Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • July 18, 2012
    Slow moving US road user charging programme
    Bern Grush recently attended the Mileage-Based User Fee Conference in Austin Texas where the fledgling American landscape for Road User Charging is beginning to take shape. When I was a kid I liked to poke sticks into the ants' nests in sidewalk cracks. Ants would scatter in every conceivable direction. They ran in circles, they ran over and through each other. They screamed without logic. I was fascinated.
  • October 28, 2016
    New solutions for catching texting drivers
    Many countries have laws prohibiting texting while driving but enforcement is proving difficult – David Crawford looks at some new approaches being tried by authorities. Finding definitive solutions – technological, regulatory and educational - to the potentially lethal practice of people driving while using mobile phones is proving elusive, while the stakes grow higher.
  • May 31, 2013
    Driverless vehicles will cause changes in society
    Paul Godsmark gives his views on what the advent of autonomous vehicles would mean for the wider society. Further to your article ‘Driver not required…’ in the Jan/Feb edition of ITS International which gave some great background to autonomous road vehicle (ARVs), I feel that the bigger picture is needed to aid understanding. There is a ‘technology freight train’ heading our way that is going to transform our roadways but we don’t seem to be aware of it and, therefore, are in no hurry to react.
  • July 12, 2016
    Global automotive cyber security market to be ‘worth US$31.8 million by 2021’
    A new report from MarketsandMarkets projects the global automotive security market to grow at a CAGR of 13.3 per cent between 2016 and 2021, reaching a market size of US$31.8 million by 2021. According to the report, Automotive Cyber Security Market by Security Type, the major factors behind the growth of the global automotive cyber security market are the growing connected cars being introduced from OEMs and rising security concerns among end-users.