Published: January 30, 2015 | Munich, Germany
BMW vehicles with the system “Connected Drive” can be opened via mobile illegally from the outside report the German association ADAC. BMW has corrected this flaw in their own words now.
As one of the leading manufacturer in the networking of driver, vehicle and the surrounding environment, the BMW Group is increasing the security of data transmission in its vehicles. This is the company’s response to reports from the Allgemeiner DeutscherAutomobil-Club (ADAC). The motorist’s association had identified a potential security gap when data is transmitted. What the ADAC found was that the cars could be opened from the outside with the help of a cellphone. The club said it had run tests of several cars, which had confirmed its findings. The BMW Group has already closed this gap with a new configuration. Please refer to the audio interview of ADAC’s Technical Advisor, Arnulf Thiemel.
The experts from the ADAC had put the company through a strategic review as market leader in vehicle networking. This check revealed a potential security gap affecting the transmission path via the mobile phone network. BMW Group hardware was not impacted. The online capability of BMW Group ConnectedDrive allowed the gap to be closed quickly and safely in all vehicles. Access to functions relevant to driving was excluded at all times. There was no need for vehicles to go to the workshop.
The update is carried out automatically as soon as the vehicle connects up to the BMW Group server or the driver calls up the service configuration manually. The online services of BMW Group ConnectedDrive communicate with this configuration via the HTTPS protocol (HyperText Transfer Protocol Secure) which had previously been used for the service BMW Internet and other functions. The BMW Group ConnectedDrive packages in the vehicle are thereby using encryption which in most cases is also being used by banks for online banking. On the one hand, data are encrypted with the HTTPS protocol, and on the other hand, the identity of the BMW Group server is checked by the vehicle before data are transmitted over the mobile phone network.
Please watch the video.
In this way, the BMW Group has responded promptly and increased the security of BMW Group ConnectedDrive, because no cases have come to light yet in which data has been called up actively by unauthorised persons from outside or an attempt of this kind is made in the first place.
Source: BMW Group