Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

581–590 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#581

Earlier quoted context omitted.

My remarks were strictly based on the claims of the article. Nothing more, nothing less. The article claims that the researchers performed prior tests, and that said tests were dismissed by auto manufacturers. If we're going to take one component at face value (the idea of the reporter putting others in danger), it would be unfair to not extend the same courtesy to the rest of the article.

"My remarks were strictly based on the claims of the article. Nothing more, nothing less." Perhaps you should educate yourself before saying stupid, reckless things. The claims of the article are no defense.

In that case, the commenter who started this whole discussion of whether or not the researchers' behavior was in the wrong should've also educated him/herself before making phone calls to law enforcement agencies based on the claims of a WiReD article.

Or is basing one's statements on the subject matter alone only valid when you happen to agree with it?

Re: Hackers Remotely Attack a Jeep on the Highway

#582

Earlier quoted context omitted.

My remarks were strictly based on the claims of the article. Nothing more, nothing less. The article claims that the researchers performed prior tests, and that said tests were dismissed by auto manufacturers. If we're going to take one component at face value (the idea of the reporter putting others in danger), it would be unfair to not extend the same courtesy to the rest of the article.

"My remarks were strictly based on the claims of the article. Nothing more, nothing less." Perhaps you should educate yourself before saying stupid, reckless things. The claims of the article are no defense.

Responding to a Hacker News discussion about the article based in information from the article seems quite reasonable. Perhaps it does not deserve phrases like "saying stupid, reckless things". Could you step back for a moment and consider how YOU want others to perceive YOUR postings? I, for one, am a big fan of civil discourse on HN.

Re: Hackers Remotely Attack a Jeep on the Highway

#583

Earlier quoted context omitted.

The actions - according to the article - of auto manufacturers in response to prior more-controlled tests is exactly equivalent to that. The manufacturers basically said "hey, thanks for showing us this crash-test footage that shows our vehicles are literal fucking coffins on wheels; we don't really care", leaving the researchers with no results after taking more "sane" measures. Researchers perform controlled experi…

What they should have done was involve the police from step #1. If the video had been conducted on a closed section of roadway with ambulances standing by, police escorts, and lots of badges and sirens, it would have been even harder for the automakers to blow off. It wouldn't have been difficult to do this right. Cops love drama and publicity. It wouldn't have taken much convincing to get them on board, and the vide…

I agree completely; there were a lot of formalities that were neglected - and had they not be neglected, there would be less backlash against the researchers.

However, this doesn't change the fact that vulnerabilities were demonstrated, nor does it change the implication that auto manufacturers are excessively sluggish about security patches on things that can and do kill people on a regular basis. Even an imperfectly-conducted demonstration like this particular case is preferable to such a demonstration not occurring at all.

Re: Hackers Remotely Attack a Jeep on the Highway

#584

Earlier quoted context omitted.

> They responded with a patch, but the researchers didn't like their response. It was my understanding that the patch was released in response to the live highway test, not the prior tests in controlled environments. > They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so. The article makes it sound like they did. > They could have ensured con…

Regarding the patch timeline, the article makes it clear they had been working on the patch for months before this went public. > Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference. With respect to letting the driver in on it, it's pretty clear they withheld most information: > Miller and Valasek r…

> With respect to letting the driver in on it, it's pretty clear they withheld most information:

The reporter knew there were going to be attacks in the first place. There was also plenty of reason to believe said attacks could severely impair safety.

> Oh look, another false dilemma.

It's a trilemma; the concept of "do the test 'responsibly'" was already implied, so I merely provided the other outcomes. There's "perfect execution of demonstration" and "no demonstration"; between that is a spectrum of perfection, on which this demonstration happens to lie somewhere near the lower-middle.

I don't disagree that the demo could've been done with more safety precautions, but the desire to do a "live" demonstration like this seems pretty reasonable, and even a demonstration lower on the perfection spectrum is preferable to the bottom end of "nothing at all".

Re: Hackers Remotely Attack a Jeep on the Highway

#585

Earlier quoted context omitted.

> This is especially the case when a safer alternative to demonstrate this exploit easily exists. If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.

Did you read the article? Here are two quotes: "Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference." "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked…

> "Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference."

I did admittedly miss the "nine months" portion of that, but that's still only one company out of many.

> "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked when Markey took note of Miller and Valasek’s work in 2013."

If you read further, you'll see the paragraphs on Markey's letters to auto makers regarding the 2013 findings; Markey's own findings only reinforce my point further.

Also, note that my point - that auto makers mostly ignored Miller and Valasek, according to the article - would not include senators (unless said senators build cars, of course).

Re: Hackers Remotely Attack a Jeep on the Highway

#586

Earlier quoted context omitted.

Agreed. I missed the video the first time and didn't believe the text that described the shutdown, video shows the stupidity here, let alone release a recording of it. I expect that will come down soon. Important research but very poorly tested. Wired and Chrysler (research was funded by Chrysler?) legal teams would not like the contents of this video. edit: wired's link to video, jump to 2:00: http://dp8hsntg6do36.c…

So watching the video, I don't see a vehicle stalled on the highway. What I see is a vehicle slowed considerably, but at least nominally over the legal minimum speed of 40 MPH on highways, and without the driver being able to accelerate on his own. He's travelling in the rightmost lane, explicitly with his hazard lights on. This is not an unusual occurrence on highways. He's then told that to regain control he needs…

Here's my attempt at a partial transcript starting from shortly after they disable the accelerator:

  Driver: "It says 43 miles an hour, but it's not really that fast."
  [voiceover omitted]
  Driver: "Guys, I'm stuck on the highway."
  Researcher A: "I think he's panicking."
  Researcher A: "He's not going to be able to hear us with that radio.  So loud."
  Driver: "Guys, I need the accelerator to work again."
  Researcher A: "The accelerator..."
  Researcher B: "It won't work!  You're doomed!"
  Driver:  "Seriously [beep] dangerous, I need to move."
  Researcher A: "You gotta turn the car off!"
Many cars can be seen passing them on the left in the video during the test.

Re: Hackers Remotely Attack a Jeep on the Highway

#587

Earlier quoted context omitted.

It was a gradual slowdown. That "non-zero" has enough zeroes after the decimal point for Japan to send the number to Hawaii and have another go at Pearl Harbor. Worst-case scenario, somebody might've been rear-ended. Maybe a bit of whiplash. That's not great, either, but seeing as more-controlled tests by these researchers were outright ignored by auto manufacturers, your priorities have to be incredibly out of whack…

Your estimates for both the "non-zero" probability of injury and the worst-case scenario are very far off from mine and from the those of the thread-starter, who appears to have some expertise in traffic considerations, and the dangers of semi trucks in particular. I wonder if your opinions about this would be different if you believed this was as dangerous as many of us believe it was, rather than merely having an e…

My estimates come from some personal and professional experience (including being a former employee of a state highway patrol, mostly tasked with - among other things - processing traffic collision reports and dealing with phone calls from those involved; not a fun job, that was). Admittedly, probably not as much as a semi truck driver, but contrary to popular belief I'm not entirely inexperienced here :)

The reporter mentions that this was uphill. Semis generally have a hard time going uphill at an appreciable speed (as I know full well being stuck behind them regularly on the mountain pass highways that connect my town to the rest of the world; lines and lines of trucks at less than 45 MPH with their flashers on); more weight leads to a harder time fighting against gravity. The uphill slope should make it easier for the truck to slow down.

If the reporter had made an abrupt stop (i.e. if the researchers slammed his brakes or something), then yeah, I'd be more concerned. That wasn't the case, though. Rather, it was a gradual deceleration according to the article. Cars can actually coast quite a distance, even uphill, when they start at 70MPH; I know this firsthand from my own SUV running out of gas once on a busy interstate, and on an uphill no less. Even with the uphill, there was enough momentum for me to put on my flashers, merge right from the fast lane, and eventually coast into the next offramp a quarter-mile away. No shoulder, either.

Now, this isn't to say that it couldn't've been safer, nor do I disagree that more safety precautions should've been implemented. For one, the researchers could've - at the very least - told the reporter "hey, if our attack comes at a really bad time and you feel like you're about to die, turn the car off and on again and you'll regain control". However, even with the described scenario as-is, risk of life is quite slim. We're not talking about a driver slamming his brakes and going from 70 to 0 in seconds; we're talking about the equivalent of an engine stall, and thus a rather gradual slowdown - graudal enough for even semis, let alone smaller vehicles, to react to.

> I wonder if your opinions about this would be different

They probably would, yes. Slightly, though; ultimately, one injurious pileup is a drop in the bucket compared to the hundreds of thousands that might actually be prevented by demonstrating precisely why proper security measures on Internet-connected heavy machinery are worth taking seriously. Not that I think the possibility of the former should be dismissed (indeed, I agree that the researchers could've done things more safely while still getting the attention of auto makers), but said possibility needs to be weighed against the possibility of the latter, with the recognition that any demonstration - ideally a totally safe one, but even one with some degree of risk - is necessary to push auto manufacturers toward taking security seriously.

Re: Hackers Remotely Attack a Jeep on the Highway

#588

Earlier quoted context omitted.

You see, the thing is some of us still believe the the police are staff by people, not some faceless conglomeration of drones that all follow the same horrible behavior, and that while there are some, probably many bad police officers, and many systemic problems, they still serve a purpose, and that life without any form of law enforcement would be a big step back in many, many ways. The amount the media reports on s…

> you're the one pulling an ad-hominem on the police While I agree with much of the rest of what you right in that comment, this is not accurate: overgeneralizing a negative stereotype of someone other than the other party in a debate isn't "pulling an ad hominem ".

That kind of argument is generally considered to be 'poisoning the well' -

https://en.wikipedia.org/wiki/Poisoning_the_well

Re: Hackers Remotely Attack a Jeep on the Highway

#589

Earlier quoted context omitted.

> Why can't we condemn both? Nobody's saying you can't. I certainly do (I strongly disagree with the researchers' obstruction of communication between themselves and their test subject). My only point is that there's a massive difference in scale between a couple dented fenders and hundreds of thousands of dead/maimed innocents.

Difference of scale? Ok, I agree with you there, but characterizing the risk as "a couple dented fenders" is intellectually dishonest. A high speed accident on an interstate could easily involve serious, even fatal injuries.

It could in some situations, yes. This was not one of those situations.

We're talking about someone coasting uphill with absolutely no braking whatsoever. There's plenty of reaction time in such situations (as I happen to know firsthand, as was the case when my SUV ran out of gas and I had to coast a quarter-mile over a hill to get to the next offramp while merging from the fast lane to the far right at 70MPH). Even for semis, the reporter's car wouldn't mean having to slam on the brakes. Not to mention that the uphill helps with stopping.

The story would be different if the researchers slammed the car's brakes. If that were the case, then yes, death would be possible. That wasn't the case.

No intellectual dishonesty here. Just thorough examination of the situation as described by the author of the article.

Re: Hackers Remotely Attack a Jeep on the Highway

#590

Earlier quoted context omitted.

Did you read the article? Here are two quotes: "Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference." "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked…

> "Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference." I did admittedly miss the "nine months" portion of that, but that's still only one company out of many. > "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new…

> I did admittedly miss the "nine months" portion of that, but that's still only one company out of many.

Yes, it's the company that owns Jeep. The company that has a demonstrated the security flaw. How different automakers responded to different security issues isn't related to this article or discussion.

> Also, note that my point - that auto makers mostly ignored Miller and Valasek, according to the article - would not include senators (unless said senators build cars, of course).

Senators may not build cars, but they can (and are trying to) force auto makers to take security seriously.

The argument in this comment chain has been whether this problem could get the attention it needed without such a dangerous publicity stunt. The fact that automaker and lawmakers were convinced to take action by less dangerous demonstrations shows that this stunt was not necessary.

Post reply on HN