We asked a cybersecurity expert to remotely access a BYD. It was too easy
On a narrow country road outside Canberra, I'm driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.
But while I'm at the wheel, I'm not the only one in control — a hacker has access to the car.
As the 2.6 tonne ute rounds a bend, he gets to work.
With the stroke of a key, he kills the headlights, plunging me into darkness.
The attack is not a total surprise. The Shark has spent the last two weeks with Dan Hreszczuk, a cybersecurity expert, who specialises in cars.
His task was to hack the vehicle and find out what could be seen and done remotely by the Shark's Chinese manufacturer.
"It was easier than we were expecting," Hreszczuk says.
Modern connected cars — particularly EVs and hybrids — are increasingly run by software, giving manufacturers the power to change, update and control vehicles, like never before.
In the case of BYD and others, that software is controlled from China.
With fuel prices on the rise, EVs and plug-in hybrids like the Shark have gone mainstream this year, making up almost a third of new cars sales to date. More than half of these are from Chinese brands.
EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers, as they can be compelled by the country's national security laws to co-operate with authorities.
To put this potential access to the test, it made sense to pick a model from China's top EV brand, BYD.
Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark's lack of cybersecurity.
"The access we took advantage of didn't even have a password," he says.
"It's a little bit scary how open … the BYD Shark is to a hacker."
This lack of a password allowed Dan to access the car's digital arteries.
From there it was a matter of unpicking the software programs which control different functions in the car.
After two weeks, Dan was ready.
Sitting by the side of the country road, he demonstrates what could be done with remote access to a vehicle.
First, he locks the doors while I'm inside, blasts music over the speakers and plays images on the BYD's giant infotainment screen.
Then, as I drive, he remotely switches the wipers on at top speed, sprays the windscreen with water and turns the lights on and off.
The combination is unsettling and highly distracting.
Adding to the distraction: Dan has the speaker telling me repeatedly; "For safety use low beam".
Fortunately, I was only travelling 30km/h and the road was pretty straight.
Then, Dan kills the lights altogether.
Dan says he wasn't able to access more critical functions like brakes and cameras as these were well protected.
But it doesn't take much imagination to understand how dangerous, even this kind of access could be in the hands of a malicious actor, with a vehicle travelling at high speed on a winding road.
Surveillance
While sabotage is one worry, the concern most-often cited is surveillance, due to the array of cameras and microphones on an EV.
Last year, the UK military banned Chinese EVs — even those made with Chinese components — from parking within 3 kilometres of some of its most sensitive locations.
China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.
In Australia, there's no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.
But there's nothing to stop them owning a Chinese EV.
Trade Minister Don Farrell has a BYD Shark 6, the same vehicle that Dan hacked.
Farrell recently told a newspaper it's the "best ute I've ever owned".
ASIO's surveillance fears appear well founded, based on what else Dan is able to do to with the Shark even at a low level of access.
We devise a demonstration: I'll take the BYD for a drive around Canberra, and give my mum a call to talk her through some internet banking.
As I drive past the war memorial and down Anzac Parade, Dan has already remotely accessed the vehicle and is tracking my progress.
Then he gets to work.
"How about we turn on the microphone?" he suggests to the crew back at his lab.
At that point Dan can hear everything.
"Hey Siri," I say to my iPhone.
"Call 'mum mobile'."
When she picks up, I'm straight into the details of how I had set up her internet banking.
"I'm going to use as a temporary password, my initials, the number of my house, and then my full date of birth. And then you can go in later and change it if you want," I tell her.
Back at the lab Dan records the whole conversation.
The key is he's now got a recording of me saying, "Hey Siri".
When I pull into a service station and leave my phone unlocked in the car, Dan seizes his opportunity.
He's done a simple audio edit, stitching together me saying "Hey Siri" and his voice asking a few questions to get the personal details he needs.
Using the car's speaker system, Dan plays the voice command from his computer into the car.
"Hey, Siri, what is my home address?" the edited audio asks.
Siri replies, without questioning why I don't know where I live.
Dan repeats this process and quickly extracts my date of birth and age.
Within minutes, he's obtained the internet banking password.
Dan keeps fishing.
"Let's try and grab a few of his contacts. Let's see if he knows a prime minister.
"Hey Siri, tell me the phone number from my contacts for Malcolm Turnbull."
Once again, Siri dutifully delivers.
Dan's hacking challenge was made easier as Australia has no minimum cybersecurity standards for cars. That means BYD is not compelled to keep its software up to date or have a system for managing cybersecurity risks to its vehicles.
"I didn't need to pick the lock as BYD left the front door open," he says.
"I think people overlook a lot of these concerns for the convenience. It is a beautiful car to drive. It looks beautiful inside, but there are real security concerns."
Surprisingly, Australia has more cybersecurity regulation around connected washing machines or vacuum cleaners than cars.
Home Affairs and Cyber Security Minister Tony Burke defends this, saying the government has started by putting regulations around connected devices in the household.
"You want to first regulate where you will get the fastest uplift and … you also want to focus first on where the cyber attacks have principally been," he says.
The government has just started consultations with industry to introduce new cybersecurity and software rules for cars in Australia, but they likely won't be in force for years.
Alastair MacGibbon, Australia's former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.
MacGibbon says a cabinet minister should not be able to own a Chinese EV.
"China has always shown its strong desire to steal things, to surveil," he says.
"No one should be in any doubt that [Chinese EVs] are used in the same manner.
"The real question would come down [to]: could they cause harm with these vehicles? The capability is definitely there.
"Is the intent? I don't know."
Opposition Defence spokesman James Paterson says Australians' data needs to be better protected.
"A connected EV vehicle from China is the highest risk product in the marketplace. And right now, there's nothing that says to that brand what data you can collect on Australians, how it can be stored, when it can be transmitted."
BYD says the data it collects is stored in Australia. It says it has not and would not hand over the data of Australians to Chinese authorities.
Watch Four Corners' full investigation, Asleep at the Wheel, tonight from 8:30 on ABC TV and ABC iview.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.