Subaru

millions-of-subarus-could-be-remotely-unlocked,-tracked-due-to-security-flaws

Millions of Subarus could be remotely unlocked, tracked due to security flaws


Flaws also allowed access to one year of location history.

About a year ago, security researcher Sam Curry bought his mother a Subaru, on the condition that, at some point in the near future, she let him hack it.

It took Curry until last November, when he was home for Thanksgiving, to begin examining the 2023 Impreza’s Internet-connected features and start looking for ways to exploit them. Sure enough, he and a researcher working with him online, Shubham Shah, soon discovered vulnerabilities in a Subaru web portal that let them hijack the ability to unlock the car, honk its horn, and start its ignition, reassigning control of those features to any phone or computer they chose.

Most disturbing for Curry, though, was that they found they could also track the Subaru’s location—not merely where it was at the moment but also where it had been for the entire year that his mother had owned it. The map of the car’s whereabouts was so accurate and detailed, Curry says, that he was able to see her doctor visits, the homes of the friends she visited, even which exact parking space his mother parked in every time she went to church.

A year of location data for Sam Curry’s mother’s 2023 Subaru Impreza that Curry and Shah were able to access in Subaru’s employee admin portal thanks to its security vulnerabilities.

Credit: Sam Curry

A year of location data for Sam Curry’s mother’s 2023 Subaru Impreza that Curry and Shah were able to access in Subaru’s employee admin portal thanks to its security vulnerabilities. Credit: Sam Curry

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry says. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

Curry and Shah today revealed in a blog post their method for hacking and tracking millions of Subarus, which they believe would have allowed hackers to target any of the company’s vehicles equipped with its digital features known as Starlink in the US, Canada, or Japan. Vulnerabilities they found in a Subaru website intended for the company’s staff allowed them to hijack an employee’s account to both reassign control of cars’ Starlink features and also access all the vehicle location data available to employees, including the car’s location every time its engine started, as shown in their video below.

Curry and Shah reported their findings to Subaru in late November, and Subaru quickly patched its Starlink security flaws. But the researchers warn that the Subaru web vulnerabilities are just the latest in a long series of similar web-based flaws they and other security researchers working with them have found that have affected well over a dozen carmakers, including Acura, Genesis, Honda, Hyundai, Infiniti, Kia, Toyota, and many others. There’s little doubt, they say, that similarly serious hackable bugs exist in other auto companies’ web tools that have yet to be discovered.

In Subaru’s case, in particular, they also point out that their discovery hints at how pervasively those with access to Subaru’s portal can track its customers’ movements, a privacy issue that will last far longer than the web vulnerabilities that exposed it. “The thing is, even though this is patched, this functionality is still going to exist for Subaru employees,” Curry says. “It’s just normal functionality that an employee can pull up a year’s worth of your location history.”

When WIRED reached out to Subaru for comment on Curry and Shah’s findings, a spokesperson responded in a statement that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The Subaru spokesperson also confirmed to WIRED that “there are employees at Subaru of America, based on their job relevancy, who can access location data.” The company offered as an example that employees have that access to share a vehicle’s location with first responders in the case when a collision is detected. “All these individuals receive proper training and are required to sign appropriate privacy, security, and NDA agreements as needed,” Subaru’s statement added. “These systems have security monitoring solutions in place which are continually evolving to meet modern cyber threats.”

Responding to Subaru’s example of notifying first responders about a collision, Curry notes that would hardly require a year’s worth of location history. The company didn’t respond to WIRED asking how far back it keeps customers’ location histories and makes them available to employees.

Shah and Curry’s research that led them to the discovery of Subaru’s vulnerabilities began when they found that Curry’s mother’s Starlink app connected to the domain SubaruCS.com, which they realized was an administrative domain for employees. Scouring that site for security flaws, they found that they could reset employees’ passwords simply by guessing their email address, which gave them the ability to take over any employee’s account whose email they could find. The password reset functionality did ask for answers to two security questions, but they found that those answers were checked with code that ran locally in a user’s browser, not on Subaru’s server, allowing the safeguard to be easily bypassed. “There were really multiple systemic failures that led to this,” Shah says.

The two researchers say they found the email address for a Subaru Starlink developer on LinkedIn, took over the employee’s account, and immediately found that they could use that staffer’s access to look up any Subaru owner by last name, zip code, email address, phone number, or license plate to access their Starlink configurations. In seconds, they could then reassign control of the Starlink features of that user’s vehicle, including the ability to remotely unlock the car, honk its horn, start its ignition, or locate it, as shown in the video below.

Those vulnerabilities alone, for drivers, present serious theft and safety risks. Curry and Shah point out that a hacker could have targeted a victim for stalking or theft, looked up someone’s vehicle’s location, then unlocked their car at any time—though a thief would have to somehow also use a separate technique to disable the car’s immobilizer, the component that prevents it from being driven away without a key.

Those car hacking and tracking techniques alone are far from unique. Last summer, Curry and another researcher, Neiko Rivera, demonstrated to WIRED that they could pull off a similar trick with any of millions of vehicles sold by Kia. Over the prior two years, a larger group of researchers, of which Curry and Shah are a part, discovered web-based security vulnerabilities that affected cars sold by Acura, BMW, Ferrari, Genesis, Honda, Hyundai, Infiniti, Mercedes-Benz, Nissan, Rolls Royce, and Toyota.

More unusual in Subaru’s case, Curry and Shah say, is that they were able to access fine-grained, historical location data for Subarus going back at least a year. Subaru may in fact collect multiple years of location data, but Curry and Shah tested their technique only on Curry’s mother, who had owned her Subaru for about a year.

Curry argues that Subaru’s extensive location tracking is a particularly disturbing demonstration of the car industry’s lack of privacy safeguards around its growing collection of personal data on drivers. “It’s kind of bonkers,” he says. “There’s an expectation that a Google employee isn’t going to be able to just go through your emails in Gmail, but there’s literally a button on Subaru’s admin panel that lets an employee view location history.”

The two researchers’ work contributes to a growing sense of concern over the enormous amount of location data that car companies collect. In December, information a whistleblower provided to the German hacker collective the Chaos Computer Computer and Der Spiegel revealed that Cariad, a software company that partners with Volkswagen, had left detailed location data for 800,000 electric vehicles publicly exposed online. Privacy researchers at the Mozilla Foundation in September warned in a report that “modern cars are a privacy nightmare,” noting that 92 percent give car owners little to no control over the data they collect, and 84 percent reserve the right to sell or share your information. (Subaru tells WIRED that it “does not sell location data.”)

“While we worried that our doorbells and watches that connect to the Internet might be spying on us, car brands quietly entered the data business by turning their vehicles into powerful data-gobbling machines,” Mozilla’s report reads.

Curry and Shah’s discovery of Subaru’s security vulnerabilities in its tracking demonstrate a particularly egregious exposure of that data—but also a privacy problem that’s hardly less disturbing now that the vulnerabilities are patched, says Robert Herrell, the executive director of the Consumer Federation of California, which has sought to create legislation for limiting a car’s data tracking.

“It seems like there are a bunch of employees at Subaru that have a scary amount of detailed information,” Herrell says. “People are being tracked in ways that they have no idea are happening.”

This story originally appeared on wired.com.

Photo of WIRED

Wired.com is your essential daily guide to what’s next, delivering the most original and complete take you’ll find anywhere on innovation’s impact on technology, science, business and culture.

Millions of Subarus could be remotely unlocked, tracked due to security flaws Read More »

automakers-excoriated-by-senators-for-fighting-right-to-repair

Automakers excoriated by Senators for fighting right-to-repair

Yesterday, US Senators Jeff Merkley (D-OR), Elizabeth Warren (D-MA), and Joshua Hawley (R-MO) sent letters to the heads of Ford, General Motors, and Tesla, as well as the US heads of Honda, Hyundai, Nissan, Stellantis, Subaru, Toyota, and Volkswagen, excoriating them over their opposition to the right-to-repair movement.

“We need to hit the brakes on automakers stealing your data and undermining your right-to-repair,” said Senator Merkley in a statement to Ars. “Time and again, these billionaire corporations have a double standard when it comes to your privacy and security: claiming that sharing vehicle data with repair shops poses cybersecurity risks while selling consumer data themselves. Oregon has one of the strongest right-to-repair laws in the nation, and that’s why I’m working across the aisle to advance efforts nationwide that protect consumer rights.”

Most repairs aren’t at dealerships

The Senators point out that 70 percent of car parts and services currently come from independent outlets, which are seen as trustworthy and providing good value for money, “while nearly all dealerships receive the worst possible rating for price.”

OEMs and their tier-one suppliers restricting the supply of car parts to within their franchised dealership networks also slows down the entire repair process for owners as well as increasing the cost of getting one’s car fixed, the letter states.

As Ars noted recently, more than one in five automotive recalls are now fixed with software patches, and increasingly the right-to-repair fight has centered on things digital—access to diagnostics, firmware, and connected services. The percentage of non-hardware recall fixes will surely grow in the coming years as more and more automakers replace older models with software-defined vehicles.

Automakers excoriated by Senators for fighting right-to-repair Read More »

the-2024-subaru-solterra-is-nimble-but-sorely-lacks-range,-personality

The 2024 Subaru Solterra is nimble but sorely lacks range, personality

how about an electric Baja —

Slow charging and inefficient driving, Solterra is no electric WRX or Forester.

A Subaru Solterra drives on a dirt road

Enlarge / With just 222 miles of range, you can’t venture far off-grid in the Subaru Solterra.

Subaru

Over the years, Subaru has generated a cult following in the US, making its name with all-wheel drive powertrains and a go-anywhere attitude. Cars like the rally-bred WRXes and STIs did a lot of work here, but lately, Subaru has seemed to go in the opposite direction, phasing out fun drives like the STI lineup in favor of volume-movers like the Ascent and bloated versions of existing models such as the Subaru Wilderness editions.

Its first electric vehicle is perhaps even less in character. The $44,995 Solterra is the result of an ongoing partnership with Toyota and was developed together with the bZ4X. Unlike the Toyota, there’s no single-motor option for the Solterra. It’s all-wheel-drive only, with a pair of identical 107 hp (80 kW) permanent magnet electric motors, one for each axle. That means you can do some, but not all, of the off-road things you’d expect to do with a Subaru.

Looks are deceiving

At first glance, the Solterra looks like the edgy, tech-leaning offspring of a Crosstrek and an Impreza wagon. The 8.3 inches of ground clearance is slightly less than the Outback or Forester, while the Solterra comes in at 184.6 inches (4,689 mm) in length, placing it squarely in the middle of the brand’s stable. It’s a rather compact SUV, even more so when you try to get comfortable in the cockpit. My short frame was cramped, and anyone taller than me won’t feel welcome on long drives.

The large multifunction steering wheel can obscure the small instrument display in front of the driver.

Enlarge / The large multifunction steering wheel can obscure the small instrument display in front of the driver.

Subaru

In what seems to be the norm with Subaru these days, the interior is full of plastic and cloth. Even on this top-line Touring trim test car, which comes in at just under $55,000, there’s a very cheap-looking dash with a plethora of rigid lines. Controls are close by, but the overall layout is borderline infuriating, with slow response times through the central infotainment system and a driver alert system that beeped and shrieked every 20 seconds for one reason or another. There were so many driver warnings and advisories popping up that I eventually tuned them out, which is probably not the intended effect.

Range Non-Rover

There’s about five miles (8 km) of charging difference between the 228-mile (367 km) Premium trim level and the Limited and Touring trims, which have an EPA range of 222 miles (357 km) on a single charge of the 72.8 kWh lithium-ion battery. In my 10 days with the car, the only time I eclipsed 200 miles (321 km) was leaving my driveway with the range reading 201. After about 10 minutes, it slumped back under 200 miles. In fairly normal city and highway conditions, I realized around 180 miles of range (290 km). When the weather called for air conditioning, I lost another 5–7 miles (8–11 km).

  • The Solterra is 184.6 inches (4,689 mm) long, 73.2 inches (1,859 mm) wide, 65 inches (1,651 mm) tall, with a 112.2-inch (2,850 mm) wheelbase. It has a curb weight of between 4,365 and 4,505 lbs (1,980–2,043 kg) depending on trim level.

    Subaru

  • The Toyota-developed infotainment system can be laggy.

    Subaru

  • The back seat has 35.5 inches (902 mm) of rear legroom.

    Subaru

  • There’s 27.7 cubic feet (783 L) of cargo volume with the rear seats in use and the cover in place.

    Subaru

  • Wireless device charging, as well as wireless Apple CarPlay and Android Auto, are available in the Limited and Touring trims.

    Subaru

Charging is slow, however. A stop to recharge from about 20 to 80 percent state of charge took the better part of 45 minutes. At launch, the Solterra was rated at an even longer 56 minutes to DC fast-charge to 80 percent, but for model year 2024, Subaru says that in ideal conditions, this should now be as quick as 35 minutes.

Charging at home was an overnight endeavor—nine hours on a level 2 charger. The Solterra currently features a CCS1 charge port, but in 2025, the company will adopt the J3400 standard, with adapters made available to existing customers so they can charge at Tesla Supercharger sites.

The 2024 Subaru Solterra is nimble but sorely lacks range, personality Read More »