Live data from Hacker News

Hackers Remotely Attack a Jeep on the Highway

wired.com

551–560 of 640 posts

Re: Hackers Remotely Attack a Jeep on the Highway

#551

Earlier quoted context omitted.

Dude, have you not been paying any attention to the War on Drugs, or the Ferguson thing or really any of the Black Lives Matter stuff? The cops will fuck with you if they want to fuck with you, and they will write up whatever paperwork they need to write up to justify it afterward. The courts will believe their testimony by default. The only way to get around this is to release video afterward showing that the cop li…

You see, the thing is some of us still believe the the police are staff by people, not some faceless conglomeration of drones that all follow the same horrible behavior, and that while there are some, probably many bad police officers, and many systemic problems, they still serve a purpose, and that life without any form of law enforcement would be a big step back in many, many ways. The amount the media reports on s…

> you're the one pulling an ad-hominem on the police

While I agree with much of the rest of what you right in that comment, this is not accurate: overgeneralizing a negative stereotype of someone other than the other party in a debate isn't "pulling an ad hominem".

Re: Hackers Remotely Attack a Jeep on the Highway

#552

Earlier quoted context omitted.

You seem to be confused. Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists. Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your…

> This is especially the case when a safer alternative to demonstrate this exploit easily exists. If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.

Did you read the article? Here are two quotes:

"Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference."

"WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked when Markey took note of Miller and Valasek’s work in 2013."

Re: Hackers Remotely Attack a Jeep on the Highway

#553

Earlier quoted context omitted.

It can be both, security researchers don't get a free pass just because they are exposing a wrong. Had someone died you might (in countries which have it) get corporate manslaughter on a company that ignored security warnings. You absolutely would on the researchers and the journalist for their reckless disregard for the lives of others.

Yes, researchers don't get a free pass. Nothing is free. They've risked lives and their reputations to save lives. It had happened before in the history. And hopefully it will happen again. Some times it is worth it. (*) without risking lives there wouldn't have been a video documenting these life-threatening vulnerabilities in the cars.

They did not only risk their own lives. They put other people around them at an increase risk when it was unnecessary. That is the argument, that it was not necessary. This same demonstration could have been done on a track or other controlled environment where the public was not in danger.

Re: Hackers Remotely Attack a Jeep on the Highway

#554

Some questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting…

I was thinking about how dangerous it was while I was reading it too, but I came away far less concerned than you I guess. The deceleration on the highway was the most worrisome, but it's not even in the ballpark of common driving hazards like distracted folks on cellphones or flying debris. A crash from such a thing is unlikely and the inconvenience is pretty minimal. Even you, the busybody who called the cops becau…

It doesn't appear like the researchers have access to the car's firmware, so how can they guarantee their code will not have other unpredictable effects? Automotive parts and firmware are put through endless testing before being allowed onto public roads. Why should I have to be at an unnecessarily increased risk of an accident when this could've been done on a track.

Re: Hackers Remotely Attack a Jeep on the Highway

#555
post #396

Earlier quoted context omitted.

Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.

Using violent methods (such as intentionally sabotaging a car on a busy freeway with someone in it) to get media attention in order to further a political goal sounds a lot like the definition of terrorism.

Only if your sense of scale has stopped functioning. It is a dangerous journalistic prank that probably does deserve a telling off from traffic cops, to much the same level as someone who is drunk driving. But I think trying to classify it as terrorism is not helpful or particularly sane.

Re: Hackers Remotely Attack a Jeep on the Highway

#556

Earlier quoted context omitted.

I was thinking about how dangerous it was while I was reading it too, but I came away far less concerned than you I guess. The deceleration on the highway was the most worrisome, but it's not even in the ballpark of common driving hazards like distracted folks on cellphones or flying debris. A crash from such a thing is unlikely and the inconvenience is pretty minimal. Even you, the busybody who called the cops becau…

> "What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early..." which implies that the trucker would have been following too closely or not paying attention (or both). Say there was a person working at a grown-up lab that deals with traffic safety. Like the University of Michigan Transportation Research Institute http://www.umtri.umich.edu/ . The person wants to know what happens when…

I thought in the article they say he gradually decreased speed, slamming brakes is a completely different story.

Re: Hackers Remotely Attack a Jeep on the Highway

#557

Earlier quoted context omitted.

We are a very visual culture, unfortunately. Unless there's a video of your average Joe driving on a regular highway and a regular car going wild, everyone would just dismiss the problem as limited to "race track" and would not connect the vulnerability to his/her own car. edit : as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers.…

You don't get to say that it's fine to put me and my family in danger because hey, in the end it'll make someone somewhere pay attention.

Yeah, you and your family. Well, you are lucky. These researchers and this reporter had already risked their reputations, lives and their livelihoods. So you, now, don't have to. And maybe you'll be even able to benefit from all their hard work, because were would be fewer vulnerable cars around. Although you would probably never know that.

Re: Hackers Remotely Attack a Jeep on the Highway

#558

Earlier quoted context omitted.

You see, the thing is some of us still believe the the police are staff by people, not some faceless conglomeration of drones that all follow the same horrible behavior, and that while there are some, probably many bad police officers, and many systemic problems, they still serve a purpose, and that life without any form of law enforcement would be a big step back in many, many ways. The amount the media reports on s…

> you're the one pulling an ad-hominem on the police While I agree with much of the rest of what you right in that comment, this is not accurate: overgeneralizing a negative stereotype of someone other than the other party in a debate isn't "pulling an ad hominem ".

You're right, so I'll update it to reflect your wording, which I think is clearer, and actually correct.

Re: Hackers Remotely Attack a Jeep on the Highway

#559

Earlier quoted context omitted.

Well, no, the manufacturers didn't ignore them. They responded with a patch, but the researchers didn't like their response. Still doesn't matter though. There are a million shades between quiet disclosure and outright stupidity that would still make headlines. 1) They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so. 2) They could have ensure…

> They responded with a patch, but the researchers didn't like their response. It was my understanding that the patch was released in response to the live highway test, not the prior tests in controlled environments. > They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so. The article makes it sound like they did. > They could have ensured con…

Regarding the patch timeline, the article makes it clear they had been working on the patch for months before this went public.

> Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference.

With respect to letting the driver in on it, it's pretty clear they withheld most information:

> Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch

And with respect to this:

> However, between "do the test with vehicles on the road" and "don't do the test at all", I'd certainly pick the former.

Oh look, another false dilemma. Between those two, I'd pick neither, and do the test responsibly.

Re: Hackers Remotely Attack a Jeep on the Highway

#560
post #60

Earlier quoted context omitted.

The obvious but security-oblivious way to do this is to just connect the entertainment system that has the internet connection to one of the car's microcontroller busses. Even if it just needs to send a single command, it's easier than adding another pin and another wire to the appropriate microcontroller on the other end. The problem is that everything on these busses is completely trusted, and there's no authentica…

Encrypted and authenticated data on the bus won't happen anytime soon for cost reasons. Filtering the commands the controller can put on the bus seams reasonable, but would only be useful, if implemented on a second controller (probably won't happen, either). I think the best approach is to secure the internet connection properly. Don't permit incoming connections at all and just permit a single outgoing TLS connecti…

"outgoing TLS connection to the server of the manufacturer"

That is one of the principles of how Audi's system operates for security reasons.

Post reply on HN