Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

571–580 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#571

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

https://en.wikipedia.org/wiki/Institutional_review_board is how normal people deal with this.

No, I think notifying the police, who then notify the IRB is how normal people would deal with this. I don't expect the normal person knows about the IRB (I'm not surprised it exists, but I was unaware of it).

In a similar vein, if you notified your local police about a kidnapping they would notify the FBI, because kidnapping is the FBI's jurisdiction.

Re: Hackers Remotely Attack a Jeep on the Highway

#572
post #46

Earlier quoted context omitted.

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

> Because you disagreed with their methods This isn't really engaging with his action. Specifically, because called the cops because he believed that their methods put people in danger of physical harm. This objection isn't coherent without an argument either that: 1) He was unreasonable in his belief that they'd put people in harm's way. or 2) It is not appropriate to contact law enforcement as a result of observing…

If he was actually concerned, and not just outraged, he would have called the police and reported Chrysler for endangering thousands of people's lives.

Re: Hackers Remotely Attack a Jeep on the Highway

#573

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Do people need to be reminded of what happens when these kind of issues are not disclosed out-of-the-blue?

Well, here you go (search for 'Volkswagen'): http://attrition.org/errata/legal_threats/

Re: Hackers Remotely Attack a Jeep on the Highway

#574
post #420

Earlier quoted context omitted.

Nobody was hurt because they rolled the dice and got lucky. There was a non-zero probability of injury or death that was completely unjustified.

It was a gradual slowdown. That "non-zero" has enough zeroes after the decimal point for Japan to send the number to Hawaii and have another go at Pearl Harbor. Worst-case scenario, somebody might've been rear-ended. Maybe a bit of whiplash. That's not great, either, but seeing as more-controlled tests by these researchers were outright ignored by auto manufacturers, your priorities have to be incredibly out of whack…

Your estimates for both the "non-zero" probability of injury and the worst-case scenario are very far off from mine and from the those of the thread-starter, who appears to have some expertise in traffic considerations, and the dangers of semi trucks in particular. I wonder if your opinions about this would be different if you believed this was as dangerous as many of us believe it was, rather than merely having an extremely low probability danger of a harmless fender-bender.

Re: Hackers Remotely Attack a Jeep on the Highway

#575

If Myth Busters tested some wacky car on a public road at 70mph without telling anyone, we'd all be freaking out. But because they were "researchers" (i.e. the same tribe as most leftist people here) from a university (leftist church) then they get a pass and all sorts of justification for why what they did was OK. EDIT: Leftists go by label. They will heart any "researcher" thinking they must be their peer in their…

I'm getting the sense that you have an issue with leftists.

Re: Hackers Remotely Attack a Jeep on the Highway

#576
post #310
post #28

Earlier quoted context omitted.

I don't think this has necessarily anything to do with engineering competence. From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle. Why? Because while you're busy building a well-secured system, your competitors are busy implementing new f…

In addition to your third paragraph, auto makers are disincentivized toward adding security features because they CAN'T advertise them. If Toyota started advertising the all new Prius with the feature "your ability to brake won't be taken away from you while you're barrelling down the highway at 70 mph", consumers wouldn't just not care, they would question why the fuck that wasn't there in the first place. This sort…

This will change as awareness of these attacks reaches the general public.

According to the article, US politicians are looking at introducing legislation to enforce cybersecurity measures. At that point, it will just be another safety rating that manufacturers can and do use to promote their vehicles.

Re: Hackers Remotely Attack a Jeep on the Highway

#577
post #201

Should hackers actually kill somebody, I struggle to find a reason why the relevant automotive engineers and their managers shouldn't be charged and convicted of negligent homicide, or worse. After all, somebody had to make the decision to connect a radio receiver to the CAN bus. Others are aware of the wireless and choose not to remove it. To be a professional is to have a duty to refuse to do stupid stuff like this…

When it comes to industrial safety, the main question when facing accusation of negligence is "what would a reasonable person have done in that situation". It takes into account things like: - would a reasonable person have identified this feature as having an exploitable vulnerability? - was it reasonably practicable to protect against it?

In this case, the manufacturer could argue that, in their review of the risks associated with their remote connection system, it was not reasonable to expect that it could be compromised and lead to a hazard.

Obviously, now that it has been demonstrated, there will be a much greater expectation that car manufacturers secure their remote access pathways.

Re: Hackers Remotely Attack a Jeep on the Highway

#578
post #242

This discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now , with more rolling off the assembly line all the time, and people are driving these around right now . Why is most of…

Ethics isn't relative. You don't get to point to some other perceived problem and say "well that's worse, so what I'm doing is fine in comparison!".

Vulnerabilities in cars is an issue that needs to be fixed. Performing dangerous tests in uncontrolled environments is not a reasonable way to bring about change.

If they HAD caused an accident, how would you go about consoling the victims? "Oh, that sucks for you, but hey maybe your pain/death will convince the car companies to finally do something! Cool right!". It is not acceptable to introduce hazards to the general public to prove a point.

Re: Hackers Remotely Attack a Jeep on the Highway

#579
As big of dicks as these researchers are, I just have to say, to anyone out there working on software to run cars, airplanes, robots, other mobile vehicles ... some day, within the next 5 or 25 years, it's pretty likely some nut job is going to use an exploit take control of one or more of these vehicles and crash them/use them as remote-controlled / swarm weapons, possibly killing lots of people.

If you're writing that software, make sure you do a really, really good job on security. Because no one wants to be the guy 'git blame' shows wrote the exploitable feature that led to ??? deaths.

The industry really should have stringent standards that prevent ridiculous breaches like this, I would say as well as simulators (or physical demo vehicles) available online/open source that people can pen-test against and win prize money. And maybe write all the code in Rust?

Re: Hackers Remotely Attack a Jeep on the Highway

#580
post #46

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

You called the cops on two security researchers and a journalist, because you disagreed with their methods and weren't sure what their plans were and what authorities they'd talked to? (And not just any cops, the cops in St. Louis, for bonus points.) Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?

> You called the cops on two security researchers and a journalist, because you disagreed with their methods...

Calling it a disagreement over methods glosses over the real issue, which is that it was a dangerous exercise and its perpetrators apparently don't have sufficiently good judgement to be left to their own devices.

Post reply on HN