April 20, 2007 3:20 PM PDT

Don't let your navigation system fool you

VANCOUVER, B.C.--That roadblock alert on your navigation system may not be real. Neither may that warning for a "terrorist incident," an "air raid" or a "bullfight."

Two Italian hackers have figured out how to send fake traffic information to navigation systems that use a data feature of FM radio for real-time traffic information. Using cheap, off-the-shelf hardware, they can broadcast traffic data that will be picked up by cars in about a one-mile radius, the hackers said during a presentation at the CanSecWest event here.

"We can create queues, bad weather, full car parks, overcrowded service areas, accidents, roadwork and so on," Andrea Barisani, chief security engineer at Inverse Path, a security company. "Traffic information displayed on satellite navigation systems is trusted by drivers. Normal people do not think that you can do nasty things."

Barisani and hardware hacker Daniele Bianco discovered that the system used by many navigation aides to get traffic data isn't secured. The data is sent using the Traffic Message Channel (TMC) of the Radio Data System (RDS), a standard way of transmitting data over FM radio also used to display station names and program titles.

With TMC, each traffic incident is sent as a TMC message that consists of an event code, location code and time details. The system is used throughout Western Europe, the U.S. and Australia.

The hackers wrote a program to decode the RDS data. "As far as we know it is the first open-source tool that tries to fully decode RDS information," Barisani said. They then figured out how to create their own TMC messages and broadcast those using an RDS encoder, an FM transmitter, an antenna and some other tools.

Barisani and Bianco found that navigation systems display different alerts based on codes sent via RDS. "The event table supports a number of security-related messages; we doubt anyone has used them so far," Barisani said. Those alerts include air raid, bomb alert, air crash and terrorist incident.

"Oh my God, World War III is happening on my way home," Barisani said after displaying a video in which the navigation system in his 2006 Honda Civic warned him of mayhem while he was on the way to Trieste, Italy.

The pair tested their work on a 2006 Honda Civic sold in Europe, but Barisani said navigation systems sold in Europe and around the world use the same method to get traffic data. A receiver inside the navigation system continuously scans radio frequencies for the information, he said.

TMC is also supported over digital and satellite radio, but it is harder for a hacker to send out data using those technologies compared with FM, Barisani said.

A new technology called TPEG, or transport protocol experts group, is ready to replace TMC, however that also doesn't support encryption for additional security, Barisani said. A more secure way of transmitting the data is provided in the U.S. by Microsoft, which operates DirectBand, a wireless datacast network that uses FM radio, Barisani said.

"We want to increase awareness about this," he said. "This is not the end of the world, but it is a nasty thing."

See more CNET content tagged:
FM-radio, hacker, radio, Europe, event

Add a Comment (Log in or register) 4 comments
Worthless excuse for a human
by kmsilver April 21, 2007 7:08 PM PDT
What will these lowlifes think of next? Perhaps a device which can disable fire trucks and ambulances whenever they turn on their sirens? Wow, wouldn't that be funny, huh? Making a device just to screw with people and cause them inconvenience is disgusting. I think an appropriate punishment for these scumbags is to put their private-parts in a blender and puree. I definitely don't want them procreating.
Reply to this comment View all 2 replies
More Fool You!
by Video Edit April 28, 2007 2:01 AM PDT
If You only believe what appears on the screen Orwell was Right! but joking aside This is a very BAD flaw in the system as not only can a hacker attack it but a very simple error can give a totally erroneous message, but not be seen on the transmission screen..
(Also the hack works)
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Creating a 'Facebook for spies'

    The CIA, FBI, and National Security Agency are reportedly testing a social-networking site designed for use by analysts within the 16 U.S. intelligence agencies.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.