Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

11–20 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#12
Some questions for the researchers, or anyone else who thinks this was okay:

1) Were public roadways and speeds of 70mph absolutely necessary to demo this?

2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others?

3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting the researchers with questions about this demo if they weren't consulted in advance.

4) What's the plan if they trigger a bug in the car software of the people they had tested this with earlier? The article mentions them tracking people remotely as they attempt to learn more about the exploit.

I could go on but why bother? In case any of you think this was cool or even remotely (no pun intended) ethical, I'd like to know if you have a problem with letting these two test this on a loved one's car. How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything?

If I ever learned this had been tested on a vehicle I was in, I'd make sure this cost the researchers dearly.

EDIT: I've just phoned 'Troop C' of the Highway Patrol at their main number, +1-636-300-2800 and they seemed pretty keen to follow up. The fact that the vehicle was disabled where there was no shoulder, was impeding traffic, and the demo not cleared with them in advance has them concerned. I'm all for testing exploits and security research, but this isn't the right way to do it. And to film it and post it to a high traffic site is nuts.

Re: Hackers Remotely Attack a Jeep on the Highway

#13

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

People, and businesses, respond to incentives. The company probably did the economically rational thing here - the money they make from their remote-access features is more than the money they will lose for the insecurity.

Companies in industries that need to find ways to make secure software; it's not a hard problem if you're willing to throw enough money at it. But as long as customers don't care whether their products or data are secure, we'll get the security we pay for.

Re: Hackers Remotely Attack a Jeep on the Highway

#14
post #2

"...whether the Internet-connected computers were properly isolated from critical driving systems, and whether those critical systems had “cyberphysical” components—whether digital commands could trigger physical actions like turning the wheel or activating brakes." Shouldn't this be the most basic design consideration for any company building autos? The liability from litigation should bankrupt any company that does…

Well self driving cars should be a load of fun. There will be calls to isolate critical components as well as demands they are accessible to the likes of Law Enforcement so they can disable cars remotely.

So it will take legislation to sort out as liability concerns needs to addressed as well as the demands of law enforcement. Don't think for one minute they will accept self driving cars they cannot disable all of them for "safety reasons". Similar how they excuse options to black out cell service in areas

Re: Hackers Remotely Attack a Jeep on the Highway

#15
post #9

Earlier quoted context omitted.

Remote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.

Remote start I can see the reasoning for, but remote stop just seems to be asking for trouble.

I cant really see the need. If your already in the vehicle. . . . Seems to be completly asking for trouble.

Re: Hackers Remotely Attack a Jeep on the Highway

#16

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless.

There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

Re: Hackers Remotely Attack a Jeep on the Highway

#17
post #9

Earlier quoted context omitted.

Remote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.

Remote start I can see the reasoning for, but remote stop just seems to be asking for trouble.

I can see law enforcement agencies loving this feature. Way easier than high-speed pursuits down busy city roads.

[edit] Though remote control would probably be sufficient, but they seem equally dangerous to me from the driver's perspective.

Re: Hackers Remotely Attack a Jeep on the Highway

#18
post #9

Earlier quoted context omitted.

Remote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.

Remote start I can see the reasoning for, but remote stop just seems to be asking for trouble.

It's been long pitched as a safety measure to prevent high-speed car chases and car thefts.

Re: Hackers Remotely Attack a Jeep on the Highway

#19

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I was wondering why they wernt in constant communication(didnt he say he had to grab his phone and ask them to stop?), wjy the f*#@ would you test this at speed?

I agree with you, i hope that the author was lying to make his story more interesting (hows that for a bad wish).

I completly agree with you, seems to have a total disregard for anyone elses safety.

Re: Hackers Remotely Attack a Jeep on the Highway

#20
post #9

Earlier quoted context omitted.

Remote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.

Remote start I can see the reasoning for, but remote stop just seems to be asking for trouble.

I was addressing the question of wireless access to vehicle systems, not trying to justify any particular feature that might be included in such an implementation.
Post reply on HN