As I discussed previously, the auto industry and the Department of Transportation (DoT) via the National Highway Traffic Safety Administration (NHTSA) plan to mandate that every new car include a technology called “Dedicated Short Range Communication” (DSRC), a device that talks to every other car with a DSRC unit (something called “vehicle-2-vehicle” or “v2v” communication). The auto industry fully supports this mandate, which is surprising (since industries rarely like mandates) until you (a) read this report by Michael Calabrese showing how the the auto industry hopes to monetize this with new services and harvesting your personal information (while piously claiming the mantle of saving lives); and, (b) the mandate helps DoT and the auto industry avoid sharing the spectrum with potential unlicensed uses (which actually do contribute to saving lives, but I will save that for latter).
As it happens, in addition to being a full time spectrum nut, I spend a fair amount of time these days on privacy, with just a touch of cybersecurity. So I started to dig into the privacy and cybersecurity implications of mandating DSRC on every car. My conclusion, as I discuss below, is that the DSRC mandate as it now stands is a disaster for both cybersecurity in cars and for privacy.
Yes, NHTSA addresses both privacy and cybersecurity in its 2014 Research Report on DSRC in terms of evaluating potential risks and solicited comment on these issues in their “Advanced Notice of Proposed Rulemaking” (ANPRM). It is in no small part from reading these documents that I conclude that either:
(a) NHTSA does not know what it is talking about; or,
(b) NHTSA does not actually care about privacy and cybersecurity; or,
(c) NHTSA is much more interested in helping the auto industry spectrum squat and doesn’t care if doing so actually makes people less safe; or,
(d) Some combination of all of the above.
As for the auto industry and its commitment to privacy and cybersecurity, I will simply refer to this report from Senator Markey issued in February 2015 (and utterly unrelated to DSRC), find that the auto industry (a) remained extremely vulnerable to cyberattacks and infiltration by hackers; (b) the auto industry had no organized capability to deal with this threat; and, (c) the auto industry routinely collected all kinds of information from cars without following basic notice obligations, providing meaningful opt out, or adequately protecting the information collected. (You can read this article summing up the report rather nicely.) For those who think the auto industry has no doubt improved in the last year, I refer you to this PSA from the FBI issued in March 2016 on vulnerabilities of cars to hacking.
I note that these remain problems regardless of whether the FCC permits sharing in the band, although it does call into question why anyone would mandate DSRC rather than rely on the much more secure and privacy friendly technologies already on the market — like car radar and LIDAR systems. But if the auto industry and NHTSA insist on making us less safe by mandating DSRC, the FCC is going to need to impose some serious service rules on the spectrum to protect cybersecurity and privacy the way they did with location data for mobile 911.
And, just to make things even more exciting, as explained in last week’s letter from the auto industry, GM is rushing out a pre-standard DSRC unit in its 2017 model cars. Because which is more important? Creating facts on the ground to help the auto industry squat on the spectrum, or making sure that DSRC units installed in cars are actually secure? Based on past history of the auto industry in the cybersecurity space, this is not a hard decision. For GM, at least, spectrum squatting rules, cybersecurity drools.
On the plus side, if you ever wanted to live through a cool science fiction scenario where all the cars on the highway get turned into homicidal killing machines by some mad hacker baddy, the NHTSA mandate for DSRC makes that a much more likely reality. In fact, it’s kinda like this Doctor Who episode. And lets face it, who wouldn’t want to drive in a car controlled by Sontarans? So, trade offs.
I explain all this in detail below . . . .