Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

271–280 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#271
DARPA researchers demonstrated this stuff on a "60 Minutes" segment a few months ago [1]. The main difference is that they were in a large empty parking lot so as to not unethically put non-participants in danger.

That work and earlier work (including that shown in the 2014 Black Hat presentation by the researchers in the present article) drew interest of the Senate [2]. Senator Markey's office produced a detailed report, and has called for the NHTSA and the FTC to develop standards to deal with these issues (and also the numerous privacy issues modern cars raise) [3].

[1] http://www.cbsnews.com/news/car-hacked-on-60-minutes/

[2] http://www.cbsnews.com/news/sen-ed-markey-on-safety-privacy-...

[3] http://www.markey.senate.gov/imo/media/doc/2015-02-06_Markey...

Re: Hackers Remotely Attack a Jeep on the Highway

#272
post #163

Earlier quoted context omitted.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

Poorly maintained vehicles that break down while driving surprise the driver. This happens daily on public roads. Should we fine them for failing to maintain their vehicle to your standards? There are autonomous vehicles being tested on our roads with a failure mode of "coast to a stop". They may not even have a human inside to react to things around them. Do the operators deserve to be jailed? People modify their ca…

> Should we fine them for failing to maintain their vehicle to your standards?

You might want to review existing laws. See, e.g.:

Georgia: http://law.justia.com/codes/georgia/2010/title-40/chapter-8/...

"O.C.G.A. 40-8-7 (2010) 40-8-7. Driving unsafe or improperly equipped vehicle; punishment for violations of chapter generally; vehicle inspection by law enforcement officer without warrant"

Ohio: http://codes.ohio.gov/orc/4513.02

"(A) No person shall drive or move, or cause or knowingly permit to be driven or moved, on any highway any vehicle or combination of vehicles which is in such unsafe condition as to endanger any person."

California: http://www.leginfo.ca.gov/cgi-bin/displaycode?section=veh&gr...

"24002. (a) It is unlawful to operate any vehicle or combination of vehicles which is in an unsafe condition, or which is not safely loaded, and which presents an immediate safety hazard."

This research appears to have happened in Missouri, where it's harder to find the actual laws on the subject. That said, I did find this: https://www.mshp.dps.missouri.gov/MSHPWeb/PatrolDivisions/MV... which tends to imply that there are laws to this effect that I cannot easily locate via internet searches.

Re: Hackers Remotely Attack a Jeep on the Highway

#273
post #220

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

Using your logic, the government doing control biological tests on an unaware population (e.g. to test the spread patterns and inform their response to an actual event) is ok because terrorists/foreign governments could do much worse with (e.g.) weaponized Anthrax. I somehow doubt that you would be ok with such actions by the government (though I could be wrong).

Re: Hackers Remotely Attack a Jeep on the Highway

#274
post #242

This discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now , with more rolling off the assembly line all the time, and people are driving these around right now . Why is most of…

> Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place.

I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it.

And given that the topic you (I assume) want to discuss is something along the lines of "negligent behavior in technology", I also find it very relevant that negligence is countered with more negligence.

Re: Hackers Remotely Attack a Jeep on the Highway

#275

Earlier quoted context omitted.

This isn't just a loud neighbor. This was a drunk loud neighbor waving a loaded gun around. The driver was clearly distressed and they were just laughing it up.

No, these are knowledgable security researchers doing serious work who are probably amenable to discussing their research methods with concerned party via email or phone instead of the concerned party immediately phoning the police.

I don't agree. They breached their own covenant, which doesn't afford them the benefit of the doubt you might assign to 'knowledgeable researchers doing serious work': "We won't do anything life threatening." Then they did precisely that: they disabled the transmission on an uphill freeway ramp with no shoulder, with a very large truck bearing down on the Jeep. Trucks cannot stop quickly. Substantial danger for the driver, the trucker, and everyone around them.

Re: Hackers Remotely Attack a Jeep on the Highway

#276

Earlier quoted context omitted.

This isn't just a loud neighbor. This was a drunk loud neighbor waving a loaded gun around. The driver was clearly distressed and they were just laughing it up.

No, these are knowledgable security researchers doing serious work who are probably amenable to discussing their research methods with concerned party via email or phone instead of the concerned party immediately phoning the police.

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#278
post #202

Earlier quoted context omitted.

> Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. But putting many lives in danger is considered acceptable behavior by security researchers? Does it actually matter that it was security researchers? Do security researchers working on banking software need to steal a million dollars in order to prove that they've found an issue? Would calling the police b…

> But putting many lives in danger is considered acceptable behavior by security researchers? We don't know, for sure, what happened. There might be some creative license in the journalism. There might be some omission of them talking to authorities (even if someone called the highway patrol and they said "oh, we don't know about this," all it proves is there's bureaucracy at the highway patrol). etc. Calling the cop…

If there's been journalistic licence employed then they should be able to demonstrate that to the authorities since the entire footage was recorded. So there isn't an issue.

It also should be noted (since nobody else has raised this point) that some people within the police force likely read Wired anyway. So complaining about the police involvement for a piece posted to a popular news site is like moaning that your boss reads your Twitter feed.

Re: Hackers Remotely Attack a Jeep on the Highway

#279

That was a lot of uninformative text to plow though... Apparently someone has found a remote exploit that affects some model of Jeep. It requires an attacker to find the IP address of the Jeep. Which implies that a Jeep has an IP address. The communication between the Jeep and the world is something called Uconnect.

They've also found a way to scan the Sprint network for cars connected to Uconnect and retrieve the cars' VIN and location.

I'm still curious if this can be done without physical access to the car in advance. The last time one of these showed up, it was very understated that all the remote access stuff involved reprogramming an ECU and plugging in a phone you control.

The article doesn't provide any clear information on whether this works purely remotely.

EDIT: Scrap that, seems it does - weird that the article doesn't lead with that more prominently. In which case wow - pinging the network and grabbing GPS coordinates for cars?

Re: Hackers Remotely Attack a Jeep on the Highway

#280
Does Wired really wonder why so many of their readers have ad blocking software? [1] I can't even read the article on their website because every ad I see is covering up some sort of text of the article. None of the ads have a close, hide, or dismiss button either so I can't just go and hide them.

[1]: http://i.imgur.com/IZymUKm.png [2]: http://i.imgur.com/C7LiA60.png

Post reply on HN