Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

471–480 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#471
post #195

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

The security industry has unanimous voiced their concern that remote controllable cars and kill switches is one of the worst ideas possible, and will be exploited and cost human lives. Nothing has yet to happen from that. So what should researchers do? Do nothing and keep their hand clean while waiting for the train wreck to happen? Continue in a fruitless effort to warn people on papers only other researchers reads,…

> So what should researchers do? Do nothing

There is a big world between "do nothing" and "put third-parties at risk by stalling a car on a three-lane highway with concrete barriers."

Doing the right thing is often boring and takes lots of work. That's why it's called "doing the right thing" and not "doing the splashy thing" or "doing the easy thing."

They already had the attention of the media. Keep on working with the media to get more and more attention. Is it hard? Then do it some more.

Re: Hackers Remotely Attack a Jeep on the Highway

#472

Earlier quoted context omitted.

You did the right thing. This was completely irresponsible. I'm shocked that Wired, the author, or either of the researchers have yet posted a "we screwed up, sorry" statement. It's a shame because this is an incredible story and the work they did was great, but what a completely reckless stunt they pulled. Totally unnecessary too, the story would have been just as effective if the demo happened on a test track or em…

No he did not do the wrong thing. Reporting them is completely wrong. When we report the people who protect us, well this sounds like a plot to a movie. PS: in movies usually a lot of people suffer before the resolution

You are missing the point by a mile.

These people did the exact opposite. They put others in potentially mortal danger.

They could have killed someone's daughter, son, mom or dad.

Stop and think about that for 10 minutes before you continue posting with this unreasonable point of view. Would your mom, dad or siblings life be worth this test? Imagine they collided with this car and died. Close your eyes and imagine that for a moment. Imagine receiving that call. Going to the hospital. Seeing the, all torn-up and suffering befor they die due to the injuries.

And then you find out it was due to two fuckers who thought it'd be funny/interesting/whatever to disable a car remotely.

Imagine that.

Re: Hackers Remotely Attack a Jeep on the Highway

#473

Earlier quoted context omitted.

> t could have just as easily been demoed in a private lot or something. It was previously demoed in parking lots and other controlled environments by these researchers, according to the article. Said demonstrations were ignored by the auto manufacturers, with some manufacturers - like Toyota - trying to claim that their systems were still "secure". The public and the manufacturers need a proper wakeup call. My fear…

Life is hard. Sometimes people don't pay attention. Pulling irresponsible stunts isn't an appropriate response "to make people pay the proper amount of attention." If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1. NB: I highly favor a bounty system where someone who can demonstrate the ability to take over a car without touching it gets paid lots of money, and if…

> If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1.

If this stunt had never happened, we'd be in a position where some less-scrupulous actor would demonstrate such exploits on a much bigger scale. I can guarantee you that the total number of deaths from remote hacking of cars would be far greater than 1.

If we're going to play the "OH NO THINK OF THE CHILDREN^H^H^H^H^H^H^H^HHYPOTHETICAL DEATHS" game, then let's put this into some goddamn perspective, eh? 1 v. hundreds of thousands (if not millions) that are currently vulnerable to remote hacking right this very instant.

In all actuality, of course, that "1" death was highly unlikely; at most, we'd probably see a few dented bumbers and a couple grand in car repairs. Maybe somebody with whiplash.

Re: Hackers Remotely Attack a Jeep on the Highway

#474

Earlier quoted context omitted.

Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. A much less aggressive (and thoughtful) move would be to contact the researchers directly. Wow. Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the d…

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

I can't say that I completely disagree with you but I do lack your faith in the authorities' ability to respond appropriately. I wouldn't mind if Beavis and Butthead recalibrated their ideas about how to conduct a demonstration. I also hope that they've edited the video for maximum effect, and that the reality was a little less exciting; but the fact is that a stalled automobile is an everyday occurrence that is about as mundane as mundane gets. Minor events such as this cannot be prevented in all cases, and therefore drivers absolutely must watch and be prepared for such an event. It wasn't the safest thing to do, but it isn't outside the normal range of "dangerous" events that one will experience on their commute daily, often more than once daily. IMO it doesn't increase the danger nearly as much as traffic patrol conducting a routine traffic stop on the freeway. If we're prepared to accept traffic patrol on busy freeways, then I don't think it's justified to treat a rare, even if foolish demonstration such as this one as anything more than a nuisance.

Re: Hackers Remotely Attack a Jeep on the Highway

#475

Earlier quoted context omitted.

The auto makers were even more reckless in their ignorance of the earlier controlled tests that these researchers performed and presented to said makers. Yet somehow the researchers are the bad guys. #JustHackerNewsThings

It's not about the fact that the Jeep was hackable it's about the fact that the demonstration was done on a crowded highway with civilians around.

It's also about the fact that more "reasonable" tests by these researchers were ignored by manufacturers.

Hundreds of thousands of potential deaths at the hands of vulnerable vehicles versus maybe a dented bumper or two. I'll take the latter, please.

Re: Hackers Remotely Attack a Jeep on the Highway

#476

Earlier quoted context omitted.

There's calling the police, and then there's publishing their phone number in the hopes of directing an angry mob. Angry mobs are dangerous and volatile and can push prosecutors to overreact. And prosecutors and politicians love to overreact when it comes to hacking.

He published the number of the local law enforcement agency. That is not directing an angry mob, that's helping people voice their opinion to the people responsible for enforcing laws.

Bogging down the local police dispatch isn't a responsible way to voice your opinion.

Imagine: you're a local and you're trying to call the police. But, you can't, because the number is busy. Or you wait forever on hold, because people on the internet are angry about a reckless driving incident that happened weeks ago and that the police already know about.

OP called the police, that's enough. They know about it now. If you want to express your opinion, write the editor of Wired or, if you're really angry, the local district attorney.

Re: Hackers Remotely Attack a Jeep on the Highway

#477

Earlier quoted context omitted.

> You can demonstrate the problem without doing it where you put real lives in danger. Indeed. And according to the article, they already did. The manufacturers ignored them.

Well, no, the manufacturers didn't ignore them. They responded with a patch, but the researchers didn't like their response. Still doesn't matter though. There are a million shades between quiet disclosure and outright stupidity that would still make headlines. 1) They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so. 2) They could have ensure…

> They responded with a patch, but the researchers didn't like their response.

It was my understanding that the patch was released in response to the live highway test, not the prior tests in controlled environments.

> They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so.

The article makes it sound like they did.

> They could have ensured constant two-way communication.

Indeed they could've. I agree with you about the recklessness of this particular element of the test.

> They could have done it when nobody was on the road.

Perhaps, and I agree that maybe they should've coordinated with local authorities (if they didn't already). However, between "do the test with vehicles on the road" and "don't do the test at all", I'd certainly pick the former.

Not to mention that the urgency involved with other vehicles on the road factors into the effectiveness of the demonstration.

Re: Hackers Remotely Attack a Jeep on the Highway

#478

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Absolutely the right thing to do. I don't care how technically gifted these people are. They are morons who deserve whatever legal consequences this might bring on.

This isn't about security researchers. There's a HUGE GAP between security research and setting up a situation that could kill someone's daughter, son, mom or dad. That incredibly stupid at the least and criminal at worst.

There are levels of this in tech all over. I don't know if it is about social isolation or something else. Things ranging from the kinds of privacy decisions made by people coding social networks to the totalitarian and inhumane approach seen in dealing with various large web players. It's almost like you are dealing with a non-human race (the Borg?) that is almost completely devoid of human feelings, emotion, consideration, respect, a sense of community and simply making decisions that are humane rather than cold and mechanistic.

The other one is morons flying multicopters above people, neighborhoods and around firefighting aircraft. How does a human being go there mentally? I don't know.

I applaud your actions.

What's worst is that it is likely this was not the first time they did this.

Re: Hackers Remotely Attack a Jeep on the Highway

#479

Earlier quoted context omitted.

If an angry bear is terrorizing your campground, then yes, call fish & wildlife so they can shoot it with a tranq dart and haul it off somewhere safe. In the meantime, though, do you go about your life as though nothing is wrong? Hell no, you get the fuck away from the angry bear! And tossing chocolate bars into your neighbor's campsite in hopes that the angry bear will wreck their stuff is just not cool.

I agree, but I fail to see how that relates to the current context. Unless the unruly bear is these security researchers, the fleeing campers are other security researchers in the same field, and their fleeing is them correctly assessing that some LEA is going to be taking down any bears nearby that even twitch wrong after this. Bad actors ruin it for everyone.

It is true that bad actors ruin it for everyone, and that's why it does not make sense to interact with cops if you have any way of avoiding them. You have no way of knowing which ones are the bad actors until it's too late to do anything about it, and you have no recourse once they have decided to mess with you. Furthermore, they have effectively unlimited resources when it comes to making your life difficult.

You seem to think that because the police are theoretically under democratic oversight, that one can safely interact with cops as though the nominal rules of engagement will restrict them, but even if - in the long run - it is possible to rein them in, the law enforcement system we actually have right now is unpredictable, unjust, and unsafe.

Re: Hackers Remotely Attack a Jeep on the Highway

#480

Earlier quoted context omitted.

Feynman had a nice story where he figured out a way to crack many of the safes in Los Alamos, then dutifully reported his method to some bigshot general. The general said "hmm interesting, thank you very much", and banned Feynman from entering rooms with safes or something. The safes stayed as unsafe as ever. You remind me of that general. You should be hanging out on Catch The Hacker News, not Hacker News.

Testing on uninformed humans is unethical. Wasn't hackernews just all up in arms about the US military spreading germs to test bioweapons? Isn't this the same exactly thing?

There can be times when it is okay to test on uninformed humans.

For example, I have relatives who do fire safety. How people do (or don't!) evacuate from buildings when fire alarms go off is a big area of research.

The ideal way to test this is to set off the fire alarm in a building where people do not know it is happening, along with some smoke and pyrotechnics.

HOWEVER, there are ethical concerns, and a review board would ask questions like:

1. Has anyone else done this study before? If not, why not? How sure are you that no one has done it before?

2. What does the previous research with similar protocols say? What key question are we trying to answer?

3. What is the harm that will be present to people? Are we doing everything we can do to reduce that harm?

4. What more could we do to reduce harm but that might impact the reliability of the research?

5. Quantify how much of a benefit this research would be so we can compare to the risk you are presenting.

6. Demonstrate that you have done all the preliminary work that is necessary to achieve good results, so that we can make sure that the research is used. It would be foolish to put humans at risk and then be unable to use the research because we forgot something we could have taken care of upfront.

These researchers would bomb most of these questions.

The reason for an INDEPENDENT review board is that researchers tend to follow this flow chart:

Have idea. ----> Wait, should I do this? ----> Yes, of course!

Post reply on HN