Earlier quoted context omitted.
The hackers' behaviour was utterly reckless. Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards. But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and vis…
To me it seems like it is gross recklessness with public safety from car manufacturers. The car manufacturers are risking lives of all these people by not keeping the air gap between CAN and Internet...
Hackers Remotely Attack a Jeep on the Highway
331–340 of 640 posts
Re: Hackers Remotely Attack a Jeep on the Highway
#332Earlier quoted context omitted.
Your post basically boils down to: 1. You don't trust the police/legal system. 2. You trust our own community more. Not saying I agree or disagree, but there are a LOT of people who would really disagree with this, and a lot more who would think that someone saying "why involved the actual people the public has chosen to deal with this, we can deal with it ourselves" would be very wrong.
It's hard to imagine how anyone familiar with any part of the police/legal system's pattern of clueless, ham-handed, hierarchy-ridden interaction with technology over the last 30 years could find justification to continue extending them trust.
Re: Hackers Remotely Attack a Jeep on the Highway
#333Earlier quoted context omitted.
Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…
Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…
That was rash. You called the police within an hour of reading this article? You didn't think it's possible the writer is embellishing or exaggerating the danger he was in here? As of right now, everything they've done has been done in good faith to try to point out the need for extra security.
Also, if they get arrested, even convicted of a crime, then what? You have two extremely angry researchers who know how to hack your car, and what, you're hoping some jail time might help them see the error of their ways and use more caution in the future? You can't see any potential problems if one of them feels vindictive about being jailed over your phone call when they weren't trying to do anything wrong in the first place?
Re: Hackers Remotely Attack a Jeep on the Highway
#334Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…
I had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.
Re: Hackers Remotely Attack a Jeep on the Highway
#335Earlier quoted context omitted.
> Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place. I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it. And given that the topic you (I assume) want to discuss is…
They might be reasonable in isolation but are not being levied remotely in proportion. I just realized what the problem is: this is bikeshedding. Everyone knows about people driving around and feels qualified to have moral indignation in that area, whereas few people know anything about actual cars.
Re: Hackers Remotely Attack a Jeep on the Highway
#336Did anyone bother to read the full article? If so, you would find out that it was a [somewhat] controlled experiment. > To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. > Instead, they merely assured me that th…
Re: Hackers Remotely Attack a Jeep on the Highway
#337To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…
> but I really can't stop thinking about my wife and kids What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner? Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.
I am unwilling to say that. This argument that somehow the ends justify the means when there was a clearly more safe means has to stop. It's just ignorant.
Re: Hackers Remotely Attack a Jeep on the Highway
#338Earlier quoted context omitted.
Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…
I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.
Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet.
Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how hard was this decision. It's a choice between risking lives and having footage that doesn't catch attention and thus allows car manufacturers to continue making unsafe cars with horrible security vulnerabilities. Amazing.
Re: Hackers Remotely Attack a Jeep on the Highway
#339Earlier quoted context omitted.
It amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned? As much as I love Tesla and what they are trying to do to the car industry, they are…
How would you like those three dials to control the rest of the car systems? And, isn't this what BMW tried to do ages back with that single 'iButton' control that everyone hated?
People have been using cars without touch screens for 50+ years. The UX is a pretty much a solved problem by this point. Yet now car manufacturers seem to want to mess with something that worked great, just so their cars seem cutting-edge.
Re: Hackers Remotely Attack a Jeep on the Highway
#340Earlier quoted context omitted.
>> The point is, car companies are not responding well to this threat even though it is well known to them. I think the problem is related to core competencies (sorry to throw in the MBA speak). The old-school car companies are good at making cars, and not secure computer systems. You can likely say the same about the skill sets of the decision-makers running these companies. Many of them just can't wrap their head a…
Car companies, possibly more than anyone else in the world, are the home to people who understand how mechanical failure affects lives. The car companies' failure to patch defects ought to have them facing severe fines. In fact, I would support a bounty system of millions of dollars for researchers who can demonstrate 1) finding a flaw, 2) telling the company, and 3) the company not fixing it in X months. All this fi…
You're completely right, but the key phrase in your sentence is "mechanical failure".
I've worked on analytics projects in the automotive industry for analyzing defects before they get into the "campaign" (aka recall) stage. They are incredibly good at that type of analysis. Most mechanical parts "make sense", since they're designed for only a few functions.
An Internet connected computer and software, on the other hand, doesn't always make sense to auto execs because they are significantly more complex.
As it relates to the article, I wouldn't be surprised if the car's computer system was perceived more as just a part having a particular set of features by Chrysler's top executives than as a computer system requiring the same types of security controls as, say, an ATM would.