Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

101–110 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#101
post #48

So if I'm understanding this correctly, the initial vulnerability is remote-exploitable and relies on a firmware patch. Why wouldn't the manufacturer use the same exploit to patch all affected vehicles rather than calling them in for service?

Presumably they lack permission to do such a thing. The researchers only experimented on a car they owned/controlled.

The manufacturer presumably has permission to do so. As for the attackers patching vulnerable vehicles, I hadn't thought of that, but of course that's a possibility as well. Pretty much the definition of white hat. :)

Re: Hackers Remotely Attack a Jeep on the Highway

#102
post #56

Earlier quoted context omitted.

You better have the Highway Patrol investigate every single person who doesn't maintain their car properly and takes it on the highway because they're causing far more risk than this demo came close to creating, IMHO. Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

The driver was aware of their activities, so he is probably the only one with any legal culpability.

Impeding traffic is a misdemeanor in Missouri, probably rates a maximum 1 year jail sentence (note 6: http://www.nhtsa.gov/people/injury/enforce/stspdlaw/mospeed.... )

Re: Hackers Remotely Attack a Jeep on the Highway

#103

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…

Yes, yes. We wouldn't be having this big thread about the safety of the experiment, and consideration for other motorists, if they hadn't done it this way.

If they had done this in a parking lot at 25 MPH with a couple cops present, the way Mythbusters does things, they would have ONLY had a story about hacking a Jeep to shut it down. And if they played their cards right, they might even be able to start some LEO contracts for car-disabling equipment.

Re: Hackers Remotely Attack a Jeep on the Highway

#104

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

It's not that your points are irrelevant, it's that they needlessly draw attention from the issue at hand: that the car manufacturers are being criminally negligent.

Re: Hackers Remotely Attack a Jeep on the Highway

#105

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I was thinking about how dangerous it was while I was reading it too, but I came away far less concerned than you I guess. The deceleration on the highway was the most worrisome, but it's not even in the ballpark of common driving hazards like distracted folks on cellphones or flying debris. A crash from such a thing is unlikely and the inconvenience is pretty minimal.

Even you, the busybody who called the cops because you read an article, said "What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early..." which implies that the trucker would have been following too closely or not paying attention (or both).

It's worth pointing out that the driver was aware of the situation and they didn't do anything dramatic like lock the brakes or throw the car in reverse. They chose a gentle deceleration in a stretch of road that had no shoulder to make it feel dangerous, but, on the spectrum of hazards that most drivers face every time they take the car out of the garage, this is pretty tame.

The fact is, had something happened, it wouldn't have been the disabled car that was at fault.

I think the researchers are in the clear, and for you to have read the article and been bothered enough to call the cops (and post the number for, presumably, the convenience of other hyper-sensitive folk who might otherwise just go back to staring at the neighbor kids from their bedroom window with their phones in their hands and 911 on their speed dial) is nuts.

Re: Hackers Remotely Attack a Jeep on the Highway

#106

So, a HN commentator apparently called the cops on these guys after reading the Wired article. Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent. Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason . And wtf you called the cops? head in hand

Because the did it on public road, intentionally causing him to lose control of the vehicle. Bunch of idiots if you ask me, no better than the clueless people you see talking on their cellphones distracted. A 1 ton vehicle is deadly in the wrong situation. Like many other people mentioned, there's many ways to demonstrate this is a safe, controlled manner rather than out in the wild.

At least now they'll face charges of reckless driving, rather than unauthorized access to the vin+gps+etc of various vehicles.

....... ... .... ....

Re: Hackers Remotely Attack a Jeep on the Highway

#107

So, a HN commentator apparently called the cops on these guys after reading the Wired article. Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent. Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason . And wtf you called the cops? head in hand

> These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason.

"Elite," seriously? Is it 1995? Is the movie "Hackers" some type of inspiration to you? I'm almost surprised you didn't go all l33t speak.

They endangered people's lives. It is as simple as that. If you too endanger people's lives "for no reason" on I-40 I hope they get you too.

Re: Hackers Remotely Attack a Jeep on the Highway

#108

Earlier quoted context omitted.

Presumably they lack permission to do such a thing. The researchers only experimented on a car they owned/controlled.

The manufacturer presumably has permission to do so. As for the attackers patching vulnerable vehicles, I hadn't thought of that, but of course that's a possibility as well. Pretty much the definition of white hat. :)

Yeah, it appears they do:

http://www.driveuconnect.com/terms/

(term 17)

Re: Hackers Remotely Attack a Jeep on the Highway

#109

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

What's more probable?

a) The developers were this incompetent

b) This "exploit" was a feature requested by the DHS

Re: Hackers Remotely Attack a Jeep on the Highway

#110

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

"A much less aggressive (and thoughtful) move would be to contact the researchers directly."

Not conducting this demonstration on a public highway would also have been a much less aggressive and thoughtful move, not to mention less dangerous.

Post reply on HN