93

cross-posted from: https://scribe.disroot.org/post/11438860

Here is the podcast about this investigation.

Archived version

On a narrow country road outside Canberra, I'm driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.

But while I'm at the wheel, I'm not the only one in control; a hacker has access to the car.

As the 2.6 tonne ute rounds a bend, he gets to work.

...

With the stroke of a key, he kills the headlights, plunging me into darkness.

The attack is not a total surprise. The Shark has spent the past two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars.

His task was to hack the vehicle and find out what could be seen and done remotely by the Shark's Chinese manufacturer.

"It was easier than we were expecting," Hreszczuk says.

...

EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country's national security laws to co-operate with authorities.

...

Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark's lack of cybersecurity.

"The access we took advantage of didn't even have a password," he says.

"It's a little bit scary how open … the BYD Shark is to a hacker."

...

While sabotage is one worry, the concern most often cited is surveillance due to the array of cameras and microphones on an EV.

Last year, the UK military banned Chinese EVs, even those made with Chinese components, from parking within 3 kilometres of some of its most sensitive locations.

China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.

...

In Australia, there's no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.

...

When I pull into a service station and leave my phone unlocked in the car, Hreszczuk seizes his opportunity.

He's done a simple audio edit, stitching together me saying "Hey Siri" and his voice asking a few questions to get the personal details he needs.

...

Using the car's speaker system, Hreszczuk plays the voice command from his computer into the car.

"Hey, Siri, what is my home address?" the edited audio asks.

Siri replies, without questioning why I don't know where I live.

Hreszczuk repeats this process and quickly extracts my date of birth and age.

Within minutes, he's obtained the internet banking password.

...

Alastair MacGibbon, Australia's former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.

MacGibbon says a cabinet minister should not be able to own a Chinese EV.

"China has always shown its strong desire to steal things, to surveil," he says.

"No-one should be in any doubt that [Chinese EVs] are used in the same manner.

...

top 38 comments
sorted by: hot top new old
[-] theacharnian@lemmy.ca 1 points 7 hours ago

The real issue here is how BYD will react to this. Technical failure is not something to be ashamed of. Not acting on it to address it is.

[-] randomname@scribe.disroot.org 1 points 50 minutes ago

For BYD and other Chinese tech companies, enabling surveillance isn't a bug but rather a feature.

[-] Cherry@piefed.social 2 points 9 hours ago

This guy fancies himself as a script writer. That was painful to read and they need to get to the point.

[-] neuromorph@lemmy.world 10 points 20 hours ago

The original tesla network had zero encryption when they were tying to pitch their cars to the military. These.companies have no idea how to operate in the real world

[-] goferking0@lemmy.sdf.org 4 points 19 hours ago

Or jeep where you could kill it remotely with no physical access

https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

[-] Tattorack@lemmy.world 8 points 22 hours ago

Oh! This might be good news! When are we getting a car distro of Linux?

[-] Jiggle_Physics@quokk.au 18 points 1 day ago

Yeah all these big brother devices are riddled with security holes because they are absolute crap being pushed out as fast as possible. This is just "China scary" horseshit. US, and European cars spy on everything, and aren't particularly difficult to hack either.

[-] mysticalone@lemmy.world 14 points 1 day ago

ooh, propaganda showing a foreign made product is bad and motivates law makers to protect local manufacturers! With all the listening and monitoring every other car brand does, I want to see how they hold up.

[-] oddsys@lemmy.world 1 points 19 hours ago

We don't have local manufacturing of cars, so all cars are foreign. If there is nothing to protect can it just be an investigation again instead?

[-] Paddzr@lemmy.world -1 points 19 hours ago

You need more valid reasons to hate... let me check my notes... ah yes, slave labour enjoyers, BYD? One of the worst satisfactory survey losers? That BYD?

Chinese sympathiser bot spotted. Please do tell me how everything we heard about China is western propaganda! I love that story.

[-] trxxruraxvr@lemmy.world 53 points 1 day ago

Within minutes, he’s obtained the internet banking password.

Why the fuck would that information be available to a car? This makes no sense at all

[-] LeapSecond@lemmy.zip 55 points 1 day ago

According to the article he recorded the driver sharing the internet banking password with his mother during a call. It's just a sensationalized way to show he has access to the microphone.

[-] pyr0ball@lemmy.dbzer0.com 5 points 1 day ago

It's not, he used the personal details obtained from the car to do a password reset

[-] phutatorius@lemmy.zip 1 points 23 hours ago

If you say it in the car, and the car has a microphone, it's available.

[-] trxxruraxvr@lemmy.world 2 points 20 hours ago

But why would you say a password out loud?

[-] Stern@lemmy.world 0 points 1 day ago

Spotify and the like on a car, subscriptions to 'features' like heated seats (iirc just bmw for that) in car web browser, to name a few

[-] Freeposity@lemmy.world 4 points 20 hours ago

OK, now try to hack a Slate truck

[-] MonkeMischief@lemmy.today 37 points 1 day ago

Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country's national security laws to co-operate with authorities.

[Laughs nervously in Patriot Act]

How about these things just collect NO personal data? Maybe vague anonymous telemetrics about collective vehicle stats or something at the very most.

There needs to be a blanket ban and strict auditing on this mass hoovering of peoples' personal lives by states and corporations.

[-] TrippaSnippa@aussie.zone 17 points 1 day ago* (last edited 1 day ago)

Laughs nervously in Assistance and Access Act 2018 (Cth).

Australia has the exact fucking same laws, but China scary!

[-] randomname@scribe.disroot.org -5 points 1 day ago

I fully agree. There must be no kill switches. But it is nevertheless clear that they pose a greater greater risk in the hands of Chinese EV makers as they can be compelled by the Chinese government to "co-operate." China is well-known for all kinds of coercion.

[-] goferking0@lemmy.sdf.org 2 points 19 hours ago

So not worried about it if just an American company flaw?

https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

[-] Cypher@aussie.zone 22 points 1 day ago

Tesla is every bit as concerning as BYD.

The US has the ability to compel companies just like China does.

Neither country is trustworthy and one is completely insane.

[-] randomname@scribe.disroot.org 4 points 1 day ago

Both are completely insane. But I agree with the rest of your comment.

[-] LeapSecond@lemmy.zip 17 points 1 day ago

I realize they can't publish how they "hacked" the vehicle but without this part, the article feels a bit lacking. Can it be done by anyone? Only by someone with physical access? Other than that it's not saying much more than what Mozilla had published about a bunch of cars, not just Chinese. And we already know other governments are also dangerous when it comes to this data.

[-] randomname@scribe.disroot.org 17 points 1 day ago

As an addition: Remote 'kill switches' in Chinese buses have been found last year in the Netherlands, UK, Denmark, Norway, ...

Here are some articles:

Kill switches: a new way of waging war

There is already evidence found of Chinese kill switches in devices like wind turbines, solar panels, and buses. These are pieces of hardware that allow the manufacturer to disable or disrupt the device. Are we surrounded by ticking time bombs?

Neighboring Norway’s discovery that buses could be controlled from China now has Denmark on high alert

American stuff also has kill switches. Everything is cloud connected and the US has coerced companies into cutting off the ICC.

[-] venusaur@lemmy.world 10 points 1 day ago

Spoiler: they couldn’t hack into anything that affected driving the vehicle, but could access the microphone inside.

[-] phutatorius@lemmy.zip 2 points 23 hours ago

Couldn't hack in during the allotted time.

[-] betterdeadthanreddit@lemmy.world 6 points 1 day ago* (last edited 1 day ago)

Couldn't break into the most safety-critical systems or potential surveillance features yet but that doesn't mean they won't or that the government whose citizens built the systems can't. Still demonstrated significant risks.

[-] haywire7@lemmy.world 5 points 1 day ago

There has to be a way to not have the thing online all the time surely?

Pull a fuse, unplug something whatever it takes ?

[-] elgordino@fedia.io 4 points 1 day ago

It’ll have at least one eSIM, and pulling the fuse will probably disconnect the entertainment, air conditioning, and other systems managed by the console, and potentially make it impossible to start the car at all.

Best you can do is toggle off the access, but that’s just a software toggle, and even then there’s probably a secondary eSIM for the emergency responder system.

Only way to get a car that doesn’t connect to the internet is to buy an old one.

[-] haywire7@lemmy.world 1 points 9 hours ago

Which I have, burns dead dinosaur goop, stereo I fitted myself. No touch screen, great MPG.

Petrol prices are hurting right now but the cost to get an electric car, the charging infrastructure and everything that goes with it is something I can't justify right now.

[-] useless007@lemmy.zip 1 points 12 hours ago

Would these have a gsm module like the fords have that people are removing?

[-] Paddzr@lemmy.world -1 points 19 hours ago

Here's an easier step, don't buy it. Just buy literally anything else not related to BYD, unfortunately that pool is shrinking fast because people keep buying byd...

[-] Tiral@lemmy.world 2 points 1 day ago

It's BYD.... It's a CCP (Communist) owned company. They block their country from the Internet, most Western apps like Google Tictok FB ect are banned, and they monitor all mobile communication. They even threaten your family if you're studying abroad and post negative shit about Xi or the CCP.

Are you seriously that nieve to believe your Chinese EV isn't tapped for easy listening?

[-] Paddzr@lemmy.world 1 points 19 hours ago

You dare offend the glorious Chinese People Republic on Lemmy??? No wonder you're getting downvoted.

this post was submitted on 21 Sep 2026
93 points (88.4% liked)

World News

58132 readers
1299 users here now

A community for discussing events around the World

Rules:

Similarly, if you see posts along these lines, do not engage. Report them, block them, and live a happier life than they do. We see too many slapfights that boil down to "Mom! He's bugging me!" and "I'm not touching you!" Going forward, slapfights will result in removed comments and temp bans to cool off.

We ask that the users report any comment or post that violate the rules, to use critical thinking when reading, posting or commenting. Users that post off-topic spam, advocate violence, have multiple comments or posts removed, weaponize reports or violate the code of conduct will be banned.

All posts and comments will be reviewed on a case-by-case basis. This means that some content that violates the rules may be allowed, while other content that does not violate the rules may be removed. The moderators retain the right to remove any content and ban users.


Lemmy World Partners

News !news@lemmy.world

Politics !politics@lemmy.world

World Politics !globalpolitics@lemmy.world

Ask Historians !askhistorians@lemmy.world


Recommendations

For Firefox users, there is media bias / propaganda / fact check plugin.

https://addons.mozilla.org/en-US/firefox/addon/media-bias-fact-check/

founded 3 years ago
MODERATORS