Earlier quoted context omitted.
Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.
OK, just making sure I follow: They should exploit security holes and put people at risk to ensure that security research is not underfunded, which could lead to someone exploiting security holes, which would put people at risk.
Hackers Remotely Attack a Jeep on the Highway
241–250 of 640 posts
Re: Hackers Remotely Attack a Jeep on the Highway
#242I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree.
But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now, with more rolling off the assembly line all the time, and people are driving these around right now.
Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place.
Re: Hackers Remotely Attack a Jeep on the Highway
#243Earlier quoted context omitted.
Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…
>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…
The people who "choose to cut security funding" (I'm assuming you mean congress?) acted within the bounds of the law and within their power as elected officials. They broke no laws and your disagreement with the results does not make them criminals.
I don't know if these researchers broke the law. All that's happening now is they are being investigated. If they did break the law, then it seems to me perfectly logical that they would be in "far greater legal trouble" than someone who didn't.
TL;DR it's not odd that someone who broke the law is in more legal trouble than someone who didn't
Re: Hackers Remotely Attack a Jeep on the Highway
#244Re: Hackers Remotely Attack a Jeep on the Highway
#245Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…
Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards.
But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and visibility impaired? That's gross recklessness with public safety. (Here's a clue: you could have put me in that car and given me all the warning in the world and I could not guarantee maintaining control or not causing a potentially fatal accident at 70mph under those conditions.)
You shouldn't run experiments on big powerful machines in public places where you can't keep by-standers out. Gross ethical breach. I just hope the journalist is exaggerating or making things up.
Re: Hackers Remotely Attack a Jeep on the Highway
#246Earlier quoted context omitted.
> These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason. "Elite," seriously? Is it 1995? Is the movie "Hackers" some type of inspiration to you? I'm almost surprised you didn't go all l33t speak. They endangered people's lives. It is as simple as that. If you too endanger people's lives "for no reason" on I-40 I hope they get you too.
They demonstrated that hackers can take lives using a laptop and a cell phone. And they displayed their own picture on the dashboard screen while doing it. Yes, elite. I'm not bringing it back; they already did.
Re: Hackers Remotely Attack a Jeep on the Highway
#247Earlier quoted context omitted.
Sorry, but the cops lost that trust from me when the started sending swat teams and abusing power way to much. Since then, to me calling the cops has become a last resort. I dont trust ANY of them because of the few a holes that are abusing their power. Mainly caused because of their policies of shutting up and protecting each others. Until they fix this, i will not trust ANY cop again.
Until you're a victim of a crime I presume
Re: Hackers Remotely Attack a Jeep on the Highway
#248It was up to WIRED to ensure the safety of the demonstration, and evidently they failed given this passage,
After narrowly averting death by semi-trailer, I managed to roll the lame Jeep down an exit ramp
Seems to me they should have at the very least had a chase car trailing the demo car with a sign, flashing lights, or flags to alert nearby drivers.
Re: Hackers Remotely Attack a Jeep on the Highway
#249Earlier quoted context omitted.
I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.
Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover. Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change. How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (wh…
Re: Hackers Remotely Attack a Jeep on the Highway
#250Earlier quoted context omitted.
> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…
They decelerated a car. The brakes weren't even applied. This happens all the time on highways. It is unfortunate that it happened where there was no shoulder on the road, but if an accident did happen then I'm not so sure the researchers or journalist would be at fault. Here's a scenario: Let's say a person is driving a car, when their car engine fails. There's no shoulder for them to drive onto, so they are just sl…
What if their proof-of-concept didn't work as predicted and did slam the brakes? This is just a reverse-engineered hack that was unleashed on a highway while the radio was blasting too loud to hear each other on the call.