As cybersecurity researchers demonstrate the ability to manipulate commercial truck systems, the industry must move past easily exploitable, self-certified ELDs to protect hours-of-service regulations and keep fatigued drivers off the road.
- Trucking vulnerabilities exposed at DEF CON: The NMFTA showcased commercial vehicle vulnerabilities at the hacker conference, revealing how easily truck systems—including braking controllers—can be manipulated.
- The flaw in self-certification: Relying on manufacturers to self-certify ELDs creates a system ripe for manipulation, turning what should be a safety device into a tool to bypass Hours-of-Service (HOS) regulations.
- The white-label loophole: Roughly three-quarters of registered ELDs share underlying hardware and software, meaning revoking a single noncompliant model does not fix the root vulnerability on America's highways.
- A call to action for the FMCSA: The FMCSA must overhaul its registry by requiring independent third-party testing, Software Bills of Materials (SBOMs), and the ability to revoke entire families of noncompliant white-labeled ELDs.
DEF CON, one of the world’s largest hacker conferences, is a weeklong event that brings cybersecurity professionals, researchers, students and hobbyists together each August in Las Vegas to share their findings and get their hands on technology to see what they can do with it.
To many in the cybersecurity and information technology industries, this is the premier event of their professional year. For me, it was a scary event where I saw what was actually possible.
This year, the National Motor Freight Transportation Association (NMFTA) brought the trucking industry to DEF CON. NMFTA extends its sincere thanks to Hirschbach for working with us to make this experience a reality, and to the Maritime Hacking Village for providing the space, support and partnership needed to make the event such a success.
In the village, attendees could examine and attempt to hack into the connected devices used by the entire supply chain, from shipboard maritime systems to freight terminal operations, railroads and now trucking.
DEF CON attendees had the opportunity to connect to the vehicle and test their ability to identify and interact with truck systems. Most of us are around trucks quite a bit; it was fun to watch people interact with and climb into the cab. We even had to ask people to please not pull the horn. The truck attracted participants of all skill levels, from those connecting to a truck for the first time to experienced hackers who arrived with specific targets in mind.
The hands-on experience provided a unique opportunity for attendees to explore the cybersecurity of commercial vehicles in a real-world environment.
NMFTA cybersecurity researcher Ben Gardiner presented his findings into a security patch quietly included into a software update pushed out as part of a safety recall for braking controllers found in tractors and trailers. The flaw allowed for a remote attacker to disable the anti-lock braking systems on tractors, putting drivers and their cargoes in danger.
NMFTA acquired Bendix EC80 units and examined pre- and post-patch firmware versions on these devices. We discovered that the security update was not associated with a published Common Vulnerability and Exposure (CVE) entry, which obscured facts from carriers which could lead to flawed risk assessments.
Though the vulnerability was patched, Gardiner emphasized the nature of modern truck telematic devices requires transparency from manufacturers about security vulnerabilities and what the manufacturers are doing about them. NMFTA believes a lack of a CVE slowed down the adoption and criticality of the patch.
Call to action: End ELD self-certification
The purpose of an ELD is not to create an electronic log. Its purpose is to create a trustworthy electronic record. Hours-of-service (HOS) rules exist for one fundamental reason: fatigued drivers operating 80,000-pound commercial vehicles are a threat to everyone on the road.
For decades, enforcement depended largely on paper logbooks. That system had an obvious weakness; the person being regulated was also responsible for documenting compliance. Drivers determined what went into the logbook, and dishonest operators could maintain records that showed compliance regardless of what occurred.
ELDs were supposed to change that. The ELD mandate replaced trust in handwritten records with trust in technology. ELDs automatically capture vehicle and driver activity, reduce the administrative burden on drivers and provide law enforcement with a standardized mechanism for verifying HOS.
But that system only works if the ELD itself can be trusted. Today, that trust is not adequately protected. ELD manufacturers self-certify their devices when registering them with the Federal Motor Carrier Safety Administration (FMCSA). The government and the trucking industry are therefore relying heavily on manufacturers to attest that their own products comply with federal requirements and accurately record driver activity.
For a technology that serves as a primary enforcement mechanism for federal HOS regulations, self-certification is no longer sufficient. As we know, an ELD is a computer. It contains hardware, software, communications capabilities, databases and applications. Like any computer system, it can contain vulnerabilities or functionality that allows information to be manipulated. If an ELD can be intentionally altered to make a driver appear compliant when that driver has exceeded legal HOS, the ELD is no longer a safety device; it becomes a tool for defeating the regulation it was designed to enforce.
The white-label problem makes this far worse
NMFTA's own research identified an even more serious systemic weakness: white-labeled ELDs. Of approximately 1,050 ELDs registered with FMCSA, NMFTA researchers determined that roughly three-quarters appear to share underlying hardware and software with other registered devices.
Essentially identical products can be rebadged and registered under dozens — or even hundreds — of different names. That means revoking a single model may accomplish very little.
FMCSA currently revokes ELD registrations largely on a model-by-model basis. But if the underlying hardware, software, application or backend infrastructure is shared across numerous registered products, removing one name from the registry does not necessarily remove the underlying problem from America's highways.
It can simply change names
NMFTA's research indicates that approximately 720 currently registered ELD models may share the same underlying vulnerability. If an ELD is revoked, an operator may be able to move to another registered product using substantially the same hardware and software. In some cases, the same physical hardware may be used with a different Android application. In others, multiple products may even rely on shared backend infrastructure.
So, let’s pause and take a moment to think about what that means. A regulator can identify a problem, revoke an ELD, announce that action to the industry — and the same underlying technology may continue operating legally under another name.
That is not an effective certification system. It is a loophole. And sophisticated, bad actors know how to exploit loopholes.
This is not merely a paperwork or technology issue. An ELD capable of falsifying HOS records can allow a driver to operate beyond federally permitted limits while presenting apparently legitimate records during an inspection. The result is potentially a fatigued driver operating a commercial motor vehicle next to families traveling on America's highways. That makes ELD integrity a public safety issue.
Certification must follow the technology, not the label on the box or on the application
FMCSA should move away from a system that primarily certifies and revokes individual product names and toward one that evaluates the underlying technology and organizations behind those products. At a minimum, FMCSA should:
- Require a Software Bill of Materials (SBOM) identifying the software components used by every registered ELD.
- Require independent, third-party testing and attestation of ELD accuracy, security and resistance to tampering.
- Identify common hardware, software, applications and backend infrastructure across white-labeled products. That is a question on the form.
- When a vulnerability or intentional manipulation capability is identified, investigate and, when warranted, revoke the entire affected family of ELDs — not simply one model name.
- Proactively analyze ERODs data for anomalies associated with specific devices and device families.
- Require meaningful alerts and records when an ELD is disconnected, disabled or otherwise prevented from accurately recording vehicle activity.
- Train roadside inspectors to recognize indicators of ELD manipulation and known problematic ELD families.
- Strengthen accountability and oversight for ELD providers whose critical operations are conducted outside North America.
- Validate the integrity of the FMCSA ELD registry itself, including manufacturer identities, physical addresses, telephone numbers, email addresses and other registration information.
Most importantly, these requirements need deadlines and consequences. Existing ELD providers should be given a defined period to meet strengthened certification requirements. Providers that cannot demonstrate compliance, security, data integrity and resistance to manipulation should lose their certification.
The trucking industry should not have to guess whether a federally registered ELD actually does what it claims to do. Law enforcement should not have to wonder whether the hours displayed on a roadside inspection are real. And the motoring public should not bear the risk created by technology designed to make an exhausted driver appear compliant.
The purpose of an ELD is not to create an electronic log. Its purpose is to create a trustworthy electronic record. If that record cannot be trusted, the entire regulatory system built around it begins to fail.
Self-certification has reached its limit. FMCSA should independently verify these devices, identify the technology behind white-labeled products and remove entire families of noncompliant ELDs from North America's highways.





















