That ABC BYD “hack” deserves a lot more context.
The vehicle was handed to a cybersecurity expert for TWO WEEKS specifically so he could find a way into it. The ABC then demonstrated the attack under controlled conditions.
Yet the headline is “We got a cybersecurity expert to hack this BYD. It was too easy.”
What actually happened?
The expert gained access to functions including lights, wipers, speakers and infotainment. But he could NOT access critical systems such as the brakes, which the ABC itself says were well protected.
Then there’s the dramatic Siri demonstration. The journalist deliberately left an UNLOCKED iPhone in the vehicle after the hacker had recorded his voice. The car speakers were then used to play commands to Siri.
That hardly demonstrates some uniquely Chinese EV vulnerability.
Connected cars, remote apps, microphones, GPS, cellular connections and OTA software aren’t unique to BYD or even EVs.
In fact, the ABC eventually gets to the real issue: Australia has no minimum cybersecurity standards for connected cars, and former national cyber security adviser Alastair MacGibbon called for better protection of data collected by ALL connected vehicles.
So test BYD. Absolutely.
But apply the same methodology to Toyota, Tesla, Hyundai, Ford and every other major connected vehicle manufacturer and publish the results.
Cybersecurity standards should be based on technology and demonstrated risk, not whether there’s a battery under the floor or which country appears on the badge.
That would be a genuinely useful investigation.