Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

161–170 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#161
post #56

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You better have the Highway Patrol investigate every single person who doesn't maintain their car properly and takes it on the highway because they're causing far more risk than this demo came close to creating, IMHO. Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#162

Well luckily my Chrysler despite only being a year old does not have this connectivity. It does have Uconnect which I despise, I keep contacting Chrysler to demand that they offer the ability to use Apple Carplay or the Google equivalent. To be fair there has yet to be a vehicle that has a nice easy to use controls for radio or media.

Same situation, same sentiment. Chrysler is apparently "on the list" for CarPlay compatibility, but across all marquees, there are only two cars you can buy today that have it installed, and both are Ferraris. (The 2015 Volvo XC90 may have some form of CarPlay "preparation".) Don't hold your breath for backwards compatibility.

All I really want is two things:

1. The Voice button on my steering wheel to activate Siri. (Not the horrible UConnect voice assist.)

2. Waze maps on screen. (UConnect navigation is shit and not worth the price.)

Re: Hackers Remotely Attack a Jeep on the Highway

#163
post #56

Earlier quoted context omitted.

You better have the Highway Patrol investigate every single person who doesn't maintain their car properly and takes it on the highway because they're causing far more risk than this demo came close to creating, IMHO. Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

Poorly maintained vehicles that break down while driving surprise the driver. This happens daily on public roads. Should we fine them for failing to maintain their vehicle to your standards?

There are autonomous vehicles being tested on our roads with a failure mode of "coast to a stop". They may not even have a human inside to react to things around them. Do the operators deserve to be jailed?

People modify their cars with various after-market upgrades and take them onto the highway. If the car fails, do they deserve to be imprisoned?

What a slippery slope!

Driving is a risk. The most deadly risk you will take each day. Drive defensively, don't be a statistic.

Re: Hackers Remotely Attack a Jeep on the Highway

#164

Earlier quoted context omitted.

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover. Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change. How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (wh…

Cars aren't toys. Just because there are many stalls doesn't mean adding one more becomes acceptable.

Here's the good test: since humans were involved, how did they present this to their ethical review board?

I'm pretty confident the answer would be "what's an ethical review board?".

Re: Hackers Remotely Attack a Jeep on the Highway

#165

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

> Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Reminds me of people who will call the police on a loud neighbor instead of just, you know, talking to them first.

You have not met our neighbours! Drug dealers, they run a vehicle repair 'service' from their garden despite local council enforcement notices. They regularly have fights in the street, my wife has been verbally abused and followed on numerous occcasions and there have been two police 'drugs raids' that have resulted in absolutlely nothing useful happening. I could go on, but it's not relevant.

This has no bearing on the original issue ('Calling police on security researchers'), but I'm just saying that you can't debate nicely with everyone.

Re: Hackers Remotely Attack a Jeep on the Highway

#166
If Myth Busters tested some wacky car on a public road at 70mph without telling anyone, we'd all be freaking out.

But because they were "researchers" (i.e. the same tribe as most leftist people here) from a university (leftist church) then they get a pass and all sorts of justification for why what they did was OK.

EDIT: Leftists go by label. They will heart any "researcher" thinking they must be their peer in their religion. They're not the sort of people that do some research before forming an opinion.

EDIT 2: There's no irony because most people defending the researchers are indeed leftists. This is like saying that there would be irony if I mistakenly thought that a politician said something (and hence argued based on that false knowledge that leftists attach themselves to politicians too quickly) when in fact it wasn't a politician but a celebrity. The point is, leftists defend people not on principles but based on how close they think they are to them - and reading "researchers" dings the "good people" bell in the leftist brain.

EDIT 3: The real irony here is that when free marketers say NASA should be shut down, leftists complain there's no way a private company can fund research, and here we are with leftists trying to shame me for mistakenly thinking a researcher was working for public money, when in fact I'm wrong and these researchers are actually the kind of researcher that leftists say can never exist: private researchers. Amazing. Do you at least now understand why NASA is a waste of taxpayer money (I don't care if it's 70c per person) or is the next excuse going to be that rockets are more expensive than cars?

Re: Hackers Remotely Attack a Jeep on the Highway

#167

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I would put this more on the reporter. He knew full well what the plan was, and chose to put himself in the situation voluntarily.

I suspect there's also a bit of embellishment going on.

Re: Hackers Remotely Attack a Jeep on the Highway

#168
post #96

Earlier quoted context omitted.

ya well all they did was stall the engine, they didn't tell the car to apply the brakes.

With what certainty did they know that was going to happen?

because they had previously tested it and knew what each function was doing. this was the Hackers movie with them flying around a computer and poking and prodding random things.

Re: Hackers Remotely Attack a Jeep on the Highway

#169
post #28

Earlier quoted context omitted.

I don't think this has necessarily anything to do with engineering competence. From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle. Why? Because while you're busy building a well-secured system, your competitors are busy implementing new f…

Ethics are part of competence in my opinion. Even if you disagree, preventing corporate liability is a component of competence in the law's opinion. That is, if the company is found liable, that's saying the employees responsible did something wrong, even if it's not holding them individually accountable.

Ianal, but from previous fallout on security issues, I'd assume legal liability stops well short of requiring actual competency.

Parent is 100% correct. It's market-adaptation. Same reason Samsung ships known-vulnerable extensions to Android: features >> security.

> So, it's perfectly possible that every engineer and manager who worked on these systems is really quite competent and perfectly aware of the potential for security flaws [...], and still the sum of all the decisions made and market pressures applied caused the resulting product to be so vulnerable despite everyone's best intentions.

I think this is key. Although I'd lump it more on management given that they allocate technical resources. When you have a lack of technical knowledge in management, you lose the ability to make technically informed decisions.

Sometimes the nuances of a situation can't be summed up in a PowerPoint slide. Especially when it's a slide that someone created to summarize a slide deck from an engineer that they saw.

You think at least some of the OPM vulnerabilities were internally unknown? Even with incompetence, you had to have actual engineers who looked at settings and/or lack of feedback and went "Hunh..."

Re: Hackers Remotely Attack a Jeep on the Highway

#170

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…

So what you're saying is this was small potatoes and they should have caused a pile-up.
Post reply on HN