Nissan Leaf electric cars hack vulnerability disclosed
Some of Nissan's Leaf cars can be easily hacked, allowing their heating and air-conditioning systems to be hijacked, according to a prominent security researcher, the BBC reports.
Troy Hunt reported that a flaw with the electric vehicle's companion app also meant data about drivers' recent journeys could be spied on.
Mr Hunt said he gave the firm a month to fix the issue before he decided to make it public.
Nissan said it could not yet comment.
The problem remains unresolved but Mr Hunt said car owners could protect themselves by disabling their Nissan CarWings account. Those who have never signed up are not at risk.
Mr Hunt acknowledged that the issue was not life-threatening, but said hackers could still exploit the NissanConnect app's vulnerability to cause mischief by running down people's batteries.
"The right thing to do at the moment would be for Nissan to turn it off altogether," Mr Hunt told the BBC.
"They are going to have to let customers know. And to be honest, a fix would not be hard to do.
"It's not that they have done authorisation [on the app] badly, they just haven't done it at all, which is bizarre."
The BBC contacted the Japanese carmaker but a spokeswoman said it was not yet able to comment.
Mr Hunt said the root of the problem was that the firm's NissanConnect app needed only a car's vehicle identification number (Vin) to take control.
The code is usually stencilled into a car's windscreen, making it relatively easy to copy.
The initial characters of a Vin refer to the brand, make of car, and country of manufacture/location of the firm's headquarters.
So, Mr Hunt said, it would only be the final numbers that varied between different Nissan Leafs based in the same region.
"Normally it's only the last five digits that differ," he explained.
"There's nothing to stop someone from scripting a process that goes through every 100,000 possible cars and tries and turn the air conditioning on in every one.
"They would then get a response that would confirm which vehicles exist."
Attackers would not even need to use the app, he added, since the commands could be sent via a web browser.
To confirm the problem, Australia-based Mr Hunt used the Vin number of a Nissan Leaf-owning acquaintance based in the UK.
"I was sat in the vehicle with everything powered off and didn't have my key on me," recalled Scott Helme, who is also a cybersecurity adviser.
"So, the vehicle was as it would be if it was completely unattended.
"As I was talking to Troy on Skype, he pasted the web address into his browser and then maybe 10 seconds later I heard an internal beep in the car.
"The heated seat then turned on, the heated steering wheel turned on. And I could hear the fans spin up and the air-conditioning unit turn on."
Further tests indicated that the hack did not work if the vehicle was in motion.
But it was possible to see the owner's registered username, which might help reveal their identity.
Furthermore, times and distances of recent journeys were disclosed, but not location data.
As soon as Mr Helme unregistered his app, Mr Hunt could no longer contact his car.
"It's not as bad as it could be," Mr Helme told the BBC.
"But if I was to monitor your movements over the course of the week and learn when you go to and from work, shortly after you got to your office I could run the heating for the remainder of the day.
"That would potentially leave you with very little power - certainly not enough to get back home."
Further analysis indicated that the app does not talk directly to the cars, but instead sent its commands via Nissan's computer servers.
As a result, Mr Hunt said, it would be easy for Nissan to suspend the service.
The researcher also discovered that some Canadian owners of the Leaf had discovered and shared knowledge of the flaw on an online forum and had posted a web address that could be used to spoof the app.
"I decided we were past the point of not letting the cat out of the bag," he said, justifying his decision to blog about the discovery before Nissan had issued a fix.
"Unfortunately what we are seeing is just another case of security being important after a problem is discovered," he added.
Videos
Interview with Francis Malige, EBRD Managing Director
Armenians Commemorating 106th Anniversary of Genocide
Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
Rep Adam Schiff Says Congress Should Recognize Artsakh
UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
NASA's Mars 2020 Perseverance Rover Landing Animations
Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
Artsakh Defense Army Units Neutralizing Azerbaijani Drone
Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
President Armen Sarkissian Meets with NATO Secretary-General in Brussels
Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
Artsakh Defense Army Units Destroying Azerbaijani Tank
Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
Armenians Protest Outside Turkrish Embassy in Los Angeles
Losses in Azerbaijan's Military Featured in Defense Army Footage
Artsakh Defense Army Neutralizing Adversary's Transport Column
Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
Artsakh Defense Army Continues High-Precision Strikes
War Situation in Karabakh on European Parliament's Agenda
Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
Nagorno-Karabakh's Capital Under Azerbaijani Strikes
Armenian Armed Forces Neutralize Azerbaijani Defense Positions
ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
EU calls for Immediate End to Hostilities over Nagorno-Karabakh
- 15:20 • 24.05.21 Interview with Francis Malige, EBRD Managing Director
- 11:39 • 24.04.21 Armenians Commemorating 106th Anniversary of Genocide
- 09:40 • 23.04.21 Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
- 15:34 • 22.04.21 Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
- 14:09 • 21.04.21 'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
- 12:37 • 03.04.21 Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
- 17:33 • 11.03.21 Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
- 17:57 • 26.01.21 Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
- 13:33 • 22.01.21 Rep Adam Schiff Says Congress Should Recognize Artsakh
- 09:42 • 29.12.20 UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
- 18:41 • 24.12.20 NASA's Mars 2020 Perseverance Rover Landing Animations
- 13:33 • 31.10.20 Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
- 16:37 • 30.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
- 11:25 • 28.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Drone
- 13:45 • 24.10.20 Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
- 11:51 • 24.10.20 Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
- 11:40 • 24.10.20 Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
- 10:39 • 24.10.20 Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
- 12:41 • 23.10.20 President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
- 12:16 • 23.10.20 Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
- 12:02 • 22.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
- 10:35 • 22.10.20 President Armen Sarkissian Meets with NATO Secretary-General in Brussels
- 10:51 • 17.10.20 Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
- 15:09 • 15.10.20 Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
- 13:13 • 13.10.20 Artsakh Defense Army Units Destroying Azerbaijani Tank
- 12:56 • 12.10.20 Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
- 12:23 • 12.10.20 Armenians Protest Outside Turkrish Embassy in Los Angeles
- 17:23 • 09.10.20 Losses in Azerbaijan's Military Featured in Defense Army Footage
- 15:53 • 09.10.20 Artsakh Defense Army Neutralizing Adversary's Transport Column
- 14:11 • 09.10.20 Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
- 15:52 • 08.10.20 Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
- 10:57 • 08.10.20 Artsakh Defense Army Continues High-Precision Strikes
- 14:24 • 07.10.20 War Situation in Karabakh on European Parliament's Agenda
- 19:31 • 05.10.20 Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
- 16:17 • 04.10.20 Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
- 12:39 • 04.10.20 Nagorno-Karabakh's Capital Under Azerbaijani Strikes
- 13:49 • 03.10.20 Armenian Armed Forces Neutralize Azerbaijani Defense Positions
- 10:12 • 29.09.20 ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
- 23:42 • 28.09.20 There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
- 18:45 • 28.09.20 EU calls for Immediate End to Hostilities over Nagorno-Karabakh
Most popular articles Today Yesterday For a week
-
Event 11:07 • 19/11 “New Career Opportunities and Perspectives”: a career fair will be organized for people of Artsakh The main goal of the event is to support the socio-economic integration of Artsakh residents displaced by the conflict into Armenian society. It aims to enhance their competitiveness in the labor market and address employment challenges.
Economy
-
16:51 • 11.11.24 New features for Armeconombank’s Premium cardholders
-
12:16 • 08.11.24 Ucom and Sunchild NGO install another solar plant in Areni
Event
-
14:40 • 19.11.24 Ucom’s 5G network launched in 11 new cities
Science/tech
-
14:18 • 08.05.24 AstraZeneca withdrawing Covid vaccine worldwide