So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…
I don't think this has necessarily anything to do with engineering competence. From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle. Why? Because while you're busy building a well-secured system, your competitors are busy implementing new f…
Hackers Remotely Attack a Jeep on the Highway
311–320 of 640 posts
Re: Hackers Remotely Attack a Jeep on the Highway
#312Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
Let's not forget Wired 's responsibility for this either. I wonder what editor Scott Dadich and owners Condé Nast have to say. OTOH, we don't know for certain that the tale of what really happened on the public highway didn't grow in the telling. EDIT: Holy moly https://twitter.com/CondeNast/status/623533074865893376 .
Re: Hackers Remotely Attack a Jeep on the Highway
#313Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
Re: Hackers Remotely Attack a Jeep on the Highway
#314Re: Hackers Remotely Attack a Jeep on the Highway
#315Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…
Who cares what their job title is? They deliberately blocked visibility and then cut the transmission of a vehicle being driven on a public road in traffic. That is well into the territory of criminal negligence.
Re: Hackers Remotely Attack a Jeep on the Highway
#316Earlier quoted context omitted.
> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…
Grass shoulder: http://www.wired.com/wp-content/uploads/2015/07/IMG_0724-102... I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (…
People who routinely test things that have the capability for real harm learn to take precautions for as many of the the things you don't think off as you can. For example, the Mythbusters are routinely testing things with cars and other bits of machinery that can cause physical harm if something goes wrong. They also routinely retire to abandoned airforce bases, remote locations, and the salt flats to test things.
Re: Hackers Remotely Attack a Jeep on the Highway
#317This discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now , with more rolling off the assembly line all the time, and people are driving these around right now . Why is most of…
> Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place. I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it. And given that the topic you (I assume) want to discuss is…
I just realized what the problem is: this is bikeshedding. Everyone knows about people driving around and feels qualified to have moral indignation in that area, whereas few people know anything about actual cars.
Re: Hackers Remotely Attack a Jeep on the Highway
#318Earlier quoted context omitted.
If it were not demonstrated under real conditions, the car companies would just say "this was a fake test not representative of real-world conditions, isn't that true Mr. Journalist?" and the journalist would have to admit that that was true and then they would say "Under real-world conditions our cars are safe; customers have nothing to worry about." This has been their playbook about everything for a long time so I…
There is no way a "not real-world conditions" argument could be made if this same test was done on a test track. No automaker would even try it because it would generate even more bad press. The "researchers" did the test on a public, in-use highway for better press/cool factor. Completely irresponsible.
Re: Hackers Remotely Attack a Jeep on the Highway
#319Earlier quoted context omitted.
You've seriously seen "dozens" of people killed?
Many car drivers forget a basic concept of physics named inertia , which is the reason why heavy vehicles (ex. trucks) take ___too long___ to brake. Emphasis in too long, because this is the reason why road signs announce dangerous sections of a road with even miles in advance.
Re: Hackers Remotely Attack a Jeep on the Highway
#320Earlier quoted context omitted.
> But putting many lives in danger is considered acceptable behavior by security researchers? We don't know, for sure, what happened. There might be some creative license in the journalism. There might be some omission of them talking to authorities (even if someone called the highway patrol and they said "oh, we don't know about this," all it proves is there's bureaucracy at the highway patrol). etc. Calling the cop…
Your post basically boils down to: 1. You don't trust the police/legal system. 2. You trust our own community more. Not saying I agree or disagree, but there are a LOT of people who would really disagree with this, and a lot more who would think that someone saying "why involved the actual people the public has chosen to deal with this, we can deal with it ourselves" would be very wrong.