Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

131–140 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#131

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

While I agree with the fact that what they did was dangerous, the fact they did it that way will garner much more attention to the root cause of this problem - connected cars allow remote control of car's most basic mechanical features, which they shouldn't. Hopefully, this will result in better safety measures in car systems in the long run.

Edit: They could've done it on the parking lot and the article would be put in a pile "some geeks are doing some geeky stuff" and forgotten. 70 MPH on the public highway is like a billboard with ten foot letters saying "PAY ATTENTION" in your face.

Re: Hackers Remotely Attack a Jeep on the Highway

#132

Earlier quoted context omitted.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

The driver was aware of their activities, so he is probably the only one with any legal culpability. Impeding traffic is a misdemeanor in Missouri, probably rates a maximum 1 year jail sentence (note 6: http://www.nhtsa.gov/people/injury/enforce/stspdlaw/mospeed.... )

According to the article, they didn't actually tell him ahead of time what they were going to do to the car.

Re: Hackers Remotely Attack a Jeep on the Highway

#133
post #46

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

I glad to see he did it. Not all "hackers" should be non-responsible kids who think about police as about enemies.

Re: Hackers Remotely Attack a Jeep on the Highway

#134
post #89

Earlier quoted context omitted.

I agree they may not make news if they did this in a safe manner. However, the goal of people researching security, shouldn't be to make news. And these people while admittedly working with Chrysler to see it fixed, seem to be forgetting that. Especially since they plan to release their code, despite the fact that Chrysler has to get people to manually update their cars. "The two researchers say that even if their co…

I saw a presentation at a departmental colloquium 3 years ago which demonstrated similar capabilities. The point is, car companies are not responding well to this threat even though it is well known to them . In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated in order to keep the general public safe. Those with know how can already exploit these fl…

> In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated

This assumes many facts not in evidence.

It may, in fact, be the best thing. But security people, as a rule, are strongly biased to love things that increase the social standing of security researchers, and chaos does that.

There are other ways of pressuring the car companies. I'd like to see companies failing to fix disclosed security holes in safety critical applications in a certain period of time face monetary damages, even without need to show harm was caused.

But lobbying is boring and getting on the top of HN is fun.

Re: Hackers Remotely Attack a Jeep on the Highway

#135
post #9

Earlier quoted context omitted.

Remote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.

Remote start I can see the reasoning for, but remote stop just seems to be asking for trouble.

What if you change your mind?

Re: Hackers Remotely Attack a Jeep on the Highway

#136

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover.

Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change.

How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (where the driver knew ahead of time it was going to happen).

Re: Hackers Remotely Attack a Jeep on the Highway

#137

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I agree: it was very poor judgment to demonstrate this on a public highway.

But when I read that you actually called the authorities and encouraged others to do the same by posting the number, a certain somewhat Tao-istic scene in The Big Lebowski [1] came to mind.

1. https://www.youtube.com/watch?v=uQl5aYhkF3E

Re: Hackers Remotely Attack a Jeep on the Highway

#138
post #71

Earlier quoted context omitted.

People do care if it makes the news. But the current official ways of doing the testing doesn't make the news and testing that is news worth gets the cops called on you. How convenient that testing a security flaw is viewed as more negligent than allowing them in the first place as a cost saving measure.

Allowing the flaw was negligent. This test was reckless. The law treats knowingly ignoring a risk as worse than unknowingly allowing one.

Unknowingly allowing a risk is a very generous way to describe policies that cut costs by increasing the chance of these risks. The ones who are endangering a small number of people to try to overall increase safety are currently looking at far more legal harm than those who endangered magnitudes more people for the sake of making more money. Don't contribute to stupidity what can be explained by amoral greed.

Re: Hackers Remotely Attack a Jeep on the Highway

#139

Earlier quoted context omitted.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

They decelerated a car. The brakes weren't even applied. This happens all the time on highways. It is unfortunate that it happened where there was no shoulder on the road, but if an accident did happen then I'm not so sure the researchers or journalist would be at fault. Here's a scenario: Let's say a person is driving a car, when their car engine fails. There's no shoulder for them to drive onto, so they are just sl…

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#140
post #56

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You better have the Highway Patrol investigate every single person who doesn't maintain their car properly and takes it on the highway because they're causing far more risk than this demo came close to creating, IMHO. Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.

> Was it life threatening? Hardly.

You really really don't know this.

If this was done by an actual research lab staffed by adults, it would never have gotten past the ERB.

Post reply on HN