Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

231–240 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#231
post #121
post #86

Earlier quoted context omitted.

Anyone could shoot up a public place... should amateur researches be showing up in malls with firearms to test preparedness? This case is even worse the the one I mentioned as there is a really easy way to safely demonstrate this exploit.

If it were not demonstrated under real conditions, the car companies would just say "this was a fake test not representative of real-world conditions, isn't that true Mr. Journalist?" and the journalist would have to admit that that was true and then they would say "Under real-world conditions our cars are safe; customers have nothing to worry about." This has been their playbook about everything for a long time so I…

I don't mind that it was demonstrated under real world conditions; I mind that no safety precautions were taken, like, you know:

- Contact the police and let them know this experiment will be conducted; and ask for police support

- Conduct this experiment on a closed road

Re: Hackers Remotely Attack a Jeep on the Highway

#233

Earlier quoted context omitted.

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover. Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change. How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (wh…

Bad calculation. One auto hacker can shut down all vulnerable cars simultaneously.

Re: Hackers Remotely Attack a Jeep on the Highway

#234
post #121
post #86

Earlier quoted context omitted.

Anyone could shoot up a public place... should amateur researches be showing up in malls with firearms to test preparedness? This case is even worse the the one I mentioned as there is a really easy way to safely demonstrate this exploit.

If it were not demonstrated under real conditions, the car companies would just say "this was a fake test not representative of real-world conditions, isn't that true Mr. Journalist?" and the journalist would have to admit that that was true and then they would say "Under real-world conditions our cars are safe; customers have nothing to worry about." This has been their playbook about everything for a long time so I…

There is no way a "not real-world conditions" argument could be made if this same test was done on a test track. No automaker would even try it because it would generate even more bad press. The "researchers" did the test on a public, in-use highway for better press/cool factor. Completely irresponsible.

Re: Hackers Remotely Attack a Jeep on the Highway

#235

If Myth Busters tested some wacky car on a public road at 70mph without telling anyone, we'd all be freaking out. But because they were "researchers" (i.e. the same tribe as most leftist people here) from a university (leftist church) then they get a pass and all sorts of justification for why what they did was OK. EDIT: Leftists go by label. They will heart any "researcher" thinking they must be their peer in their…

Do you see the searing irony in your edit?

Edit: The irony I see is not political, it is in saying They're not the sort of people that do some research before forming an opinion. while making a declaration that was not especially well researched.

I also probably disagree with your characterization of the people defending the researchers (but who knows what your definition of "leftists" encompasses).

Re: Hackers Remotely Attack a Jeep on the Highway

#236
post #220

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

It's not either/or. You're presenting a false dilemma. You can demonstrate the problem without doing it where you put real lives in danger. The researchers acted recklessly.

Re: Hackers Remotely Attack a Jeep on the Highway

#237

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I was thinking about how dangerous it was while I was reading it too, but I came away far less concerned than you I guess. The deceleration on the highway was the most worrisome, but it's not even in the ballpark of common driving hazards like distracted folks on cellphones or flying debris. A crash from such a thing is unlikely and the inconvenience is pretty minimal. Even you, the busybody who called the cops becau…

They did NOT "slam on their brakes" and it was NOT a large hazard. I understand that, if something had happened, they would have FELT partly responsible. But it's the kind of responsible that people with a lot of bumper stickers experience when someone wrecks because someone was paying too much attention to the stickers and not enough attention to the road.

Yes, they created conditions that might have made it possible for a lousy driver to wreck a car, but, no, they did not do anything inherently dangerous. A driver--ANY driver--is expected to be able to handle gently decelerating cars on the highway. They should also be able to pay attention despite big billboards, confusing traffic signs, and attractive people gallivanting on the sidewalks.

The average traffic jam is much more likely to cause an accident, but it typically doesn't and, when it does, we blame the driver that rear ends someone, not the masses of people who have actually stopped on the highway, often NOT gently.

Re: Hackers Remotely Attack a Jeep on the Highway

#238
post #220

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

You seem to be confused.

Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists.

Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your family.

1) This is a dangerous exploit

2) This was a dumb way to demonstrate it

Those are not mutually exclusive.

Re: Hackers Remotely Attack a Jeep on the Highway

#239

Earlier quoted context omitted.

They decelerated a car. The brakes weren't even applied. This happens all the time on highways. It is unfortunate that it happened where there was no shoulder on the road, but if an accident did happen then I'm not so sure the researchers or journalist would be at fault. Here's a scenario: Let's say a person is driving a car, when their car engine fails. There's no shoulder for them to drive onto, so they are just sl…

> but if an accident did happen then I'm not so sure the researchers or journalist would be at fault. So the people that purposely tried to cause the accident wouldn't be at fault for the accident if it occurred..? I find it highly amusing that in your scenario you're using an unpredictable failure as an equal for an intentional act. A better scenario would be: I open your car bonnet while you go to the bathroom. I h…

There's a huge difference between stopping on the highway and decelerating due to lack of engine power. The driver knew what was happening, turned on his hazard lights, and didn't apply the brakes. Slowing down on the highway, although annoying, shouldn't be an unfamiliar or unsafe scenario (ex: construction, traffic backup, etc.)

This would be a completely different story if the researchers applied full force to the brakes or accelerator since those are unexpected (to other drivers), sudden, and difficult to react to behaviours.

Re: Hackers Remotely Attack a Jeep on the Highway

#240
post #60

Earlier quoted context omitted.

The obvious but security-oblivious way to do this is to just connect the entertainment system that has the internet connection to one of the car's microcontroller busses. Even if it just needs to send a single command, it's easier than adding another pin and another wire to the appropriate microcontroller on the other end. The problem is that everything on these busses is completely trusted, and there's no authentica…

Encrypted and authenticated data on the bus won't happen anytime soon for cost reasons. Filtering the commands the controller can put on the bus seams reasonable, but would only be useful, if implemented on a second controller (probably won't happen, either). I think the best approach is to secure the internet connection properly. Don't permit incoming connections at all and just permit a single outgoing TLS connecti…

Given the risks to safety, it's necessary to use defense in depth and secure every layer by air gaps where possible, and a strict message whitelist where not. This might add $100 to the cost of each car, which is a ton of money when multiplied by millions of cars, but it simply has to be done.
Post reply on HN