The dangers you don't expect in terms of security, hacking and electric car charging

The race towards electric car and charging services is proceeding at a speed; such as to attract hundreds of & quot; players & quot ;, including many startups. The goal seems to be to take a slice of this cake at any cost , which is bound to rise enormously, not worrying about doing things right , and & egrave; one of the reasons behind Carge's recent hacking.

Startups enter the market with a MVP logic (Minimal Viable Product): rapid development, commercial launch as soon as possible, user response testing and, if this is; good, they proceed with the development while integrating the other aspects, security included, at a later time. It works like this everywhere, we know, but in a society more and more; software-based, security cannot; be overshadowed or developed later.


By now even the stones know it, the future will be; dominated by software . There are countries and companies (Eastern Europe is fertile ground) where headhunters literally wage war to find experts and developers, but there are still very few companies; in the recharging sector who have understood that information security & egrave; the first leg on which to build the infrastructure .

One of those that has proven to know how to do it & egrave; Juice Technology AG, manufacturer of hardware that actually can & ograve; be considered a software house just like Tesla. The Swiss even organized a panel not to talk about the product, but about safety, launching an appeal to all the other companies.

Think about it: electric car charging is based, both in public and in private, on creating access points that & quot; connect & quot; Internet with electricity . The car itself is a first entrance door. The column or the wallbox then represent a further and potential weak point , which can be exploited by the bad guys to do damage even in the real world .

Blackout Amazon & euro 5.99 & euro See offer

A tip for reading

Maybe the concept can be; be difficult to understand: how can it be; a hacker working with “intangible” lines of code create problems with something physical? The examples are many.


The physical dangers of an unsafe charging infrastructure are of any kind. It starts with the banal data theft of the users, proceeding with the theft of money when you enter the top-up payment system that uses third-party services. Here & egrave; It is possible, for example, to manipulate an invoice : it is intercepted, the numbers are replaced (making it cheaper or more expensive) and only then is it re-routed in its traditional path by sending it to the payment processor. Still on the subject of theft, a recent study has shown how easy it can be to steal energy for recharging through unsafe stations.

Another example of an attack is & egrave; the & quot; denial of service & quot;, capable of causing the recharge to fail. It might seem like a negligible damage, a bore for the user, but it becomes the key to a ransomware-type initiative to the reload networks.

Still on the subject of blackmail , very experienced and organized attackers may be able to disable the power grid of a building, a condominium/company or a neighborhood by exploiting continuous cycles of activation/deactivation of the recharge, carrying out the operation in a synchronized manner. This is an unrealistic scenario today, there are not many electric cars, but in the future it is not; so & igrave; science fiction given the necessity; of the charging infrastructure to be connected to the network, both for billing reasons and for managing the load within the power limits of the system when it is necessary to distribute the energy to several; car being recharged at the same time.

So far it has been; talked about inefficiencies, blackmail or theft. But what would happen if, through a cyber attack, the attacker could damage the car battery by changing the charging parameters? The risk is that of deactivating the cell control systems, sophisticated and delicate. With an increase in power, an increase in temperature is easily obtained if the control systems of the same are compromised … up to the possible fire of the batteries.


Software First and Security by Design are the keywords known to those involved in programming: simplifying, it means that any connected product that will have to & agrave; born in the next few years, will have to to have a genesis that starts from its software and security will have to & agrave; be developed already from the early stages, running in parallel from birth to the debut on the market.

Juice Technology's solution represents excellence and has recently obtained ISO/IEC 27001 certification for information security and data protection.

< strong> Why & eacute; & egrave; important? For the data collection of the Tesla Model 3 I use a & quot; homemade & quot; system, with a Raspberry where the information accessible only in the local network is recorded (I will talk about it shortly). Precisely because & eacute; I do not trust anybody. I also recently tried j + pilot (Android – iOS), the Juice application, which asks for Tesla account data on first login. I only did it because are not stored anywhere and a token is generated that guarantees the connection, with the advantage of providing (albeit only for the moments necessary to guarantee access) this sensitive information to a company that has tried its attention to security

The strategy of the company is that of using proprietary chipsets developed in house, encryption as the standard for all aspects and a large array of tests , carried out both by the internal team and by independent software engineers, so much so that there is a & quot; bug bounty program & quot; which allows anyone to obtain a cash reward for reporting vulnerabilities; and security risks. Furthermore, the business partners to collaborate with are also chosen based on their approach to security, discarding those who do not make this aspect a priority. In addition, safety also exceeds the ease of use. of use, for this Juice & egrave; was among the first to allow you to activate the recharge with your credit card, without apps or devices to carry around.

The fundamental problem, and & egrave; this is the appeal launched by the company, & egrave; that all the actors involved must be made aware of the issue . Safety must also be the primary aspect for owners of buildings where charging points are installed or for companies; who manage the infrastructure, because otherwise it would create weak points, access doors for criminals that only a holistic approach can do; remove.

5G without compromise? Oppo Reno 4 Z, buy it at the best price from Unieuro at 239 euros .


Posted

in

by

Tags: