Sat nav systems at risk from hackers
In-car route-planning equipment could be the next target for hackers after researchers expose wireless data vulnerability.

The satellite navigation systems in many cars are wide open to potentially dangerous abuse by hackers, warns a security expert.
Andrea Barisani, chief security engineer with Italian consultancy Inverse Path, says systems based on Radio Data System-Traffic Message Channel (RDS-TMC) technology are particularly vulnerable.
He says his own tests show how a hacker could get into such systems and send drivers wrong messages about where to go, and other misleading information.
RDS-TMC is used widely in vehicles across the UK, Europe and the US, typically to provide data on traffic conditions, accidents and detours. Because it does not authenticate the source of data sent to it, says Barisani, the system is open to senders of bogus information, or large amounts of data aimed at swamping it and causing a denial of service.
"I recently bought a new car with an RDS-TMC sat nav feature, which made me wonder how easy it would be for someone to detect it and then inject it with false data," Barisani said. "A colleague and I tested it and discovered it was relatively easy."
He believes there are a number of ways that navigation systems could be abused: "You could divert someone to a secondary road that you know of, and ambush them there. You could create a traffic jam by sending everyone down a narrow street. You could use it to send false terror alerts and spread alarm."
He says company car drivers could be especially at risk from competitors making them divert, or springing a denial of service attack. "A lot of professional people no doubt depend on this technology," he says.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"The trouble is that people trust sat nav," he points out. "It's not like your PC which everyone knows is vulnerable to hackers and viruses, so are wary of. Sat nav naturally inspires blind faith."
Barisani says he is amazed that there is no authentication on RDS-TMC systems: "I know some manufacturers are working on new and more secure standards, primarily for billing purposes though," he says. "These new standards will solve most of the issues but it's going to take quite some time before wide implementation and adoption."
He says he'd like to see more awareness of this, 'so at least the good guys know what the risks are before the bad guys get to work'.
Barisani and colleague Daniele Bianco plan to present their full research at next month's CanSecWest security conference in Vancouver.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Best satnavs for 2017
Vs Apps vs hardware - which satnavs will do the best job of getting you from A to B?
By Rene Millman Published
-
UK government wants Google to trial driverless cars in London
News News follows government's £20m investment in autonomous car projects
By Aaron Lee Published
-
TfL trials interactive bus stop technology in Regent Street
News TfL teams up with Clear Channel UK to bring real-time, interactive travel information to tourists and commuters.
By Caroline Donnelly Published
-
EU wants mobile devices to have universal charger
News Manufacturers including Apple could be forced into using a common standard.
By Rene Millman Published
-
Apple Maps leaves users lost in Australia, claim police
News Police force claims iPhone users have been left stranded in local national park by gaffe-prone navigation product.
By Caroline Donnelly Published
-
MWC 2012: News roundup
News We round up all the news and announcements from this year's Mobile World Congress (MWC) event in Barcelona.
By IT Pro Published
-
BSA settles at £29,000 for unlicensed software use
News The Salamander Organisation feels the force of the Business Software Alliance for not paying their software licences.
By Jennifer Scott Published
-
Ofcom cuts mobile termination rates
News The communications regulator announces plans to dramatically reduce the amount operators can charge one another, leading to consumer cost savings.
By Maggie Holland Published