Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

291–300 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#291
post #265

Earlier quoted context omitted.

Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. IMO, the danger to the public caused by the researchers somewhat-controlled exploit is utterly dwarfed by the danger Jeep/uConnect is causing by directly connecting its cars to the internet. If the researchers are successful in getting car manufacturers to remove…

> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…

Grass shoulder: http://www.wired.com/wp-content/uploads/2015/07/IMG_0724-102...

I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (read: vulnerable Jeep Cherokees) from the road, which could ultimately reduce danger and save lives. It's not clear-cut when you're dealing with a vendor who chooses to ignore and/or litigate upon an initial disclosure instead of fix their product.

Re: Hackers Remotely Attack a Jeep on the Highway

#292
Every single highway crash involving a loss of control is now potentially a high-end assassination, including those that have taken place in the last few years.

How many people do you think will be murdered this way before investigators and the justice system catch up?

Re: Hackers Remotely Attack a Jeep on the Highway

#293
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

As much as it seem over the top, those researcher could have hurt people. Calling the police will not have them go to jail or have their data deleted. It might (rightfully) get them a fine. It will however ensure that their next experiments are done in a safer, more legal way. Calling the police isn't all about emergency. You can call them to talk about issues that worry you such as this one. They will take care of b…

Calling the police is just going to discourage more researchers from even attempting "safe" experiments. Calling the Highway patrol is like trying to open an egg with a sledgehammer.

Re: Hackers Remotely Attack a Jeep on the Highway

#294
post #220

Earlier quoted context omitted.

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

First off, a "dangerous thing you can do" and "exploit" are not synonyms. So examples like anthrax attacks or home invasion are stupid and massively miss the point.

Secondly, nobody would give a fuck about this exploit if it was performed in controlled environment. The researchers knew it because they did this kind of stuff before. Guess what, the cars did not become any safer!

This much should be obvious to anyone with a hacking mindset. The comments in this thread read more like "Moms Against Drunk Driving Bulletin Board" than "Hacker News".

Re: Hackers Remotely Attack a Jeep on the Highway

#295
post #109

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

What's more probable? a) The developers were this incompetent b) This "exploit" was a feature requested by the DHS

Oh, I know this one! Is it c) "The developers were competent at designing car control software, but insufficiently concerned about the possibilities for remote control, and therefore didn't test appropriately"?

Re: Hackers Remotely Attack a Jeep on the Highway

#296

Earlier quoted context omitted.

Your argument would make sense if all exploits were equal. Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease. The weakened form, while it may not be risk free, is not equal to the harm of a full own infection.

> Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease. If these guys want to be regarded as researchers, they need to act like them and be accountable like them. No ethics committee would ever approve a test like this.

The IRB as it currently stands it too strict with its regulations. Also, why should the researchers be regulated when the ones producing the things that are initially putting people into danger are not regulated (or are regulated by bureaucrats who couldn't tell you the difference between a buffer overflow and a SQL injection).

Re: Hackers Remotely Attack a Jeep on the Highway

#297

All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except…

It amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned? As much as I love Tesla and what they are trying to do to the car industry, they are…

How would you like those three dials to control the rest of the car systems? And, isn't this what BMW tried to do ages back with that single 'iButton' control that everyone hated?

Re: Hackers Remotely Attack a Jeep on the Highway

#298

Earlier quoted context omitted.

No, these are knowledgable security researchers doing serious work who are probably amenable to discussing their research methods with concerned party via email or phone instead of the concerned party immediately phoning the police.

Doesn't matter who they are. They have a loaded gun in their hands. Use it somewhere private or not at all. Anything else is unacceptable and extremely dangerous.

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#299
post #242

This discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now , with more rolling off the assembly line all the time, and people are driving these around right now . Why is most of…

Because it hits at a core philosophical dilemma. Is it ok to kill one person because their organs will save the lives of 5 others?

Re: Hackers Remotely Attack a Jeep on the Highway

#300
Hah, I found it really funny as I scrolled down there's a big ad for a Fiat in the article: http://i.imgur.com/rSyYPO4.png Fiat owns Chrysler who owns Jeep... maybe not the best marketing idea to advertise your cars in an article about exploiting them with potentially catastrophic results.
Post reply on HN