top of page

Eric Shaw

7 minutes ago
4 min read
SpongeBob, via Wikimedia Commons
SpongeBob, via Wikimedia Commons

I was not familiar with Eric Shaw, nor have I ever really watched SpongeBob SquarePants, though I am familiar with the characters through their impact on popular culture. According to Wikipedia, Mr Shaw is a television writer, credited with a number of episodes of SpongeBob, along with a number of other works.


With that in mind, I was a bit confused when I heard the reference to Eric Shaw on Smashing Security Episode 476, in a conversation between Graham Cluley and Geoff White. In the context of cybersecurity in India, it didn’t seem to make much sens-


Pardon?


Not Eric Shaw?


E-rickshaw?


Oh! That makes a LOT more sense.


India has quite a few e-rickshaws, and not many animated sponges or American television writers.


The rickshaw is a very interesting vehicle, which appears to have been invented independently in France, in the late 17th century, and in Japan around 1869, at the beginning of the Meiji Restoration. TIL that the term ‘rickshaw’ is actually derived from the Japanese word jinrikisha (人力車, 人 jin = human, 力 riki = power or force, 車 sha = vehicle), though it has evolved and developed, and acquired a variety of different names.


There are ‘cycle rickshaws’, also called ‘bike taxi’, ‘velotaxi’, ‘pedicab’, and a variety of other names. And then, of course, there are ‘auto rickshaws’, often called ‘tuk tuk’.


Which leads us, of course, to the Eric Shaw ‘electric rickshaw’, which is what they were discussing on Smashing Security.


Full disclosure: To the degree feasible, I am being dragged into the ‘IoT everything’ craze kicking and screaming. I don’t WANT a ‘smart’ TV. And, while I am very interested in the content people like Troy Hunt produce relating to IoT and Home Automation, I would really prefer to wait about a decade for the technology and standards to catch up with the current hype.


I’ve written about the Escalator Principle, and about new Lightweight Cryptography standards for IoT, and am interested in understanding how the industry will evolve, but I really have no reason to believe that the bulk of current IoT devices are secure, or likely to be in the near-term.


I deal with them when I must, but am constantly aware of the associated risks.


And then there are cars. As cars evolve, they become more and more ‘connected’, which raises a whole host of concerns about the basic security of the vehicle, but also about the security of the ‘infotainment’ systems within it. While there has been a lot of work done over the past few years, I am not confident that the industry has developed enough to be considered ‘secure’. Data access and privacy are a whole other question, which I won’t get into at present.


When considering the security of any device, it would be wonderful if there were ways to ensure that certain minimal quality standards are met. For electrical products, for example, there are a number of certification marks, which indicate that the product meets or exceeds a set of basic quality standards.


A globally-consistent approach for cybersecurity would be wonderful, but regulation of such things appears to be in its infancy, globally.


And, of course, everything is complicated by the fact that there will be overlap between different types of standards, depending on the type of device, how different aspects of its function are regulated, international relations, market forces, and so on.


With all of this in mind, let’s get back to the e-rickshaws.


The story in question is about a ‘viral trend’ involving an app called BAT-BMS, which is a Battery Management System (BMS) that allows users to connect to compatible lithium batteries via Bluetooth, with a range of 10-15 metres.


The app allows a user to monitor the charge level, voltage, temperature, and other factors of the battery, which is clearly of great value for someone managing a fleet of electric vehicles, such as e-rickshaws.


If it’s secure.


But, predictably enough, it’s not. And this is where standards come in. If the battery’s Bluetooth module is ‘left unsecured’, it is vulnerable to anyone in range who has the app available, but why is it possible to leave such a device unsecured?


Money. Simply put, it’s easier and cheaper to skimp on security and try to shift the responsibility to the owner of the device. And it’s possible because we don’t yet have a sufficiently robust set of global standards which enforce such basic types of cyber hygiene.


So, when someone buys an e-rickshaw using one of these batteries, many will use default settings or set poor passwords, which means that anyone in range can use the BAT-BMS app to trigger the ‘discharge switch’ – a safety feature which cuts power in order to perform maintenance on the unit.


Now, the ‘right’ way (or at least one of several ‘right’ ways) to do this would be for each device to ensure that a non-trivial password be created on setup, and ensure that commands are accepted only if that password is presented. It’s not that hard, and should be required for all IoT devices, in my humble opinion.


Let’s say that Alice has just bought a dozen batteries for their new fleet of e-rickshaws, and each one has a unique serial number, and a unique QR code embossed on the back. In order to install each battery, Alice needs to use the app to scan the serial number, then scan the unique QR code. The serial number uniquely identifies the battery, while the QR code contains a unique, factory-default password, which can only be used on initial setup (or factory-reset), then automatically forces the creation of a long, complex password for managing the battery.


That’s it. A bit more work on the manufacturing side, but easy for the end-user, and reasonably secure.


Why don’t we do it?


As noted before, money. Because we, as a society, are not enforcing what I would consider adequate minimal standards for ensuring that the devices we buy are secure. Changing this will require time, effort, and the development of standards, but I think it will be to the benefit of all.


We can be more secure. We just need to decide that we want to be.


Cheers!

Comments


Want to learn more?

Thanks for subscribing!

What do you think?

Thanks for submitting!

© 2026 by RG

88x31.png

TIL Technology by RG is licensed under a Creative Commons Attribution 4.0 International License, except where otherwise specified. 

​

Please feel free to share, but provide attribution.

bottom of page