Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

461–470 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#461

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

> Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow.

So, you don't care about the fact that this experiment on public roads could have killed people? Just because it's for security research it's ok to recklessly endanger lives? What Wow's me is your cavalier attitude, I'm glad he informed the police and I hope they face repercussions. What they did needlessly endangered people's lives and public safety to add a sensational bit to a story, I find that way more "aggressive" than informing the proper authorities of those actions.

Re: Hackers Remotely Attack a Jeep on the Highway

#462
post #269
post #154

Earlier quoted context omitted.

Calling the police was completely inappropriate, but downvoting the comment as a way to signal your disapproval with his action in the real world isn't helpful. The comment itself is well written, on topic, and leading to good discussion. I agree with what others have already said: Since nobody was actually hurt he should have contacted the researchers to make his point.

Right, yesterday my neighbor shot a gun at me several times but since he missed and no one was hurt, it would have been utterly inappropriate for me to contact the authorities.

Being shot at (intentionally or otherwise) is entirely different than a car in front of you slowing to a stop.

Re: Hackers Remotely Attack a Jeep on the Highway

#463

Earlier quoted context omitted.

Wow, I'm shocked at how contentious this comment is. Count me in the "thanks for being a responsible citizen" column. I feel like there's a lot of cargo cult thinking going on here. The situation is _almost_, but not quite, like a lot of other ones where the security researcher is unreasonably blamed. For example, I could easily see some people being up in arms about announcing this exploit at Black Hat. But that's n…

> t could have just as easily been demoed in a private lot or something. It was previously demoed in parking lots and other controlled environments by these researchers, according to the article. Said demonstrations were ignored by the auto manufacturers, with some manufacturers - like Toyota - trying to claim that their systems were still "secure". The public and the manufacturers need a proper wakeup call. My fear…

Life is hard. Sometimes people don't pay attention. Pulling irresponsible stunts isn't an appropriate response "to make people pay the proper amount of attention."

If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1.

NB: I highly favor a bounty system where someone who can demonstrate the ability to take over a car without touching it gets paid lots of money, and if the company fails to fix it they get fined even more money. But "someone else is doing something bad, too" is never a good justification.

Re: Hackers Remotely Attack a Jeep on the Highway

#464

Earlier quoted context omitted.

The two options here are not "test on highway with other drivers" and "let flaw exist with no testing and no exposure". There are many ways to responsibly test this while not endangering others on a public road. For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The Mythbusters test stuff like this all the time. What do they do? Use an abandoned airforce bas…

> For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The researchers did many of these things, according to the article. They were ignored by auto makers.

If you increase the danger of a situation to increase it's exposure, you can't be surprised when that causes repercussions. I doubt they will go to jail, but I do think alerting the authorities was the right call.

In fact, they may have been counting on that. If they really want to increase the exposure of a story, start a public debate. The easiest way to do that? Get some public outrage going. They called this all out, they'll need to deal with the consequences.

Re: Hackers Remotely Attack a Jeep on the Highway

#465

All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except…

Seriously, though. The trend that annoys me the most is touchscreens in cars. A touchscreen is the last thing I want on a car. I want physical buttons that I can find and operate by touch alone without having to take my eyes off the road. Maybe voice control if it can be made sufficiently reliable, but that's about it.

It's like car manufacturers nowadays want people to crash their cars so that they can sell more of them.

Re: Hackers Remotely Attack a Jeep on the Highway

#466

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

>unlike the typical TPMs that only allow vendor software to be authenticated, these TPMs would allow the user to directly authenticate the firmware. If you know the firmware is good, then each layer can validate the next layer up all the way to the OS.

nothing novel there in terms of having to have some "new" TPM. Just OEMs choose to lock down their boot chain. Probably most secure boots are minimally implemented to only support the use case of secure/trusted boot (device/chip/OEM key) xor untrusted boot (no key).

If both are supported, whatever functionality that relies on OEM firmware or chain of trust would be disabled if it is an untrusted boot (like fastboot oem unlock for some android devices) situation.

May be tricky to enable certain desirable/required features if user wants to run their own firmware.

>I have yet to hear of a system that allows the user to directly authenticate software/firmware at the hardware level. Is anybody working on research of this nature? Or are there insurmountable problems with this approach?

I think chromebooks/chromeOS folks have been looking at this. Not sure of the current state of things.

p.s. TPMs kind of suck if they are not able to be updated OTA.

Re: Hackers Remotely Attack a Jeep on the Highway

#467

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

> but I really can't stop thinking about my wife and kids What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner? Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.

> What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner?

Because, he said anything like that right? What a gratuitous use of a strawman.

It's not appealing to emotions, it's pretty rational to think this experiment could have easily caused an accident and hurt people. We all rationally know that driving is one of the most dangerous forms of travel. Seriously, a car is a dangerous, fast, multi-ton piece of metal, it's not a toy to experiment on when other people's safety is at stake. Respect the vehicle and the damage it could cause.

The exploits can and will be published and reported on quite easily without these reckless theatrics.

Re: Hackers Remotely Attack a Jeep on the Highway

#468
post #290

Earlier quoted context omitted.

As much as it seem over the top, those researcher could have hurt people. Calling the police will not have them go to jail or have their data deleted. It might (rightfully) get them a fine. It will however ensure that their next experiments are done in a safer, more legal way. Calling the police isn't all about emergency. You can call them to talk about issues that worry you such as this one. They will take care of b…

> Calling the police will not have them go to jail or have their data deleted. Do we read the same Internet news? Having seen the way the law enforcement + prosecution machine works in cases like Aaron Schwartz, I would be surprised if these researchers did not spend time in jail, and didn't at least face charges of some Serious Nature. If there's a case to be made, the police will build it. If they build it, the DA…

> Having seen the way the law enforcement + prosecution machine works in cases like Aaron Schwartz, I would be surprised if these researchers did not spend time in jail, and didn't at least face charges of some Serious Nature.

Having considered how dangerous their little stunt was, I'd almost expect them to be sentenced to some gaol time. What they did was pretty darn Serious!

Re: Hackers Remotely Attack a Jeep on the Highway

#469

Earlier quoted context omitted.

> For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The researchers did many of these things, according to the article. They were ignored by auto makers.

If you increase the danger of a situation to increase it's exposure, you can't be surprised when that causes repercussions. I doubt they will go to jail, but I do think alerting the authorities was the right call. In fact, they may have been counting on that. If they really want to increase the exposure of a story, start a public debate. The easiest way to do that? Get some public outrage going. They called this all…

I don't disagree with you on that. The researchers (and WiReD) should certainly be aware of the risks here, and be prepared to accept the repercussions thereof.

On the other hand, while two wrongs don't make a right, I'm glad that the researchers made that choice, so long as said choice results in manufacturers actually taking car security seriously for once.

Re: Hackers Remotely Attack a Jeep on the Highway

#470

Earlier quoted context omitted.

I appreciate your call to the cops and your reasoning. I also have driven a significant number of miles for work and have seen a number of people killed in traffic accidents. This "test" was extremely irresponsible. I know I will be downvoted for saying this, but I think you made the correct decision.

They've risked people's lives to produce real life looking footage documenting a life threatening event. Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how h…

> Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet.

Oh really, can you point to the responsible tests that were done in the past that proved inconsequential necessitating this reckless alternative? Or are you just inventing that the car manufacturers would ignore this and somehow the story would just go away?

Post reply on HN