Subaru security vulnerability exposed millions of cars to tracking risks

Two security researchers discovered a security vulnerability in Subaru’s Starlink-connected vehicles last year that gave them “unrestricted targeted access to all vehicles and customer accounts” across the U.S., Canada, and Japan, according to a Wired report.

The researchers, Sam Curry and Shubham Shah, alerted the Japanese automaker to the flaws in November and they were quickly fixed. Subaru told Wired that “after being notified by independent security researchers, [Subaru] discovered a vulnerability in its Starlink service that could potentially allow a third party to access Starlink accounts. The vulnerability was immediately closed and no customer information was ever accessed without authorization.”

The researchers said that a hacker who only knew the car owner’s last name and ZIP code, email address, phone number, or license plate could remotely start, stop, lock, unlock, and retrieve the current vehicle, retrieve any vehicle’s complete location history from the past year, and find personally identifiable information of any customer.

Curry and Shah said that similar web-based flaws have been found in several other carmakers, including Kia, Honda, and Toyota.

While Curry and Shah acknowledged the security fixes, they warned that simply patching security updates after issues were found isn’t enough to remedy the more pervasive issue of privacy in the automotive industry. And even if those vulnerabilities are all remedied, employees still have access to location data.

“You can retrieve at least a year’s worth of location history for the car, where it’s pinged precisely, sometimes multiple times a day,” Curry told Wired. “Whether somebody’s cheating on their wife or getting an abortion or part of some political group, there are a million scenarios where you could weaponize this against someone.”

https://www.fastcompany.com/91266251/subaru-security-vulnerability-exposed-millions-of-cars-to-tracking-risks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

созданный 6mo | 23 янв. 2025 г., 21:10:03


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

I’m a two-time tech founder. But restaurants are where I learned to lead

Sudden equipment failures. Supply chain surprises. Retaining staff as the goalposts move in real time. These aren’t challenges I’ve faced as a tech founder—but I have faced them running restaurant

19 июл. 2025 г., 13:10:05 | Fast company - tech
Forget chatbots. Physical and embodied AI are now coming for your job

Amazon recently announced that it had deployed its one-millionth robot across its work

19 июл. 2025 г., 10:50:03 | Fast company - tech
Staying hands on made scaling to $1B+ fun for Cloudflare’s founder

On this week’s Most Innovative Companies podcast, Cloudflare COO Michelle Zatlyn talks with Fast Company staff writer David Salazar about hitting $1B in revenue and going global, as well as

19 июл. 2025 г., 08:30:05 | Fast company - tech
‘Who did this guy become?’ This creator quit his job and lost his TikTok audience

If you’ve built an audience around documenting your 9-to-5 online, what happens after you hand in your notice?

That’s the conundrum facing Connor Hubbard, aka “hubs.life,” a creator who

18 июл. 2025 г., 20:50:06 | Fast company - tech
OpenAI advisory board says it should remain a nonprofit

OpenAI should continue to be 

18 июл. 2025 г., 18:40:03 | Fast company - tech
Meta-owned WhatsApp could be banned in Russia. Here’s why

WhatsApp should prepare to leave the Russian market, a lawmaker who regulates the IT sector

18 июл. 2025 г., 16:20:03 | Fast company - tech
The simple pleasures of computing in 1995

This is an edition of Plugged In, a weekly newsletter by Fast Company global technology editor Harry McCracken. You can sign up to receive it each Friday and read all issues

18 июл. 2025 г., 13:50:08 | Fast company - tech