Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

431–440 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#431

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I can't believe that you snitched on these guys and you're proud to share it with us! WoW!

The guy consented to their experiment and he voluntarily engaged with them. It is not like they set him up for this.

Maybe you could argue that they could have jeopardized the lives of people on the highway with their reckless behavior esp the engine shutdown stunt and I believe that they didn't exercise wise judgement in doing so but didn't they instruct the driver to switch off and back on to regain control of his vehicle and move ahead?

You also claimed that they're boasting of their act by publishing this video when it was Wired that produced and made the whole report and experiment and not them. The reporter himself the subject of this experiment didn't file any report with the authorities so you come and act more royal than the king!

What a mess!

What was that snitching for? This is completely uncalled for.

This is a knee jerk reaction from you and testament of your true character.

You should be ashamed of yourself snitching on your colleagues like this and your phony outrage at this act is not fooling anyone.

Grow up you are not in elementary school anymore!

Re: Hackers Remotely Attack a Jeep on the Highway

#432
post #367

Earlier quoted context omitted.

I was thinking about how dangerous it was while I was reading it too, but I came away far less concerned than you I guess. The deceleration on the highway was the most worrisome, but it's not even in the ballpark of common driving hazards like distracted folks on cellphones or flying debris. A crash from such a thing is unlikely and the inconvenience is pretty minimal. Even you, the busybody who called the cops becau…

When it comes to ethics and moral responsibility, intent and agency are everything! For ethical purposes, it is similar to injecting a person with a flu virus to test if their acaiberry diet has improved their immunity. Yes, they could, even without your intervention, have caught flu and also spread it to others, but as an agent, you have increased that probability of flu occurring and spreading in the community to c…

Wow, they were really lucky an accident didn't occur since there was a "close to 100%" chance of an accident occurring!

Re: Hackers Remotely Attack a Jeep on the Highway

#433
post #265

Earlier quoted context omitted.

> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…

Grass shoulder: http://www.wired.com/wp-content/uploads/2015/07/IMG_0724-102... I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (…

FYI, here's a link to a video[1] of the situation (which bengali3 posted up-thread). The grass shoulder was later, cutting the power was actually done on a fairly busy stretch of highway with no shoulder. The reporter's words during that incident are particularly telling.

1: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...

Re: Hackers Remotely Attack a Jeep on the Highway

#434

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

I don't know where the threshold is, but calling yourself a "security researcher" is not a blank slate to do whatever you want. I think it's 100% OK to test on a private car on a private track.

They did test in controlled environments previously, according to the article. Said tests were ignored by the auto manufacturers.

Re: Hackers Remotely Attack a Jeep on the Highway

#435

Earlier quoted context omitted.

So demo it at a race track. The essential point here is that the uninvolved public were placed at real risk of maiming or death. Your argument is ludicrous, because you're attempting to cast the actors as either good or bad. IMHO they are guys with a good idea and motivation who did a bad thing.

We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. edit : as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers.…

>We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car.

If optics is your justification for this, then perhaps having these two irresponsible researchers arrested would bring even more attention to this.

>edit: as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.".

Where do you see that in the article? Only thing I read was manufacturers downplaying a wired-in attack they demoed.

Re: Hackers Remotely Attack a Jeep on the Highway

#436

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

The fact that a dashboard system that controls your radio or AC has access to cut your transmission is also a hardware configuration issue. Accessories should be physically secured from ignition and drive train. The internet connected features of the car, in turn, should be severed from both of these. It should not be physically possible to turn on the wipers from the embedded processor that receives packets on the I…

Read up on CAN-BUS. The entire industry is moving to one-wire protocols to reduce the labrynthine copper network that prevailed in the past. If you can put your transmissions diagnostic information on the radio's nice big LCD, why wouldn't you?

Some would say "this, this is why", but those people are not responsible for selling and maintaining millions of vehicles.

Re: Hackers Remotely Attack a Jeep on the Highway

#437

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Wow, I'm shocked at how contentious this comment is. Count me in the "thanks for being a responsible citizen" column. I feel like there's a lot of cargo cult thinking going on here. The situation is _almost_, but not quite, like a lot of other ones where the security researcher is unreasonably blamed. For example, I could easily see some people being up in arms about announcing this exploit at Black Hat. But that's n…

> t could have just as easily been demoed in a private lot or something.

It was previously demoed in parking lots and other controlled environments by these researchers, according to the article. Said demonstrations were ignored by the auto manufacturers, with some manufacturers - like Toyota - trying to claim that their systems were still "secure".

The public and the manufacturers need a proper wakeup call. My fear is that even a "reckless" test like this one isn't enough of a wakeup call.

Re: Hackers Remotely Attack a Jeep on the Highway

#438

Earlier quoted context omitted.

I support your decision. Disabling a vehicle in uncontrolled conditions on a freeway is reckless, plain and simple.

The auto makers were even more reckless in their ignorance of the earlier controlled tests that these researchers performed and presented to said makers. Yet somehow the researchers are the bad guys. #JustHackerNewsThings

It's not about the fact that the Jeep was hackable it's about the fact that the demonstration was done on a crowded highway with civilians around.

Re: Hackers Remotely Attack a Jeep on the Highway

#440

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Sure it was not a smart move but you're really overreacting.
Post reply on HN