Skip to main content

OnStar hack can remotely unlock cars and start engines, GM claims to have a fix

gm maps for self driving cars onstar
Image used with permission by copyright holder
Following a dramatic demonstration of car hacking involving a Jeep Cherokee, a researcher claims to have found a way to break into General Motors’ OnStar telematics system and take control of certain vehicle functions remotely. GM says it has a fix, though.

Sammy Kamkar built a small device about the size of a router that he calls, a bit cheekily, “OwnStar.” It’s designed to break into the OnStar system and do anything one of its operators can do, including remotely track a car, lock or unlock doors, or start the engine, according to Wired.

Kamkar reported the issue to GM before the Wired story was published, and plans to reveal full details of the hack during the DefCon conference next week. The carmaker claims to have already fixed the problem by instituting stronger certificate controls at the servers that control the OnStar RemoteLink remote-access app.

OwnStar relies on this smartphone app, which sends signals to a car’s onboard computers. The device must be positioned somewhere on the car itself, close enough to intercept these signals. It then poses as the car’s actual systems, and harvests the car owner’s credentials. A hacker can use those credentials to mimic the app, and give remote commands to the car.

This was possible because the OnStar app wasn’t originally programmed to check for fake encryption certificates, something GM claims to have corrected in its recent update. Unlike with the Chrysler vulnerability exposed by researchers Chris Valasek and Charlie Miller, this was done through the OnStar system’s servers, so owners won’t have to take any action.

However, Kamkar isn’t convinced that the problem has been fixed. Yesterday, he tweeted that the issue is “not actually resolved yet.” He said he had spoken to GM, and was told the company was working on a final fix.

Earlier this week, GM announced that it had surpassed 1 billion OnStar customer interactions, including those using the app, phone calls, and in-vehicle interfaces. It says about 8.8 million of those interactions were done through the app, and claims to have over 7 million OnStar subscribers right now.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
Bentley Continental GT and GTC Speed get performance boost as plug-in hybrids
Front three quarter view of the new Bentley Continental GT Speed coupe.

A few years ago, Bentley set off on a path to electrification that was paved with plug-in hybrids and added models like the Bentayga Hybrid to its lineup. However, that path was more of a parallel side road, with plug-in hybrids augmenting the lineup rather than replacing traditional gasoline-only models. Now they're heading for the fast lane.

Unveiled Tuesday, the fourth-generation Bentley Continental GT Speed coupe and GTC Speed convertible are the most powerful Bentley road cars ever — and they're plug-in hybrids. These performance models herald a new era for the Continental GT, Bentley's signature vehicle, along with its GTC convertible variant.

Read more
Tesla recalls Cybertruck to fix two more issues
A Tesla Cybertruck throws red dust in a press photo.

Tesla CEO Elon Musk behind the wheel of a Cybertruck. Tesla

Two more issues have emerged with Tesla’s new Cybertruck pickup, causing the automaker to issue two recalls on Tuesday.

Read more
5 upcoming budget EVs we can’t wait for
Chevrolet Bolt EV on the beach

Electric cars are finally getting cheaper. For years, EVs were becoming more widely available -- but still at a high price. These days, the push is becoming less about simply developing an initial wave of EVs, and more about actually competing with them. Part of that has to do with price, so as we head toward a second, much wider wave of electric vehicles, we can expect to see some great inexpensive models.

There are plenty of budget EVs that have been announced and are set to roll out in the near future -- and we're pretty excited about many of them. Of course, for this piece we're being a little liberal with the term "budget." Budget for many buyers is totally different than "budget" for others. Still, here are five cheaper electric vehicles we can't wait to see on the roads.
Chevrolet Bolt EV Redesign

Read more