Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

411–420 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#411
post #220

Earlier quoted context omitted.

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

> This is especially the case when a safer alternative to demonstrate this exploit easily exists.

If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.

Re: Hackers Remotely Attack a Jeep on the Highway

#412
post #220

Earlier quoted context omitted.

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

It's not either/or. You're presenting a false dilemma. You can demonstrate the problem without doing it where you put real lives in danger. The researchers acted recklessly.

> You can demonstrate the problem without doing it where you put real lives in danger.

Indeed. And according to the article, they already did. The manufacturers ignored them.

Re: Hackers Remotely Attack a Jeep on the Highway

#413

Earlier quoted context omitted.

Blocking the visibility through the windscreen, then shutting off the transmission of a car, that is driving on an interstate overpass in traffic, is not white hat by any stretch of the imagination.

Perhaps not, but it's necessary to get the attention of auto makers so that they stop building such trivially-compromisable systems. This was a couple of security researchers on one car for a proof-of-concept; better to demonstrate these flaws early and with a more limited sample than to watch the pileup of epic proportions that would happen should someone even less scrupulous acquire such control over vehicles on th…

Had that Jeep run into you or you ran into it as a result of this experiment, you may have found that you have a profoundly different threshold for what is, "necessary to get the attention of auto makers".

Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. And let's face it – a multi-ton vehicle that is not entirely in its driver's control puts lives at risk in just about any situation. The reason you and others argue that the demo's methodology is effective is precisely because of the risks involved; not in spite of them.

It is the responsibility of researchers to demonstrate risks without exercising the extent of those risks. Imagine if virologists regularly demonstrated communicability risk by injecting humans with disease outside of the lab.

Re: Hackers Remotely Attack a Jeep on the Highway

#414
post #201

Should hackers actually kill somebody, I struggle to find a reason why the relevant automotive engineers and their managers shouldn't be charged and convicted of negligent homicide, or worse. After all, somebody had to make the decision to connect a radio receiver to the CAN bus. Others are aware of the wireless and choose not to remove it. To be a professional is to have a duty to refuse to do stupid stuff like this…

Criminal negligence is a high bar. We don't want to send people to jail for mistakes, accidents and miscalculations.

Civil liability is a lower bar. Regular negligence is essentially not using reasonable care. Whether air-gaping a cars computer is reasonable car would be up for debate. But I think you'd have a good case.

Product liability is similar to negligence. It holds the builder, designers, sellers, etc. liable for design defects. But I'm not familiar with caselaw about how hacking vulnerabilities intersect with design flaws.

>If history has shown us anything, it's that we cannot rely on software to separate two systems sharing a network. Only physics can do that.

Yet, a shocking number of critical systems are exposed to the internet.

Re: Hackers Remotely Attack a Jeep on the Highway

#415

Earlier quoted context omitted.

They've risked people's lives to produce real life looking footage documenting a life threatening event. Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how h…

So demo it at a race track. The essential point here is that the uninvolved public were placed at real risk of maiming or death. Your argument is ludicrous, because you're attempting to cast the actors as either good or bad. IMHO they are guys with a good idea and motivation who did a bad thing.

We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car.

edit: as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.".

Re: Hackers Remotely Attack a Jeep on the Highway

#416

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

You did the right thing. This was completely irresponsible. I'm shocked that Wired, the author, or either of the researchers have yet posted a "we screwed up, sorry" statement. It's a shame because this is an incredible story and the work they did was great, but what a completely reckless stunt they pulled. Totally unnecessary too, the story would have been just as effective if the demo happened on a test track or em…

No he did not do the wrong thing. Reporting them is completely wrong. When we report the people who protect us, well this sounds like a plot to a movie. PS: in movies usually a lot of people suffer before the resolution

Re: Hackers Remotely Attack a Jeep on the Highway

#417

Earlier quoted context omitted.

Blocking the visibility through the windscreen, then shutting off the transmission of a car, that is driving on an interstate overpass in traffic, is not white hat by any stretch of the imagination.

Perhaps not, but it's necessary to get the attention of auto makers so that they stop building such trivially-compromisable systems. This was a couple of security researchers on one car for a proof-of-concept; better to demonstrate these flaws early and with a more limited sample than to watch the pileup of epic proportions that would happen should someone even less scrupulous acquire such control over vehicles on th…

> it's necessary to get the attention of auto makers

That's mere conjecture. And it's an assertion you could easily test by first doing the remote hack in a controlled environment (e.g. a racetrack) and seeing if automakers respond before trying this on an actual freeway!

Re: Hackers Remotely Attack a Jeep on the Highway

#418
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

As much as it seem over the top, those researcher could have hurt people. Calling the police will not have them go to jail or have their data deleted. It might (rightfully) get them a fine. It will however ensure that their next experiments are done in a safer, more legal way. Calling the police isn't all about emergency. You can call them to talk about issues that worry you such as this one. They will take care of b…

Hah.

If prior HN articles are anything to go by, it's a matter of time before SWAT kicks down their doors, beats them up a bit, and maybe even a few officers "fearing for their own lives" (yeah right) take a couple of shots in "self defense" against unarmed nerds.

You're delusional if you trust in a law enforcement agency to take reasoned and measured action in any situation.

Re: Hackers Remotely Attack a Jeep on the Highway

#419
post #318

Earlier quoted context omitted.

There is no way a "not real-world conditions" argument could be made if this same test was done on a test track. No automaker would even try it because it would generate even more bad press. The "researchers" did the test on a public, in-use highway for better press/cool factor. Completely irresponsible.

Look at what Toyota did with the whole unintentional acceleration thing. About as irresponsible as you can get.

The ones that turned out to be mostly old people hitting the gas instead of the accelerator?

Re: Hackers Remotely Attack a Jeep on the Highway

#420
post #204

Earlier quoted context omitted.

Murdering a family of 4 using the hack would garner even more attention. The ends don't justify the means.

Those particular means are unjustified. What actually happened wasn't nearly as extreme as you're indicating, and given the previous behavior of auto manufacturers to security hole demonstrations in their cars, this sort of demonstration was viewed by the researchers as the next logical step. I don't entirely agree with the methodology, but nobody was hurt, unlike what would would likely be the case should even less…

Nobody was hurt because they rolled the dice and got lucky. There was a non-zero probability of injury or death that was completely unjustified.
Post reply on HN