Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

General Motors Launches Vulnerability Disclosure Program

General Motors launched a vulnerability disclosure program last week, but the carmaker is currently not offering any rewards.

The carmaker has invited researchers who find security vulnerabilities in GM products and services to submit a report via the HackerOne platform.

General Motors launched a vulnerability disclosure program last week, but the carmaker is currently not offering any rewards.

The carmaker has invited researchers who find security vulnerabilities in GM products and services to submit a report via the HackerOne platform.

“There is not a specific list of products or services in scope. If a researcher has information related to security vulnerabilities in our products and services, we want to hear about it,” GM representatives told SecurityWeek.

GM is currently not offering any bounties, but the carmaker says it will continue to assess and adapt the program, and will consider recognition and incentive opportunities in the future.

Those who want to report security bugs to General Motors have to follow a set of rules in order to avoid any legal problems. Participants are instructed to avoid causing harm to GM or its customers, not violate any laws, and not compromise the privacy or safety of GM customers and the operation of its services. The vulnerability disclosure program guidelines also specify that the details of the reported flaws cannot be disclosed until the problem is resolved.

“GM takes cybersecurity very seriously, has devoted substantial resources to address it, and continues to do so,” GM said in an emailed statement. “We also value the work of third party researchers, and want to hear directly from anyone who finds a security vulnerability in one of our products or services. This program complements our overall cybersecurity program, including the work done by our team of internal experts and our collaboration with other outside specialists and third parties.”

Researchers Charlie Miller and Chris Valasek, who last year got Fiat Chrysler to recall over a million vehicles after remotely hacking a Jeep, took to Twitter to share their opinion on GM’s “bountyless” bug bounty program.

Miller and Valasek brought car hacking into the spotlight after first locally hacking a Toyota Prius and later remotely taking over a Jeep via its Uconnect in-vehicle connectivity system. The vulnerabilities they demonstrated on the Jeep affected many FCA models, including Ram, Dodge and Chrysler.

GM software has also been targeted by white hat hackers. Last year at the Def Con conference, researcher Samy Kamkar showcased a $100 gadget that allowed him to remotely capture access credentials for OnStar RemoteLink, a GM service that allows vehicle owners to locate, unlock and even start their car from a smartphone app.

In September 2014, after lawmakers started putting pressure on car manufacturers to ensure that their vehicles can’t be hacked, and after a group of researchers launched the “I am the Cavalry” initiative, GM announced the appointment of Jeffrey Massimilla as its first-ever chief product cybersecurity officer.

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

IoT Security

A group of seven security researchers have discovered numerous vulnerabilities in vehicles from 16 car makers, including bugs that allowed them to control car...

Vulnerabilities

A researcher at IOActive discovered that home security systems from SimpliSafe are plagued by a vulnerability that allows tech savvy burglars to remotely disable...

Risk Management

The supply chain threat is directly linked to attack surface management, but the supply chain must be known and understood before it can be...

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Vulnerabilities

Patch Tuesday: Microsoft warns vulnerability (CVE-2023-23397) could lead to exploitation before an email is viewed in the Preview Pane.

IoT Security

A vulnerability affecting Dahua cameras and video recorders can be exploited by threat actors to modify a device’s system time.