The Major Problem With EVs No One Is Talking About

When GM earlier this year started recalling Bolts, it issued a warning to owners of the EV: don’t charge your car battery to 100 percent. Normally, this would be easy enough to do. But what if your charger got hacked?

Last year, researchers from the Southwest Research Institute in Texas successfully hacked the most popular charging system used in North America. The hack limited the charging rate, then blocked charging, and then overcharged the battery. The reason for the hack:

“This was an initiative designed to identify potential threats in common charging hardware as we prepare for widespread adoption of electric vehicles in the coming decade,” according to lead researcher Austin Dodson.

Mission accomplished.

Earlier this month, UK cybersecurity firm Pen Test Partners said that it had found cyber vulnerabilities in six home EV chargers and a large public charging network.

Some of the vulnerabilities were no small potatoes.

Among the findings of Pen Test Partners was a vulnerability that could potentially make possible the hacking of millions of EV chargers simultaneously and another that exposed user and charger data for the hacker to use.

Perhaps the most dangerous vulnerability that the cybersecurity experts uncovered, however, was the possibility for a hacker to take control over millions of chargers.

“As one could potentially switch all chargers on and off synchronously, there is potential to cause stability problems for the power grid, owing to the large swings in power demand as reserve capacity struggles to maintain grid frequency,” the firm said.

EVs have been touted as the future of transportation. Governments in Europe and North America are allocating billions in financing that focuses precisely on public charging networks. Yet, there is little talk about the cybersecurity implications of having a huge network of hundreds of chargers that can be hacked.

Public chargers are the riskiest, it seems. While one could hack a home charger, they would only gain access to that device and possibly the home network of that household. If they hack a public charger, they could gain access to the whole network, explains Baksheesh Singh Ghuman, Senior Director of Product and GTM Strategy at Finite State, a cybersecurity firm that specializes in connected devices.

Gaining access to data is one risk associated with the vulnerabilities of EV chargers. Another is even more straightforward: electricity theft. If a hacker breaches a public charger, they could siphon electricity off it and make someone else pay, says Singh Ghuman.

Attacks on home chargers can be serious, too, despite their much more limited focus. Since both EVs and EV chargers are connected devices, hacking the charger could grant the attacker access to things like passwords and other credentials. 

And that’s not even the worst that can happen.

“Threat actors can also gain control of the electric vehicles themselves, which includes control over steering, brakes, acceleration, and other functions which could result in an accident,” Singh Ghuman told Oilprice.

“They would have the ability to listen in on phone conversations held within the car and steal personal data from the vehicle’s connected network too.”

Everything is hackable, cybersecurity experts have warned repeatedly, from a corporate computer system to a pacemaker. And cybercriminals are often ahead of their opponents in the game of cat and mouse, forcing governments and cybersecurity service providers to often catch up.

Luckily, in the wake of the latest massive hack attacks in the U.S., action is being taken. A recent executive order by President Biden will oblige manufacturers of hackable equipment to start implementing more stringent cybersecurity standards, Singh Ghuman says.

It is important to act preemptively and remove as many vulnerabilities as possible as early as possible.

A lot of hopes are being pinned on electric vehicles as a crucial element of the low-carbon economy of the future. Automakers are spending billions on their shift to EVs, and one could only hope some of that money is being spent on guaranteeing the cybersecurity of the vehicles. It should be, given how much is at stake.

And with carmakers already aware of the challenges they face in promoting their EV models as the better cars, they need to be exceptionally wary of the possibility that the hackability of an EV could very well become a monumental issue alongside range anxiety.

Chargers are even more important. If a hacker can make several hundred chargers switch on and off when the hacker tells them to, that becomes a problem for the grid. And if a larger-scale attack can be launched, the situation would become a lot more serious.

There are already concerns about the addition of millions of EVs to city grids that were not built for this sort of electricity demand. Investments in the upgrade of grids so it can take the additional demand are seen at between $1,630 and $5,380 per EV, according to Boston Consulting Group.

And that’s for EV penetration rates of 10-20 percent. The more EVs are added, the more money will need to be spent to keep the grid stable.

The EV revolution is becoming a challenging endeavor in more aspects than one. The cybersecurity theme needs to be at the center of the EV discourse. The threats might be potential for now but let’s remember: everything can be hacked.

See more here: zerohedge.com

Header image: Forbes

Please Donate Below To Support Our Ongoing Work To Defend The Scientific Method

PRINCIPIA SCIENTIFIC INTERNATIONAL, legally registered in the UK as a company incorporated for charitable purposes. Head Office: 27 Old Gloucester Street, London WC1N 3AX. 

Trackback from your site.

Comments (8)

  • Avatar

    John V

    |

    Yeah, I remember when people complained about pumping their own gas starting in the ’70’s lol Hmm, funny how the deeper it gets in regards to alternative energy, we find more and more issues, and issues that are really dangerous. Killing wildlife, destroying forests, batteries catching on fire, cyber hacking, waste disposal of millions of turbines and solar panels, etc…

    Reply

  • Avatar

    Tom Anderson

    |

    Of course, batteries are only a technical glitch waiting for a fixer What we all seem to be missing is the classic advice about putting carts before horses.
    Back when the first oil well was sunk, inaugurating the petroleum age, we had the energy – in abundance – before the wheels. Whether it is true or not, I was told when young that gasoline (petrol) fractionally distilled from the raw crude was at first burned off as an unwanted byproduct. It only took a few years to find it a use, and we were on our way.
    We have it backwards now, with a theoretical automotive replacement waiting for enough energy to get it on the road.

    Reply

  • Avatar

    VMFAT-101

    |

    Why in the world does a battery charger need to be connected to the internet?

    Reply

    • Avatar

      Howdy

      |

      They are connected for monitoring purposes, plus of course, the feedback can be used for profit. Got a “smart meter”? Same thing. Hold most of the country to ransom by disabling the meter, thus denying electricity supply? History shows it can be done. Or this:
      https://www.wired.com/story/how-30-lines-of-code-blew-up-27-ton-generator/
      https://www.schneier.com/blog/archives/2007/10/staged_attack_c.html

      “It is important to act preemptively and remove as many vulnerabilities as possible as early as possible.”
      Don’t make me laugh. Security of all applications is not known fully until actually tested in the wild, and even then, It appears many are in the “cross the bridge when we come to it” class. Operating systems are a good example, though some are particularly bad…

      Most things are designed for a lazy society. Remote everything, apps for everything, push button get in your car and start it, smart everything.. All will end in tears, and self driving will be the pinnacle of (personal) disaster.

      Anything computer, in control of anything of value, or with possibility of control, with any kind of connection protocol, is an opportunity, though remote connection is worst.

      Reply

  • Avatar

    ЯΞ√ΩLUT↑☼N

    |

    Hack all the Kommiekrat party’s electric cars and crash ’em off a bridge. Very tempting..☺

    Reply

  • Avatar

    Mad Mike

    |

    So if a hacker can control your car then your murder would be a simple thing to do and it would look like an accident. Not to worry though as most hackers are sensible well adjusted people with a strong sense of community.

    Reply

  • url shortening

    |

    url shortening

    The Major Problem With EVs No One Is Talking About | Principia Scientific Intl.

    Reply

  • seo lists

    |

    seo lists

    The Major Problem With EVs No One Is Talking About | Principia Scientific Intl.

    Reply

Leave a comment

Save my name, email, and website in this browser for the next time I comment.
Share via