Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

181–190 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#181

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

I think researchers should have complete 100% legal cover if they test private vehicles and private roads.

But as someone who says the car manufacturer ought to face legal consequences for failing to fix a remotely exploitable stall-out in a timely manner (even without demonstration of anyone being harmed), I also say that people who fuck with moving cars on the road are a menace as well.

Re: Hackers Remotely Attack a Jeep on the Highway

#182

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

Or test on an official research highway such as Virginia Tech's Smart Road: https://en.wikipedia.org/wiki/Virginia_Smart_Road

Re: Hackers Remotely Attack a Jeep on the Highway

#183
post #62

Earlier quoted context omitted.

I agree they may not make news if they did this in a safe manner. However, the goal of people researching security, shouldn't be to make news. And these people while admittedly working with Chrysler to see it fixed, seem to be forgetting that. Especially since they plan to release their code, despite the fact that Chrysler has to get people to manually update their cars. "The two researchers say that even if their co…

They could have made still made the news if they had taken a few extra precautions to reduce the risk of an accident. However, they do need to make the news. Them making the news makers it easier and more likely that politicians will prioritize the political capital of working to solve this over the lobbyist from the automotive industry. If Chrysler and other car manufacturers were taking this sufficiently seriously…

You do realize a recall doesn't make all the cars come back on their own to get fixed right? Hell many consumers don't even realize there was a recall till their product fails for the reason it was recalled.

Chrysler seems to be taking this sufficiently seriously enough that releasing the code will do more harm than good. Could they take it more seriously? Well everything can always be taken more seriously, and someone will always claim it should. So I will say that's a matter of opinion.

EDIT: If their plan to 'release their code' is nothing more than a bluff to raise awareness I would consider that a much more appropriate course of action.

Re: Hackers Remotely Attack a Jeep on the Highway

#184

Earlier quoted context omitted.

There's plenty of safe ways to accomplish this kind of demonstration. The fact they choose to do so in a way that endangered the public is in fact criminal. Being a security researcher or journalist doesn't give you a license to put the public in physical danger.

I'm sure the police are even more ill-equipped to understand the ramifications of this demonstration and will over-react and start jailing anyone with a laptop and suspicious intent. I can't wait for the pathetic outrage when "racial profiling" now means harassing white kids with laptops that fit the profile of hacker . This is a matter for a company like Google to take on politically, not some beat cop in St. Louis…

This has nothing to do with the type of test they ran and everything to do with where and how they ran it.

Re: Hackers Remotely Attack a Jeep on the Highway

#185

All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except…

It amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned? As much as I love Tesla and what they are trying to do to the car industry, they are…

Agreed. I got infotainment/navigation touch screen in my Subaru. It is really hard to use without looking at the screen. Even after 2 months of driving, I haven't been able to develop muscle memories like I have for other controls on the car.

Luckily, infotainment screen doesn't really host anything critical. My uses include navigation and phone. Both of those functions should be used while parked anyways. I just cannot imagine changing a/c settings only at stop light.

Re: Hackers Remotely Attack a Jeep on the Highway

#186

Earlier quoted context omitted.

The fact that a dashboard system that controls your radio or AC has access to cut your transmission is also a hardware configuration issue. Accessories should be physically secured from ignition and drive train. The internet connected features of the car, in turn, should be severed from both of these. It should not be physically possible to turn on the wipers from the embedded processor that receives packets on the I…

And what are we going to do for self-driving cars? These are almost certainly going to rely heavily on internet access to perform basic driving functions. Figuring out how to make complex systems like these be secure in a trustworthy way is going to be a huge challenge as more and more critical devices are connected to the Internet.

Which is the primary and most valid criticism of self-driving cars.

Re: Hackers Remotely Attack a Jeep on the Highway

#187

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

A small risk? Disabling a car on a busy highway is not a small risk.

What about this "experiment" could not be done in controlled environment on a track… or a country road… or an empty parking lot.

I suppose we could just have infectious disease researchers set up shop on a street corner by this logic. Whatever! It's just a small risk! They're doing it for the sake of increasing safety standards!

Re: Hackers Remotely Attack a Jeep on the Highway

#188

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Performing this test on an open highway is incredibly irresponsible behavior on all parties. This is why they have test tracks (or even sandlots). Cutting the transmission to a vehicle going 70 miles an hour on an open highway is reckless endangerment -- even if the person behind the wheel knows it is going to happen.

Re: Hackers Remotely Attack a Jeep on the Highway

#189

If Myth Busters tested some wacky car on a public road at 70mph without telling anyone, we'd all be freaking out. But because they were "researchers" (i.e. the same tribe as most leftist people here) from a university (leftist church) then they get a pass and all sorts of justification for why what they did was OK. EDIT: Leftists go by label. They will heart any "researcher" thinking they must be their peer in their…

The researchers in question are employed in industry.

As your sibling comment points out, the review board at a university would not sanction doing the test in the article.

Re: Hackers Remotely Attack a Jeep on the Highway

#190
post #46

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

> Because you disagreed with their methods

This isn't really engaging with his action. Specifically, because called the cops because he believed that their methods put people in danger of physical harm. This objection isn't coherent without an argument either that:

1) He was unreasonable in his belief that they'd put people in harm's way.

or

2) It is not appropriate to contact law enforcement as a result of observing one person put another in harms way.

I'm guessing you're arguing both, correct?

aside: He contacted the state highway patrol, not the local St. Louis police. aside2: Hi Geofft! How are things going?

Post reply on HN