Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

451–460 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#451

Earlier quoted context omitted.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

> This is especially the case when a safer alternative to demonstrate this exploit easily exists. If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.

And yet somehow the sins of the auto manufacturers in no way excuses the reckless behavior demonstrated in this video. It is possible that more than 1 person/entity in this story is in the wrong. Its clear you've already made up your mind and have posted more than a dozen comments here defending the researchers, so I'm not sure what more can be said. The ends simply do not justify the means.

Re: Hackers Remotely Attack a Jeep on the Highway

#452

Earlier quoted context omitted.

It's not either/or. You're presenting a false dilemma. You can demonstrate the problem without doing it where you put real lives in danger. The researchers acted recklessly.

> You can demonstrate the problem without doing it where you put real lives in danger. Indeed. And according to the article, they already did. The manufacturers ignored them.

Well, no, the manufacturers didn't ignore them. They responded with a patch, but the researchers didn't like their response.

Still doesn't matter though. There are a million shades between quiet disclosure and outright stupidity that would still make headlines.

1) They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so.

2) They could have ensured constant two-way communication.

3) They could have done it when nobody was on the road.

Re: Hackers Remotely Attack a Jeep on the Highway

#453
post #420

Earlier quoted context omitted.

Those particular means are unjustified. What actually happened wasn't nearly as extreme as you're indicating, and given the previous behavior of auto manufacturers to security hole demonstrations in their cars, this sort of demonstration was viewed by the researchers as the next logical step. I don't entirely agree with the methodology, but nobody was hurt, unlike what would would likely be the case should even less…

Nobody was hurt because they rolled the dice and got lucky. There was a non-zero probability of injury or death that was completely unjustified.

It was a gradual slowdown. That "non-zero" has enough zeroes after the decimal point for Japan to send the number to Hawaii and have another go at Pearl Harbor.

Worst-case scenario, somebody might've been rear-ended. Maybe a bit of whiplash. That's not great, either, but seeing as more-controlled tests by these researchers were outright ignored by auto manufacturers, your priorities have to be incredibly out of whack to villify the researchers over the auto manufacturers - who are willfully endangering hundreds of thousands, if not millions, of Americans every day - in this scenario.

Re: Hackers Remotely Attack a Jeep on the Highway

#454
post #265

Earlier quoted context omitted.

Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. IMO, the danger to the public caused by the researchers somewhat-controlled exploit is utterly dwarfed by the danger Jeep/uConnect is causing by directly connecting its cars to the internet. If the researchers are successful in getting car manufacturers to remove…

> Slowing down and eventually driving off on to a grass shoulder wouldn't even crack the bottom 1% of crazy shit I've seen people do on highways, on purpose. The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something…

>'Slowing down on the freeway'...

With or without shoulder, a stalled automobile is an everyday occurrence that drivers must absolutely watch and be prepared for. It wasn't the safest thing to do, but it isn't outside the normal range of "dangerous" events that one will experience on their commute daily, often more than once daily. IMO it doesn't increase the danger nearly as much as traffic patrol conducting a routine traffic stop on the freeway. If we're prepared to accept traffic patrol on busy freeways, then I don't think it's justified to treat a rare, even if foolish demonstration such as this one as anything more than a nuisance.

Re: Hackers Remotely Attack a Jeep on the Highway

#455
post #79
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

HN is chock full of self-righteous hall monitors. They usually don't progress to the point of calling the cops.

It's definitely elementary school stuff to snitch and play the informant on your colleagues. The worst thing that this was coming from an old fart stuckup who thinks that they could police every thing and everyone around them and act more royal than the king himself.

Old habits die hard.

Re: Hackers Remotely Attack a Jeep on the Highway

#456

Earlier quoted context omitted.

Feynman had a nice story where he figured out a way to crack many of the safes in Los Alamos, then dutifully reported his method to some bigshot general. The general said "hmm interesting, thank you very much", and banned Feynman from entering rooms with safes or something. The safes stayed as unsafe as ever. You remind me of that general. You should be hanging out on Catch The Hacker News, not Hacker News.

Testing on uninformed humans is unethical. Wasn't hackernews just all up in arms about the US military spreading germs to test bioweapons? Isn't this the same exactly thing?

There's a pretty significant difference in scale between two nerds putting maybe 2 or 3 vehicles in danger of a dented bumper v. the world's largest military conducting live-fire bioweapon testing.

Re: Hackers Remotely Attack a Jeep on the Highway

#457

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Tell your wife not to tailgate and get off her facebook while driving, and all will be well.

Stop acting like it takes negligence on the part of the other drivers to make this a dangerous situation.

Re: Hackers Remotely Attack a Jeep on the Highway

#458

Earlier quoted context omitted.

> Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease. If these guys want to be regarded as researchers, they need to act like them and be accountable like them. No ethics committee would ever approve a test like this.

The IRB as it currently stands it too strict with its regulations. Also, why should the researchers be regulated when the ones producing the things that are initially putting people into danger are not regulated (or are regulated by bureaucrats who couldn't tell you the difference between a buffer overflow and a SQL injection).

> The IRB as it currently stands it too strict with its regulations.

WTF are you talking about? There is no the IRB.

Re: Hackers Remotely Attack a Jeep on the Highway

#459

Earlier quoted context omitted.

> but I really can't stop thinking about my wife and kids What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner? Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.

The two options here are not "test on highway with other drivers" and "let flaw exist with no testing and no exposure". There are many ways to responsibly test this while not endangering others on a public road. For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The Mythbusters test stuff like this all the time. What do they do? Use an abandoned airforce bas…

> For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc.

The researchers did many of these things, according to the article. They were ignored by auto makers.

Re: Hackers Remotely Attack a Jeep on the Highway

#460
post #220

Earlier quoted context omitted.

Now imagine the exploit being used by a blackhat. The hackers aren't the problem here. The fact that somebody can even control cars over the Internet at all is.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

> This is especially the case when a safer alternative to demonstrate this exploit easily exists.

And when said safer demonstrations are ignored by manufacturers, as was the case here?

Post reply on HN