Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

81–90 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#81
post #56

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You better have the Highway Patrol investigate every single person who doesn't maintain their car properly and takes it on the highway because they're causing far more risk than this demo came close to creating, IMHO. Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.

> Was it life threatening? Hardly.

Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in the shoulder due to vehicles drifting, failing to pay attention, or otherwise being distracted.

I cannot remotely begin to fathom how anyone can think a car going 0-10 MpH on a freeway ISN'T dangerous. And it is absolutely life threatening. If a car behind didn't notice the change in speed, panicked and either hit you or the concrete barrier(s) that could very easily cost them their life. Or leave them with life-long disabilities. Bigger things like trucks and those "road-trains" are even bigger liabilities.

Honestly I'll defend security research strongly in almost all contexts, but when you put people's actual lives in danger you clearly cross a line. There's no shades of gray there, endangering people's lives and health to effectively show off is absolutely immoral and should be illegal (and likely is).

Saying "well nobody got hurt" completely misses the point. It is the intent that is wrong, not the result. The result could have multiplied the wrongness of the intent and resulting in tens of years of jail time, but luckily for them their only "crime" this time was the intent of their dangerous actions.

And let's be frank here luck is the only reason nobody got hurt. The only reason why these two won't be in jail for many years.

Re: Hackers Remotely Attack a Jeep on the Highway

#82
So, a HN commentator apparently called the cops on these guys after reading the Wired article.

Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent.

Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason.

And wtf you called the cops? head in hand

Re: Hackers Remotely Attack a Jeep on the Highway

#83
post #79
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

HN is chock full of self-righteous hall monitors. They usually don't progress to the point of calling the cops.

Hall monitors are the best way I could imagine these people being described as. I completely agree.

Re: Hackers Remotely Attack a Jeep on the Highway

#84
post #64
post #30

Wow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research. Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.

They could certainly have done a much better job of demoing this safely. On the other hand, I'd rather that they be doing this work with the way they did it than not at all...

"On the other hand, I'd rather that they be doing this work with the way they did it than not at all..."

That's such a stupid tradeoff. Putting it as an either/or is silly. Doing this safely and demonstrating the alarming conclusion are not mutually exclusive.

I'd go as far as to say that the way they demonstrated this actually diminishes the message of the danger of this exploit and put's the focus on their stupidity.

Re: Hackers Remotely Attack a Jeep on the Highway

#85

All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except…

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#86
post #65
post #30

Wow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research. Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.

I don't think you understand. Anyone in the world can do this. Right now. Any time.

Anyone could shoot up a public place... should amateur researches be showing up in malls with firearms to test preparedness?

This case is even worse the the one I mentioned as there is a really easy way to safely demonstrate this exploit.

Re: Hackers Remotely Attack a Jeep on the Highway

#87

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#88

All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except…

It amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned?

As much as I love Tesla and what they are trying to do to the car industry, they are the worst offenders in this. Hopefully by the time I can afford one, there will be legislation making entirely touch-screen dashes illegal and they'll have the usual 3 dials for climate control, that you can operate without having to take your eyes off the road.

Re: Hackers Remotely Attack a Jeep on the Highway

#89

Earlier quoted context omitted.

You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…

I agree they may not make news if they did this in a safe manner. However, the goal of people researching security, shouldn't be to make news. And these people while admittedly working with Chrysler to see it fixed, seem to be forgetting that. Especially since they plan to release their code, despite the fact that Chrysler has to get people to manually update their cars. "The two researchers say that even if their co…

I saw a presentation at a departmental colloquium 3 years ago which demonstrated similar capabilities. The point is, car companies are not responding well to this threat even though it is well known to them. In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated in order to keep the general public safe. Those with know how can already exploit these flaws and likely have been for years. The car companies need to act to secure their customer's systems.

Re: Hackers Remotely Attack a Jeep on the Highway

#90
post #46

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

The fact of the matter is that this is Startup News not Hacker news. Hardly anybody on this website is a hacker. Most are people that code html and php in their day job and go home and do normal shit. These are people that complain about how the industry "pressures" them into coding in their free time.
Post reply on HN