Tesla Car Hacked Remotely from Drone via Zero-Click Exploit
securityweek.com
securityweek.com
To my surprise, the military researcher wasn't particularly concerned about software vulnerabilities in cars and similar vectors. We discussed some specific instances of remote car software exploits. His point was, in essence, that all cars with advanced software can potentially be exploited, but that it's not a real threat because all such exploits require special knowledge, equipment and money. For someone looking to assassinate a specific individual, there are far cheaper and simpler methods that are also more reliable, including several methods that involve physically tampering with a car. For someone who wants to cause mass chaos, such as attacking many vehicles in an area, the researcher estimates it requires the capabilities of a state actor or at least a large organization, and they also have cheaper and simpler ways to plunge a city into chaos.
I also find the outlook a bit optimistic admittedly, but there are definitely plenty of better targets than cars for a sophisticated actor. Car software is very different from model to model, and there's a large variety of models on the road - even if you can cause all cars of model X in an area to accelerate to dangerous speeds (something far beyond the capability of current exploits), that will only affect a small proportion of all cars in the area. It will undoubtedly cause chaos, but nothing on the scale you can get by attacking some weaker systems.
Even a coordinated attack against traffic lights is easier to pull off and has no less potential damage.
As to versions, you may be familiar with Cellebrite? Their stock in trade is having a huge database of exploits for every popular phone. And cars frequently have common software and computing components. It's just a matter of time before script kiddies can pop an unpatched car -- as soon as their is an external wifi / 3g connection. At the moment most only have Bluetooth to the stereo.
I'm curious as to what weaker systems they were thinking about. Obviously the OT at various plants, but that can be air gapped. Most traffic light systems have in built low level safeguards to prevent conflicting states, and the high level system is centrally managed and patched. Attacking requires a multi-stage attack, maintaining access requires continual maintenance, so it just doesn't have the impact an unpatchable vuln in embedded devices does.
And that's back to the original point, if you are looking for such small scale problems, make a spike strip and deploy it on the highway. Same scale of destruction as taking one car over, orders of magnitude less skill and money required.
Cars have standard components, but even for cars that don't take digital security seriously (Tesla has that reputation), no driving functions should be on the same network as the external 3G/4G. Yeah you have the infotainment or door opener there, but any ECU running an ASIL-qualified function should be on a separate network, and treat anything connected to the external world as untrusted. That was definitely one of the core architecture assumptions in all car software I've seen. The infotainment system is considered to be compromised and possibly sending malicious data. All the important communication happens on a different network, where internal signing and authentication mechanisms are also used.
And at that level, the internals are too different for the same exploit to work everywhere. What you need to send on the network to make the car brake, or what data format represents the gearbox position, those are different.
A spike strip, you have to be in the area. A remote attack, you don't have to particularly care about any specific area enough to physically travel to it.. someone can cause chaos simply because they are bored.
And immediately after, they can go do something else.
Tech vulnerabilities aren't yet accessible enough to these types of people, but soon enough they will be and it is not like security is in a temporary poor state. A lot of these systems will remain unchanged for a long time because they are part of an already working business model
A centralised and timed attack against a tech stack that has significant dominance in the market in the future has one of the biggest potential ceilings out there. Cars are effectively kinetic weapons and if you could say, get 30% of vehicles to turn into on coming traffic on a Friday afternoon the outcome could be seriously ugly.
I guess if it was possible to remotely take over or disable the brakes on an entire fleet of self-driving cars then we could have problems. Likewise, if it was possible for school kids to "prank" their teacher by downloading some exploit software from the internet we could have problems. But in both cases you would hope security would at least be good enough that these types of events could not happen.
Remember someone with a bit of knowledge could easily tamper with your mechanical car today if they wanted to. Digital tech provides new attack vectors for someone seeking to do damage, but if designed correctly any new digital attack vector shouldn't present any greater risk than the existing mechanical attack vectors.
In contrast, there are tens to hundreds of thousands of popular car models sold every year. Eg 55k Ford Focus sold in the UK in 2019. https://www.statista.com/statistics/463148/ford-focus-annual...
Just a DOS attack would require every car to be taken by tow truck to the garage or visited by a tech to patch it, and the resulting reputational damage would be huge. I'm sure Ford/Toyota/etc would pay a ransom to avoid that.
In this new scenario, someone could have a remote rootkit loaded on their phone. Trigger it from across a parking lot or approaching the target and then simply walk up to the car and pull anything valuable out of it. They would look like the owner to most observers.
The key here is that one person can make a tool and sell it to many common criminals, and even if the auto manufacturer notices that they are doing this, there isn't an easy way to patch the issue. For something like a Tesla, it's difficult to imagine a software vulnerability that cannot be fixed with an OTA update, but for a manufacturer that doesn't have OTA update capabilities, I could definitely see cyber hacking tools being distributed and used in a similar way.
What?
https://eu.usatoday.com/story/money/cars/2014/03/31/nhtsa-re...
European airbag regulations also allow for smaller airbags that explode with less force since US regulations require automotive manufacturers to assume an unbelted driver. ECE specifications are based on people wearing seatbelts.
I don't know what your point is about airbags. Some sort of weird defence of European safety standards?
The airbag thing was a dig that Americans are too stupid to wear seatbelts :p
I thought the seatbelt thing was a dig at Americans, who I never mentioned, and blatant whataboutism, but whatever.
For the countries with the highest death rates (~80/million), which are poorer former Eastern Block countries, they predominantly occur in urban areas. Making cars 0.1% safer for Germans/French/Swedish, who have >50% of fatalities in the countryside, makes cars more expensive for the whole block, delaying the changeover to cars with massive safety features, like monocoque passenger safety cells, ABS/ESC and airbags.
Incidentally,10% of US fatalities occured where no seat belt was worn.[1] In the UK this was 30%, but with a quarter of the fatality rate. All you can say is that people without seat belts on die.
[1] https://www.iihs.org/topics/fatality-statistics/detail/urban...
It's probably way later than 2005 when pretty much every car included Bluetooth handsfree.
Most of us tech people are good at imagining ways technology might be abused, but we’re not as good at thinking like actual criminals.
It’s a simile story with smart home gear: Tech people go to great lengths to imagine how their smart locks might be compromised by hackers who will break into their homes, but real burglars will just break a window and go around it. Tech people imagine how their wireless security cameras might be vulnerable to WiFi jamming, but criminals will just wear a face covering and park around the corner.
I’m sure high value targets have specialized vehicles where these systems are removed, replaced, or disconnected. For the rest of us, the biggest concern would be if a hack enabled vehicle theft, as that would be more likely to be abused than a movie-style assassination where someone locks up our brakes from a drone or something equally complicated.
Real problem is if attackers would activate ALL alarms in entire city, night after night. Or your "smart doors" would tip attackers that owner is away from home/
most doors can be kicked down fairly easily. A window with plastic foil is only as good as its framing.
I remember reading a reddit AMA from a former burglar and he said that these windows did stop him, because he would be looking to get in and out as quickly and inconspicuously as possible and these would slow him down enough that he would try elsewhere instead.
So, for a random opportunistic burglar, they may work quite well, but for somebody determined or someone with more time (eg if you live in a secluded area and they know you're away for long enough), there's always a way in. I've watched enough lockpicking videos to know its not that hard and enough defcon talks to know that lockpicking is rarely necessary. If someone determined wants to get into your home, they will.
Here's some $50k windows that Nordstrom in Seattle was using that used that film. The windows couldn't stand up to Antifa with hammers, which makes me question the bulletproofness claim. It might not be the same exact stuff that you're claiming, but I'm guessing it is due to the description ("due to their thickness and a protective film that internally self-adheres after strikes or damage"), and that this has happened numerous times to them in the last year and I'm sure they're tired of replacing them and went for the best, strongest windows they could. $50k-70k EACH seems quite expensive for a single display window.
https://www.seattletimes.com/seattle-news/crime/downtown-nor...
I wouldn't limit it to tech people. I hear the same ideas from non-technical folks who are often even more adamant.
And you'd be shocked at how many people don't realize that home burglaries are primarily a daytime activity.
I'm not sure if the fact that most people can't think like a criminal makes me more or less comfortable. :)
In that vein, rogue traffic signs or other objects designed to confuse a car's inputs are probably more of a threat.
There is lots of research in the topic though, so I'm fairly confident most V2V systems will be robust, but it depends on regulation. If they froze capability at a specific 'approved' version then attacks could become serious. Especially for systems using lots of ML, at higher levels of autonomy. At the moment it seems like Looney Tunes attacks (draw a picture of a tunnel with the word TUNNEL on it, paint the road markers towards it) work amazingly well.
Reminds me of crypto-nerd reality:
"His laptop's encrypted. Drug him and hit him with this $5 wrench until he tells us the password." https://xkcd.com/538/
source: https://groups.google.com/g/sci.crypt/c/W1VUQlC99LM/m/ANkI5z... via wikipedia.
For clarity: this exploit isn't to the autonomy or vehicle control system, it's to the infotainment system. It can command auxilliary systems like wipers and doors, and in theory it could do somewhat nefarious stuff like present incorrect data to the user or provide faked waypoints to the navigation system. But it can't actually drive the car.
Really the security model here is fairly reasonable: car control over the motion and autonomy systems is handled by distinct hardware that talks only to one system over a specified protocol, with audited capabilities. And that system then runs the bluetooth and wifi and USB and user interface where the attack surfaces lie.
Doesn't sound that reassuring, though. For a self-driving car it wouldn't matter, but as long as a human driver is in control, the infotainment system does affect motion of the car, by proxy of the driver. Could the infotainment system, or the wipers, make a driver crash their car? I find it highly likely. Imagine speeding down the highway - suddenly, your in-car speakers start blasting your ears with 80dB music, while the wipers start to dance and the car keeps spraying the cleaning fluid all over your windshield.
Or, for a glib answer: if you need to stop the car safely, engage autopilot and unbuckle your seatbelt. The car will turn the hazards on and pull over on its own.
Calling the critical ui interface the 'infotainment' system for a tesla is slightly misleading.
It is directly connected to the 'backend' below and doesn't go through the infotainment system/UI.
You can manually kick off a reboot of the infotainment system on a Tesla while you are waiting at a traffic light, and still drive like usual just fine if the light goes green a second after. The only non-functional stuff will be the visuals on the screen and anything infotainment related (like playing music). All driving aspects are preserved even with the infotainment system being broken/in the middle of a reboot.
ZAP!!!
(Now playing: "I wear my sunglasses at night.")
Hopefully. Remember this vulnerability:
https://www.csoonline.com/article/2951746/hackers-remotely-t...
The initial intrusion was through the infotainment system but from there they moved to the more critical systems.
This is the writeup if you want details, certainly I'm no expert on this particular hack: http://illmatics.com/Remote%20Car%20Hacking.pdf
What I'm saying is that Tesla seems to have learned from that experience and gone with a very different architecture where vehicle commands simply aren't accessible to the public-facing computer, from which motor/brake/steering control systems only get general direction (e.g. waypoints).
That's not saying it can't have a hole. But they don't seem to have made the kind of messup that would permit an attack like the Jeep hack.
Have circuit diagrams?
Maybe. From a few decades in the industry in and around security, I have no faith in assuming that a serious vulnerability triggers any kind of change in the culture that led to it.
Remember Cisco and curl? https://news.ycombinator.com/item?id=19507225
Next time there is a mass scale hack: a few dozen people die, grid lock for couple of days, hardware worth of billions bricked.
And US government can bomb any country it marks as an attacker....
But on the other hand, this was done only by two dudes (even if they did not yield drive control).
I'm not sure that's true. If I were China or the US, I would totally be interested in an exploit that would allow me to hack even a single model across the entire country and set the accelerator to be unconditionally floored and the car no longer able to turn off. Heck, that second one is even optional, given how many people are going to panic. Getting multiple models would be an even bigger bonus.
As others in the thread point out, we have publicly-known instances of companies that collect vulnerabilities. It's hardly a stretch to imagine that state actors already have the vulnerabilities, or even already have this capability essentially turnkey for whenever they need it. I mean, fund a decent hacker group of ~10 people for a year and they could probably build "the button to crash every Tesla, Ford truck between 2018 and 2020, and all Volvos after 2015 on the road in the US"... our impression of how hard security work is is colored by civilian researchers who are incredibly poorly funded. How many of our reports of deeply broken things come from people working in their spare time? I wouldn't underestimate what someone systematically collecting vulnerabilities could do with not much funding, relatively speaking.
The problem is, it's not even that you can turn a whole city into chaos... you can turn a whole country into chaos for cheap enough that it's worth adding to your portfolio.
In my opinion, the only reason to be unworried about that is precisely that there are so many other things that can be done that this somehow doesn't even rate as "interesting" and that is far from good news!
If the hacker could detect speed and make the cars swerve when they've been at highway speed for X seconds, it would be pretty horrific.
For instance. the Aquaducts that feed water to the city of LA go through some deserts north of there that are remote - and the giant pipes are exposed. There are no guards, nothing.
For a state level actor, a small explosive charge on one of those is probably trivial to do and would lock up LA in fear and panic for a long time - and essentially untraceable. Every major metropolis has some equivalent to this (contamination in a specific water supply, or damage to a specific bridge).
Being able to do similar things to vehicles of different types is also interesting, but the space is rapidly changing, and exploits would lose 'potency' rapidly compared to that small block of C4 and knowing someone who would place it for you. So more an R&D type interest than a practical operational capability one.
It's also easy for us to look at the trajectory, know the tech, and say 'this will change the world and we need to be prepared' - but most militaries and intelligence agencies tend to focus on what they already have experience with, or what happened last time. The old quote 'Generals always fight the last war' is very applicable. Part of the reason why is because until it has happened, you don't have any real data - just endless speculative paths, all of which are too divergent from each other to prepare for all at once, and too theoretical to justify funding because the projected costs of it happening are too divergent.
You saw it with COVID - we suspected something like this would happen soonish, we'd even had some scares recently like H1N1/swine flu - but even if you'd asked the most prepper types of us if they'd be willing to spend 100 billion to stop what happened - they'd go 'yeah right, that's not going to happen', or 'that would be a waste of money'
Now, I'm sure you'd get 75% or more of the popular vote on such a measure nation wide and everyone would consider it dirt cheap. Even if the odds of a repeat surprise event are quite low now.
Which is still a body on the ground in one place. These hacks can go country-wide pretty easily. It still seems like something that would be worth digging into because that digital scale can't be replicated by any physical action.
Plus attack-in-depth is a thing. If you can cheaply add "mess up all civilian automotives", you might want to do it, even if you are also blowing up aqueducts and such.
War sucks.
Remember Oklahoma city bombing. It's trivial to do for a couple guys, never mind anyone more organized.
Someone COULD go to the store, grab a hammer, and smash my computer. It's a different type of situation however when someone has figured out what model of hammer they would want, from which store (and if it is in stock or not), how they would pay for it, and who they would call to do all these things in a way that I couldn't figure out who ordered or paid for it, to smash my particular workstation at my home on a specific desk tomorrow at 6am - if they wanted to.
It's important to keep in mind capabilities, inclinations, and consequences - when that person with that plan is playing against me in competitive gaming the next day, I need that workstation to win, and I just bet them $10k I could beat them in front of all of my friends.
Thankfully most of us don't have to deal with this in our daily lives, but we can still be collateral damage when someone else is playing these kinds of games. And nation states do on the regular.
In other words they (that military research lab) have the resources and you don't. Sounds like the ideal vulnerability from their perspective.
In any case, that overstates the difficulty. Plenty of examples of low budget research teams finding remote vulnerabilities in newer cars.
Also, remember that a vulnerability is laborious to find, once. After it's out every script kiddie can do it.
> physically tampering with a car
That doesn't scale. If you're after one single specific person it's done, but if you want widespread ability to cause mayhem, you'll take the remote vulnerability.
> A hacker who exploits the vulnerabilities can perform any task that a regular user could from the infotainment system. That includes opening doors, changing seat positions, playing music, controlling the air conditioning, and modifying steering and acceleration modes. However, the researchers explained, “This attack does not yield drive control of the car though.”
Two things.
I feel the title of the article should have included this information, eg. "Tesla Car's Infotainment System Hacked Remotely.." to make the headline a little less scary.
Secondly, though, can someone explain how "modifying steering and acceleration modes" does not "yield drive control"? This sounds like it does affect the driving of the car.
> opening doors
> changing seat positions
> modifying steering and acceleration modes
> However, the researchers explained, “This attack does not yield drive control of the car though.”These researchers must have a very unorthodox opinion on what driving safety actually is. Hint: it's not only about the driver's safety.
I have a car (2019 Seat Leon) with Dynamic Chassis Control. Modes are Eco, Normal, Comfort and Sport. Of these, only Eco really has any special characteristics like reduced acceleration. So while it may indeed affect how the car drives and steers, it’s nothing dramatic. I’m sure it’s relatively similar in a Tesla. But maybe I’m just numb. :-)
This becomes obvious in a Tesla when you play that racing game on the MCU with the steering wheel as input. It moves the wheels. If the car was drive-by-wire they wouldn't move as thats just causing excess wear for no reason.
I may have the titles of the modes wrong. But the gist is the same.
Not sure about the Tesla, but several other cars[2] have their infotainment connected to the rest of the control systems. So in general, it's not "just" the infotainment system.
[1]: https://www.youtube.com/watch?v=MK0SrxBC1xs
[2]: https://www.bleepingcomputer.com/news/security/volkswagen-an...
I linked the video as the Wired article was behind subscription wall.
The one saving grace here is perhaps "This attack does not yield drive control of the car"... I'd be fascinated to know what the separation of systems looks like in a modern connected vehicle. I'm assuming it's not likely to be physically possible to gain drive control of the vehicle through its infotainment system?
Let the worm spread for a while through the fleet and activate a malicious piece of code at a set moment that accelerates and steers the cars into an object. There's not enough medical personnel to tend to all these accidents. Total chaos.
Am I wrong in thinking that with the passing of time the probability of such an event tends to 1?
What's the bigger issue?
Adversarial manipulation of the sensor inputs. This can be equated to verbal or visual manipulation in humans, something that becomes much harder to detect. While most of these attacks would be against a local target, I could also see a widespread deployment that goes unnoticed and slowly degrades many neural networks, and those being erroneously propagated.
The latter is a much bigger problem than "worms" because it's effectively invisible. We can audit and identify malicious code, there's an entire industry built around that. But, neural networks are for the most part still a black box solution. How does one detect and solve manipulation in a black box solution?
Well, maybe my Tesla will meet your Tesla in therapy and they can talk about it.
What are those reasons?
Edit: downvote for what?
I would imagine that's a certainty.
"sufficiently capable nation state..."
Which I doubt is as many as you're implying given the use of the term "certainty."
"... with the intent to directly harm average citizens."
Which yes, I'd argue is a negligible amount.
Contingency plan: go back to the technology of 50+ years ago. Remember the old unwired unhackable Battlestar Galactica vs the newer ships hacked by Cylons.
Something like https://www.wired.com/story/how-30-lines-of-code-blew-up-27-... applied on wide scale to a developed nation's power infrastructure has the potential for enormous numbers of deaths without the "well obviously the rest of the world will hate us" consequences of nuking someone.
But, private corporations can be wound up. Nobody is ultimately obligated to maintain this kind of work.
If shit hits the fan, then it's not obvious that "Tesla, Inc." will stick around to deal with the consequences. (If it becomes medium-term unprofitable, then it seems to me obvious that it won't.)
I'll add that while I think it's unlikely ANY incorporated publicly traded business would stick it out to deal with the consequences... TESLA seems to have treated medium-term unprofitablity as a consequence of failing to meet quality and production goals without heavy divergence from long-term profitability plans.
The truth is the moment it's technically possible to hack a car remotely, cars will be hacked remotely. We've had computers of all kinds for decades and couldn't manage to make them "hack-proof". Consoles are as close as it gets and I'm sure if they were as critical as a car they would have been thoroughly hacked by now.
Having any kind of "self driving" feature means safety critical systems (acceleration, braking, steering) can be controlled entirely by the car's computer. And having OTA updates means there is some link between that critical computer and the outside world. And in that outside world people managed to hack airgapped computers in a military nuclear facility. If only that facility was "a software company"... they could have CI/CDed the malware in their infrastructure.
No code required.
Fixed that for you.
I wonder if, as we do at the moment with human piloted cars, we'll just shrug it off and offer a passing "poor human" (in the case of injury/death) and continue with our day.
Death is around us 24/7 and I am not convinced even if cars were hacked and told to drive into objects we'd care very much, we'd probably fix the bug and move on.
Tesla is a software company and probably has a lower chance of getting hit due to expertise and funds being poured into security (even tho not infallible as this post shows), but there’s a race to the bottom and soon enough Car companies that couldn’t pull of decent navigation will have some form of computer-controlled-steering as stockholders are looking at Tesla stock price and breathing down their necks.
I have been worrying about this for some time, even tho I am also a tech lover and Tesla driver. was thinking of writing a blog post about this, but seeing this comment, maybe it isn’t a new thought and everybody is already aware of this risk.
I think you are right about medical personel. But also: if you make everyone crash around rush hour, you take out a significant share of the working population. And how do you clean up the infrastructure to let trucks and ambulances through again. Not to mention the catastrophe of cars crashing into stores and pedestrians in city centers.
You're forgetting to factor in the human element. Technology doesn't progress independently. There are dampening effects when the "real world" decides technological possibilities don't fit the world they want (for example, copyright applies artificial limits to the infinite copying potential of digital assets, or the recent EU politics around AI).
So I suspect relatively isolated cases like this will eventually lead to a push for legislation on automotive digital security. Cynically, I suspect in a way that raises barriers to entry to the market after the incumbents have secured their market share, but that's still probably better than the alternative.
No good for self-driving cars though.
Yeah, if you have visions of the Joker hacking control of the Batmobile turning into a large RC car then we are safe from that. But that’s far from saying that remote control isn’t an issue.
The new thing with some current and most future cars is that everything will be controlled by a computer that has software that is connected to internet and even Wi-Fi, which makes it prone to "computer hacks" we know so well.
From that point, the problems being faced come from both worlds: car world (stealing, accident, ...) and computer world (access to location or cameras, ransomware, ...).
Seems safer for the customer than a spike mat or a shot to the tyre.
It can be rometely shut down?
It can be found via gps information?
Wealthy owners can afford Lowjack.
(I actually don't know, and to lazy to research. Just going off stuff I've heard here.)
If I had a big enough faraday cage, a flat bed, and winch; it might be an appealing target though? Oh yea, a lot of motorcycles are stollen by two guys lifting the bike onto a pickup--locks, and all.
It's not about having a working exploit you can monetize. These hackers aren't gonna steal cars. They're showcasing their skills and picking their targets for that purpose.
Had they hacked a Daweoo wearing Chevy clothes or an FCA product nobody would blink twice. The comments would all be people saying you get what you pay for or repeating the typical Reddit tropes about the big3 being crap.
They picked one of the brands that starts with T, ends with A because those brands are sacred cows of the upper middle class and have rabid online fan-bases who will greatly amplify and publicize these hackers work.
Jeep hack (part of FCA, that doesn’t exist anymore BTW - it’s Stellantis now) was a huge huge thing.
Here's 2 antennas in a Model S mirror: https://teslamotorsclub.com/tmc/attachments/img_0748-jpg.211...
In Cuba, I got a chance to ride on some 60's cars. Looks amazing but it's essentially a pretty metal can accelerated to highway speeds.
There's no going back to pre-electronic, even pre-computers era if safety is a concern.
Airbags, crumple zones, belt pre-tensioners and all the other high tech stuff that the internet worships are basically a rounding error compared to "a strong cabin and some basic stuff to keep the occupants in the right place inside it".
https://www.iihs.org/api/datastoredocument/status-report/pdf... (starting page 4)
These days, even the cheapo cars have stuff like ESP, Crash Prevention, Blind Spot monitoring, Lane assist and more systems that compensate greatly for driver skills and human errors.
The electronics are good at crash prevention and in the pre-electronics, the crash prevention is non existent besides for lightning, markings and the horn.
Also, you don't need to get a 60s car. Any car up to early 2000s (and many models even into earlier 2010s) is still safe from remote exploits while having all the benefits.
...
Very strange position when Intel sinks 7 digit sums into salaries of top tier computer programmers working on it.
Does it do it for nothing then?
It's these situations when people can't tell what the heck they are doing what they do for for $200k a year which signal of company's dysfunction.
It's desktop usage is abysmal with no GUI supporting its up to date API.
Where the use-case was a simple connect to that fucking T-Offline hotspot at the edge of reception and automagically point some browser tab to the captive portal, FAST! Also RECONNECT fast!
That worked for me.
Demanding that employers be somehow magically responsible for the community contributions of their employees in perpetuity is the easiest way to make sure employers never let their employees contribute to the community.
Whether ConnMan, which is semi-abandonware now, was a good choice for Tesla to have integrated is sort of a different question. Personally I was never a fan. But that's the magic of free software, we all get to choose what works for us.
Seriously, the warranty disclaimer is is really clear in the GPL. They even put it in caps:
NO WARRANTY
11. BECAUSE THE PROGRAM IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
12. IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MAY MODIFY AND/OR REDISTRIBUTE THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
https://www.fastcompany.com/28121/they-write-right-stuff
The software running our cars should be the most bulletproof in existence. Literally millions of lives hang in the balance.
Maybe it has. Could it be that you could remotely hack the current space crafts, but nobody is allowed close enough for bluetooth to work?
Egad :p
State actors can destroy buildings, so I guess we shouldn't make buildings /s.
Or less sarcastically, state actors can compromise laptops, so I guess we should stop allowing "over the air" security patches to laptops? Should we just stop using computers?
The reality is that state actors murdering people is an incredibly low risk threat. If state actor really want to kill someone, that is, assassinate someone, they can do it with a gun or a poison or whatever. If state actors casually want to kill one person, finding novel exploits is a pretty expensive way of doing it. If state actors want to kill a lot of people, you're basically at war, so we can use actual weapons.
Laptops and buildings are a necessity, while cars with wireless modems and always on internet connections are not. All the usecases are solvable with Apple/Android/Car with infotainment serving as a dumb terminal, without any connection to anything important in a car. Since we already always have government surveillance devices on us (mobile phones) why add additional ones, which have the ability to crush us into oncoming traffic? Cars also had perfectly functional navigation with SD cards.
>"over the air" security patches to laptops?
Yes. Over the air security patches are a very very bad thing. The fact that this issue still hasn't been solved is a disgrace, with all the formal verification advances. Still laptops are a necessity, and can't kill us directly.
>State actors can destroy buildings,
That's not very plausibly deniable method. Buildings don't collapse or blow up by themselves. It leaves lots of material evidence of foul play.
>with a gun or a poison or whatever.
Not if they want to avoid suspicions and make it look like it was something natural, which is almost all the time.
>murdering people is an incredibly low risk threat.
Not if you are an activist and are up against an authoritarian regime, which can even follow you abroad. There is also surveillance you can't turn off like you can with a phone -- i.e. you can't talk with people in a car about anything important.
Hear hear and well worth repeating.
I’m waiting for the (probably not too distant) day when insurance companies demand access to car telemetry in order to obtain reasonable insurance rates.
Tick Tock…
Literally yes.
To do a code exploit you need to find something, sit on it hoping its upatched, and then hope nobody can figure out that you did it when they do their extensive analysis of why a car suddenly did something extremely rare and dangerous, else you lose the exploit.
In absence of anything else, and cleaned up dram + fake logs is really an absence, it's always ascribed to driver oversight, distraction, loss of control.
>Realistically both methods leave evidence.
Yes, computing leaves "evidence" in form of heat(entropy).
That someone could hack into a car, force it to drive into a guaranteed lethal accident, and successfully remove all traces, and manage to fool the telemetry analysts into thinking that it was just a fluke when things like this never happen is extremely improbable to me.
If they didn't stop in time, you'd have the risk that the accident wouldn't be fatal. This can easily lead to an investigation and a failed assassination.
The lowest risk option is the one that works every time, despite how fun the movie plot scenarios are to think about.
When I was younger a “Tesla car” would have been Nikola Tesla’s rumored car that drew its power from the earth.
However, the researchers explained, “This attack does not yield drive control of the car though.”
General purpose computers do general things. As much as people say things like 'safety first' or 'security first' (do people even say security first?) it is quite clear that getting products to market is the priority. If you don't get to market, then security doesn't matter.
As you add components to a computer enabled product, you add surface area vulnerable to attacks. This would indicate that you should have a small number of well designed and tested components, but remember your product does not exist in a vacuum, a competitor will release a product with more capabilities; customers cannot easily compare security, but they can easily compare a feature list and a price point.