Skip to main content

Security loopholes found in BMW’s connected drive

On 30 January, security loopholes in BMW vehicles equipped with connected drive technologies were revealed. Believed to affect 2.2 million BMW vehicles worldwide, these flaws in the software allow thieves to unlock doors and track car data through a mobile phone without leaving a trace. The Federation Internationale de l'Automobile (FIA) has long advocated for secure, open networks for vehicle connectivity. Vehicle manufacturers have argued that only closed networks can be truly secure. In fact, the loop
January 30, 2015 Read time: 2 mins
On 30 January, security loopholes in 1731 BMW vehicles equipped with connected drive technologies were revealed. Believed to affect 2.2 million BMW vehicles worldwide, these flaws in the software allow thieves to unlock doors and track car data through a mobile phone without leaving a trace.

The Federation Internationale de l'Automobile (FIA) has long advocated for secure, open networks for vehicle connectivity. Vehicle manufacturers have argued that only closed networks can be truly secure. In fact, the loopholes in BMW’s closed, wireless connected car network prove that a closed network is not necessarily secure.

Jacob Bangsgaard, director general of FIA Region I said: “We are concerned about these findings as car owners have been unknowingly at risk of having their vehicle tracked and opened without a single trace. We have always supported strong data protection for consumers, which should be the leading concern as connected vehicles come to market. As has been proven in this example, a closed network does not necessarily result in data security and car owners must be assured that their vehicle data cannot be abused by tracking or theft.”

The gaps in security were discovered as part of a study performed by the German Automobile Club, ADAC, to discover what repair and maintenance data is sent over the BMW network. The functions that were found to be accessible remotely were opening of doors, location of the vehicle, recorded speed data, programming of the emergency call number, and emails. BMW has announced that the security loopholes will be closed by 31 January 2015 by activating encrypted communication with the affected vehicles. This is the first-ever ‘digital recall’; it will not require a workshop call or the replacement of any parts and will be carried out remotely.

For more information on companies in this article

Related Content

  • Technology and finance shapes up to make MaaS happen
    June 7, 2017
    The technology and finance aspects needed for Mobility as a Service (MaaS) to become widely adopted are taking shape as Geoff Hadwick and Colin Sowman hear. Sampo Hietanen, CEO of MaaS Global and ‘father’ of MaaS, started his address to ITS International’s recent MaaS Market conference in London by saying: “All of the problems that can be solved by a company or group of companies have already been solved, and now we are left with the big ones such as housing, transport and health. He called MaaS the “Netfli
  • European Mobility-as-a-Service Alliance launched
    October 6, 2015
    Twenty European organisations have joined forces to establish the first Mobility as a Service (MaaS) Alliance. This new initiative will work towards a truly European and common approach to MaaS through public and private stakeholder cooperation, providing the basis for the economy of scale needed for a successful implementation in Europe. The Alliance will be officially launched in the Finnish Pavilion (C37) at the ITS World Congress in Bordeaux on 6 October at 1300. The key concept behind MaaS is to
  • Dutch to level EU protest against German toll plan
    August 28, 2014
    A petition with almost 45,000 signatures will be submitted to the European Parliament on 2 September by the Royal Dutch Touring Club (ANWB) in protest at a proposed German road toll that will fall primarily on foreign drivers. The Dutch Club is urging the European Parliament to get involved and address the question of discrimination against international motorists. The ANWB will be represented by their President, Frits van Bruggen, and the European Parliament will be represented by Dutch MEP, Wim van de
  • Connected Car offers plug-and-play remote vehicle access
    March 1, 2013
    Connected Car, Delphi’s plug-and-play connectivity device, connects into an OBDII port on any vehicle sold in the US from 1996 onwards and allows consumers to quickly lock and unlock their vehicle’s doors, as well as locate, track and even monitor their vehicles through a smartphone app or the internet. Delphi has teamed up with Verizon Wireless to ensure data transmitted through the device and via the internet remains secure and encrypted, allowing users to safely lock their vehicles remotely, track their