditioning, open or close doors, or have the exact location. This has its bad side, increases the vulnerability to pirates and crackers, but has its positive side.

In some instances, the manufacturers have to make modifications in their cars, having detected a potential safety issue, as unlikely as that is. For example, the Tesla Model S received an update to not move with the suspension so lowered and so as to avoid hitting objects abandoned on the roadway and suffered a fire.

agujeros-de-seguridad-en-los-coches-cone

When a call is made to review, passes a time until the clients pass through the service, even if it is free and has no small print in the warranties or fidelity to the house. And it also happens that some clients do not know about the revisions, or they find out and they do not perform.

Spend per workshop is inevitable for the replacement of physical parts or readjustment, such as steering columns, screws, inflators, airbag, etc, however, it is not essential that the vehicle arrives at the workshop to do a reprogramming of any of its functions; it would be sufficient with a service updates remote.

can Be updated remotely through Internet connection of the own vehicle (via WiFi in a garage, or with a mobile phone with a data connection), or with USB drives that the client prepares downloads from the manufacturer’s Website. This latter method is less convenient, but it is a little more secure. All that is accessible to critical areas of the car should be done with caution.

bmw-evita-que-puedan-hackear-tu-coche-20

The models of Tesla have Internet connection and can be updated remotely in a very few steps, securely, for which the owners receive improvements of functionality that the car did not have, but they don’t require new parts. This system could save many lives before bugs.

In the united States we have a good example, the recent death of actor Anton Yelchin. Was run over by his own Jeep Grand Cherokee to get out of the car, believing that the automatic switch was in position “P” (parking), but in reality it was in neutral “N”. He had the bad luck to park in a slope, and after a few seconds, the car rolled down and hit her. He could not do anything for him.

The problem was already known by the manufacturer, Fiat Chrysler Automobiles, and had already made a call to review. For whatever reason, that car did not go through an official service, so that you did not receive an improvement software that prevented the car to follow in “N” if you open any of the doors. There are audible and visual warnings to alert you of this, but it was not enough.

jeep-cherokee-hackeado-201522371_1.jpg

To the obvious concerns are for the safety, say that there are systems sufficiently reliable as to ensure that only the manufacturer will have access to critical functions of the vehicle, such as cryptography public/private key. In fact, there are models of ACF that have been hacked, and distance have been able to apply brakes or turn on windshield wipers. why the manufacturer doesn’t do that same with a good end?

Some calls to review could be resolved in a matter of a few days if there are systems of remote update. it Is much faster to send an update by the Internet to wait for hundreds of thousands of customers pass by the official services. In addition, economically it is very interesting, because it would save thousands of hours of labor that cannot be charged to the customer.

Can with the time we finish seeing this type of progress in our cars. Anyway, it is not a magic solution, as there will be customers who choose not to update, for any reason, and the problem persists. Finally, it should be expected that do not pass as with some operating systems of computer, the security updates leave the machine unused for several minutes, even an hour or more. When that happens with much frequency, it becomes a real nuisance.