E-scooters can be hacked to eavesdrop on riders: Study

Image
Press Trust of India Houston
Last Updated : Jan 27 2020 | 6:30 PM IST

Micromobility vehicles such as e-scooters -- which are seen as potential solution to help tackle traffic congestion in cities -- may pose security and privacy risks for the riders, researchers, including those of Indian origin, have found.

The researchers from the University of Texas at San Antonio (UTSA) in the US found that e-scooters have risks beyond the perils of potential collisions.

"We were already investigating the risks posed by these micromobility vehicles to pedestrians' safety. During that study, we also realised that besides significant safety concerns, this new transportation paradigm brings forth new cybersecurity and privacy risks as well," said Murtuza Jadliwala, an assistant professor at UTSA, who led the study.

According to their review, hackers can cause a series of attacks, including eavesdropping on users and even spoof GPS systems to direct riders to unintended locations.

Vendors of e-scooters can suffer denial-of-service attacks and data leaks, according to the researchers, including Nisha Vinayaga-Sureshkanth, and UTSA postdoctoral fellow Anindya Maiti.

"We've identified and outlined a variety of weak points or attack surfaces in the current ride-sharing, or micromobility, ecosystem.

This could potentially be exploited by malicious adversaries right from inferring the riders' private data to causing economic losses to service providers and remotely controlling the vehicles' behaviour and operation," said Jadliwala.

Some e-scooter models communicate with the rider's smartphone over a Bluetooth Low Energy channel, the researchers said.

Someone with malicious intent could eavesdrop on these wireless channels, and listen to data exchanges between the scooter and riders' smartphone app by means of easily and cheaply accessible hardware, and software tools, they said.

Those who sign up to use e-scooters also offer up a great deal of personal and sensitive data beyond just billing information.

According to the study, providers automatically collect other analytics, such as location and individual vehicle information.

This data can be pieced together to generate an individual profile that can even include a rider's preferred route, personal interests, and home and work locations, according to the researchers.

"Cities are experiencing explosive population growth. Micromobility promises to transport people in a more sustainable, faster and economical fashion," said Jadliwala.

"To ensure that this industry stays viable, companies should think not only about rider and pedestrian safety but also how to protect consumers and themselves from significant cybersecurity and privacy threats enabled by this new technology," he said.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jan 27 2020 | 6:30 PM IST

Next Story