A cybersecurity specialist spent two weeks probing a BYD Shark 6 plug-in hybrid and demonstrated how easily someone with remote access could interfere with the vehicle. Because a key entry point had no password protection, he was able to move through the car’s internal systems, lock doors from outside, blast audio, toggle the infotainment screen, switch wipers and headlights on and off, and even cut the lights while the reporter was driving on a country road. More critical systems such as brakes and cameras were reportedly segmented and harder to reach, but the disruptions shown were highly distracting and could be dangerous at speed.
The expert also used the vehicle’s microphones and speakers to eavesdrop and manipulate voice assistants during a drive through Canberra, recording a casual “Hey Siri” and then playing edited audio to extract location, date of birth and banking information, and to pull contact numbers. The demonstration underscores surveillance and data risks tied to connected EVs, especially those manufactured in China, prompting warnings from security agencies and calls for stronger rules. Government consultations on vehicle software and cybersecurity have begun, while the manufacturer maintains data is stored locally and denies sharing it with foreign authorities.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.