惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
Cyberwarzone
Cyberwarzone
博客园_首页
爱范儿
爱范儿
腾讯CDC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
K
Kaspersky official blog
H
Help Net Security
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
S
SegmentFault 最新的问题
L
LINUX DO - 热门话题
T
Tenable Blog
P
Privacy & Cybersecurity Law Blog
N
News | PayPal Newsroom
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
LangChain Blog
L
Lohrmann on Cybersecurity
P
Palo Alto Networks Blog
云风的 BLOG
云风的 BLOG
A
Arctic Wolf
N
News and Events Feed by Topic
AWS News Blog
AWS News Blog
美团技术团队
U
Unit 42
月光博客
月光博客
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
S
Secure Thoughts
有赞技术团队
有赞技术团队
C
Cyber Attacks, Cyber Crime and Cyber Security
Schneier on Security
Schneier on Security
Cloudbric
Cloudbric
B
Blog
NISL@THU
NISL@THU
Help Net Security
Help Net Security
Y
Y Combinator Blog
J
Java Code Geeks
S
Securelist
宝玉的分享
宝玉的分享
T
Threat Research - Cisco Blogs
S
Security @ Cisco Blogs
O
OpenAI News
D
DataBreaches.Net
Know Your Adversary
Know Your Adversary
Hacker News - Newest:
Hacker News - Newest: "LLM"
Vercel News
Vercel News
Forbes - Security
Forbes - Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security Elastic MCP Apps bring security and observability workflows into AI tools - Help Net Security Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - Help Net Security Tencent's QClaw AI agent app arrives on Windows and macOS - Help Net Security Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security OneDrive updates focus on AI, access control, and compliance - Help Net Security PentAGI: Open-source autonomous AI penetration testing system - Help Net Security Apple Intelligence flaw kept stolen tokens reusable on another device - Help Net Security Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook - Help Net Security Thunderbird 150 arrives with encrypted message search and OpenPGP improvements - Help Net Security VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes - Help Net Security Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Meta and PortSwigger drive offensive security further to find what others miss - Help Net Security EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines - Help Net Security How to spot a North Korean fake in a job interview - Help Net Security Product showcase: Syncthing for secure, private file synchronization - Help Net Security Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits Google wipes out 602 million scam ads with Gemini on duty Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery Mozilla challenges enterprise AI providers with Thunderbolt, open-source AI client under your control Codex can now operate between apps. Where are the boundaries? Android 17 Beta 4 arrives with post-quantum cryptography and new memory limits Apple AirTag tracking can be misled by replayed Bluetooth signals Social media bans might steer kids into riskier corners of the internet Workplace stress in 2026 is still worse than before the pandemic New infosec products of the week: April 17, 2026 - Help Net Security ImmuniWeb brings AI upgrades, post-quantum detection and more in Q1 2026 NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards - Help Net Security Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) - Help Net Security Google Play is changing how Android apps access your contacts and location Tails 7.6.2 patches vulnerability that could expose saved files Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug OpenAI updates Agents SDK, adds sandbox for safer code execution Anthropic tests user trust with ID and selfie checks for Claude GitHub lays out copyright liability changes and upcoming DMCA review for developers EU cybersecurity standards are at risk if supplier ban passes Command integrity breaks in the LLM routing layer The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast ClickFix campaign delivers Mac malware via fake Apple page Poisoned “Office 365” search results lead to stolen paychecks Gmail’s end-to-end encryption comes to mobile, no extra apps required To counter cookie theft, Chrome ships device-bound session credentials Product showcase: Session, a messenger without phone numbers or metadata Little Snitch for Linux shows what your apps are connecting to - Help Net Security Apiiro CLI turns AI coding assistants into full-stack security engineers - Help Net Security April 2026 Patch Tuesday forecast: Spring-cleaning of a preview - Help Net Security What vibe hunting gets right about AI threat hunting, and where it breaks down - Help Net Security Health insurance lead sites sell personal data within seconds of form submission - Help Net Security
Securing digital keys when your phone unlocks the car - Help Net Security
Mirko Zorz · 2026-06-18 · via Help Net Security

In this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers.

She talks through what changed with Version 4, why the team focused on interoperability and testing instead of one new threat, and how NFC fallback access stays protected. She also covers fast credential revocation when a phone is lost or stolen, and how crypto agility prepares the standard for post-quantum demands over a car’s long life.

securing digital keys

Digital car keys started as a convenience feature tied to one brand’s phones and vehicles, but the direction now is a wallet-style credential meant to travel across devices, automakers, and suppliers. From a security standpoint, what assumptions that held when a key only had to work inside one company’s own hardware no longer hold once it must work everywhere?

The main change is that trust is no longer implicit.

In a single-vendor environment, the OEM controls the entire technology stack, from the device to the vehicle and supporting infrastructure. In a multi-vendor ecosystem, trust must instead be established through standardized certification, secure hardware anchors such as secure elements, and interoperable protocols.

This shifts security from “trust your own device” to “trust any certified device” in a heterogeneous ecosystem.

From the CCC’s perspective, that’s one of the most important challenges to address in digital vehicle access. Security can no longer depend on who manufactured the device or the vehicle; it has to be consistently verifiable across the ecosystem. That’s why certification, interoperability testing, and common security requirements are foundational to the CCC Digital Key framework.

Version 3 brought ultra-wideband into the standard in 2021 to answer relay attacks against passive entry. When the working group scoped Version 4, what categories of attack did you decide v3 had left open, and which one drove the timeline hardest?

Version 3 already established a very high security baseline, particularly through the introduction of UWB-based distance bounding to address relay attacks.

When we scoped Version 4, the focus was not on addressing a major unresolved attack class. Instead, the emphasis was on improving interoperability, validation, and consistent behavior across a much broader ecosystem of devices and vehicles. As a result, the timeline was driven less by a specific new threat and more by ensuring secure, predictable operation in real-world deployments while maintaining the high security bar established in Version 3.

One reality of global standards is that security is not just about cryptography. It’s also about ensuring that implementations behave consistently across different devices, vehicle platforms, and wireless technologies. Much of the work behind Version 4 focused on strengthening that validation and interoperability layer while preserving the security properties already established in Version 3.

The updated NFC test cases also ran for the first time here. NFC tends to be the path a driver reaches for when a battery dies or the radios are unavailable. Does that fallback risk becoming the soft entry point, and how do you keep it from being the easy door?

NFC is an important part of the Digital Key architecture because it provides a reliable access method across a wide range of real-world scenarios, including situations where batteries are depleted or other radios are unavailable. However, it is not a “soft entry point.”

NFC requires very close physical proximity and explicit user action, which significantly reduces the attack surface compared with remote access technologies.

In addition, a single NFC interaction does not automatically grant unrestricted vehicle access. OEMs can enforce user-intent checks, authentication requirements, and access policies depending on the use case.

More broadly, our approach is that fallback mechanisms should meet the same security expectations as primary access methods. That’s one reason the CCC continues to expand interoperability and certification testing across NFC, Bluetooth Low Energy, and UWB implementations: to help ensure security is maintained regardless of how a user accesses the vehicle.

As a result, NFC maintains the same security principles as the broader Digital Key architecture while providing a reliable access experience across a variety of operational conditions.

A digital key lives in a phone that gets lost, sold, or compromised. From a defender’s point of view, how quickly can a key be suspended across the chain, and what assurance does an owner have that a revoked credential cannot be replayed against the car later?

CCC Digital Key supports fast revocation across the ecosystem through backend connectivity. As soon as either the phone or the vehicle reconnects, revocation information can be synchronized, and the credential is no longer accepted.

A key design principle is that vehicle owners retain control throughout the credential lifecycle, including issuance, sharing, suspension, and revocation. Even when a device remains offline, the system does not rely on a single point. Vehicle-side controls provide an additional enforcement mechanism to support revocation policies.

In addition, relay attacks are prevented through cryptographic challenge-response mechanisms, ensuring that a previously valid credential cannot simply be captured and reused later.

This combination of owner control, distributed enforcement, and cryptographic verification helps provide resilience even in scenarios involving lost, stolen, or compromised devices.

Cars stay on the road for fifteen years or longer, so the cryptography chosen now has to outlive several generations of phones. How is crypto agility engineered into v4, and is post-quantum migration part of the conversation for both the credentials and the protocols?

Digital Key Versions 3 and 4 rely on well-established cryptographic mechanisms that are widely trusted and appropriate for high-assurance applications today. At the same time, crypto agility is a key design principle, allowing algorithms and security mechanisms to evolve over the vehicle’s lifetime as requirements and threat models change.

Vehicle lifecycles are measured in decades, which makes long-term security planning particularly important for the automotive industry. The architecture is designed to support future evolution without requiring fundamental changes to the user experience or broader ecosystem.

Post-quantum readiness is actively being discussed within our member ecosystem, both at the credential and protocol level. While the current focus is on maintaining a secure and deployable baseline today, standards organizations also have a responsibility to consider long-term migration paths and ensure future cryptographic transitions can be introduced in a practical and interoperable way as the technology matures.