Skip to main content

OnStar hack can remotely unlock cars and start engines, GM claims to have a fix

Following a dramatic demonstration of car hacking involving a Jeep Cherokee, a researcher claims to have found a way to break into General Motors’ OnStar telematics system and take control of certain vehicle functions remotely. GM says it has a fix, though.

Sammy Kamkar built a small device about the size of a router that he calls, a bit cheekily, “OwnStar.” It’s designed to break into the OnStar system and do anything one of its operators can do, including remotely track a car, lock or unlock doors, or start the engine, according to Wired.

Recommended Videos

Kamkar reported the issue to GM before the Wired story was published, and plans to reveal full details of the hack during the DefCon conference next week. The carmaker claims to have already fixed the problem by instituting stronger certificate controls at the servers that control the OnStar RemoteLink remote-access app.

OwnStar relies on this smartphone app, which sends signals to a car’s onboard computers. The device must be positioned somewhere on the car itself, close enough to intercept these signals. It then poses as the car’s actual systems, and harvests the car owner’s credentials. A hacker can use those credentials to mimic the app, and give remote commands to the car.

This was possible because the OnStar app wasn’t originally programmed to check for fake encryption certificates, something GM claims to have corrected in its recent update. Unlike with the Chrysler vulnerability exposed by researchers Chris Valasek and Charlie Miller, this was done through the OnStar system’s servers, so owners won’t have to take any action.

However, Kamkar isn’t convinced that the problem has been fixed. Yesterday, he tweeted that the issue is “not actually resolved yet.” He said he had spoken to GM, and was told the company was working on a final fix.

Earlier this week, GM announced that it had surpassed 1 billion OnStar customer interactions, including those using the app, phone calls, and in-vehicle interfaces. It says about 8.8 million of those interactions were done through the app, and claims to have over 7 million OnStar subscribers right now.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
Plug-in hybrids are becoming more popular. Why? And will it continue?
Kia Niro EV Charging Port

There's a lot of talk about the idea that the growth in electric car sales has kind of slowed a little. It's not all that surprising -- EVs are still expensive, early adopters all have one by now, and they're still new enough to where there aren't too many ultra-affordable used EVs available. But plenty of people still want a greener vehicle, and that has given rise to an explosion in hybrid vehicle sales.

That's especially true of plug-in hybrid vehicles, which can be charged like an EV and driven in all-electric mode for short distances, and have a gas engine as a backup for longer distances or to be used in combination with electric mode for more efficient driving.

Read more
EV drivers are not going back to gas cars, global survey says
ev drivers are not going back to gas cars global survey says screenshot

Nearly all current owners of electric vehicles (EVs) are either satisfied or very satisfied with the experience, and 92% of them plan to buy another EV, according to a survey by the Global EV Drivers Alliance.

The survey of 23,000 EV drivers worldwide found that only 1% would return to a petrol or diesel car, while 4% would opt for a plug-in hybrid (PHEV) if they had to replace their car.

Read more
Trump team in sync with Tesla on ending crash-reporting requirements, report says
Beta of Tesla's FSD in a car.

The transition team of President-elect Donald Trump is planning to end existing car-crash reporting requirements to safety regulators, according to a Reuters report.

The report cites a document obtained by Reuters that lays out the transition team’s 100-day strategy for automotive policy. In the document, the team says the crash-reporting requirement leads to “excessive” data collection, Reuters says.

Read more