Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Ford Research looking to help drivers manage stressful situations on the road
    June 28, 2012
    Engineers in the Ford Research and Innovation labs are developing ways to help the driver stay focused in busy situations by intelligently managing incoming communications. Data from the sensing systems of driver-assist technologies can be used to determine the amount of external demand and workload upon a driver at any given time including traffic and road conditions. In addition, Ford continues its health and wellness research with the development of a biometric seat, seat belt and steering wheel that can
  • Need for secure approach to connected vehicle technology
    January 7, 2013
    Accidental or malicious issue of false messages to connected vehicles could result in dire consequences, so secure systems of authentication and certification are likely to be necessary, write Paul Avery and Sandra Dykes. Connectivity among vehicles in urban traffic systems will provide opportunity for beneficial impacts such as congestion reduction and greater safety. However, it also creates security risks with the potential for targeted disruption. Security algorithms, protocols and procedures must take
  • Delivering accurate vehicle identification
    August 1, 2012
    In the Netherlands, TNO, the independent research organisation, has been engaged in a project on behalf of the RDW, the Dutch vehicle registration and licensing authority, intended to look at the feasibility of using electronic means to make vehicle identification more accurate and less susceptible to fraud. Electronic Vehicle Identification (EVI) has been in existence in various forms for several years now but TNO was tasked with finding out whether OnBoard Unit (OBU)-based applications could be complement
  • What's next for traffic management and data collection?
    January 26, 2012
    As the technologies and stakeholders in traffic management evolve, what can we expect to see happening in the coming years? For many, the conversation of the moment is just how, and how far, the newer technologies and services provided principally by the private sector should be allowed to intrude into the realms of traffic management.