cancel
Showing results forย 
Search instead forย 
Did you mean:ย 

Researcher says can hack GM's OnStar app

DakotaDad
Explorer
Explorer
I hesitate to even bring this up after recent history in this forum. But if you use the OnStar app on your phone, look for an update soon to fix a security vulnerability. Not a huge risk at this stage, just something to be fixed.

I'll just leave it at that. No offense taken if mods would prefer to delete this.

Researcher says can hack GM's OnStar app, open vehicle, start engine

A researcher is advising drivers not to use a mobile app for General Motors Co's (GM.N) OnStar vehicle communications system, saying hackers can exploit a security flaw in the product to unlock cars and start engines remotely.

"White-hat" hacker Samy Kamkar posted a video on Thursday saying he had figured out a way to "locate, unlock and remote-start" vehicles by intercepting communications between the OnStar RemoteLink mobile app and the OnStar service.

Kamkar said he plans to provide technical details on the hack next week in Las Vegas at the Def Con conference, where tens of thousands of hacking aficionados will gather to learn about new cybersecurity vulnerabilities.
Jason, Angie, and our boys, Sean (13) and Liam (8)
Now with Radar and Daisy, both Boston Terriers. Missing Artemus the Labrador, gone on ahead.
2016 Ram 3500 CC Big Horn - 6.7 Cummins - B&W RVK3600 hitch
2015 Palomino Sabre 33RETS Platinum fifth wheel
11 REPLIES 11

Perrysburg_Dodg
Explorer
Explorer
Yep just like FCA did for the Uconnect. However unless they ALL provide regular security patches the hackers will find a different door/window to come in. Just like your desktop, laptop, tablet or smartphone. Every device that connects to the internet is vulnerable to being hacked.

Don
2015 Ram 1500 Laramie Crew Cab SWB 4X4 Ecodiesel GDE Tune.

Dadoffourgirls
Explorer
Explorer
OnStar sent out a new application at 4pm today.
Dad of Four Girls
Wife
Employee of GM, all opinions are my own!
2017 Express Ext 3500 (Code named "BIGGER ED" by daughters)
2011 Jayco Jayflight G2 32BHDS

Ductape
Explorer
Explorer
Blondestar

Need to lighten the mood around here. TGIF. :C
49 States, 6 Provinces, 2 Territories...

dodge_guy
Explorer II
Explorer II
Is this where I'm supposed to bash GM because all they make is junk products that can be hacked?!

I think these "hacked" threads would be more interesting if they hacked one car from another!
Wife Kim
Son Brandon 17yrs
Daughter Marissa 16yrs
Dog Bailey

12 Forest River Georgetown 350TS Hellwig sway bars, BlueOx TrueCenter stabilizer

13 Ford Explorer Roadmaster Stowmaster 5000, VIP Tow>
A bad day camping is
better than a good day at work!

45Ricochet
Explorer
Explorer
I hope this goes better than the Ram recall threads of the past week :W
2015 Tiffin Phaeton Cummins ISL, Allison 3000, 45K GCWR
10KW Onan, Magnum Pure Sine Wave Inverter
2015 GMC Canyon Toad

Previous camping rig
06 Ram 3500 CC LB Laramie 4x4 Dually 5.9 Cummins Smarty Jr 48RE Jacobs brake
06 Grand Junction 15500 GVWR 3200 pin

pconroy328
Explorer
Explorer
I have NOT followed this in any detail but have read a dumbed-down version that said, more or less, these vehicles all have a phone number, if you know that phone number and the format of the SMS message, you can do a lot of things.

My Hyundai comes with their own OnStar version. After I downloaded and used their phone app, I figured the security level was pretty low...

Perrysburg_Dodg
Explorer
Explorer
This is not the same hack that the FCA 8.4 Uconnect suffered. The hack is through the users app on the cell phone. The hack on the Uconnect was though the radio itself via the internet. That has been addressed and the backdoor they used closed.

The real question is, is GM's 4G internet radios protected? That is how a hacker can take control over your vehicle not an app!

Don
2015 Ram 1500 Laramie Crew Cab SWB 4X4 Ecodiesel GDE Tune.

Ductape
Explorer
Explorer
I predict a burgeoning future market in vehicle protection. Firewalls, malware protection, intrusion protection.

Sound familiar?
49 States, 6 Provinces, 2 Territories...

Winnebago_Bob
Explorer
Explorer
3oaks wrote:
I go on the premise, that if it's computerized and connected in any way to a remote system via hardwire, Wi-Fi, satellite, etc., it can be hacked. ANYTHING!

Do I think about it? Sometimes. Do I worry about it? No.
We cannot avoid the modern world of technology and the hazards that go with it. About all we can do is take precautions.


^This..
2017 Winnebago Aspect 27K

3oaks
Explorer
Explorer
I go on the premise, that if it's computerized and connected in any way to a remote system via hardwire, Wi-Fi, satellite, etc., it can be hacked. ANYTHING!

Do I think about it? Sometimes. Do I worry about it? No.
We cannot avoid the modern world of technology and the hazards that go with it. About all we can do is take precautions.

DutchmenSport
Explorer
Explorer
Hackers may be able to remotely start the vehicle. They may also be able to unlock the door. If they unlock the door they may take something from inside that I have left laying there. But they are welcome to collect the cookie and cracker crumbs from my 2 and 1/2 year old grandson any time! (we keep nothing inside the car or truck.... ever).

So they can start the engine! No problem there. It will run for 10 minutes and shut itself off. So they start the engine a second time? It will run the engine another 10 minutes. No biggie there.... they won't be able to drive it anyway. Without the key ... the stearing is locked, the gear shifter is locked, the heat-air conditioning is locked to a pre-set setting (depending upon what the last setting was when the key was in). The electric windows don't work, the radio does not work, and that vehicle is not moving unless it's picked up and put on tow wheels.... in which case, why bother hacking the remote start to begin with if it's not driveable anyway. I'd rather have the doors opened remotely, than a window smashed any day!

The app only does 4 things. Turn the engine on and off. Blow the horn, and unlock the doors. Not very threatening in my opinion!

Oh... and yes ... on-star will give a read out of your mileage and oil life left percentage ... duh! Does a hacker really care how much oil life you have left? Maybe they are looking to steel the engine oil! No ... I'm not concerned.