Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

211–220 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#211
All the researchers and the journalist had to do was to talk to the Highway Patrol and say, "We'd like to test this on a highway; what do we need to do to make that happen?"

That's it. Maybe the State Patrol would say, "Sorry, there's nothing you can do to test this here legally", or maybe they would have said, "Pay for overtime for 10 troopers and you can do it."

The point is, we don't know. We can speculate, but we don't know.

The 'researchers' and journalist elected instead to conduct this experiment on a state highway, in "real world" conditions, without any safety mechanisms in place. Not only is this unethical and dangerous, it is (and should be) illegal.

No one should stop these experiments from taking place; and the CFAA should be amended to allow security researchers to research issues; but the problem I have is the inherent danger in this experiment.

What would we be saying if the journalist had been killed, or a mother and her two kids because of this? Do you think public sentiment would support security researchers if this had turned out differently?

If anyone had gotten hurt, you'd be looking at legislation that strengthens penalties for security researchers; not at legislation that takes security research more seriously.

This was an extremely childish move that had the propensity to hurt our industry more than help it. It is incumbent upon us take safety seriously in conducting these experiments.

We can't count on level heads from outside the tech industry if we aren't willing to show that we care about people's lives and their safety when we're conducting these experiments.

Re: Hackers Remotely Attack a Jeep on the Highway

#212

Earlier quoted context omitted.

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

A small risk? Disabling a car on a busy highway is not a small risk. What about this "experiment" could not be done in controlled environment on a track… or a country road… or an empty parking lot. I suppose we could just have infectious disease researchers set up shop on a street corner by this logic. Whatever! It's just a small risk! They're doing it for the sake of increasing safety standards!

Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.

Re: Hackers Remotely Attack a Jeep on the Highway

#213

Earlier quoted context omitted.

"A much less aggressive (and thoughtful) move would be to contact the researchers directly." Not conducting this demonstration on a public highway would also have been a much less aggressive and thoughtful move, not to mention less dangerous.

Finally some IT guys getting how the press works and now you want to change their story to something like "how I hacked a car in my backyard".

I understand why they did it this way, and I'm glad that this issue getting more publicity. But that does not mean that the means they chose are justified by the end of greater publicity. They simply did not have the right to endanger the other people on that road without their consent.

Re: Hackers Remotely Attack a Jeep on the Highway

#214

That was a lot of uninformative text to plow though... Apparently someone has found a remote exploit that affects some model of Jeep. It requires an attacker to find the IP address of the Jeep. Which implies that a Jeep has an IP address. The communication between the Jeep and the world is something called Uconnect.

They've also found a way to scan the Sprint network for cars connected to Uconnect and retrieve the cars' VIN and location.

Re: Hackers Remotely Attack a Jeep on the Highway

#215
post #89

Earlier quoted context omitted.

I saw a presentation at a departmental colloquium 3 years ago which demonstrated similar capabilities. The point is, car companies are not responding well to this threat even though it is well known to them . In such situations it is in the public's best interest that information about the vulnerabilities be widely disseminated in order to keep the general public safe. Those with know how can already exploit these fl…

>> The point is, car companies are not responding well to this threat even though it is well known to them. I think the problem is related to core competencies (sorry to throw in the MBA speak). The old-school car companies are good at making cars, and not secure computer systems. You can likely say the same about the skill sets of the decision-makers running these companies. Many of them just can't wrap their head a…

Car companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives.

The car companies' failure to patch defects ought to have them facing severe fines. In fact, I would support a bounty system of millions of dollars for researchers who can demonstrate 1) finding a flaw, 2) telling the company, and 3) the company not fixing it in X months. All this finances by fines on the car companies.

The above facts doesn't mean that what these guys did was okay.

Re: Hackers Remotely Attack a Jeep on the Highway

#216

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police.

While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and remotely disabling a vehicle on a multi-lane interstate highway, like it was a big joke. The reporter in the Jeep literally says "This is dangerous" and asks urgently for help. This all filmed and posted to Wired for the world to see, like they are proud of it.

Before working with computers I drove tractor-trailers for a while and was lucky to achieve a million-mile safe driving award. I have a pretty good idea of the dangers here and I know that stretch of road well, I've crossed it many times. I know from experience that a car stopped in the middle of a multi-lane interstate is one of the most dangerous situations you can be in. I've had people hit me who didn't see my huge trailer with flashers on and warning triangles out on a sunny day - it happens quite often. I've seen dozens of people killed in situations exactly like this. You see it coming and a random driver just plows into the stopped vehicle.

I exercised my judgement and decided to phone the local Highway Patrol office. I've read the negative comments and I disagree, I still think it was the correct thing to do. If you are a researcher and you do something this dangerous, and are foolish enough to then post it on a high-traffic site like Wired, I think you forfeit any right to a discreet warning and you deserve to have the police show up demanding answers to some tough questions.

Re: Hackers Remotely Attack a Jeep on the Highway

#217
post #202

Earlier quoted context omitted.

> Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. But putting many lives in danger is considered acceptable behavior by security researchers? Does it actually matter that it was security researchers? Do security researchers working on banking software need to steal a million dollars in order to prove that they've found an issue? Would calling the police b…

> But putting many lives in danger is considered acceptable behavior by security researchers? We don't know, for sure, what happened. There might be some creative license in the journalism. There might be some omission of them talking to authorities (even if someone called the highway patrol and they said "oh, we don't know about this," all it proves is there's bureaucracy at the highway patrol). etc. Calling the cop…

After Alice Goffman, a publication with this kind of journalist involvement has to be seen with a certain suspicion.

Re: Hackers Remotely Attack a Jeep on the Highway

#218

Earlier quoted context omitted.

This isn't just a loud neighbor. This was a drunk loud neighbor waving a loaded gun around. The driver was clearly distressed and they were just laughing it up.

No, these are knowledgable security researchers doing serious work who are probably amenable to discussing their research methods with concerned party via email or phone instead of the concerned party immediately phoning the police.

Doesn't matter who they are. They have a loaded gun in their hands. Use it somewhere private or not at all. Anything else is unacceptable and extremely dangerous.

Re: Hackers Remotely Attack a Jeep on the Highway

#219

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

You've seriously seen "dozens" of people killed?

Re: Hackers Remotely Attack a Jeep on the Highway

#220

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.
Post reply on HN