The automotive industry is increasingly using OTA (Over-The-Air) technology to remotely update vehicle software. This method enables faster updates and feature upgrades, and reduces recall and factory maintenance costs. However, analysts point out that the deeper the vehicle's connection to the network, the larger the potential attack surface, and the associated risks have extended from data privacy to traffic safety and infrastructure security.
Tesla is driving OTA (Over-The-Air) updates to become the industry norm.
OTA (Over-The-Air) technology sends software, firmware, patches, and data to connected devices via wireless networks. CNBC, citing researchers, reports that since Tesla began pushing remote updates to the Model S in 2012, this model has gradually been widely accepted by the automotive industry and embedded in more models and systems.
Siraj Ahmed Shaikh, Professor of Systems Security at Swansea University in the UK, stated that OTA (Over-The-Air) updates are faster and cheaper than traditional recalls or routine maintenance updates, making them popular with automakers. However, while offering greater convenience, it also means that more critical systems will be constantly connected to the internet.
European tests expose vulnerabilities in remote access.
Risk concerns have been amplified in recent tests. Late last year, Norwegian public transport company Ruter discovered potential risks related to over-the-air (OTA) payments in one of its buses after testing them.
Ruter stated that the vehicle's battery and power control system are accessible via a mobile network, and the connection path involves a Romanian SIM card. According to him, theoretically, the manufacturer could stop the vehicle or render it inoperable.
This investigation subsequently prompted separate investigations by the UK and Denmark. The UK Department for Transport stated that it is working closely with the National Cyber Security Centre to assess the issues.
Concerns have expanded from individual vendors to the industry level.
The report mentioned that the survey covered buses manufactured by the Chinese automaker Yutong. However, experts interviewed believe that the problem is not limited to a single manufacturer or country, but rather represents a common risk brought about by the widespread adoption of OTA (Over-The-Air) technology in the transportation sector.
Gabriel Lim, an analyst at the S. Rajaratnam School of International Studies in Singapore, said that such technologies have become a unique national security concern. In addition to data privacy issues, the possibility of external actors interfering with vehicle control systems while in motion has also raised concerns in countries such as Norway, Denmark, and the United Kingdom.
In May of this year, the American Enterprise Institute also suggested that if the United States wants to limit the intelligence-gathering capabilities of foreign governments, it should strengthen security reviews of the automotive industry, consider restricting some foreign-made in-vehicle hardware and software, and require companies to disclose more data collection information.
The impact extends beyond automobiles.
Shaikh also pointed out that it's not just the automotive industry that's adopting OTA (Over-The-Air) updates. Shipping, rail, aerospace, especially drones, as well as industrial machinery and robotics are also introducing similar capabilities.
As these systems expand their reach, scrutiny of their deployment methods, remote access permissions, and accountability is intensifying. Analysts believe the key issues are no longer just the convenience of the technology, but rather who can access the system, what they can do after access, and whether relevant regulations are keeping pace.











