
Remember when a couple of computer programmers hacked into a Jeep Cherokee in 2015 and took full control of the vehicle?
It raised many questions about the potential of cyber security – even cyber terrorism – where someone thousands of kilometres away could override control of your vehicle, autonomous or not. All they needed was a phone and a laptop.
So now Jeep's parent company in the US, Fiat Chrysler Automobiles (FCA), is offering cash rewards to clever individuals who can hack into its vehicle software, in what it calls a "public bug bounty program".
The cash incentives range from $US150 to $US1500 for code monkeys who sniff out any backdoors, cracks or vulnerabilities in its software – namely its UConnect website and smartphone app systems for iOS and Android.
The car maker announced it has teamed up with Bugcrowd to facilitate the hack-fest, a crowd-funded company that specialises in security testing.
FCA's stated objective is to make its cars resilient to cyber-attacks but it's not the first time a company has offered the Joe public cash incentives to probe and prod the security of a given system. US car-sharing service Uber and electric car maker Tesla have both undertaken a similar approaches.
FCA wants to "foster a spirit of transparency and cooperation within the cybersecurity community" reads the press statement and according to Titus Melnyk, senior manager of security architecture at FCA US, it's not just about making PR noise.
"Exposing or publicising vulnerabilities for the singular purpose of grabbing headlines or fame does little to protect the consumer," said Melnyk. "Rather, we want to reward security researchers for the time and effort, which ultimately benefits us all."
Bugcrowd founder and CEO, Casey Ellis, reckons the initiative is important and will continue to be so as cars become more reliant on complex software to function.
"The consumer is starting to understand that these days the car is basically a two ton computer.
"Automotive cybersafety is real, critical, and here to stay. Car manufacturers have the opportunity to engage the community of hackers that is already at the table and ready to help, and FCA US is the first full-line automaker to optimise that relationship through its paid bounty program," he said.
Two German car makers, Audi and Mercedes, reckon its cars are unhackable.
Are cyber-attacks on vehicles something you worry about, or is this all hogwash in your view? Have your say in the comments below.