Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

21–30 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#23

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

The fact that a dashboard system that controls your radio or AC has access to cut your transmission is also a hardware configuration issue. Accessories should be physically secured from ignition and drive train. The internet connected features of the car, in turn, should be severed from both of these. It should not be physically possible to turn on the wipers from the embedded processor that receives packets on the IP address of the car.

Re: Hackers Remotely Attack a Jeep on the Highway

#24

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

> There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

At some point you probably want to test it at highway speeds. I agree that a closed course would be the only responsible option, however.

Re: Hackers Remotely Attack a Jeep on the Highway

#25

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

I imagine a not terribly experienced new team being told to do connected stuff in a car, not really understanding security and having ridiculous demands thrown at them as the manufacturer drools about getting subscription revenue from every car. But would be nice to have an inside story.

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#26

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

They are not testing it, they are showing it.

Reckless yes and still probably not enough....

I believe people will need to be killed, or get their cars destroys before the rest of the population takes enough of a stance against "neglecting" security.

Re: Hackers Remotely Attack a Jeep on the Highway

#27

Earlier quoted context omitted.

I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

They are not testing it, they are showing it. Reckless yes and still probably not enough.... I believe people will need to be killed, or get their cars destroys before the rest of the population takes enough of a stance against "neglecting" security.

Nowhere near as reckless as missing oncoming traffic by mere feet at speed differentials exceeding 100MPH. Happens billions of times a day without anyone expressing the slightest concern. People are regularly killed and cars destroyed; the rest of the population doesn't care.

Re: Hackers Remotely Attack a Jeep on the Highway

#28

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

I don't think this has necessarily anything to do with engineering competence.

From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle.

Why? Because while you're busy building a well-secured system, your competitors are busy implementing new features that give them an actual advantage in the marketplace. As unfortunate as it might be, consumers tend to understand things like “remotely start your car with your phone” better than “your ability to brake won't be taken away from you while you're barrelling down the highway at 70 mph.”

It's sad and more than a little scary, but it's also nothing really new. Computer security, at least in the consumer sector, wasn't really a feature until viruses started showing up in the Eighties, and Internet security wasn't really a feature until the average Windows user's PC was getting taken over remotely the moment it was connected to the Net. Even Apple has only been able to tout security and privacy as a feature in its products by juxtaposing it to Google's business model—had the latter not existed and its data grab become part of public discourse, I doubt that Cupertino would have been able to make so much noise about it.

So, it's perfectly possible that every engineer and manager who worked on these systems is really quite competent and perfectly aware of the potential for security flaws (indeed, I doubt that they would have been able to make something so complex work otherwise), and still the sum of all the decisions made and market pressures applied caused the resulting product to be so vulnerable despite everyone's best intentions. It's not because people don't care or don't know, but rather because there are only so many resources available, and the market has pushed them all in a specific direction that happens to be away from security.

But this is also why we need this kind of research. Now that these problems are out in the open, and politicians are starting to take notice, security will become a feature that the public will care about, and, hopefully, car manufacturers will start adopting (or be forced to adopt) better standards.

Re: Hackers Remotely Attack a Jeep on the Highway

#29

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

The fact that a dashboard system that controls your radio or AC has access to cut your transmission is also a hardware configuration issue. Accessories should be physically secured from ignition and drive train. The internet connected features of the car, in turn, should be severed from both of these. It should not be physically possible to turn on the wipers from the embedded processor that receives packets on the I…

For sures. The ECEs are very much complicit too. Perhaps this is a ECEsoftware team communication or power problem? ECEs invent the systems architecture and some poor chap has to attempt to secure the thing? Or maybe the software guys have no avenue to push back against bad systems-level design.

Re: Hackers Remotely Attack a Jeep on the Highway

#30
Wow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research.

Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.

Post reply on HN