LOUISVILLE, Ky. — During a presentation on automotive hacking at DerbyCon last month, security consultant Craig Smith said that a malware-infected vehicle coming in for service could potentially infect a dealership’s testing equipment. In turn, that malware could spread to every vehicle the dealership services, WIRED reports.
Smith, who founded the open source car hacking group Open Garages, unveiled a tool at the conference to find security vulnerabilities in the equipment dealerships use to update car software and run vehicle diagnostics. Using the tool, Smith said he has identified multiple security flaws, including dealership equipment that doesn’t check for the length of a VIN — which would allow an infected vehicle to submit a much longer number, potentially breaking the diagnostic tool’s software and allowing a malware payload to be delivered.











