Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

321–330 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#321

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

> but I really can't stop thinking about my wife and kids

What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner?

Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.

Re: Hackers Remotely Attack a Jeep on the Highway

#322

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.

Agreed. I missed the video the first time and didn't believe the text that described the shutdown, video shows the stupidity here, let alone release a recording of it. I expect that will come down soon.

Important research but very poorly tested. Wired and Chrysler (research was funded by Chrysler?) legal teams would not like the contents of this video.

edit: wired's link to video, jump to 2:00: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...

Re: Hackers Remotely Attack a Jeep on the Highway

#323

Earlier quoted context omitted.

Absolutely. But I can think of one very easy check that would solve many potentially serious problems. Disable remote operation of car hardware when a conscious human is detected at the manual controls. For some reason, this reminds me of Star Trek episodes where the crew has to transfer operation control of the Enterprise from the bridge down to engineering, or to another Starfleet ship. Even on a sci-fi television…

It's usually convenient to a plot to have characters do things. In real life, people generally prefer not doing things. Which isn't meant to excuse a problematic implementation like is seen in this article, I'm just not sure the writers were actually sweating the system details when they did that stuff.

While I don't think the original writers paid much attention to any of that, by the time Star Trek: the Next Generation began, computer security cracking was present in the popular culture. That's how the invading Borg were defeated, after all. At some point, when the plot for a current episode demands that it be possible for a ship to be controlled remotely, they then have to ask the continuity expert how to fix it so that the newly introduced thing doesn't significantly impact previous canon. That burden adds up across multiple seasons of multiple spinoffs.

The plot solution didn't even have to make sense. All they need is some technobabble, ready to spout for any fan wearing plastic ears who might stand up at a con and ask, "If Enterprise had capability X in episode Y, why wasn't that used in episode Z?"

In this case, it is very reasonable that someone, somewhere, might have asked, "What should we do if this command is used while the owner is driving along a busy highway at 70 mph, and executing it would stall out the engine?" This is a question that would provoke a stop-and-assess moment in even the most dysfunctional software company I have ever worked in.

From the architectures we typically see for in-car computer networks, it looks like no one is asking these questions.

Re: Hackers Remotely Attack a Jeep on the Highway

#324
post #294

Earlier quoted context omitted.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

First off, a "dangerous thing you can do" and "exploit" are not synonyms. So examples like anthrax attacks or home invasion are stupid and massively miss the point. Secondly, nobody would give a fuck about this exploit if it was performed in controlled environment. The researchers knew it because they did this kind of stuff before. Guess what, the cars did not become any safer! This much should be obvious to anyone w…

Actually home invasion is an "exploit" of the home security (i.e. locked doors / windows).

Just because they do it from behind a screen doesn't make it a less culpable crime. Computers don't insulate you from ethics...

We put locks on our doors to prevent people from entering. They have always been exploitable but we use threat of laws to prevent it. Now we put locks in our software to prevent people from entering it (encryption). Somehow this generation believes that these locks are exempt from decency and law. It's sad that people think exposing vulnerabilities at any cost is righteous. There's plenty of people researching security in responsible ways. These two are not in that camp.

Have fun... it's no different than kicking your neighbors door down and tell him to pay you for exposing his security flaw. Still makes you are jerk.

Re: Hackers Remotely Attack a Jeep on the Highway

#325

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

This is like testing the new trigger safety on a gun by firing into a crowd. Its incredibly negligent and unethical. That section of i-64 is very busy and the police should get involved.

Re: Hackers Remotely Attack a Jeep on the Highway

#326
Previous research on this topic from 2010:

http://www.autosec.org/pubs/cars-oakland2010.pdf6

Experimental Security Analysis of a Modern Automobile

"Even at speeds of up to 40 MPH on the runway, the attack packets had their intended effect, whether it was honking the horn, killing the engine, preventing the car from restarting, or blasting the heat. ... In particular, we were able to release the brakes and actually prevent our driver from braking; no amount of pressure on the brake pedal was able to activate the brakes. Even though we expected this effect, reversed it quickly, and had a safety mechanism in place, it was still a frightening experience for our driver."

Re: Hackers Remotely Attack a Jeep on the Highway

#327

Earlier quoted context omitted.

The hackers' behaviour was utterly reckless. Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards. But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and vis…

To me it seems like it is gross recklessness with public safety from car manufacturers. The car manufacturers are risking lives of all these people by not keeping the air gap between CAN and Internet...

It can be both, security researchers don't get a free pass just because they are exposing a wrong.

Had someone died you might (in countries which have it) get corporate manslaughter on a company that ignored security warnings. You absolutely would on the researchers and the journalist for their reckless disregard for the lives of others.

Re: Hackers Remotely Attack a Jeep on the Highway

#328
post #208

Earlier quoted context omitted.

Let's not forget Wired 's responsibility for this either. I wonder what editor Scott Dadich and owners Condé Nast have to say. OTOH, we don't know for certain that the tale of what really happened on the public highway didn't grow in the telling. EDIT: Holy moly https://twitter.com/CondeNast/status/623533074865893376 .

That looks like a staged shot. Highways don't have corners like that.

It certainly doesn't seem to be from the main transmission-shutdown incident, at least. I'm much less interested in the photo than in the fact that Condé Nast corporate thought it was a good idea to proudly Tweet this article to the world.

Re: Hackers Remotely Attack a Jeep on the Highway

#329

So, a HN commentator apparently called the cops on these guys after reading the Wired article. Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent. Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason . And wtf you called the cops? head in hand

Make sure you watch the video, i missed it the first time through.

Re: Hackers Remotely Attack a Jeep on the Highway

#330
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

The fact of the matter is that this is Startup News not Hacker news. Hardly anybody on this website is a hacker. Most are people that code html and php in their day job and go home and do normal shit. These are people that complain about how the industry "pressures" them into coding in their free time.

look mom I'm a hacker too :^)
Post reply on HN