Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?
Hackers Remotely Attack a Jeep on the Highway
61–70 of 640 posts
Re: Hackers Remotely Attack a Jeep on the Highway
#62Earlier quoted context omitted.
You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…
I agree they may not make news if they did this in a safe manner. However, the goal of people researching security, shouldn't be to make news. And these people while admittedly working with Chrysler to see it fixed, seem to be forgetting that. Especially since they plan to release their code, despite the fact that Chrysler has to get people to manually update their cars. "The two researchers say that even if their co…
However, they do need to make the news. Them making the news makers it easier and more likely that politicians will prioritize the political capital of working to solve this over the lobbyist from the automotive industry.
If Chrysler and other car manufacturers were taking this sufficiently seriously the releases might not be necessary. They gave Chrysler plenty of warning, Chrysler could have issued a recall (and still can), the consequences are on Chrysler, not on the security researchers.
Re: Hackers Remotely Attack a Jeep on the Highway
#63Re: Hackers Remotely Attack a Jeep on the Highway
#64Wow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research. Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.
On the other hand, I'd rather that they be doing this work with the way they did it than not at all...
Re: Hackers Remotely Attack a Jeep on the Highway
#65Wow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research. Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.
Re: Hackers Remotely Attack a Jeep on the Highway
#66So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…
People, and businesses, respond to incentives. The company probably did the economically rational thing here - the money they make from their remote-access features is more than the money they will lose for the insecurity. Companies in industries that need to find ways to make secure software; it's not a hard problem if you're willing to throw enough money at it. But as long as customers don't care whether their prod…
Re: Hackers Remotely Attack a Jeep on the Highway
#67Earlier quoted context omitted.
You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?
Are you not supposed to report dangerous, and possibly criminal, situations to the authorities? A witness to such events cannot know if it has already been reported or is known about, are they supposed to just go on with their day? Yep, just drive by that car accident with possible injuries without calling it in because I'm sure someone else has already taken care of it. What's the worse that could happen? The author…
Re: Hackers Remotely Attack a Jeep on the Highway
#68If you talk to auto manufacturers in a way that they understand, they will understand.
Re: Hackers Remotely Attack a Jeep on the Highway
#69I think a basic idea should be: panic stops disconnect all wireless access. Which will probably result in lots of calls from people after they avoid hitting a dog. But still.
The root problem is that they were able to flash an ECU with custom code. From there they are 'trusted' on the vehicle network and can trigger or emulate any other component.
Requiring the firmware image to be signed, or not accepting a bootload from the physical interface that's connected to the internet would be a more comprehensive solution.
Re: Hackers Remotely Attack a Jeep on the Highway
#70Earlier quoted context omitted.
Are you not supposed to report dangerous, and possibly criminal, situations to the authorities? A witness to such events cannot know if it has already been reported or is known about, are they supposed to just go on with their day? Yep, just drive by that car accident with possible injuries without calling it in because I'm sure someone else has already taken care of it. What's the worse that could happen? The author…
Sorry, but the cops lost that trust from me when the started sending swat teams and abusing power way to much. Since then, to me calling the cops has become a last resort. I dont trust ANY of them because of the few a holes that are abusing their power. Mainly caused because of their policies of shutting up and protecting each others. Until they fix this, i will not trust ANY cop again.