Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Creată 1mo | 23 ian. 2025, 21:10:03


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

Trump promised to keep spying agencies in check. Then he fired the watchdogs he appointed

President Donald Trump vowed to fight government abuse and introduce more transparency, a stance that might align him with a little-known agency charged with watching over the U.S.’s powerful spyi

27 feb. 2025, 15:30:03 | Fast company - tech
Meme coins aren’t just harmless fun

For some time, meme coins have occupied a peculiar space in online culture. While there are peopl

27 feb. 2025, 13:10:06 | Fast company - tech
Yope wants to be your inner circle’s Instagram

Yope is the latest photo-sharing app vying to take on Instagram and TikTok.

The pitch? A hybrid of a private Instagram and a group chat. While WhatsApp and Snapchat allow for group messa

27 feb. 2025, 10:50:02 | Fast company - tech
‘Everyone wants to be a content creator’: Gen Alpha’s dream job? YouTuber

It used to be that if you asked a classroom of kids what they want to be when they grow up, you’d get answers like “firefighter” and “astronaut.” These days, Gen Alpha dreams of becoming content c

27 feb. 2025, 06:10:06 | Fast company - tech
How AI is unlocking a cleaner energy future

The Fast Company Impact Council is a private membership community of influential leaders, experts, executives, and entrepreneurs who share their insights with our audience. Members pay annual

27 feb. 2025, 01:30:06 | Fast company - tech
Nvidia revenue forecasts for first quarter exceed estimates

Nvidia forecast first-quarter revenue above market estimates on

26 feb. 2025, 23:20:02 | Fast company - tech