Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

421–430 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#421

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Yep, totally agree with you. Good job for phoning the police. People need to know that's not ok!

Re: Hackers Remotely Attack a Jeep on the Highway

#422

Earlier quoted context omitted.

Perhaps not, but it's necessary to get the attention of auto makers so that they stop building such trivially-compromisable systems. This was a couple of security researchers on one car for a proof-of-concept; better to demonstrate these flaws early and with a more limited sample than to watch the pileup of epic proportions that would happen should someone even less scrupulous acquire such control over vehicles on th…

> it's necessary to get the attention of auto makers That's mere conjecture. And it's an assertion you could easily test by first doing the remote hack in a controlled environment (e.g. a racetrack) and seeing if automakers respond before trying this on an actual freeway!

If you read the article, you'd know full well that the researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.

Re: Hackers Remotely Attack a Jeep on the Highway

#423

Earlier quoted context omitted.

I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.

Agreed. I missed the video the first time and didn't believe the text that described the shutdown, video shows the stupidity here, let alone release a recording of it. I expect that will come down soon. Important research but very poorly tested. Wired and Chrysler (research was funded by Chrysler?) legal teams would not like the contents of this video. edit: wired's link to video, jump to 2:00: http://dp8hsntg6do36.c…

Reporter: "Seriously, this is fucking dangerous. I need to move."

And that was while the security researchers caused the radio to blare so loud that he couldn't hear them on the other end of the phone. The more I see, the more I think they were really negligent in how they planned this out, and I was already firmly in that camp.

Re: Hackers Remotely Attack a Jeep on the Highway

#424

Earlier quoted context omitted.

Perhaps not, but it's necessary to get the attention of auto makers so that they stop building such trivially-compromisable systems. This was a couple of security researchers on one car for a proof-of-concept; better to demonstrate these flaws early and with a more limited sample than to watch the pileup of epic proportions that would happen should someone even less scrupulous acquire such control over vehicles on th…

Had that Jeep run into you or you ran into it as a result of this experiment, you may have found that you have a profoundly different threshold for what is, "necessary to get the attention of auto makers". Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. And let's face it – a multi-ton vehicle that is not entirely in its driver's control…

> Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk.

So condemn the auto manufacturers for putting hundreds of thousands - if not millions - of lives at risk instead of yammering about a couple of nerds who put at most 2 vehicles in probably-nonfatal danger in a worst-case scenario.

Re: Hackers Remotely Attack a Jeep on the Highway

#425
post #405
post #400

Earlier quoted context omitted.

I would like to give some other perspective. FCA (parent co. of Jeep) have been slow about a number of safety recalls and are under increased scrutiny by NHTSA: http://www.detroitnews.com/story/business/autos/chrysler/201... Here is a choice quote about the culture relating to safety at Fiat - Sergio Marchionne is CEO: >> Marchionne said in January that the auto industry may have “overreacted” to some safety issues,…

>Also, I accidentally clicked on "flag" above when I wanted to click on "parent." I am sorry, that was not my intention, I just wanted to refer back to the Wired article as I was responding, and they are small and right next to each other. There should be an "unflag" where "flag" used to be.

Thank you, I noticed when I refreshed and clicked unflag.

Re: Hackers Remotely Attack a Jeep on the Highway

#426

Earlier quoted context omitted.

They've risked people's lives to produce real life looking footage documenting a life threatening event. Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how h…

That's borderline like saying using crash test dummies is useless because it's not realistic enough for car manufacturers to take it seriously

The actions - according to the article - of auto manufacturers in response to prior more-controlled tests is exactly equivalent to that. The manufacturers basically said "hey, thanks for showing us this crash-test footage that shows our vehicles are literal fucking coffins on wheels; we don't really care", leaving the researchers with no results after taking more "sane" measures.

Researchers perform controlled experiments. Controlled experiments are ignored. Researchers opt for more damning (though less controlled) experiments to further prove their point, and now they're suddenly the bad guys here.

Re: Hackers Remotely Attack a Jeep on the Highway

#427

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

There's calling the police, and then there's publishing their phone number in the hopes of directing an angry mob. Angry mobs are dangerous and volatile and can push prosecutors to overreact. And prosecutors and politicians love to overreact when it comes to hacking.

He published the number of the local law enforcement agency. That is not directing an angry mob, that's helping people voice their opinion to the people responsible for enforcing laws.

Re: Hackers Remotely Attack a Jeep on the Highway

#428

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I support your decision. Disabling a vehicle in uncontrolled conditions on a freeway is reckless, plain and simple.

The auto makers were even more reckless in their ignorance of the earlier controlled tests that these researchers performed and presented to said makers. Yet somehow the researchers are the bad guys.

#JustHackerNewsThings

Re: Hackers Remotely Attack a Jeep on the Highway

#429
post #333

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

>I exercised my judgement and decided to phone the local Highway Patrol office. That was rash. You called the police within an hour of reading this article? You didn't think it's possible the writer is embellishing or exaggerating the danger he was in here? As of right now, everything they've done has been done in good faith to try to point out the need for extra security. Also, if they get arrested, even convicted o…

I suggest you view the video[1] that bengali3 linked.

1: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...

Re: Hackers Remotely Attack a Jeep on the Highway

#430
The two researchers say that even if their code makes it easier for malicious hackers to attack unpatched Jeeps, the release is nonetheless warranted because it allows their work to be proven through peer review.

Huh? If they have a video of their turning a care off remotely, do they really need peer review of the details?

Post reply on HN