Skip to main content

Today, hacks are annoying. In future smart cities, they could kill

Image used with permission by copyright holder

Lax computer security is something everybody complains about, but no one does anything to fix it. Witness the egregious examples of security lapses ranging from Equifax to Yahoo that have compromised the personal data of billions of people.

But that lackadaisical attitude toward cybersecurity is going to have to change if smart cities are going to succeed. As more of a city’s physical infrastructure relies on connected services to control everything from traffic lights to the power grid, the more vulnerable it potentially becomes—and the more dangerous it becomes for citizens walking its streets.

Cities across the globe are installing technology to gather data in the hopes of saving money, becoming cleaner, reducing traffic, and improving urban life. In Digital Trends’ Smart Cities series, we’ll examine how smart cities deal with everything from energy management, to disaster preparedness, to public safety, and what it all means for you.

Until now, the compromised security at businesses like Dunkin’ Donuts, Marriott’s SPG loyalty program, and Quora has been, for many people, a mere annoyance. True, the breach at Marriott involved as many as 500 million customers and their passport information, a costly mistake that could run into billions of dollars if the documents have to be replaced. But in general, cyber fraud and identity theft has become an accepted cost of the convenience of leading a digital life.

However, such security mistakes could prove fatal in smart cities of the future where everything from public transportation to water filtration systems rely on the integrity of a municipality’s cyber connections.

Perhaps nowhere is the threat more keenly perceived than in the nexus between self-driving vehicles and a city’s traffic infrastructure. What would happen, security researchers worry, if such communications were interrupted or, even worse, falsified? Could cars and buses be sent careening at each other at full speed or remotely directed to speed over sidewalks into pedestrians and buildings?

Argus Cyber Security

Fortunately, several security focused companies, such as Argus and Upstream, have been working for some time in the connected car space, trying to button down automotive systems. Argus demonstrated some of the vulnerabilities to Digital Trends by using a known hack to remotely turn on a Jeep’s headlights, windshield wipers, and even brake the car while this reporter was driving the vehicle. It’s an unnerving experience, to say the least. But imagine hundreds of cars all being remotely controlled by digital pirates looking to cause citywide mayhem.

Lackadaisical attitude toward cybersecurity is going to have to change if smart cities are going to succeed.

Such scenarios are the stuff of engineers’ nightmares. So automakers have been building out their own security operation centers, anticipating the connected future. Major parts suppliers have also been expanding their offerings. (German auto systems company Continental acquired Argus, for example.) In general, such security work has focused on watching for nefarious communications with cars, anticipating hacks before an incursion can occur.
But beyond self-driving cars, smart cities require a broader approach.

So last month BlackBerry announced it was going to make a security credential management system (SCMS) freely available to cities and automakers working on smart city projects. The idea: use a public key-based certificate system to authenticate transmitted instructions and information between transportation systems and the municipal infrastructure. It would ensure, for example, that a message from the city’s traffic system that a light ahead was turning red was genuine, so that self-driving cars would stop in time. Conversely, an ambulance could turn lights ahead green and send warnings to other vehicles on the road. Such vehicle-to-infrastructure and vehicle-to-vehicle (V2X) communications need to be virtually instantaneous and reliable to ensure safety.

Jim Alfred, the head of BlackBerry’s Certicom product group, told Digital Trends during a press conference that such certificates would be generated on the fly, so that they couldn’t be spoofed or faked. Furthermore, the cloud-based approach would be fast enough to accommodate the needs of such V2X systems, including alerts about accidents or sudden changes in road conditions ahead.

BlackBerry, which has arguably more experience with in-car systems via its QNX division than any other company, also said that the communications between vehicle and infrastructure would remain anonymized to maintain privacy. The initial tests of the company’s system will take place early this year in coordination with the Invest Ottawa development program and its supported 10-mile autonomous vehicle test track in Canada’s capital.

Ottawa's Autonomous Vehicle Ecosystem
Ottawa’s Autonomous Vehicle Ecosystem Invest Ottawa

[Toronto wants to get smart, but citizens are concerned about privacy.]
The need for such a secure communications system has been noted by the U.S. Department of Transportation, but no standard has yet been proposed. That means municipal governments are on their own when it comes to ensuring the reliability and safety of such systems.

Further underscoring the issue, cybersecurity is a moving target. As new services like smart city integration come online, it opens up new attack vectors and more opportunities for new hacking techniques. Mozilla, for example, recently noted the lack of security on popular drones from DJI and Parrot, a concern as cities look to such unmanned aircraft to assist first responders and law enforcement–never mind the kind of disruptions caused by rogue drones at London’s Gatwick airport. And as has been painfully demonstrated over the past couple of years, larger companies have been unable to stay ahead of such threats on their own. So many businesses and governments are looking to smaller security startups for help.

In New York City, a new Global Cyber Center is being created for just such a purpose under the direction of the New York City Economic Development Corporation. Last fall, the city selected the Israeli firm, SOSA, to establish and manage the center, which will bring together venture capitalists, security startups, and Fortune 500 companies seeking solutions to tomorrow’s digital threats.

“The biggest worry is about autonomous vehicles where one single hack can go global,” Uzi Scheffer, SOSA’s CEO, told Digital Trends. He said the fact that New York is also a global financial center makes it an even more attractive target for hackers.

“The biggest worry is about autonomous vehicles where one single hack can go global.”

SOSA expects the 15,000-square-foot Global Cyber Center will open in Manhattan’s Chelsea neighborhood by the spring. It’s intended to be a launching pad for new security initiatives that larger corporate and municipal clients can tap into. But it’s also going to take a significant amount of money: $30 million from the city and a reported $70 million from private partners.

Obviously, not every municipality can attract such substantial investments or afford such vertically oriented technology initiatives. Hence, the need for a security standard is rapidly becoming one of the more pressing problems for smart cities looking to integrate intelligent systems. Whether we’ll see the adoption of such an industry standard or see a service like that from Blackberry become a de facto standard for cities to build on, remains to be seen.

John R. Quain
Former Digital Trends Contributor
John R. Quain writes for The New York Times, Men's Journal, and several other publications. He is also the personal…
Global EV sales expected to rise 30% in 2025, S&P Global says
ev sales up 30 percent 2025 byd sealion 7 1stbanner l

While trade wars, tariffs, and wavering subsidies are very much in the cards for the auto industry in 2025, global sales of electric vehicles (EVs) are still expected to rise substantially next year, according to S&P Global Mobility.

"2025 is shaping up to be ultra-challenging for the auto industry, as key regional demand factors limit demand potential and the new U.S. administration adds fresh uncertainty from day one," says Colin Couchman, executive director of global light vehicle forecasting for S&P Global Mobility.

Read more
Faraday Future could unveil lowest-priced EV yet at CES 2025
Faraday Future FF 91

Given existing tariffs and what’s in store from the Trump administration, you’d be forgiven for thinking the global race toward lower electric vehicle (EV) prices will not reach U.S. shores in 2025.

After all, Chinese manufacturers, who sell the least expensive EVs globally, have shelved plans to enter the U.S. market after 100% tariffs were imposed on China-made EVs in September.

Read more
What to expect at CES 2025: drone-launching vans, mondo TVs, AI everywhere
CES 2018 Show Floor

With 2024 behind us, all eyes in tech turn to Las Vegas, where tech monoliths and scrappy startups alike are suiting up to give us a glimpse of the future. What tech trends will set the world afire in 2025? While we won’t know all the details until we hit the carpets of the Las Vegas Convention Center, our team of reporters and editors have had an ear to the ground for months. And we have a pretty good idea what’s headed your way.

Here’s a sneak peek at all the gizmos, vehicles, technologies, and spectacles we expect to light up Las Vegas next week.
Computing

Read more