Securing Software-Defined Vehicles – Ted Miracco, Approov
Approov CEO Ted Miracco explains what makes securing software-defined vehicles a major challenge as more software is embedded within them.
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with Ted Morocco. Who's the CEO for approve? And we're talking about the safety of software-defined vehicles given the fact that there's so much dependent on software and apis these days 10.
Welcome the show. Thank you very much. It's great to be here Mike.
We think about cars is kind of Hardware in the grand scheme of things, but it's pretty clear these days that they are being more of a software-defined platform and much the same way that our phone is a platform for developing applications and deploying it these days. How we give it enough thought to the security of these environments because every time that we have historically added a new platform security has been an afterthought and maybe that might be not the time for this to happen. Yeah, so you're right right on target.
You know that the vehicle is is a rolling laptop these days. In fact, you know, I've even heard of you know, it's it's a it's a number of laptops because if you look at all of the different operating systems, you know, most of them, you know Linux based in some sort of this a lot of operating systems rolling around in that vehicle and they all have apis and they all have their filled with sensors and they're filled with a lot of communication going back and forth and if you read the headlines, which I'm sure you do, you know virtually every major Vehicle Manufacturer has been hit with security issues data breaches and other things associated with their vehicles from people being able to start the vehicle or monitor the location or pull payment information out of an app that's connected to the vehicles account. So this the security problems all over the the ecosystem, you know.
When in the automotive sector and it is a big problem? So I think this is a very good topic. Today the phone platform is this huge massive ecosystem, but I wonder if the car will develop in the same way or is that going to be a little more tightly controlled because system because we just can't have everybody in his brother creating an application for a car.
So we might wind up with a scenario where the manufacturers are pretty much tightly controlling the software ecosystem that goes into that car. Yeah, the manufacturers are trying to tightly control it but you know, the the automotive industry is there's a supply chain in it. There's always been a supply chain when it came to everything from you know, chassis and frames and wheels and bearings and and engine components and the that model has been continued within the automotive sector to the electronics.
So they are our experience and we work with many of the major Automotive manufacturers on on the on protecting their mobile apps, but we're generally not dealing with the manufacturer directly. We're dealing with a subcontractor. So they are coming up with specifications and bids as to what functionality they want in in the mobile app.
And then they're you know, generally I would say always but they're they're rolling it out to the lowest bidder and there's an app development company. There that's responsible for producing, you know the apps and and other systems that have access to apis. And that's where a lot of the security breaches are coming from is is that they you know, this the secrets the the certificates the fastest way to get the app out is is not the most secure way to get the app out.
So you have you know, certificates being buried in apps and plain sight and you have mechanisms where Bots and and other things can be used to once you get get access to an API. You can roll through the database and extract information which could include personal data. It could include a lot of other sensitive information that that and information that might affect safety in the vehicle.
So, you know securing those apis is got to become a bigger priority and you know, we've seen lots of headlines, you know on these kind of breaches that are taking place. So yeah everybody is talking That securing the software supply chain these days, but what in general is the challenge that you're seeing people have and then specifically is that more complicated for the automotive industry. Um well for the automotive industry, I think that it is important that they select, you know vendors based on you know, they're not the low cost vendor necessarily, you know that they really they pick from vendors that have a track record in this space and that are that are using best practices from a secure some security perspective.
And I think that they need to in addition to passing down the functionality requirements. There has to be a series of specifications from a security perspective that address, you know API access and and encryption and some of these these details that are important and maybe having a tighter control over it, you know, we we've worked with a number of the leading manufacturers and and feel extremely strong about our technology when it comes to really Securing the application from from making sure that the phone itself is has not been compromised or is in jailbroken or isn't isn't compromised right through the application itself, including the API and including the back end on the server where information is being sent so that whole Channel needs to be protected from end to end and and that's a really important requirement and the protection of Secrets is is another thing that becomes challenging is because you know, you have not only have first party apis, but you have third party apis, you know, so being able to protect access to third party apis is a important, you know security precautions to take as well because the manufacturer might not have control over all of the back ends, you know a mobile app, you know, maybe connected to as many may have as many lives. It doesn't you know different apis that it's accessing some of which are controlled, you know by the manufacturer some Your third party apps so the whole chain the whole complex Network needs to be well protected from a secret perspective.
Anytime there is a safety issue. It's not too long before government folks get involved. So do you think we'll see a lot more regulations in this space?
Because all it will take is one crash for somebody to kind of stand up and go. Hey what's going on here? Yeah, I think we will the problem is the pace of government and the pace of the legal system is is rather slow and I think that unfortunately, you know, history is kind of told us that the legislation is almost a decade behind in, you know, the reality of what's going on.
So, I think it's it would be naive on the consumers part to believe that that the government is going to come to the rescue or the legal system is going to come to the rest, you know, there are obviously are the liability concerns and and the law from a liability perspective is quite robust, but in terms of regulating it, I'm not sure that the Regulators understand the problem at a sufficient level today to solve the problem and in the near future, so I think it's going to take It's going to take the CIS, you know to really in the cto's of these companies to be, you know, forward-thinking and you know, they have to balance cost but you know, you know, there are there are very well known best practices that can be taken and there's there's also pen testing and other things that need to be invested in, you know to try to see if you know you build the security in but then you really need to turn turn the hackers lose and see what kind of damage they can do and what access they can get to it to do a complete job, you know in terms of developing these things the Automobiles of the future. We do know of organizations that either buy or at least fleets of vehicles for a variety of purposes. Will the csos for those companies have to figure out how to secure what amounts to a new platform in much the same way that they secure any type of server or endpoint.
Yeah, yeah, they they will they will have to figure it out and we've actually worked with one of them is notable one, you know that we've seen some interesting things going on in the car sharing space as well. And we have a large Automotive account that uses our technology for right car sharing and the challenge they face there was more financial and that hackers were trying to unlock and get into Vehicles so that they could drive them off off the lot and part amount. So, you know securing that yeah, I made a lot of financial sense, you know to address that that issue and they were very thorough in in the way that they evaluated the technology and the choices that they made and we've had no problems, you know, all of the issues that they were facing it gone away so that yeah, they're gonna have to get involved in it and it isn't it isn't a problem that you can easily Outsource.
You know to us to a sub. Is this problem gonna get more complicated because it seems like every year and new wave of cars or vehicles or rolling off the manufacturing line and they're increasingly driven by software and they have thousands of processors in them. As we go forward does this become something every year that we're going to see kind of the spike in attacks because there's going to be new apis and new components that people can go after and it seems like the cybercriminal community is pretty active in the space already.
Yeah, they are. They're extremely active. We will see more of it.
The types of attacks are going to change, you know, the the nature of the attacks will will change and we'll evolve. as the defenses evolved so it's going to be you know, it's going to be job security for a lot of people who are in this industry because it will be you know, a, you know a game of cat and mouse and we will see continue to see new vectors and and new defenses pop up for different things and that's brings me to any kind of another another point that is important for csios to think about is that you don't want to build you know, this the security for yesterday's, you know problems you want to put in place security mechanisms that can be updated and and I had a conversation just last week with a very forward-thinking, you know automotive company and the problem that that they were dealing with was that they knew that they could they could protect their mobile app to for today's threats, but they were concerned about the ability to update the security and not have to really These you know their mobile application when a new threat emerged so that you need to be able to have had that ability just like you do with with other systems to auto update and to push out new security patches to to the mobile application without having to rewrite the code and go through the whole release process through the app store because that that can delay things and it takes a long so there is a vulnerability. It takes a long time for the new app to get to everybody who's driving that vehicle and it leaves a lot of people vulnerable so being able to push updates and take into account new threats.
Instantaneously or as soon as they're detected and as soon as they're they're fixed to be able to change the certificates and update the certificate so that if that actors are using are access you can change things and you can update, you know, the security measures in those devices. So that's an important piece of it. And the thread itself may not be targeted specifically at the cloud if there's all these apis or the let me try that again.
The thread itself might not be specifically aimed at the vehicle because it has all these apis and it's connected to all these external services. So the attack may be coming through one of these external Services, right? Correct.
Yeah, and that's you know, that's one of the things that is very important from our perspective. And one of the things we kind of innovated in is that you want to be able to do what's called app attestation, which means that you the back end wants to be able to determine if the API request is coming from a genuine non-modified mobile app because that what's a hackers do is they basically modify the app or find a way to imitate a genuine app and make those API calls and they can do that with Bots and they can do that with man in the middle of taxes a lot of things that can be done. So you want to make sure that you're back and just talking to only a genuine untampered with mobile application not talking to a a network of Bad actors and network of thoughts that are set up.
actors to extract information from the backend databases So those are preventable and and that is an addressable, you know solvable capability today. Do you think there'll be subsystems in the car that are essentially firewalls and detection systems for these types of tax that somebody's going to build as well just like we do in traditional it environments. Yeah, I think that they're already are and and a lot of them have been put in place because of some of the breaches that have taken place and I think that we will see more of those as well, you know in in the future and the security will get better.
But so we'll so the tactics and and attack methods of the bad guys. What's your confidence level in these vehicles then would you put your family in these things? You feel good about driving these things or your little concerned?
Well, you know I am I I am very privacy motivated and and aware of some of the problems. So there are things that are within the user's control. so one of the things that I suggest and do myself is that when when you install apps, there's usually a series of questions that most people just click I agree and accept the defaults and I don't tend to do that.
You know that they every app you you pretty much install these days once access to all of your information your location your contacts your call history Etc. And there's no reason for it. So you want to be careful about what permissions you give and then you also want to be careful about what else you integrate into your vehicle, like one of the things you can do with I have a Tesla and you can connect apps within the console to it.
I'm very wary of that because I know that if you if they're if you connect an app that and there's a security breach within their app, it's connected to your data and your data. Could you get out through every connection that you enable so only enable a permissions and the connections and with things that are really Essential and important to you, so you should be pretty concerned that way and then there are other things you can do from it from a security perspective is that you can limit, you know, some of the features in the vehicle you can turn turn things off. So for example, you know again I'll sing about Tesla.
It's very common for people to break into Teslas within door handles that present themselves automatically because you can take if you're if you're key is admitting an RF signal thieves to figure it out a way to use antennas to collect that signal aim it at the doors and open up a vehicle even if the keys inside your house. So you can turn off that feature that the doors will present the door handles will present themselves to you and you can present that type prevent that type of attack, you know, so there's just a basic common sense and and you know, generally you got to be a little wary of why they're asking you for permission for certain certain things and if it's not necessary, don't don't provide it. All right function here if it connects to the internet no matter how mobile it is.
It still has an attack service that needs to be defended. Thanks for being on the show. Hey Mike.
Appreciate it. Thank you. All right back to you guys in the studio.