Skip advert
Advertisement

Mitsubishi Outlander PHEV at risk of hacking

Security experts showed how hackers and thieves can exploit a weakness in the Mitsubishi Outlander PHEV's Wi-Fi system to disarm the alarm

Mitsubishi Outlander PHEV - front

The Mitsubishi Outlander PHEV - UK's best selling plug-in electric car - has become the latest car susceptible to hacking, after weaknesses in the car's on-board Wi-Fi security allowed researchers to turn off security alarms.

Security expert Ken Munro and his colleagues at Pent Test Partners security firm began investigating the Outlander PHEV after Munro noticed the mobile app used to communicate with the car had an unusual characteristic.

Advertisement - Article continues below

Most mobile apps use a GSN module to communicate between the car and the mobile phone, but the Outlander PHEV does without one. Instead, the Mitsubishi has a wireless access point on-board the car, which means it can be talked to directly.

Munro then realised the password to the Wi-Fi key can be easily cracked. He said: “The password is not long enough. The format is four lower cases, plus six numeric digits. That just isn’t enough.” On a relatively slow cracking rig, it took Munro and his team just four days to crack the password key. With top notch software the key can be accessed within a day. 

Munro then looked if there was any more security between phone and the Wi-Fi access point other than the key. He said: “ We listened to look at the traffic going between the car and the device, and discovered a relatively simple binary protocol that was incredibly straightforward to understand and reverse engineer.”

This allowed Munro to communicate with the car directly, and gave him control of functions like lights and air-conditioning, and more worryingly, access to the charging and security status. Munro was able to turn off the car’s alarm and disconnect it from charging, showing how potential perps could break into the car and drive away with it. 

A short-term fix exists, according to Munro. He advises to first unpair all mobile devices that have been connected with the car's access point. Then, using the app, he advises users to go to 'Settings' and select 'Cancel VIN registration', to effectively put the device to sleep. A long-term fix would require intervention from Mitsubishi. 

Mitsubishi has since said it has taken the “matter seriously". It also pointed out that the hack affects the car's app and gives hackers limited access: “It should be noted that without the remote control device, the car cannot be started and driven away." 

Are you worried about car hackers? Tell us in the comments below...

Skip advert
Advertisement
Skip advert
Advertisement

Recommended

Drivers pay £1.6 billion extra for fuel as retailers maintain “outrageous” profit margins
Diesel pump
News

Drivers pay £1.6 billion extra for fuel as retailers maintain “outrageous” profit margins

Fuel profit margins way above the historical average mean drivers are being ripped off at the pumps
26 Jul 2024
It’s official: new expanded ULEZ has worked… but not as well as the old one
ULEZ sign
News

It’s official: new expanded ULEZ has worked… but not as well as the old one

ULEZ expansion has helped bring down emissions in Greater London, but results show it isn’t as effective as original implementations of the scheme
26 Jul 2024
Drink-driving at a 13-year high: could alcolocks be the solution?
Car keys next to an alcoholic drink
News

Drink-driving at a 13-year high: could alcolocks be the solution?

The RAC is calling for the introduction of alcolocks as over 1,900 people were killed or seriously injured by drink-drive collisions in 2022
25 Jul 2024
“Bleak picture” as 130,000 cars were stolen in the UK last year with 77% of cases never solved
Thief breaking in to car
News

“Bleak picture” as 130,000 cars were stolen in the UK last year with 77% of cases never solved

The latest Office of National Statistics data showcases how as many as 350 vehicles are stolen in the UK every day
25 Jul 2024

Most Popular

New Tesla Model 2: CEO Elon Musk reaffirms affordable, entry-level electric car will arrive in 2025
Tesla 'Model 2' teaser image
News

New Tesla Model 2: CEO Elon Musk reaffirms affordable, entry-level electric car will arrive in 2025

The baby Tesla, also referred to as as project ‘Redwood’, is scheduled to enter production in the first half of 2025
24 Jul 2024
Car Deal of the Day: brand-new VW ID.7 EV with 381-mile range for less than you’d expect
Volkswagen ID.7 - front cornering
News

Car Deal of the Day: brand-new VW ID.7 EV with 381-mile range for less than you’d expect

If you want an electric car that can go the distance, then maybe you should consider our Deal of the Day for 23 July
23 Jul 2024
'Luxury car' tax grab to hit 70% of EVs, fuelling calls for exemption
Luxury car tax
News

'Luxury car' tax grab to hit 70% of EVs, fuelling calls for exemption

New Labour Government urged by UK motor industry to address concerns of potential EV purchasers and boost uptake of electric vehicles among private bu…
25 Jul 2024