You might just roll the whole thing back a release, in the first instance to 'update' the hacker to a 'safe' version. If there were a need to roll everyone back then some type of patched new version would need to be released, or, if speed really mattered, just remote downgrade everyone to something safe. The major version numbers might not be the safe releases, the last release from a previous major version might be safer. Hence back to v.12.x.y for him. No malice be involved, just prudent reaction.
It's not malice, it's panic and it's profoundly stupid.
Only those with root access to the car can access the secret info.
There are a handful of people out there who rooted their cars. They are individuals of extraordinary technical ability.
You think they don't know how to make a backup? Or how to stop remote access?
That's exactly what happened. He blocked them and then deleted the pending downgrade.
Would you agree that this extraordinary technical ability individual should be criminally liable in this case?
No.
Cars have had software for a while. Tesla is the FIRST and ONLY company to do over-the-air updates. I don't think you should be criminally liable for turning a feature off.
Sorry, but once you push to production, the cat is out of the bag. I absolutely HATE this new attitude that it's OK to not thoroughly test code before pushing it to production, because hey, you can always fix it later or roll back, right?
No. There's no mens rea. He should be liable for damages in civil court.
What if you are the owner of a building and you decide you want to "optimize" the fire detection/fighting system because you have some ideas in this area, or maybe you want to run an "open" software on it, with better reporting, and as a result some people die in a fire.
Yes, is totally hypothetical, but you seem to be saying that one is not responsible if he does that, because he was just "hacking", with no mens rea.
It happens every time I put more air in my tires.
https://en.wikipedia.org/wiki/Criminal_negligence
In your case, the person was being reckless. I don't think gaining access to hardware you own can be considered reckless, regardless of the unlikely circumstances that may result. Your death-by-rooting example is entirely hypothetical and has never happened.
Just like drone accidents, each year we get closer and closer to an actual kill as their number increases (https://youtu.be/MvF49R_ZX5E). One day heavier drones will be required to run only certified software if flown over crowds, and rooting those drones will raise the same question.
It has never happened? Who cares, what does that matter?
By your logic, if the manufacturer puts out software that is responsible for a death, would you throw the software developer who wrote in jail? That's silly.
All this stuff is limited to civil liability.
If I root my phone and accidentally brick it, nobody here would say, "Gosh, that's terrible, it's all Motorola's fault!" They would say, correctly, that if blame is to be assigned, it'd all be mine.
I think it's even clearer with something where even small errors could be fatal. Anybody rooting a car is betting both their life and those of the people they encounter on their technical skill. It might be an excellent bet, but they should be entirely aware that they're betting.
Yes?
So is every guy who pops his trunk and starts working on the car? And people have been doing that since the very beginning. This isn't anything new.
There are three new things here.
One is that automotive mechanical systems are relatively well understood. If you are a mechanic working on a car, it was literally designed for that. The manufacturer makes manuals explaining how to do it well, and they sell extra parts that are meant to be swapped in. There is a century or so of evolved practice an understanding here. This is not true with drive-by-wire software, which is certainly novel, and is frequently terrible.
The second is that mechanical stuff is generally linear and easy to understand. If I change a lightbulb, I have a pretty good understanding of what that will affect and what it won't. Software is highly non-linear. A novice working on, e.g., a device driver, can have effects they will find extremely surprising.
The third is that in software we have a long culture of consequence-free tinkering. We're used to being able to power-cycle something, to restore from backup, to just re-install the OS. Any software person is going to have a lot of habits and biases that become extremely dangerous when working with life-critical systems.
But in the case of drunk driving, you were negligent at the point of taking the first drink for not making safe transportation (or lodging) arrangements while sober.
Unfortunately from this thread it seems clear that we'll just have some blowhard Tesla manager swearing that "our code is perfect and any change to our code would automatically cause vehicular Armageddon, never mind the fact that we change it on a regular basis!" They won't want me on the jury...