Earlier quoted context omitted.
He published the number of the local law enforcement agency. That is not directing an angry mob, that's helping people voice their opinion to the people responsible for enforcing laws.
Bogging down the local police dispatch isn't a responsible way to voice your opinion. Imagine: you're a local and you're trying to call the police. But, you can't, because the number is busy. Or you wait forever on hold, because people on the internet are angry about a reckless driving incident that happened weeks ago and that the police already know about. OP called the police, that's enough. They know about it now.…
Hackers Remotely Attack a Jeep on the Highway
481–490 of 640 posts
Re: Hackers Remotely Attack a Jeep on the Highway
#482Earlier quoted context omitted.
> Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. So condemn the auto manufacturers for putting hundreds of thousands - if not millions - of lives at risk instead of yammering about a couple of nerds who put at most 2 vehicles in probably-nonfatal danger in a worst -case scenario.
Why can't we condemn both? And as busy as that highway was in the video, it was far more than just 2 vehicles, especially if one of those vehicles was the 18 wheeler. At the very least they could have done this on a less busy stretch of highway that had a wide shoulder and with control vehicles in front and behind with paramedics at the ready (just like a movie production that is shooting on public streets). Instead…
Agreed, the researchers deserve some criticism, but let's not lose sight of the forest for these two goofball trees.
Re: Hackers Remotely Attack a Jeep on the Highway
#483Earlier quoted context omitted.
So demo it at a race track. The essential point here is that the uninvolved public were placed at real risk of maiming or death. Your argument is ludicrous, because you're attempting to cast the actors as either good or bad. IMHO they are guys with a good idea and motivation who did a bad thing.
We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. edit : as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers.…
In this article it mentions how Chrysler is working with them and has developed a patch, indicating that they did not dismiss previously done tests. So basically saying the opposite of what I take your point to be.
Re: Hackers Remotely Attack a Jeep on the Highway
#484Earlier quoted context omitted.
> This is especially the case when a safer alternative to demonstrate this exploit easily exists. If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.
And yet somehow the sins of the auto manufacturers in no way excuses the reckless behavior demonstrated in this video. It is possible that more than 1 person/entity in this story is in the wrong. Its clear you've already made up your mind and have posted more than a dozen comments here defending the researchers, so I'm not sure what more can be said. The ends simply do not justify the means.
Most of those comments, however, are only clearing up a specific misconception: the belief that the researchers jumped straight to a "live" test before trying tests in closed conditions. My idea of "right" v. "wrong" does not factor into doing my part to ensure that discussions on this matter are based on accurate information.
My "defense" of the researchers is more just identifying a lesser evil. Between the evil of a couple of nerds hacking one car and the evil of auto manufacturers willingly putting hudreds of thousands - if not millions - of innocent people in mortal danger, I'd sooner take the former (assuming that it actually makes a difference re: security priorities of auto manufacturers; in reality, even this particular demonstration is probably insufficient, though perhaps I'm just jaded).
Re: Hackers Remotely Attack a Jeep on the Highway
#485Earlier quoted context omitted.
This has nothing to do with the type of test they ran and everything to do with where and how they ran it.
I totally agree that there's a problem here, but I strongly disagree with the method of action. Why not engage the FBI? This is not an issue specific to St. Louis. Throwing some researchers in jail solves nothing. This is a way bigger deal than some local offense. You need an agency with the ability to see the bigger picture.
Re: Hackers Remotely Attack a Jeep on the Highway
#486Earlier quoted context omitted.
No, when people's lives are at stake, I extremely disagree about calling that "bikeshedding".
Please make an effort to read and understand my point. Yeah, maybe there was a case when a couple peoples' lives were at stake but nothing happened. The real issue is that tens of thousands or hundreds of thousands of peoples' lives are at stake RIGHT NOW, under conditions that are much less controlled than what people are deriding as uncontrolled conditions. But people are griping about the 1-2 instead of the 10,000…
Re: Hackers Remotely Attack a Jeep on the Highway
#487Earlier quoted context omitted.
> Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. So condemn the auto manufacturers for putting hundreds of thousands - if not millions - of lives at risk instead of yammering about a couple of nerds who put at most 2 vehicles in probably-nonfatal danger in a worst -case scenario.
Why can't we condemn both? And as busy as that highway was in the video, it was far more than just 2 vehicles, especially if one of those vehicles was the 18 wheeler. At the very least they could have done this on a less busy stretch of highway that had a wide shoulder and with control vehicles in front and behind with paramedics at the ready (just like a movie production that is shooting on public streets). Instead…
Nobody's saying you can't. I certainly do (I strongly disagree with the researchers' obstruction of communication between themselves and their test subject).
My only point is that there's a massive difference in scale between a couple dented fenders and hundreds of thousands of dead/maimed innocents.
Re: Hackers Remotely Attack a Jeep on the Highway
#488Earlier quoted context omitted.
Nobody was hurt because they rolled the dice and got lucky. There was a non-zero probability of injury or death that was completely unjustified.
It was a gradual slowdown. That "non-zero" has enough zeroes after the decimal point for Japan to send the number to Hawaii and have another go at Pearl Harbor. Worst-case scenario, somebody might've been rear-ended. Maybe a bit of whiplash. That's not great, either, but seeing as more-controlled tests by these researchers were outright ignored by auto manufacturers, your priorities have to be incredibly out of whack…
Re: Hackers Remotely Attack a Jeep on the Highway
#489Earlier quoted context omitted.
They've risked people's lives to produce real life looking footage documenting a life threatening event. Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how h…
> Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet. Oh really, can you point to the responsible tests that were done in the past that proved inconsequential necessitating this reckless alternative? Or are you just inventing that the car manufacturers would ignor…
Re: Hackers Remotely Attack a Jeep on the Highway
#490Earlier quoted context omitted.
If you read the article, you'd know full well that the researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.
I've read the article. Where does it mention controlled environments? The only mention of exploits being dismissed by manufacturers was in regard to a wired exploit, not a remote one.
The findings before physical tests (identifying cars with a lack of airgapping or other basic security measures) were also reported to Cadillac (as one example among others); said findings were basically dismissed with a "well we've already released a newer Escalade model with some more security features, so whatever".
This isn't to mention that the wired exploits should've been enough to at least spark some level of concern.