Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

621–630 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#621

Earlier quoted context omitted.

> If you can put your transmissions diagnostic information on the radio's nice big LCD, why wouldn't you? Surely there's a way to make this information read-only. I can see information about my engine on my dashboard via the speedometer and tachometer; it would be ludicrous if I could kill my engine by grabbing the little needles and cranking them down to zero.

> Surely there's a way to make this information read-only. There absolutely is a way. Just off the top of my head you could relay the information from the high-sec CAN bus to a low-sec one with a micro-controller. So the low-sec bus can only receive messages from the high-sec one. Not enabling firmware loading over CAN on the relay is a must as well for obvious reasons, but the key is the code on the relay microcontr…

Isn't that what the hacked car already doing? I don't know about Jeep specifically, but most cars have several CAN busses and some micro-controller passing messages from high-speed control network to low-speed infotainment network.

Problem is, most automotive engineers are clueless about security and most "hackers" are clueless about automotive hardware, software and protocols. There is no dialog.

I wish articles like these posted at least some specifics. A lot of these hacks in the past were completely impractical. Yes, yes, they had shown some interesting possibilities, but it was disingenuous to present them as real-life attacks (which many media outlets did).

Re: Hackers Remotely Attack a Jeep on the Highway

#622

Earlier quoted context omitted.

"Hacking" is not what's portrayed in movies. The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. Heck, if the writer had contacted the cops, they could have given him an escort to make sure nothing bad happens. If you ask me, it is this kind of behavior that makes the work of real researchers harder , as the med…

> The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. According to the article, the researchers already did as early as 2013. Auto manufacturers ignored the reports while continuing to pretend that their vehicles are secure.

According to the article, that experiment required physical access to the car; it was NOT a remote experiment like this one.

Re: Hackers Remotely Attack a Jeep on the Highway

#623
post #562

Earlier quoted context omitted.

Only if your sense of scale has stopped functioning. It is a dangerous journalistic prank that probably does deserve a telling off from traffic cops, to much the same level as someone who is drunk driving. But I think trying to classify it as terrorism is not helpful or particularly sane.

At what scale would you consider it to be terrorism?

To my mind, it would have to be some form of an attack, if untargeted, at least hundreds of cars, and if small would have to be targeted and strongly political, dangerous stupidity in a single instance for the purposes of having a good press story, doesn't qualify as either causing terror, or having an intent to, notwithstanding the broad legal definition that has been adopted over the past 15 years.

Re: Hackers Remotely Attack a Jeep on the Highway

#624

Earlier quoted context omitted.

Only if your sense of scale has stopped functioning. It is a dangerous journalistic prank that probably does deserve a telling off from traffic cops, to much the same level as someone who is drunk driving. But I think trying to classify it as terrorism is not helpful or particularly sane.

Seeing as how drunk driving kills a very large number of people every year and is now punishable by imprisonment and extremely steep fines, you might be onto something here.

If people were screwing with cars like this as often as drunks were driving, I think you would end up with mortality figures that were at least in the same ballpark.

Re: Hackers Remotely Attack a Jeep on the Highway

#625

So, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's…

I imagine a not terribly experienced new team being told to do connected stuff in a car, not really understanding security and having ridiculous demands thrown at them as the manufacturer drools about getting subscription revenue from every car. But would be nice to have an inside story.

I don't know about the automotive industry, but this is absolutely true at some industrial equipment manufacturers.

Re: Hackers Remotely Attack a Jeep on the Highway

#626

Earlier quoted context omitted.

> The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. According to the article, the researchers already did as early as 2013. Auto manufacturers ignored the reports while continuing to pretend that their vehicles are secure.

According to the article, that experiment required physical access to the car; it was NOT a remote experiment like this one.

It still demonstrated the same root problem: that the computerized systems on cars today have very little in way of basic safeguards. And there was indeed quite a bit of cracking UConnect and wirelessly spying on Dodges and Chryslers throughout the country before the experiment.

If I were an auto manufacturer, I wouldn't wait until someone finds a wireless exploit (at which point it's too late to do anything about it before people die or are maimed unless I'm lucky enough for the zero-day to be found by a white-hat or grey-hat). I'd see those earlier reports, say "holy shit if we have one wireless bug, the whole car could be pwned", and start working on a better isolation of critical systems from internet-connected systems immediately.

Re: Hackers Remotely Attack a Jeep on the Highway

#627

Earlier quoted context omitted.

> To repeat what others have said: why on earth did they do this on open roads and high speeds? Because - according to the article, at least - they'd already demonstrated similar exploits in more controlled environments, and said demonstrations were handwaved and dismissed by the auto manufacturers.

The risk still doesn't justify the supposed reward. Why not a lower speed in a quiet street if you absolutely feel you have to do this on open roads?

I don't disagree with you; the researchers could have taken better safety measures (most notably, better communication between themselves and the reporter would have eliminated most of the risk by allowing the reporter to cut the experiment early), and had they done so, they would have been more clearly in the right.

However, there's some usefulness to the higher speed, since it indicates that the car can be isolated among highway traffic even at high speed. The researchers were also smart to not slam brakes (which would have turned the minimal danger from unpowered coasting into the maximal danger of sudden stops).

Re: Hackers Remotely Attack a Jeep on the Highway

#628

Earlier quoted context omitted.

I take it you also can't stop thinking about your wife and kids being behind someone whose engine stalls, or who slams one's brakes to avoid hitting a deer, or who runs out of gas on an interstate (which has happened to me, thanks to my car's faulty fuel gauge). You must have a lot on your mind. I don't agree with the methodology, either, but based on the information in the article, it sounded like the researchers di…

"I didn't have a choice but to fire a gun in the middle of a crowd of people. It was just a wake up call!. You always have a choice. One of those choices is to do the demo, but with the proper safety authorities helping. One of those choices is to perform the demo in a place where it is safe to pull your car over. One of those choices is to do the demo somewhere where the speeds are a little lower. All of those thing…

There's a big difference between firing a gun and a car gradually slowing down.

Yes, the researchers could have made better choices. They could have made worse choices, too. The "danger" here is significantly exaggerated given the descriptions of the scenario in the article (gradual slowdowns, contrary to popular belief, aren't that hard to react to in a timely manner), and it certainly does not compare to firing a gun.

Re: Hackers Remotely Attack a Jeep on the Highway

#629

Earlier quoted context omitted.

According to the article, that experiment required physical access to the car; it was NOT a remote experiment like this one.

It still demonstrated the same root problem: that the computerized systems on cars today have very little in way of basic safeguards. And there was indeed quite a bit of cracking UConnect and wirelessly spying on Dodges and Chryslers throughout the country before the experiment. If I were an auto manufacturer, I wouldn't wait until someone finds a wireless exploit (at which point it's too late to do anything about it…

You don't think there's a difference between exploiting physical access, and remote network exploits? Given physical access to a computer, you can break into it almost trivially; but you don't see people sweating about that.

Re: Hackers Remotely Attack a Jeep on the Highway

#630

Earlier quoted context omitted.

No he did not do the wrong thing. Reporting them is completely wrong. When we report the people who protect us, well this sounds like a plot to a movie. PS: in movies usually a lot of people suffer before the resolution

You are missing the point by a mile. These people did the exact opposite. They put others in potentially mortal danger. They could have killed someone's daughter, son, mom or dad. Stop and think about that for 10 minutes before you continue posting with this unreasonable point of view. Would your mom, dad or siblings life be worth this test? Imagine they collided with this car and died. Close your eyes and imagine th…

To be fair, a good proportion of the blame -- and a very good proportion of my subsequent lawsuit -- would be directed at the car company whose negligent engineering made the wreck possible in the first place.

Although I do agree with you, I modded you down and the GP up in this case because appeals to emotion aren't the answer. Your post is a form of the "If it saves just one child" thought-ending pattern.

Post reply on HN