Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

241–250 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#241

Earlier quoted context omitted.

Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.

OK, just making sure I follow: They should exploit security holes and put people at risk to ensure that security research is not underfunded, which could lead to someone exploiting security holes, which would put people at risk.

Your argument would make sense if all exploits were equal. Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease. The weakened form, while it may not be risk free, is not equal to the harm of a full own infection.

Re: Hackers Remotely Attack a Jeep on the Highway

#242
This discussion is going insane.

I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree.

But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now, with more rolling off the assembly line all the time, and people are driving these around right now.

Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place.

Re: Hackers Remotely Attack a Jeep on the Highway

#243

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

It doesn't strike me as so odd, and your framing of the situations doesn't strike me as particularly conducive to honest discussion.

The people who "choose to cut security funding" (I'm assuming you mean congress?) acted within the bounds of the law and within their power as elected officials. They broke no laws and your disagreement with the results does not make them criminals.

I don't know if these researchers broke the law. All that's happening now is they are being investigated. If they did break the law, then it seems to me perfectly logical that they would be in "far greater legal trouble" than someone who didn't.

TL;DR it's not odd that someone who broke the law is in more legal trouble than someone who didn't

Re: Hackers Remotely Attack a Jeep on the Highway

#244
I feel like, public safety aside, people should be mad at these researchers because they give credibility to every ignorant politician, prosecutor, or journalist out there who says that all hackers threaten the public good. How are you supposed to draw a line between blackhat and ethical hackers when the "ethical" ones endanger public safety all the same?

Re: Hackers Remotely Attack a Jeep on the Highway

#245

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

The hackers' behaviour was utterly reckless.

Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards.

But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and visibility impaired? That's gross recklessness with public safety. (Here's a clue: you could have put me in that car and given me all the warning in the world and I could not guarantee maintaining control or not causing a potentially fatal accident at 70mph under those conditions.)

You shouldn't run experiments on big powerful machines in public places where you can't keep by-standers out. Gross ethical breach. I just hope the journalist is exaggerating or making things up.

Re: Hackers Remotely Attack a Jeep on the Highway

#246

Earlier quoted context omitted.

> These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason. "Elite," seriously? Is it 1995? Is the movie "Hackers" some type of inspiration to you? I'm almost surprised you didn't go all l33t speak. They endangered people's lives. It is as simple as that. If you too endanger people's lives "for no reason" on I-40 I hope they get you too.

They demonstrated that hackers can take lives using a laptop and a cell phone. And they displayed their own picture on the dashboard screen while doing it. Yes, elite. I'm not bringing it back; they already did.

They could have demonstrated that in a closed parking lot, and not a real highway.

Re: Hackers Remotely Attack a Jeep on the Highway

#247
post #70
post #67

Earlier quoted context omitted.

Sorry, but the cops lost that trust from me when the started sending swat teams and abusing power way to much. Since then, to me calling the cops has become a last resort. I dont trust ANY of them because of the few a holes that are abusing their power. Mainly caused because of their policies of shutting up and protecting each others. Until they fix this, i will not trust ANY cop again.

Until you're a victim of a crime I presume

I've never had the police even bother to show up in those cases.

Re: Hackers Remotely Attack a Jeep on the Highway

#248
Lot of comments here are accusing the "hackers" of negligence, but do not forget the writer, camera crew, and editors of WIRED were fully in control of the demonstration. This happened in the context of journalism, not security research. Blame WIRED if you think they screwed up, not the folks behind the computer.

It was up to WIRED to ensure the safety of the demonstration, and evidently they failed given this passage,

After narrowly averting death by semi-trailer, I managed to roll the lame Jeep down an exit ramp

Seems to me they should have at the very least had a chase car trailing the demo car with a sign, flashing lights, or flags to alert nearby drivers.

Re: Hackers Remotely Attack a Jeep on the Highway

#249

Earlier quoted context omitted.

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover. Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change. How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (wh…

I will point out that the car didn't stall. Power brakes and power steering weren't affected. The transmission was forced into neutral which did affect his ability to accelerate. Still reckless and stupid. And probably worthy of a call to the police -- though debatable. I don't understand why they didn't just test this in the drive way or on jackstands or at a track or on a dyno. Driving the car on a public street was not needed.

Re: Hackers Remotely Attack a Jeep on the Highway

#250

Earlier quoted context omitted.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

They decelerated a car. The brakes weren't even applied. This happens all the time on highways. It is unfortunate that it happened where there was no shoulder on the road, but if an accident did happen then I'm not so sure the researchers or journalist would be at fault. Here's a scenario: Let's say a person is driving a car, when their car engine fails. There's no shoulder for them to drive onto, so they are just sl…

They decelerated a car enough for other drivers to honk. It was slowed to a crawl. States have adopted minimum highway speeds for 50 years for a reason.

What if their proof-of-concept didn't work as predicted and did slam the brakes? This is just a reverse-engineered hack that was unleashed on a highway while the radio was blasting too loud to hear each other on the call.

Post reply on HN