Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

331–340 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#331

Earlier quoted context omitted.

The hackers' behaviour was utterly reckless. Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards. But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and vis…

To me it seems like it is gross recklessness with public safety from car manufacturers. The car manufacturers are risking lives of all these people by not keeping the air gap between CAN and Internet...

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#332
post #260

Earlier quoted context omitted.

Your post basically boils down to: 1. You don't trust the police/legal system. 2. You trust our own community more. Not saying I agree or disagree, but there are a LOT of people who would really disagree with this, and a lot more who would think that someone saying "why involved the actual people the public has chosen to deal with this, we can deal with it ourselves" would be very wrong.

It's hard to imagine how anyone familiar with any part of the police/legal system's pattern of clueless, ham-handed, hierarchy-ridden interaction with technology over the last 30 years could find justification to continue extending them trust.

So what are we supposed to do instead? Rely on self policing by the individuals or the industry? The the police or judicial system is off track, you attempt to correct them, not ignore them and route around them. That may unfortunately end up with injustice for some while the correction is ongoing, but that's the normal state. There's always correction that needs to happen, and there's always injustice, that's the normal state, the point is to try to minimize the injustice as much as possible. Ignoring the built in mechanisms for steering the government in the right direction doesn't yield a better situation in the end.

Re: Hackers Remotely Attack a Jeep on the Highway

#333

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

>I exercised my judgement and decided to phone the local Highway Patrol office.

That was rash. You called the police within an hour of reading this article? You didn't think it's possible the writer is embellishing or exaggerating the danger he was in here? As of right now, everything they've done has been done in good faith to try to point out the need for extra security.

Also, if they get arrested, even convicted of a crime, then what? You have two extremely angry researchers who know how to hack your car, and what, you're hoping some jail time might help them see the error of their ways and use more caution in the future? You can't see any potential problems if one of them feels vindictive about being jailed over your phone call when they weren't trying to do anything wrong in the first place?

Re: Hackers Remotely Attack a Jeep on the Highway

#334

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.

You're officially wrong per Federal Certifications (some courtesy Jeep, some the dealer,) so that's the Safe way for researchers to have approached it; mountains and no easement would've brought it down to rules for scratch journalists (please try to recover my GoPro...) State (etc.) laws are 80% hate speech against cyclists. Not even tagged Florida; my car's entertainment system made me climb a tree and launch t-shirts at traffic, blister, etc. If they'd done it as a vetted demo in a lot that could have been a Federal lot...insert stdSecLetter, stdClearance, stdDeclarationOfInterest...meh.

Re: Hackers Remotely Attack a Jeep on the Highway

#335
post #317

Earlier quoted context omitted.

> Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place. I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it. And given that the topic you (I assume) want to discuss is…

They might be reasonable in isolation but are not being levied remotely in proportion. I just realized what the problem is: this is bikeshedding. Everyone knows about people driving around and feels qualified to have moral indignation in that area, whereas few people know anything about actual cars.

No, when people's lives are at stake, I extremely disagree about calling that "bikeshedding".

Re: Hackers Remotely Attack a Jeep on the Highway

#336

Did anyone bother to read the full article? If so, you would find out that it was a [somewhat] controlled experiment. > To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. > Instead, they merely assured me that th…

be sure to check out the video http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...

Re: Hackers Remotely Attack a Jeep on the Highway

#337

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

> but I really can't stop thinking about my wife and kids What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner? Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.

By saying this you are basically saying there was no reasonable alternative method of exposing this.

I am unwilling to say that. This argument that somehow the ends justify the means when there was a clearly more safe means has to stop. It's just ignorant.

Re: Hackers Remotely Attack a Jeep on the Highway

#338

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.

They've risked people's lives to produce real life looking footage documenting a life threatening event.

Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet.

Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how hard was this decision. It's a choice between risking lives and having footage that doesn't catch attention and thus allows car manufacturers to continue making unsafe cars with horrible security vulnerabilities. Amazing.

Re: Hackers Remotely Attack a Jeep on the Highway

#339
post #297

Earlier quoted context omitted.

It amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned? As much as I love Tesla and what they are trying to do to the car industry, they are…

How would you like those three dials to control the rest of the car systems? And, isn't this what BMW tried to do ages back with that single 'iButton' control that everyone hated?

Uhh, the same way almost every non-luxury car made between 1960 and 2010 did it? A dial each for temperature, fan speed, and where the air is blowing. Plus a button for air conditioning and/or recirculate. No touch screens, no menus.

People have been using cars without touch screens for 50+ years. The UX is a pretty much a solved problem by this point. Yet now car manufacturers seem to want to mess with something that worked great, just so their cars seem cutting-edge.

Re: Hackers Remotely Attack a Jeep on the Highway

#340

Earlier quoted context omitted.

>> The point is, car companies are not responding well to this threat even though it is well known to them. I think the problem is related to core competencies (sorry to throw in the MBA speak). The old-school car companies are good at making cars, and not secure computer systems. You can likely say the same about the skill sets of the decision-makers running these companies. Many of them just can't wrap their head a…

Car companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives. The car companies' failure to patch defects ought to have them facing severe fines. In fact, I would support a bounty system of millions of dollars for researchers who can demonstrate 1) finding a flaw, 2) telling the company, and 3) the company not fixing it in X months. All this fi…

>> Car companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives.

You're completely right, but the key phrase in your sentence is "mechanical failure".

I've worked on analytics projects in the automotive industry for analyzing defects before they get into the "campaign" (aka recall) stage. They are incredibly good at that type of analysis. Most mechanical parts "make sense", since they're designed for only a few functions.

An Internet connected computer and software, on the other hand, doesn't always make sense to auto execs because they are significantly more complex.

As it relates to the article, I wouldn't be surprised if the car's computer system was perceived more as just a part having a particular set of features by Chrysler's top executives than as a computer system requiring the same types of security controls as, say, an ATM would.

Post reply on HN