Hacking this BYD was too easy. It didn't even have a password
On a narrow country road outside Canberra, I'm driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.
But while I'm at the wheel, I'm not the only one in control — a hacker has access to the car.
With the stroke of a key, he kills the headlights, plunging me into darkness.
The attack is not a total surprise. The Shark has spent the last two weeks with Dan Hreszczuk, a cybersecurity expert, who specialises in cars.
His task was to hack the vehicle and find out what could be seen and done remotely by the Shark's Chinese manufacturer.
Modern connected cars — particularly EVs and hybrids — are increasingly run by software, giving manufacturers the power to change, update and control vehicles, like never before.
In the case of BYD and others, that software is controlled from China.
With fuel prices on the rise, EVs and plug-in hybrids like the Shark have gone mainstream this year, making up almost a third of new cars sales to date. More than half of these are from Chinese brands.
EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers, as they can be compelled by the country's national security laws to co-operate with authorities.
To put this potential access to the test, it made sense to pick a model from China's top EV brand, BYD.
Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark's lack of cybersecurity.
"The access we took advantage of didn't even have a password," he says.
This lack of a password allowed Dan to access the car's digital arteries.
From there it was a matter of unpicking the software programs which control different functions in the car.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.abc.net.au — the content belongs to ABC News Australia - Top Stories.