Live data from Hacker News

We Tested Comma AI's OpenPilot

thedrive.com

21–30 of 163 posts

Re: We Tested Comma AI's OpenPilot

#21
post #5

Very nicely executed device with a good price point. Of course it's an utter nightmare with regards to privacy and I'd be very nervous regarding security and safety when I'd hand over the controls of my car to basically an android phone. Maybe I skimmed over it but I'd be interested in knowing which phones they use exactly. So I applaud the engineering but it's not a device I'd buy (and yes I do own and carry around…

My main concern would be that the architecture of an OTS Android system does not offer any guarantees regarding real-time i.e. hard deadlines.

Ever had an android app or even the whole phone locking up? Even if it is only for a second or two, I don't want this to happen to a device that feeds live data into my car's controller.

Even if this is only level 2 driver assist. If a car would get a bogus "you are crossing a divider line" signal for e.g. 2 seconds, it would start to steer quite persistently (even if with limited force) in a certain direction and you would have to counter that action.

Nope, I wouldn't use this.

Re: We Tested Comma AI's OpenPilot

#23
post #19

Earlier quoted context omitted.

CAN bus is the standard physical interface. What is not standard is the message being passed, so each car will have it's own message for car information. What surprised me about OpenPilot is how some of the electric steering system can be tricked into turning using false sensor data. It's actually amazing that almost all cars now can be driven by software the only thing missing are more accurate and complicated senso…

It is actually concerning that you can inject false sensor data this easily. I mean, sure, the messages on the CAN will not be encrypted or signed in any way, I know, but still...

It's not that easy and it's getting harder with each new car platform. But on the other end, some of the sensors are basic and will always be suspectable to false inputs. But don't worry, maybe it looks easy -> but it's not.

Re: We Tested Comma AI's OpenPilot

#24
post #18

Earlier quoted context omitted.

> on your own at your own risk It is not just your own risk but also that of other pedestrians, cyclists, and drivers that share the road with you.

that's not what "at your own risk" means. "At your own risk" means you bear the risk (legally). If something happens, it is on you, and the manufacturer offloads any liability on you. That does not imply what the risks are. Life threatening? You are risking other people's lives.

No need to be pedantic. No-one's arguing about the meaning of 'at your own risk', it's just that your decision to use this software affects more than just yourself.

Re: We Tested Comma AI's OpenPilot

#25
post #19

Earlier quoted context omitted.

CAN bus is the standard physical interface. What is not standard is the message being passed, so each car will have it's own message for car information. What surprised me about OpenPilot is how some of the electric steering system can be tricked into turning using false sensor data. It's actually amazing that almost all cars now can be driven by software the only thing missing are more accurate and complicated senso…

It is actually concerning that you can inject false sensor data this easily. I mean, sure, the messages on the CAN will not be encrypted or signed in any way, I know, but still...

Why exactly would be concerning? You need to physically plug cables in the car you yourself own.

If anything, every access to hardware you own SHOULD be this easy.

Re: We Tested Comma AI's OpenPilot

#26
post #25
post #19

Earlier quoted context omitted.

It is actually concerning that you can inject false sensor data this easily. I mean, sure, the messages on the CAN will not be encrypted or signed in any way, I know, but still...

Why exactly would be concerning? You need to physically plug cables in the car you yourself own. If anything, every access to hardware you own SHOULD be this easy.

Well, not exactly. Once you have plugged this device into your can, it can be hacked. It's just a phone after all, and it has normal wireless connection options available.

Re: We Tested Comma AI's OpenPilot

#27
The article reads that OpenPilot uses facial recognition to detect a distracted driver.....Can that be fooled with an image, or perhaps a mannequin? I wonder if you could apply this autonomous car tech to vehicle-borne IEDs. The driver could dismount a few hundred meters short of the target and provide eyes-on ground-level surveillance (if for some reason you aren't using a UAV for the same) while the vehicle drives on a final attack vector.

Re: We Tested Comma AI's OpenPilot

#29

The article reads that OpenPilot uses facial recognition to detect a distracted driver.....Can that be fooled with an image, or perhaps a mannequin? I wonder if you could apply this autonomous car tech to vehicle-borne IEDs. The driver could dismount a few hundred meters short of the target and provide eyes-on ground-level surveillance (if for some reason you aren't using a UAV for the same) while the vehicle drives…

They probably also check for movements, blinks, etc. In any case, it should be viewed as an help for the driver (beep when falling asleep), rather than something working against him. If you wan to actively fool the device, do as you please (the software is open-source, after all, you can probably fork it to disable that feature) but face the consequences: your life is on the line!

Re: We Tested Comma AI's OpenPilot

#30
post #25
post #19

Earlier quoted context omitted.

It is actually concerning that you can inject false sensor data this easily. I mean, sure, the messages on the CAN will not be encrypted or signed in any way, I know, but still...

Why exactly would be concerning? You need to physically plug cables in the car you yourself own. If anything, every access to hardware you own SHOULD be this easy.

Because that means not only you (the owner) can do it.

Also (caution, tangent): MCUs in cars is one of the systems where I want more encryption/signing and less hacking - especially for owners. Foremost to get rid of all the chip-tuned soot sources I am constanly driving behind.

The manufacturer knows how to control the engine, the random idiot with a laptop in 95% of the cases does more harm then good. If the manufacturer botched the MCU (hello VW), then he is held accountable. If he allows users to cause harm to the environment (chip-tuning), he should be held accountable too.

Post reply on HN