1 min readfrom TechCrunch

US government lab is probing Chinese lidar for security vulnerabilities

Our take

Idaho National Laboratory is conducting a critical security review of Chinese-manufactured lidar systems, a move funded by the electric and autonomous vehicle sectors. This probe seeks to identify potential vulnerabilities that could impact vehicle safety and data integrity. The assessment underscores growing concerns about the security of increasingly integrated automotive technologies. This follows similar scrutiny of other critical components, highlighting the need for robust security evaluations.
US government lab is probing Chinese lidar for security vulnerabilities

The news that the Idaho National Laboratory is probing Chinese LiDAR technology for security vulnerabilities is a significant development, underscoring a growing concern within the autonomous vehicle and electric vehicle industries. It's not merely about the performance of these sensors; it's about the potential for embedded vulnerabilities that could compromise vehicle safety and data security. This echoes the recent scrutiny faced by Waymo, which [Waymo hands over documents in NHTSA’s child collision probe] has been compelled to redact substantial portions of its responses to a National Highway Traffic Safety Administration (NHTSA) investigation, citing confidential business information. The increasing complexity of autonomous systems, relying on intricate sensor networks and AI algorithms, inherently expands the attack surface, making security reviews like this one increasingly vital. The reliance on third-party components, particularly from regions with differing regulatory landscapes, presents a unique challenge that the industry is only beginning to fully grapple with.

The decision to task a national laboratory with this assessment speaks to the seriousness of the concern. It's a move beyond internal testing and represents a more independent and rigorous evaluation. The fact that the research is funded by companies within the EV and AV space further highlights the industry’s proactive approach to identifying and mitigating potential risks. This isn't an isolated incident either; the recent case of [Someone targeted security researchers using a fake crypto conference as a lure] demonstrates the sophistication and persistence of actors seeking to exploit vulnerabilities in emerging technologies. The consequences of a compromised LiDAR system in an autonomous vehicle could be catastrophic, ranging from targeted disruption to outright safety failures. It’s also worth noting the broader context of technological ambition, as evidenced by the failed venture of [The Enhanced Games — tech’s steroid extravaganza — didn’t pay off, as company posts $60 million loss]; pushing boundaries without addressing fundamental risks can lead to significant setbacks.

The implications extend beyond just vehicle safety. LiDAR data is incredibly rich, containing detailed information about the surrounding environment, including pedestrian movements, infrastructure details, and even potentially identifying individuals. If this data is compromised, it could be used for malicious purposes, such as targeted surveillance or even coordinated attacks. The geopolitical context is also crucial. Concerns about supply chain security and data sovereignty are already prominent themes in international relations, and this review adds another layer of complexity. The potential for Chinese-manufactured LiDAR systems to be used for espionage or to collect data that could be exploited for strategic advantage is a legitimate concern, prompting a careful examination of the technology's architecture and potential vulnerabilities. The focus on LiDAR specifically is noteworthy; while cameras and radar are also critical components of autonomous driving systems, LiDAR's high-resolution 3D mapping capabilities make it a particularly attractive target for those seeking to gain an advantage.

Looking ahead, we can expect to see increased scrutiny of the entire autonomous vehicle supply chain, not just LiDAR. Companies will likely prioritize security audits and vulnerability assessments of all third-party components, and governments will likely introduce stricter regulations to ensure the safety and security of autonomous systems. The question now is how effectively the industry can balance the drive for innovation with the imperative of robust security measures. Will the cost of these security reviews become a barrier to entry for smaller companies, potentially consolidating the market in the hands of a few large players? And will governments be able to keep pace with the rapidly evolving threat landscape, or will autonomous vehicles become a new frontier in the ongoing battle for cybersecurity?

The security review is being performed by the Idaho National Laboratory, and the research is being funded by a company -- or a group of companies -- in the electric and autonomous vehicle industries.

Read on the original site

Open the publisher's page for the full experience

View original article