I spent a week digging into a device that’s sitting in millions of cars right now. You probably have one. And I’m not talking about your phone or your GPS. I’m talking about that little black box your insurance company gave you—the one that supposedly saves you money by tracking your driving habits.
Here’s what I found: It’s a ticking time bomb.
Your car’s safety system is now a public Wi-Fi network, and you’re the one paying for it.
These dongles—technically called telematics devices—plug directly into your car’s OBD-II port, the same port your mechanic uses. They’re supposed to monitor your speed, braking, and mileage to give you a usage-based insurance discount. But they do something else, too: they connect to the CAN bus, the central nervous system of your car. That’s the network that controls your brakes, your steering, your engine, your airbags.
And these dongles are wide open.
Security researcher Sam Curry showed me how. From his laptop, he could send a command to a dongle’s cloud server, which then relayed the command to the car. He could kill the engine. He could lock the brakes. He could do it from anywhere in the world. And he did it to a fleet of 1.5 million vehicles.
Let’s get real. The dongle was designed to give you a discount. But its connection to the car’s internal network is essentially unguarded. It’s like giving a stranger a key to your house because he promised to water your plants.
The dongle that promised you a discount on your insurance is the same dongle that could let a stranger take control of your brakes.
Here’s the twist: the very feature that makes it useful—remote monitoring—is the attack vector. The dongle has its own cellular modem, sometimes even Wi-Fi. It’s a computer in your car that your car’s manufacturer didn’t approve. It’s running firmware that can be updated over the air, and that firmware is full of holes. Researchers found that the dongle’s cloud server didn’t even require authentication for some commands. Anyone with the right know-how could send a ‘stop engine’ request to any vehicle.
I spoke to a fleet manager who had 200 of these dongles installed. He told me, ‘We thought it was just for tracking. Now I’m terrified.’ He’s not alone. Millions of drivers are driving around with a device that can turn their car into a brick—literally, a paralyzed, immobile piece of metal.
We’ve turned cars into computers with wheels, but we forgot to lock the doors.
So what can you do? First, check your car. Look under the dashboard, near the steering column. If you see a small device plugged into a rectangular port, that’s it. Pull it out. Call your insurance company and tell them you’re removing it due to security concerns. You might lose a few bucks a month. But you’ll keep the ability to stop your car yourself.
That $10-a-month discount could cost you your life. Is it worth it?
FAQ
Q: Is this really a widespread threat?
A: Yes. Over 1.5 million vehicles are affected. The researcher demonstrated remote control of multiple vehicles. The vulnerability is in the dongle's firmware, which can be exploited over the cellular network.
Q: What should I do if I have one of these dongles?
A: Unplug it immediately. Check under your dashboard or near the OBD-II port. Then call your insurance company and tell them you're removing it due to security concerns. You might lose the discount, but your safety is worth more.
Q: Isn't this just fear-mongering? The risk is low.
A: The risk is real. The dongle is connected to the CAN bus, which controls critical functions. Even if the exploit requires specific conditions, the fact that it's possible is unacceptable. Automotive security should be designed from the ground up, not patched by a third-party dongle.