Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

601–610 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#602
post #586

Earlier quoted context omitted.

Here's my attempt at a partial transcript starting from shortly after they disable the accelerator: Driver: "It says 43 miles an hour, but it's not really that fast." [voiceover omitted] Driver: "Guys, I'm stuck on the highway." Researcher A: "I think he's panicking." Researcher A: "He's not going to be able to hear us with that radio. So loud." Driver: "Guys, I need the accelerator to work again." Researcher A: "The…

Right, but the video never shows the car stalled on the highway. It's moving in every highway shot. It's in the righthand lane, not in the center. The driver is somewhat panicked. We can see how fast he's moving relative to the background. This discussion has been distorted and sensationalized, and it has not been based on observable recorded facts.

I can agree that the car is not shown at a full stall in the video, however it is the case that the driver reports that they are unable to control the vehicle during the test. I cannot agree that this would matter regarding the idea that this is "[beep] dangerous" as was stated by the driver, because that is supported by the driver's own statements as well as observable facts.

Re: Hackers Remotely Attack a Jeep on the Highway

#603

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

The fact that a dashboard system that controls your radio or AC has access to cut your transmission is also a hardware configuration issue. Accessories should be physically secured from ignition and drive train. The internet connected features of the car, in turn, should be severed from both of these. It should not be physically possible to turn on the wipers from the embedded processor that receives packets on the I…

I immediately thought of an unlocked firmware update (or boot over CAN) in some entertainment computer component that can then spoof other subsystems. The security model in modern cars is broken, esp with regard to control and data.

Re: Hackers Remotely Attack a Jeep on the Highway

#604
post #40

Earlier quoted context omitted.

Are you pointing to the stellar security record of the software industry here?

Exactly. I'd like to see the perfect security implementations over large scale systems that exist in the software industry today.

Aviation is doing pretty well. I'd hope for the same standard of safety and security from automobile manufacturers.

Re: Hackers Remotely Attack a Jeep on the Highway

#605
post #219

Earlier quoted context omitted.

Too late to edit my original comment again so I'll post a reply here as a general reply to those who reacted negatively to my decision to phone the police. While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and…

You've seriously seen "dozens" of people killed?

40,000 people a year in the US. I wouldn't be surprised at all if an experienced truck driver has seen dozens of dead people.

Re: Hackers Remotely Attack a Jeep on the Highway

#606
post #396

Earlier quoted context omitted.

Using violent methods (such as intentionally sabotaging a car on a busy freeway with someone in it) to get media attention in order to further a political goal sounds a lot like the definition of terrorism.

Only if your sense of scale has stopped functioning. It is a dangerous journalistic prank that probably does deserve a telling off from traffic cops, to much the same level as someone who is drunk driving. But I think trying to classify it as terrorism is not helpful or particularly sane.

Seeing as how drunk driving kills a very large number of people every year and is now punishable by imprisonment and extremely steep fines, you might be onto something here.

Re: Hackers Remotely Attack a Jeep on the Highway

#607

Earlier quoted context omitted.

This was my first thought. To repeat what others have said: why on earth did they do this on open roads and high speeds? I can only assume it was for additional 'shock impact' of the story. Reckless in many, many ways, no matter how interesting the story actually is. In fact it's so reckless that it actually devalues the interesting and important core of the story itself.

> To repeat what others have said: why on earth did they do this on open roads and high speeds? Because - according to the article, at least - they'd already demonstrated similar exploits in more controlled environments, and said demonstrations were handwaved and dismissed by the auto manufacturers.

The risk still doesn't justify the supposed reward. Why not a lower speed in a quiet street if you absolutely feel you have to do this on open roads?

Re: Hackers Remotely Attack a Jeep on the Highway

#609

Earlier quoted context omitted.

"Hacking" is not what's portrayed in movies. The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. Heck, if the writer had contacted the cops, they could have given him an escort to make sure nothing bad happens. If you ask me, it is this kind of behavior that makes the work of real researchers harder , as the med…

> The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. According to the article, the researchers already did as early as 2013. Auto manufacturers ignored the reports while continuing to pretend that their vehicles are secure.

You've said that a dozen times in this thread with no direct quotes or proof

Re: Hackers Remotely Attack a Jeep on the Highway

#610

Earlier quoted context omitted.

> it's necessary to get the attention of auto makers That's mere conjecture. And it's an assertion you could easily test by first doing the remote hack in a controlled environment (e.g. a racetrack) and seeing if automakers respond before trying this on an actual freeway!

If you read the article, you'd know full well that the researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.

Did you miss the link in the article to the webpage where you can already download a fix? It's not the manufacturers they were trying to convince.
Post reply on HN