Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

391–400 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#391

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Thank you. This was very irresponsible. Ignore the vigilantes saying this doesn't cause harm. My family had a close friend killed on the freeway when she ran into a stalled tractor trailer and it decapitated her.

We've had 2 MAJOR accidents just recently by my house (I-85 near Atlanta) due to foreign objects and/or stalled vehicles.

Anyone who thinks this isn't unsafe is absolutely delusional. Any unexpected failure is hazardous on the interstate. Especially failures to the drivetrain, suspension, steering, or braking system. Beyond that, I hope everyone can agree spraying the windshield with washer-fluid and thereby completely obscuring the vision of the driver while he was traveling at 70mph is absolutely a hazard (what if the car in front had stopped for some reason).

Re: Hackers Remotely Attack a Jeep on the Highway

#392

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

This was my first thought. To repeat what others have said: why on earth did they do this on open roads and high speeds? I can only assume it was for additional 'shock impact' of the story. Reckless in many, many ways, no matter how interesting the story actually is. In fact it's so reckless that it actually devalues the interesting and important core of the story itself.

> To repeat what others have said: why on earth did they do this on open roads and high speeds?

Because - according to the article, at least - they'd already demonstrated similar exploits in more controlled environments, and said demonstrations were handwaved and dismissed by the auto manufacturers.

Re: Hackers Remotely Attack a Jeep on the Highway

#393

Earlier quoted context omitted.

> Was it life threatening? Hardly. Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in…

The driver was aware of their activities, so he is probably the only one with any legal culpability. Impeding traffic is a misdemeanor in Missouri, probably rates a maximum 1 year jail sentence (note 6: http://www.nhtsa.gov/people/injury/enforce/stspdlaw/mospeed.... )

Accomplice liability would make the researcher exactly as guilty as the driver.

Re: Hackers Remotely Attack a Jeep on the Highway

#394
post #242

This discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now , with more rolling off the assembly line all the time, and people are driving these around right now . Why is most of…

What if that reporter had been rear-ended and killed?

Re: Hackers Remotely Attack a Jeep on the Highway

#395
post #43

Earlier quoted context omitted.

You're not gonna make the news unless the media can spin up a headline that scares people People won't pay attention until they're scared People won't demand action if they're not paying attention Nothing will happened if people don't demand action. If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and…

>I'm not sure if you're actually this dense or just trolling. What good can involving the police, after the fact, in a situation where nobody was harmed do? I don't know, maybe if they get in trouble the next researcher who wants to do a test by disabling a car doing 70mph on a public road will maybe just alert a few people and make sure that it would be impossible for someone innocent to die during their testing. I…

> Who do you think should be the random person to get killed for change?

If we decide now, then it wouldn't be a random person, now would it? :)

Re: Hackers Remotely Attack a Jeep on the Highway

#396

Earlier quoted context omitted.

A small risk? Disabling a car on a busy highway is not a small risk. What about this "experiment" could not be done in controlled environment on a track… or a country road… or an empty parking lot. I suppose we could just have infectious disease researchers set up shop on a street corner by this logic. Whatever! It's just a small risk! They're doing it for the sake of increasing safety standards!

Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.

Using violent methods (such as intentionally sabotaging a car on a busy freeway with someone in it) to get media attention in order to further a political goal sounds a lot like the definition of terrorism.

Re: Hackers Remotely Attack a Jeep on the Highway

#397

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I agree with your move. Not sure who else was supporting you so I figured I'd offer my support. This was stupid as hell and I'm sure was likely set-up/suggested by Wired as a shock film.

Re: Hackers Remotely Attack a Jeep on the Highway

#398

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Feynman had a nice story where he figured out a way to crack many of the safes in Los Alamos, then dutifully reported his method to some bigshot general. The general said "hmm interesting, thank you very much", and banned Feynman from entering rooms with safes or something. The safes stayed as unsafe as ever. You remind me of that general. You should be hanging out on Catch The Hacker News, not Hacker News.

Testing on uninformed humans is unethical.

Wasn't hackernews just all up in arms about the US military spreading germs to test bioweapons? Isn't this the same exactly thing?

Re: Hackers Remotely Attack a Jeep on the Highway

#399
post #365

Earlier quoted context omitted.

So what are we supposed to do instead? Rely on self policing by the individuals or the industry? The the police or judicial system is off track, you attempt to correct them, not ignore them and route around them. That may unfortunately end up with injustice for some while the correction is ongoing, but that's the normal state. There's always correction that needs to happen, and there's always injustice, that's the no…

"So what are we supposed to do instead" and "Do I trust the police right now" are different questions. I don't like the fact that I trust self-policing by any community (even my own) more than the institution that is supposed to be doing policing. But whether I like it doesn't affect things. I agree that it is important for us, as a free society, to fix policing. In the meantime, the best way to minimize injustice is…

This is exactly why I don't think self policing is suitable. If someone broke the law and endangered other people, you or I as possible community members should not be able to decide no police action is involved when others are the people that were actually endangered. Do the people on the road during this situation not have a voice? We are not incentivized correctly to handle this situation suitably.

The police and judicial system sometimes have conflicting incentives as well, but at least they are aligned more with the public good than ours are. There are laws and they are, for the most part, rewarded for enforcing them.

Re: Hackers Remotely Attack a Jeep on the Highway

#400

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I would like to give some other perspective. FCA (parent co. of Jeep) have been slow about a number of safety recalls and are under increased scrutiny by NHTSA:

http://www.detroitnews.com/story/business/autos/chrysler/201...

Here is a choice quote about the culture relating to safety at Fiat - Sergio Marchionne is CEO: >> Marchionne said in January that the auto industry may have “overreacted” to some safety issues, especially the massive air bag recalls, which may have been “overkill,” he said. So yes the demonstration described in this article was somewhat reckless, but the facts that FCA has not notified owners beyond a posting online about a firmware update (who checks that?), tacitly condemns security researchers' decision to publish some details in their communications with Wired, all the while stonewalling recalls - for example in Jeep vehicles where they catch fire in rear end collisions, killing occupants - that upsets me much more.

In my opinion, when a company is notified of a safety or security issue, they should do all that can be done as quickly as possible, here instead FCA has once again done the minimum plus has the gall to respond in writing, "We appreciate the contributions of cybersecurity advocates to augment the industry’s understanding of potential vulnerabilities. However, we caution advocates that in the pursuit of improved public safety they not, in fact, compromise public safety." I guess I embrace hacker spirit more than anything else I considered here is what it boils down to.

So I would have written to the NHTSA trying to make this yet another recall if I thought it would have done any good, but in that culture of 21%-compliance-is-acceptable, I don't think it would do a lick of good, so I won't bother.

Also, I accidentally clicked on "flag" above when I wanted to click on "parent." I am sorry, that was not my intention, I just wanted to refer back to the Wired article as I was responding, and they are small and right next to each other. Ah, I notice when I refresh there is an unflag option, I have just taken that action, again sorry.

Post reply on HN