Security Experts:

Ford Test Drives New Consumer Firmware Updates

Ford Testing Firmware Update Program, Encourages Customers to Have a Unique USB for Each Ford They Own

This month, Ford is borrowing something from the software industry: updates. With a fleet of new cars using the sophisticated infotainment system they developed with Microsoft called SYNC, Ford has the need to update those vehicles—for both features and security reasons. But how do you update the software in thousands of cars?

Updating Automotive FirmwareTraditionally, the automotive industry has resorted to automotive recalls. These are expensive, and a pain for the consumer. Scheduling an hour or so to go to the shop for what might only be a ten-minute update is not going to leave a good experience in the minds of consumers, especially if it becomes a quarterly or monthly event. So Ford is experimenting with having the consumer do it themselves through downloads.

According to a tweet from Chris Murphy of InformationWeek, Ford will be releasing thirty thousand USB sticks to Ford owners with the new SYNC infotainment system, although the update will also be available for online download. In addition to fixing a few bugs, the company is including a few new features in an effort to get consumers to adopt the update.

To get users used to the idea, Ford has a YouTube video extolling the efforts of its “technologists.” And that’s a good thing. As the video explains, the update requires a series of steps and will require about 30 minutes to install. InformationWeek has an analysis of the new features from last November. The video also reminds customers to keep their phone software updated as well.

Consumer Updates Ford SYNC in the Ford EdgeIn preparing to update your car, Ford encourages users to have a unique USB for each Ford they own, and to have the USB drive empty and not password protected. Once the drive is ready, you are advised to bring printed instructions out to the car. You will also need to have a full tank of gas, as you’ll need to keep the car and radio turned on throughout the update process. However, don’t plan on listening to your mobile phone or media device while you wait–SYNC will disconnect from these devices during the update.

What’s confusing (and Ford says as much) is that there’s a first “Installation Complete” message after about a minute–but, wait, there’s more. Leave the USB drive in and keep the car turned on as a second installation then begins and will last much longer. After about five to ten minutes, the update is finally complete. You’ll then need to pair your mobile device again, but the contact information and your files should still be in the SYNC system.

You will then need to take the USB drive back to your laptop or home computer to report that the update was successful so that Ford can advance you to the next update, should one become available. This last step might not be completed by most consumers who will move on to other things. It'll be interesting to see how many downloads correspond to successful installations of the update.

As we move into the Internet of Things, updating our gadgets, large and small, will become routine. But for now, it’s going to be really cumbersome and a little weird. “Honey, I’m updating the car’s firmware now.” “Okay.” Also, imagine explaining the steps above to your elderly neighbor.

Play this forward a bit. Image taking Patch Tuesday to a logical extreme, where you walk around your house or office apply all the patches to all the gadgets you own.

It's hard not to criticize Ford a little bit. The process still has too many steps, including the follow up phase. But this does, however, beat the alternative: taking your car into the shop.

Related Content: Car Hacking - Researchers Highlight Emerging Security Risks in Automobiles

Related Content: Forget Carjacking, What about Carhacking?

Robert Vamosi, CISSP, an award-winning journalist and analyst who has been covering digital security issues for more than a decade, is a senior analyst for Mocana, a device security start up. He is also the author of When Gadgets Betray Us and a contributing editor at PCWorld, a blogger at Forbes.com, and a former Senior Editor at CNET. He lives in Northern California.