Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

631–640 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#631

Earlier quoted context omitted.

Had my car stall on the highway once. Pretty scary because you lose power-brakes and power-steering as you're trying to pullover. Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change. How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (wh…

Cars aren't toys. Just because there are many stalls doesn't mean adding one more becomes acceptable. Here's the good test: since humans were involved, how did they present this to their ethical review board? I'm pretty confident the answer would be "what's an ethical review board?".

DARPA don't need no ethics board.

Re: Hackers Remotely Attack a Jeep on the Highway

#632
post #297

Earlier quoted context omitted.

How would you like those three dials to control the rest of the car systems? And, isn't this what BMW tried to do ages back with that single 'iButton' control that everyone hated?

Uhh, the same way almost every non-luxury car made between 1960 and 2010 did it? A dial each for temperature, fan speed, and where the air is blowing. Plus a button for air conditioning and/or recirculate. No touch screens, no menus. People have been using cars without touch screens for 50+ years. The UX is a pretty much a solved problem by this point. Yet now car manufacturers seem to want to mess with something tha…

You do understand that there is more than just climate control that can be adjusted in a vehicle these days? There's navigation and direction finding, traffic alerts, radar proximity warnings from other traffic, radio and entertainment systems, telephony functions, systems monitoring and alerting for various components, current engine and transmission ststus, location data, environmental data...

Re: Hackers Remotely Attack a Jeep on the Highway

#633

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

Jesus, just google similar researches in 2011, which has been done in "safe environment" without naming manufacturers etc. etc. and in 2015, after 4 years we see that manufacturers did say "meh, thank you but no, we aint gonna do shit about it"

How about that - "Fiat Chrysler now says that 10 vehicles from its 2013, 2014 and 2015 model years are vulnerable to hacking, including five 2013-2014 Ram truck models, the 2014 Jeep Cherokee and Grand Cherokee, the 2014 Dodge Durango and 2014 Dodge Viper, and some 2015 Chrysler 200s."

and that - "Miller and his associate, Chris Valasek, director of vehicle security research at the consultancy IOActive, estimates that hundreds of thousands of Fiat Chrysler vehicles on the road today could be vulnerable. That’s unsettling." just read people! 2013 models. And now, this a hole calling police because this guys opened your eyes. Wouldn't it be better if they made "safe" test again, manufacturers ignore it AGAIN & then some sick bastard simply crashed thousand of those?

And yes the main thing I like is - “Customers can either download and install this particular update themselves or, if preferred, their dealer can complete this one-time update at no cost to customers.” DOWNLOAD & INSTALL THEMSELVES? What? but yeah right blame the researches of course.

"In case any of you think this was cool or even remotely (no pun intended) ethical, I'd like to know if you have a problem with letting these two test this on a loved one's car. How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything?"

I would certainly let this guys to check on my car and my wife's car, just to make sure that if it can be hacked then I'd better get rid of that crap and sue a holes which let me drive a car which can be controlled remotely. Cause I would rather trust ex NSA and current director of vehicle security research at the consultancy IOActive, rather than have even a 0,00001% chance that some unknown hacked crew can end my life sipping coffee in starbucks.

Re: Hackers Remotely Attack a Jeep on the Highway

#634
post #163

Earlier quoted context omitted.

Poorly maintained vehicles that break down while driving surprise the driver. This happens daily on public roads. Should we fine them for failing to maintain their vehicle to your standards? There are autonomous vehicles being tested on our roads with a failure mode of "coast to a stop". They may not even have a human inside to react to things around them. Do the operators deserve to be jailed? People modify their ca…

Failure to maintain your vehicle such that it puts other people at risk is against the law. The people testing self-driving cars had IRBs that go over their test cases. Do these guys even know what IRB stands for?

and it's rarely prosecuted.

Re: Hackers Remotely Attack a Jeep on the Highway

#635

Earlier quoted context omitted.

It still demonstrated the same root problem: that the computerized systems on cars today have very little in way of basic safeguards. And there was indeed quite a bit of cracking UConnect and wirelessly spying on Dodges and Chryslers throughout the country before the experiment. If I were an auto manufacturer, I wouldn't wait until someone finds a wireless exploit (at which point it's too late to do anything about it…

You don't think there's a difference between exploiting physical access, and remote network exploits? Given physical access to a computer, you can break into it almost trivially; but you don't see people sweating about that.

> Given physical access to a computer, you can break into it almost trivially; but you don't see people sweating about that.

Sure you do. This is why large businesses (smart ones, anyway) require employees' smartphones to be locked with a password or PIN. This is why standards like HIPAA require secure data to be encrypted at rest. This is why laptops being stolen from government agencies leads to things like millions of confidential records disclosed (true story).

And you're still missing my point: that the likes of Toyota and Ford are relying on their wireless systems being secure. That's reckless, since now their wireless systems are the single point of security failure. The lack of even basic safeguards, access levels, etc. should a breach occur is the point of this article, more so than the specific UConnect breach. Having only one layer between "secure" and "pwned" is by no measure a good idea.

Re: Hackers Remotely Attack a Jeep on the Highway

#636
post #582

Earlier quoted context omitted.

"My remarks were strictly based on the claims of the article. Nothing more, nothing less." Perhaps you should educate yourself before saying stupid, reckless things. The claims of the article are no defense.

Responding to a Hacker News discussion about the article based in information from the article seems quite reasonable. Perhaps it does not deserve phrases like "saying stupid, reckless things". Could you step back for a moment and consider how YOU want others to perceive YOUR postings? I, for one, am a big fan of civil discourse on HN.

Given this is in the context of people loudly condemning a poster here for actually being concerned about other human beings' well-being, I think your claimed concern about "civility" in this one instance is dubious at best.

If someone prefers people making stupid and reckless arguments to other people civilly pointing out that those arguments are stupid and reckless, I'm not concerned about their perception of me.

Re: Hackers Remotely Attack a Jeep on the Highway

#637
post #570
post #232

I'm willing to bet FCA wil recall all of these "UConnect" enabled vehicles within a month to patch this. This will blow up fast.

You might lose some money: http://www.detroitnews.com/story/business/autos/chrysler/201... There is a patch available, but that is not a recall. A recall takes some time under the best circumstances and FCA pushes back hard on expensive ones.

The feds have been breathing down their necks lately due to too many defects. I'm sure they brought the hammer down hard (behind the scenes) on this one, thus forcing them to announce the recall this morning.

Re: Hackers Remotely Attack a Jeep on the Highway

#638
post #560
post #60

Earlier quoted context omitted.

Encrypted and authenticated data on the bus won't happen anytime soon for cost reasons. Filtering the commands the controller can put on the bus seams reasonable, but would only be useful, if implemented on a second controller (probably won't happen, either). I think the best approach is to secure the internet connection properly. Don't permit incoming connections at all and just permit a single outgoing TLS connecti…

"outgoing TLS connection to the server of the manufacturer" That is one of the principles of how Audi's system operates for security reasons.

Interesting. It's the Blackberry way and generally a good idea.

Re: Hackers Remotely Attack a Jeep on the Highway

#639
post #637
post #570

Earlier quoted context omitted.

You might lose some money: http://www.detroitnews.com/story/business/autos/chrysler/201... There is a patch available, but that is not a recall. A recall takes some time under the best circumstances and FCA pushes back hard on expensive ones.

The feds have been breathing down their necks lately due to too many defects. I'm sure they brought the hammer down hard (behind the scenes) on this one, thus forcing them to announce the recall this morning.

I just saw the news and came here to say you would have made a great bet, cheers!

Re: Hackers Remotely Attack a Jeep on the Highway

#640

Earlier quoted context omitted.

>Calling the police on security researchers...I honestly cannot believe this is considered acceptable behavior. There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of mak…

I think researchers should have complete 100% legal cover if they test private vehicles and private roads. But as someone who says the car manufacturer ought to face legal consequences for failing to fix a remotely exploitable stall-out in a timely manner (even without demonstration of anyone being harmed), I also say that people who fuck with moving cars on the road are a menace as well.

Depends. For example, in some states, it's still illegal to put someone intoxicated in a car driving on private vehicles on private roads.

http://www.lawyerinlongbeach.com/Torrance-DUI-Attorney.html

Post reply on HN