Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

521–530 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#521

Earlier quoted context omitted.

I agree, but I fail to see how that relates to the current context. Unless the unruly bear is these security researchers, the fleeing campers are other security researchers in the same field, and their fleeing is them correctly assessing that some LEA is going to be taking down any bears nearby that even twitch wrong after this. Bad actors ruin it for everyone.

It is true that bad actors ruin it for everyone, and that's why it does not make sense to interact with cops if you have any way of avoiding them. You have no way of knowing which ones are the bad actors until it's too late to do anything about it, and you have no recourse once they have decided to mess with you. Furthermore, they have effectively unlimited resources when it comes to making your life difficult. You s…

If you don't want to interact with the police, you shouldn't do illegal things, or present your actions as possibly illegal.

If you distrust the police to the degree that you think even if your actions weren't illegal you will still have negative consequences from interacting with them, definitely don't do the above.

When someone's actions extend to endangering the public to the degree we see here (which I think is obvious once you've watched the video), they are past any good will I would have extended them in not contacting the police for fear of an overreaction. Their clear disregard for public safety is reason enough for me.

Additionally, on the chance that it was entirely intentional and they are counting on the media and possibly even law enforcement response to help make this an issue, they they definitely don't need our restraint, and nor do they want it.

Re: Hackers Remotely Attack a Jeep on the Highway

#522

To recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention…

Is there anything more human than to react with fear and anger towards scientists who make a difficult problem easy to understand?

Maybe just the desire to extend the lives of those we love.

Re: Hackers Remotely Attack a Jeep on the Highway

#523

Earlier quoted context omitted.

Agreed. I missed the video the first time and didn't believe the text that described the shutdown, video shows the stupidity here, let alone release a recording of it. I expect that will come down soon. Important research but very poorly tested. Wired and Chrysler (research was funded by Chrysler?) legal teams would not like the contents of this video. edit: wired's link to video, jump to 2:00: http://dp8hsntg6do36.c…

So watching the video, I don't see a vehicle stalled on the highway. What I see is a vehicle slowed considerably, but at least nominally over the legal minimum speed of 40 MPH on highways, and without the driver being able to accelerate on his own. He's travelling in the rightmost lane, explicitly with his hazard lights on. This is not an unusual occurrence on highways. He's then told that to regain control he needs…

[deleted]

Re: Hackers Remotely Attack a Jeep on the Highway

#524
I'm not going to comment on the question of whether or not the highway patrol should have been called or not - just say I understand where poster tombrossman was coming from.

However, I fully agree this was a ridiculous stunt. They could have gotten the same results by demonstrating (on the highway, if they insisted) the air conditioner going full blast, the radio, and the picture of the hackers on the screen. Anything else (cutting transmission, obscuring visibility) should have been saved for a safer environment. The point still would have been made.

And it's got nothing to do with the vehicle and driver itself (though I wonder how the hackers knew the exact driving situation - was it plastered with cameras?) - what if two unrelated vehicles got in an accident for some reason and the test driver had to get out of the way, but couldn't?

And to make it worse, the cranked radio made it hard for the tester to communicate with the hackers. Very dangerous stunt.

Also, and I know it was unrelated to this particular hack, but if the UConnect recognizes voice commands (I assume so), and sends it back for processing, then might it not also be able to bug (eavesdrop) on the car's interior?

Many disturbing revelations came out of this, and I applaud them for making it known, but I criticize them harshly for the cavalier way they endangered public safety.

Re: Hackers Remotely Attack a Jeep on the Highway

#525

Earlier quoted context omitted.

Life is hard. Sometimes people don't pay attention. Pulling irresponsible stunts isn't an appropriate response "to make people pay the proper amount of attention." If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1. NB: I highly favor a bounty system where someone who can demonstrate the ability to take over a car without touching it gets paid lots of money, and if…

> If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1. If this stunt had never happened, we'd be in a position where some less-scrupulous actor would demonstrate such exploits on a much bigger scale. I can guarantee you that the total number of deaths from remote hacking of cars would be far greater than 1. If we're going to play the "OH NO THINK OF THE CHILDREN^H^H^…

But you're ignoring the fact that this exploit could have been demonstrated in a safe manner on a racetrack or similar with just as much effectiveness.

Re: Hackers Remotely Attack a Jeep on the Highway

#526

Earlier quoted context omitted.

We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. edit : as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers.…

>We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. If optics is your justification for this, then perhaps having these two irresponsible researchers arrested would bring even more attention to thi…

> "researchers arrested would bring even more attention to this."

Yep.

> Where do you see that in the article? Only thing I read was manufacturers downplaying a wired-in attack they demoed.

No "air gap" between "CAN bus and Internet" equals vulnerable.

We know that. Auto manufacturers know that.

Yet they dismiss the possibility of a hack and continue producing unsafe vehicles. And the trend is toward more vulnerabilities.

I was to lazy to search a direct quote, but here it is now: "Miller and Valasek represent the second act in a good-cop/bad-cop routine. Carmakers who failed to heed polite warnings in 2011 now face the possibility of a public dump of their vehicles’ security flaws.".

Re: Hackers Remotely Attack a Jeep on the Highway

#527

Earlier quoted context omitted.

It's hard to imagine how anyone familiar with any part of the police/legal system's pattern of clueless, ham-handed, hierarchy-ridden interaction with technology over the last 30 years could find justification to continue extending them trust.

Have you seen the damage being caused by "hackers" lately? I don't trust the police, but I don't trust my fellow hackers any more, especially when you consider their clueless, ham-handed interaction with the general public over the last 30 years.

Hackers can steal your money. You may be able to get reimbursed, depending on how they did it. The novel thing about this Jeep story is precisely the fact that hackers are demonstrating an ability to do something worse than stealing money.

The cops can wreck your house, break your stuff, take your money, shoot your dog, deprive you of your liberty, and - if they think they can get away with describing you as a threat - shoot you dead. Even if you spend the time and money it would take to prove in court that all of this activity was illegal and unjustified, most of the time you'll fail, and even if you succeed you'll never get anything back.

I don't trust hackers or cops, but I can sure as hell see which one is the bigger threat.

Re: Hackers Remotely Attack a Jeep on the Highway

#528

Earlier quoted context omitted.

The two options here are not "test on highway with other drivers" and "let flaw exist with no testing and no exposure". There are many ways to responsibly test this while not endangering others on a public road. For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The Mythbusters test stuff like this all the time. What do they do? Use an abandoned airforce bas…

> For example, using a private road, a large empty parking lot, an abandoned airforce base, the salt flats, etc. The researchers did many of these things, according to the article. They were ignored by auto makers.

Did they publicize it on Wired like they did with this post?

I'm reasonably sure that if they had tested in a private track and made a public article it would have the same effect as what they did in their post.

In essence, the publicity factor is the most important, not where they tested it.

Re: Hackers Remotely Attack a Jeep on the Highway

#529
post #2

"...whether the Internet-connected computers were properly isolated from critical driving systems, and whether those critical systems had “cyberphysical” components—whether digital commands could trigger physical actions like turning the wheel or activating brakes." Shouldn't this be the most basic design consideration for any company building autos? The liability from litigation should bankrupt any company that does…

Well self driving cars should be a load of fun. There will be calls to isolate critical components as well as demands they are accessible to the likes of Law Enforcement so they can disable cars remotely. So it will take legislation to sort out as liability concerns needs to addressed as well as the demands of law enforcement. Don't think for one minute they will accept self driving cars they cannot disable all of th…

Law Enforcement can already disable cars remotely.

Re: Hackers Remotely Attack a Jeep on the Highway

#530

Lot of comments here are accusing the "hackers" of negligence, but do not forget the writer, camera crew, and editors of WIRED were fully in control of the demonstration. This happened in the context of journalism, not security research. Blame WIRED if you think they screwed up, not the folks behind the computer. It was up to WIRED to ensure the safety of the demonstration, and evidently they failed given this passag…

This is wired, they sensationalize their stories.
Post reply on HN