Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

301–310 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#301

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Can you clarify exactly where the line is between what you've done here today, and an outright swatting?

I'm not trying to equivocate the two, but it would seem they both exist somewhere on the same continuum of personal information and police involvement.

How much do you think your decision to make this call was influenced by your perception of what law enforcement does in Europe vs. what law enforcement does here in the United States?

Re: Hackers Remotely Attack a Jeep on the Highway

#302
post #118

Earlier quoted context omitted.

> Was it life threatening? Hardly. Danger Checklist: ✔ 70mph ✔ Public highway ✔ Driver not in control

This is also the checklist for most of the traffic that's currently driving on US interstate highways.

There's a lot of bad drivers out there that make a lot of bad decisions, but saying "most" of them are essentially not in control of their vehicles is frankly ridiculous.

Re: Hackers Remotely Attack a Jeep on the Highway

#303
post #202

Earlier quoted context omitted.

> Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. But putting many lives in danger is considered acceptable behavior by security researchers? Does it actually matter that it was security researchers? Do security researchers working on banking software need to steal a million dollars in order to prove that they've found an issue? Would calling the police b…

> But putting many lives in danger is considered acceptable behavior by security researchers? We don't know, for sure, what happened. There might be some creative license in the journalism. There might be some omission of them talking to authorities (even if someone called the highway patrol and they said "oh, we don't know about this," all it proves is there's bureaucracy at the highway patrol). etc. Calling the cop…

If only there was some agency or agencies responsible for investigating possible illegal activity, we could have contacted them instead, and then they could investigate the matter with the input of the judicial system, interview the people involved, and come to the appropriate response.

Re: Hackers Remotely Attack a Jeep on the Highway

#304
post #265

Earlier quoted context omitted.

> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…

Grass shoulder: http://www.wired.com/wp-content/uploads/2015/07/IMG_0724-102... I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (…

> the danger was small relative to the normal everyday danger of driving with humans

The danger of a car having its transmission crap out on the freeway is non-zero, yes. On the other hand, they explicitly cut a vehicle's transmission on the freeway. The danger for the people in the immediate area of this vehicle was increased because the situation (a cut transmission) went from "maybe it will happen" to "it is definitely happening." At that point, whether or not an accident happened depended entirely on the skill and attention of the drivers around this vehicle something completely out of the control of the researchers.

Re: Hackers Remotely Attack a Jeep on the Highway

#305

Does Wired really wonder why so many of their readers have ad blocking software? [1] I can't even read the article on their website because every ad I see is covering up some sort of text of the article. None of the ads have a close, hide, or dismiss button either so I can't just go and hide them. [1]: http://i.imgur.com/IZymUKm.png [2]: http://i.imgur.com/C7LiA60.png

Something is wrong with your browser or screen resolution. The page renders fine in Chrome with no artifacts like that, etc.

Re: Hackers Remotely Attack a Jeep on the Highway

#306

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I've seen Mr. Miller present at Black Hat and have talked with him about my own vulnerability reports to automotive vendors (I worked with one about two years ago to fix a rather embarrassing remotely exploitable flaw). However, I do not support testing or demonstrating any of the flaws on open public roads. Unforeseen things can and do happen. If the reporter would have been rear-ended this wouldn't have gone well for either researcher & that's enough right there to justify not doing this on public roads. The term "keep it to the track" which is often applied to the automotive racing scene is more than applicable here. The general public already tends to have a negative view of security researchers and performing "research" like this just re-enforces the perception.

Re: Hackers Remotely Attack a Jeep on the Highway

#307

Earlier quoted context omitted.

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

I think researchers should have complete 100% legal cover if they test private vehicles and private roads. But as someone who says the car manufacturer ought to face legal consequences for failing to fix a remotely exploitable stall-out in a timely manner (even without demonstration of anyone being harmed), I also say that people who fuck with moving cars on the road are a menace as well.

We could easily reverse that reasoning:

Security researchers should only be liable for potential risks if we manage to hold those companies for potential risks.

If we fail to do the latter it's quite unfair to let individuals bear the brunt of legal enforcement.

Re: Hackers Remotely Attack a Jeep on the Highway

#308

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

The hackers' behaviour was utterly reckless. Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards. But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and vis…

To me it seems like it is gross recklessness with public safety from car manufacturers. The car manufacturers are risking lives of all these people by not keeping the air gap between CAN and Internet...

Re: Hackers Remotely Attack a Jeep on the Highway

#309
post #265

Earlier quoted context omitted.

> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…

Grass shoulder: http://www.wired.com/wp-content/uploads/2015/07/IMG_0724-102... I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (…

That photo is next to the parking lot where he "found an empty lot where [he] could safely continue the experiment" and then "they cut the Jeep’s brakes, leaving [him] frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch"

Not the highway.

Re: Hackers Remotely Attack a Jeep on the Highway

#310
post #28

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

I don't think this has necessarily anything to do with engineering competence. From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle. Why? Because while you're busy building a well-secured system, your competitors are busy implementing new f…

In addition to your third paragraph, auto makers are disincentivized toward adding security features because they CAN'T advertise them. If Toyota started advertising the all new Prius with the feature "your ability to brake won't be taken away from you while you're barrelling down the highway at 70 mph", consumers wouldn't just not care, they would question why the fuck that wasn't there in the first place. This sort of stuff is expected to have been there from the start by consumers, so at this point its nothing but a cost sink to add it.
Post reply on HN