Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

441–450 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#441
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

"Hacking" is not what's portrayed in movies. The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. Heck, if the writer had contacted the cops, they could have given him an escort to make sure nothing bad happens. If you ask me, it is this kind of behavior that makes the work of real researchers harder , as the med…

> The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road.

According to the article, the researchers already did as early as 2013. Auto manufacturers ignored the reports while continuing to pretend that their vehicles are secure.

Re: Hackers Remotely Attack a Jeep on the Highway

#442

Earlier quoted context omitted.

Had that Jeep run into you or you ran into it as a result of this experiment, you may have found that you have a profoundly different threshold for what is, "necessary to get the attention of auto makers". Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. And let's face it – a multi-ton vehicle that is not entirely in its driver's control…

> Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. So condemn the auto manufacturers for putting hundreds of thousands - if not millions - of lives at risk instead of yammering about a couple of nerds who put at most 2 vehicles in probably-nonfatal danger in a worst -case scenario.

Why can't we condemn both?

And as busy as that highway was in the video, it was far more than just 2 vehicles, especially if one of those vehicles was the 18 wheeler.

At the very least they could have done this on a less busy stretch of highway that had a wide shoulder and with control vehicles in front and behind with paramedics at the ready (just like a movie production that is shooting on public streets). Instead the researchers and the journalist chose to be reckless.

Re: Hackers Remotely Attack a Jeep on the Highway

#443

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You're garbage.

Re: Hackers Remotely Attack a Jeep on the Highway

#444

Earlier quoted context omitted.

I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.

They've risked people's lives to produce real life looking footage documenting a life threatening event. Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how h…

"I have to act bad because of the nature of my enemies." > And just think how hard was this decision

Given that they did the easy thing, it wasn't very hard at all.

Re: Hackers Remotely Attack a Jeep on the Highway

#445
post #318

Earlier quoted context omitted.

Look at what Toyota did with the whole unintentional acceleration thing. About as irresponsible as you can get.

The ones that turned out to be mostly old people hitting the gas instead of the accelerator?

Yeah, no. Check this out: http://www.edn.com/design/automotive/4423428/Toyota-s-killer...

Re: Hackers Remotely Attack a Jeep on the Highway

#446

Earlier quoted context omitted.

> it's necessary to get the attention of auto makers That's mere conjecture. And it's an assertion you could easily test by first doing the remote hack in a controlled environment (e.g. a racetrack) and seeing if automakers respond before trying this on an actual freeway!

If you read the article, you'd know full well that the researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.

I've read the article. Where does it mention controlled environments? The only mention of exploits being dismissed by manufacturers was in regard to a wired exploit, not a remote one.

Re: Hackers Remotely Attack a Jeep on the Highway

#447
post #407

Earlier quoted context omitted.

It'll also be the checklist for even more of the traffic that drives on US interstate highways once self-driving cars become all the rage.

A self-driving car is still being driven, by a computer that has control, situational awareness, and the ability to recognize and avoid dangerous situations. This demonstration was specifically about removing those three factors.

So what happens when (not if, but when) said computer encounters a fatal error? What happens when future security researchers like the ones in this article manage to break into said computers and manipulate them?

If we're going to condemn researchers for potential danger, then we might as well extend the same courtesy to car-driving AI and the makers thereof.

Re: Hackers Remotely Attack a Jeep on the Highway

#448

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

"Before working with computers I drove tractor-trailers for a while and was lucky to achieve a million-mile safe driving award. I have a pretty good idea of the dangers here and I know that stretch of road well, I've crossed it many times."

Game, set, match.

Re: Hackers Remotely Attack a Jeep on the Highway

#449

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Well done. I agree.. there is no way they should have jeopardize safety of people who were on the road.

They could have easily demo'ed it in million other ways.

Kudos for the hack but shame for the demo.

Re: Hackers Remotely Attack a Jeep on the Highway

#450

Earlier quoted context omitted.

You did the right thing. This was completely irresponsible. I'm shocked that Wired, the author, or either of the researchers have yet posted a "we screwed up, sorry" statement. It's a shame because this is an incredible story and the work they did was great, but what a completely reckless stunt they pulled. Totally unnecessary too, the story would have been just as effective if the demo happened on a test track or em…

No he did not do the wrong thing. Reporting them is completely wrong. When we report the people who protect us, well this sounds like a plot to a movie. PS: in movies usually a lot of people suffer before the resolution

Who protects me from the people who think they are doing the right thing by endangering me?
Post reply on HN