Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

71–80 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#71
post #13

Earlier quoted context omitted.

People, and businesses, respond to incentives. The company probably did the economically rational thing here - the money they make from their remote-access features is more than the money they will lose for the insecurity. Companies in industries that need to find ways to make secure software; it's not a hard problem if you're willing to throw enough money at it. But as long as customers don't care whether their prod…

People do care if it makes the news. But the current official ways of doing the testing doesn't make the news and testing that is news worth gets the cops called on you. How convenient that testing a security flaw is viewed as more negligent than allowing them in the first place as a cost saving measure.

Allowing the flaw was negligent. This test was reckless. The law treats knowingly ignoring a risk as worse than unknowingly allowing one.

Re: Hackers Remotely Attack a Jeep on the Highway

#72

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

Which entire meta-categories of horrific errors do you ascribe to software development for jets? Commercial avionics, while not error-free, is surely one of the most stringent sectors of software development around today.

Re: Hackers Remotely Attack a Jeep on the Highway

#73
post #32

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

There was a "documentary" of these guys when they were testing via a hardwire to the car's computers. They were also in the car with the driver as well as in a parking lot and on some non-busy country road. I wonder if the reporter just added in those details about the highway to make it seem like more of a real threat or if they actually did test on a busy public roadway. edit: Found the video - https://www.youtube.…

The Wired article has a video of the test on the busy public roadway.

Re: Hackers Remotely Attack a Jeep on the Highway

#74
All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone.

I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except through a one-way (to display information) link, like it's done on airplanes.

I'm happy to have a much older vehicle with none of these "enhancements". It has a physical throttle, hydraulic brakes, and steering linkage for which remote hijacking is physically impossible. I can add navigation and entertainment with a smartphone mounted on the dash. It may not be as fuel-efficient or safe(?) as the cars today, but maybe the tradeoff is worth it. That also suggests there could be a market for new "dumb" cars which have all the modern improvements to engines and safety, but none of these "smart" exploitable features.

(I'm not so paranoid as to get a mechanical EMP-proof diesel though...)

Re: Hackers Remotely Attack a Jeep on the Highway

#75
post #32

Earlier quoted context omitted.

There was a "documentary" of these guys when they were testing via a hardwire to the car's computers. They were also in the car with the driver as well as in a parking lot and on some non-busy country road. I wonder if the reporter just added in those details about the highway to make it seem like more of a real threat or if they actually did test on a busy public roadway. edit: Found the video - https://www.youtube.…

The Wired article has a video of the test on the busy public roadway.

Ahh, I skipped right over it to the text. Woopsies. :D

Re: Hackers Remotely Attack a Jeep on the Highway

#76

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

Get a German car and you will not have such problems from what I know from my people. ;)

Re: Hackers Remotely Attack a Jeep on the Highway

#77
post #55

Earlier quoted context omitted.

Disconnecting will not restore corrupted firmware. Once virus is there, disconnecting just prevents data transfer.

Exactly. But at least you'd break the current control link and possibly/hopefully be able to stop and steer. Maybe in addition to breaking a link on a panic stop, stopping and steering would be set to a non-commanded mode that relies less or not at all (maybe impossible with current design?) on software commands.

The malicious firmware could just omit all that stuff.

I guess the disconnect could be physical/mechanical and require physical intervention to reconnect (but cost, etc.).

Re: Hackers Remotely Attack a Jeep on the Highway

#78

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…

They didnt have to do this on a public highway. A large parking lot would have be sufficient. Why should other motorists be subject to harm because a couple hackers and a reporter want to make a story. They could've easily gone on one of the 24hr news channels to scare the masses.

Re: Hackers Remotely Attack a Jeep on the Highway

#79
post #46

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

HN is chock full of self-righteous hall monitors. They usually don't progress to the point of calling the cops.

Re: Hackers Remotely Attack a Jeep on the Highway

#80
post #79
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

HN is chock full of self-righteous hall monitors. They usually don't progress to the point of calling the cops.

Can you expand a little on how calling the police about something is more or less self righteous than doing the (at least somewhat dangerous) experiment on a public highway?
Post reply on HN