Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

591–600 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#591

Earlier quoted context omitted.

The paragraphs after the photo of Charlie Miller describe the process of identifying and isolating wireless exploits, including remote-activation of windshield wipers on a vehicle in one of the researchers' driveways. This did admittedly escalate quickly to passive "tagging" of vulnerable vehicles by VIN, but that's a far cry from the experiment in question. The findings before physical tests (identifying cars with a…

You're reaching. First, there's no indication in the article that the researchers or Wired presented the remote windshield wiper hack to the car's manufacturer and that they subsequently ignored it. Second, there is plenty of indication that the exact opposite is true. The remote windshield wiper hack occurred this June, whereas the article states that they've been working with Chrysler on this for nearly nine months…

My point wasn't about Chrysler specifically. My point was about auto manufacturers in general (and I've made this clear from the beginning). By pinning it to Chrysler alone, you're also reaching, I'd reckon.

Also, it's worth noting that the root flaw here - a hole in UConnect - is not limited to Chrysler. The article mentions tracking and surveilling GM vehicles, too (particularly Dodge), which makes sense, seeing as a lot of recent Dodge vehicles have UConnect as well (per http://www.driveuconnect.com/features/uconnect_access/packag...).

> For starters, it looks like they [Cadillac] were contacted by Wired, not the researchers, so it's unclear whether they were contacted before the dangerous freeway demonstration took place.

The article doesn't actually say that. Infiniti was contacted by Wired according to the article, but the initiator of Cadillac's response isn't specified (as far as I can tell).

If they were contacted in the same manner as Infiniti, then it's implied that said contact happened after the wireless hack, since the Infiniti contact involves a notification that the researchers' predictions were "borne out" in at least one of the three of them (in this case, Chrysler).

Re: Hackers Remotely Attack a Jeep on the Highway

#592

Earlier quoted context omitted.

> If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1. If this stunt had never happened, we'd be in a position where some less-scrupulous actor would demonstrate such exploits on a much bigger scale. I can guarantee you that the total number of deaths from remote hacking of cars would be far greater than 1. If we're going to play the "OH NO THINK OF THE CHILDREN^H^H^…

But you're ignoring the fact that this exploit could have been demonstrated in a safe manner on a racetrack or similar with just as much effectiveness.

It could have been demonstrated, yes. It's the effectiveness that's in question, seeing as similar demonstrations weren't particularly effective.

And yes, they could've easily done this demonstration with better safety constraints (particularly regarding communication between the researchers and the driver; said communication was seriously impaired), but the implication is that the researchers believed a "live" test to be necessary to actually get that attention. The point is less "this is what happens to your car" than "this is the sort of danger your car poses to the general public".

My fear, of course, is that even this won't be effective. Hopefully proper basic security measures (like, say, not connecting the transmission, brakes, and steering to the bloody Internet) will be taken seriously before some multi-fatality catastrophe happens because of such security flaws.

Re: Hackers Remotely Attack a Jeep on the Highway

#593

Earlier quoted context omitted.

> "Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference." I did admittedly miss the "nine months" portion of that, but that's still only one company out of many. > "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new…

> I did admittedly miss the "nine months" portion of that, but that's still only one company out of many. Yes, it's the company that owns Jeep. The company that has a demonstrated the security flaw. How different automakers responded to different security issues isn't related to this article or discussion. > Also, note that my point - that auto makers mostly ignored Miller and Valasek, according to the article - woul…

> How different automakers responded to different security issues isn't related to this article or discussion.

It is related to the article when the article discusses those responses.

> The fact that automaker and lawmakers were convinced to take action by less dangerous demonstrations shows that this stunt was not necessary.

One automaker (even this is dubious; Chrysler seriously expects people to believe that the only way to patch a bug that allows total control over a car's transmission and brakes - let alone the rest of the car - is via a USB stick, and that over-the-air patching isn't an option? Please.) and two senators. There are dozens more automakers and 98 more senators to convince. Hopefully the demo helps make that a better situation.

Meanwhile, a bunch of Dodges and Chryslers are driving around America totally susceptible to UConnect bugs, and a very large number of new cars on the road don't even have the most basic safety precautions (like, you know, not connecting the brakes and transmission to the Internet willy-nilly).

The convincing so far has been negligible. Hopefully that'll change soon, before someone with less-benevolent motives follows in Miller's and Valasek's footsteps.

Re: Hackers Remotely Attack a Jeep on the Highway

#594

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Agreed, and now the headline reads more like "Hackers endanger people on public highways" instead of the more interesting (in its consequences) "Jeep cars can be taken over almost completely over an Internet connection while they are running". I'm sure this generates tons of traffic for Wired but this does not bring the necessary focus on the security issue.

Re: Hackers Remotely Attack a Jeep on the Highway

#595

Earlier quoted context omitted.

But you're ignoring the fact that this exploit could have been demonstrated in a safe manner on a racetrack or similar with just as much effectiveness.

It could have been demonstrated, yes. It's the effectiveness that's in question, seeing as similar demonstrations weren't particularly effective. And yes, they could've easily done this demonstration with better safety constraints (particularly regarding communication between the researchers and the driver; said communication was seriously impaired), but the implication is that the researchers believed a "live" test…

Presumably you are leaning on this paragraph when you say that their earlier attacks were ignored?

When they demonstrated a wired-in attack on those vehicles at the DefCon hacker conference in 2013, though, Toyota, Ford, and others in the automotive industry downplayed the significance of their work, pointing out that the hack had required physical access to the vehicles. Toyota, in particular, argued that its systems were “robust and secure” against wireless attacks. “We didn’t have the impact with the manufacturers that we wanted,” Miller says. To get their attention, they’d need to find a way to hack a vehicle remotely.

But you are apparently ignoring this paragraph, which discusses Chrysler responding to the hack, as I read it, prior to the events in the article:

Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference. On July 16, owners of vehicles with the Uconnect feature were notified of the patch in a post on Chrysler’s website that didn’t offer any details or acknowledge Miller and Valasek’s research. “[Fiat Chrysler Automobiles] has a program in place to continuously test vehicles systems to identify vulnerabilities and develop solutions,” reads a statement a Chrysler spokesperson sent to WIRED. “FCA is committed to providing customers with the latest software updates to secure vehicles against any potential vulnerability.”

The way I put the information in those two paragraphs together, it's the fact that the attack can be done without physical access to the car that got the attention of Chrysler, not the publication of a stunt in some web rag.

Re: Hackers Remotely Attack a Jeep on the Highway

#596

Earlier quoted context omitted.

It could have been demonstrated, yes. It's the effectiveness that's in question, seeing as similar demonstrations weren't particularly effective. And yes, they could've easily done this demonstration with better safety constraints (particularly regarding communication between the researchers and the driver; said communication was seriously impaired), but the implication is that the researchers believed a "live" test…

Presumably you are leaning on this paragraph when you say that their earlier attacks were ignored? When they demonstrated a wired-in attack on those vehicles at the DefCon hacker conference in 2013, though, Toyota, Ford, and others in the automotive industry downplayed the significance of their work, pointing out that the hack had required physical access to the vehicles. Toyota, in particular, argued that its system…

Even Chrysler is ignoring the root problem that was demonstrated even with wired access: that should the outermost layer of security be compromised in a modern car, the whole car is likely compromised due to a lack of separation between the car's inner workings and the numerous attack surfaces. That's why the paragraph about Ford and Toyota is very relevant here; once that wireless exploit is found (and believe me, it will be found; this is a question of when, not if), drivers of Toyotas and Fords are hosed. Being anywhere on that list of "hackable" cars [0] should be recognized as a significant problem, but manufacturers are continuing to blow off the core problem and only react to specific breaches.

Basically, folks like Chrysler, Ford, and Toyota (and other mentioned manufacturers, too, like Cadillac) are relying on white hats and grey hats to be the ones finding the zero-day exploits in their wireless systems. And even when those exploits are found, they're being "addressed" with half-assed solutions like requiring an upgrade via USB (never mind that if a remote attacker can hijack the brakes and transmission, of all things, an OTA upgrade should at least be possible).

In other words, I'm not ignoring Chrysler's "response" at all. Rather, I'm noting that their response isn't actually indicative of the attitude shift that's actually necessary to prevent death and maiming of drivers.

[0]: http://www.wired.com/wp-content/uploads/2014/08/Screen-Shot-...

Re: Hackers Remotely Attack a Jeep on the Highway

#597
post #529

Earlier quoted context omitted.

Well self driving cars should be a load of fun. There will be calls to isolate critical components as well as demands they are accessible to the likes of Law Enforcement so they can disable cars remotely. So it will take legislation to sort out as liability concerns needs to addressed as well as the demands of law enforcement. Don't think for one minute they will accept self driving cars they cannot disable all of th…

Law Enforcement can already disable cars remotely.

You mean, with guns?

Re: Hackers Remotely Attack a Jeep on the Highway

#598

Earlier quoted context omitted.

So demo it at a race track. The essential point here is that the uninvolved public were placed at real risk of maiming or death. Your argument is ludicrous, because you're attempting to cast the actors as either good or bad. IMHO they are guys with a good idea and motivation who did a bad thing.

We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. edit : as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers.…

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#599
post #586

Earlier quoted context omitted.

So watching the video, I don't see a vehicle stalled on the highway. What I see is a vehicle slowed considerably, but at least nominally over the legal minimum speed of 40 MPH on highways, and without the driver being able to accelerate on his own. He's travelling in the rightmost lane, explicitly with his hazard lights on. This is not an unusual occurrence on highways. He's then told that to regain control he needs…

Here's my attempt at a partial transcript starting from shortly after they disable the accelerator: Driver: "It says 43 miles an hour, but it's not really that fast." [voiceover omitted] Driver: "Guys, I'm stuck on the highway." Researcher A: "I think he's panicking." Researcher A: "He's not going to be able to hear us with that radio. So loud." Driver: "Guys, I need the accelerator to work again." Researcher A: "The…

Right, but the video never shows the car stalled on the highway. It's moving in every highway shot. It's in the righthand lane, not in the center. The driver is somewhat panicked. We can see how fast he's moving relative to the background.

This discussion has been distorted and sensationalized, and it has not been based on observable recorded facts.

Re: Hackers Remotely Attack a Jeep on the Highway

#600
Good research by the hackers, stupid execution.

Calling the police was indeed the right thing to do.

Maybe next time, the hackers can test on the vehicles driven by the car executives, while they are driving, have their family in the car with them, etc.

Can't wait to see that comment thread...

Post reply on HN