Hackers Remotely Attack a Jeep on the Highway
wired.com
wired.com
1) Were public roadways and speeds of 70mph absolutely necessary to demo this?
2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others?
3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting the researchers with questions about this demo if they weren't consulted in advance.
4) What's the plan if they trigger a bug in the car software of the people they had tested this with earlier? The article mentions them tracking people remotely as they attempt to learn more about the exploit.
I could go on but why bother? In case any of you think this was cool or even remotely (no pun intended) ethical, I'd like to know if you have a problem with letting these two test this on a loved one's car. How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything?
If I ever learned this had been tested on a vehicle I was in, I'd make sure this cost the researchers dearly.
EDIT: I've just phoned 'Troop C' of the Highway Patrol at their main number, +1-636-300-2800 and they seemed pretty keen to follow up. The fact that the vehicle was disabled where there was no shoulder, was impeding traffic, and the demo not cleared with them in advance has them concerned. I'm all for testing exploits and security research, but this isn't the right way to do it. And to film it and post it to a high traffic site is nuts.
There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.
At some point you probably want to test it at highway speeds. I agree that a closed course would be the only responsible option, however.
Reckless yes and still probably not enough....
I believe people will need to be killed, or get their cars destroys before the rest of the population takes enough of a stance against "neglecting" security.
I agree with you, i hope that the author was lying to make his story more interesting (hows that for a bad wish).
I completly agree with you, seems to have a total disregard for anyone elses safety.
Reckless in many, many ways, no matter how interesting the story actually is. In fact it's so reckless that it actually devalues the interesting and important core of the story itself.
Because - according to the article, at least - they'd already demonstrated similar exploits in more controlled environments, and said demonstrations were handwaved and dismissed by the auto manufacturers.
However, there's some usefulness to the higher speed, since it indicates that the car can be isolated among highway traffic even at high speed. The researchers were also smart to not slam brakes (which would have turned the minimal danger from unpowered coasting into the maximal danger of sudden stops).
I wonder if the reporter just added in those details about the highway to make it seem like more of a real threat or if they actually did test on a busy public roadway.
edit: Found the video - https://www.youtube.com/watch?v=oqe6S6m73Zw
People won't pay attention until they're scared
People won't demand action if they're not paying attention
Nothing will happened if people don't demand action.
If nothing happens the status quo (vulnerable systems) will remain. Until some bad actor (I'm sure several nations states would love that capability) gets into onStar and turns every connected vehicle (every GM made in the last 8yr or so) into a brick at an inconvenient time (rush hour on a monday).
>I've just phoned 'Troop C' of the Highway Patrol at their main number, +1-636-300-2800 and they seemed pretty keen to follow up. The fact that the vehicle was disabled where there was no shoulder, was impeding traffic, and the demo not cleared with them in advance has them concerned. I'm all for testing exploits and security research, but this isn't the right way to do it. And to film it and post it to a high traffic site is nuts.
I'm not sure if you're actually this dense or just trolling. What good can involving the police, after the fact, in a situation where nobody was harmed do?
To clarify: If a story involving events of questionable legality, no matter how small to were hit the news the police would be obligated to investigate on some level. Think about the kind of message that "we saw it on the news but we don't think it's worth investigating" would send. By informing them before it hits the general news, one enables the "swat teams and more" knee-jerk response that the police love (if I had cool toys I'd want to play with them too) but without any media scrutiny. For example, law enforcement was plenty eager to screw the guy that "hacked and airplane" (through similar means I might add) until the story became more widespread and they had to use their discretion to act in a manner that would not reflect poorly on them.
By alerting the State Police in advance they're
I don't expect this to hit the news. University of IIRC Michigan (something with an M) was doing similar things at closer range (bluetooth) on a test track back in 09(?) and nobody cared.
And for all the people saying they were "reckless and dangerous, etc, etc," sure, yeah, to a small extent. If they wanted to be reckless they'd have made the car go instead of stop, swapped left and right on the electronic power steering, disabled the brakes on one side or end of the car, etc, etc.
The hackers may have crossed the line if they disabled the engine on a narrow stretch of a busy highway. It should be investigated.
People who do one reckless thing such as this demo are likely to do others. Calling the police about this incident means that they'll have a record of the people doing this, and if it becomes a pattern, handle it considerably harsher than an isolated incident.
I don't know, maybe if they get in trouble the next researcher who wants to do a test by disabling a car doing 70mph on a public road will maybe just alert a few people and make sure that it would be impossible for someone innocent to die during their testing.
I was with your comment until you called the GP dense or a troll. Because to follow your logic, to get action, they should've just actually killed a random person. Then you'd be right, we would get some changes, pretty quick.
Who do you think should be the random person to get killed for change?
If we decide now, then it wouldn't be a random person, now would it? :)
However, the goal of people researching security, shouldn't be to make news. And these people while admittedly working with Chrysler to see it fixed, seem to be forgetting that. Especially since they plan to release their code, despite the fact that Chrysler has to get people to manually update their cars.
"The two researchers say that even if their code makes it easier for malicious hackers to attack unpatched Jeeps, the release is nonetheless warranted because it allows their work to be proven through peer review."
Their justification for releasing their code, as someone who works in peer reviewed industries is weak and they clearly are prioritizing attention over security at this point.
However, they do need to make the news. Them making the news makers it easier and more likely that politicians will prioritize the political capital of working to solve this over the lobbyist from the automotive industry.
If Chrysler and other car manufacturers were taking this sufficiently seriously the releases might not be necessary. They gave Chrysler plenty of warning, Chrysler could have issued a recall (and still can), the consequences are on Chrysler, not on the security researchers.
Chrysler seems to be taking this sufficiently seriously enough that releasing the code will do more harm than good. Could they take it more seriously? Well everything can always be taken more seriously, and someone will always claim it should. So I will say that's a matter of opinion.
EDIT: If their plan to 'release their code' is nothing more than a bluff to raise awareness I would consider that a much more appropriate course of action.
This assumes many facts not in evidence.
It may, in fact, be the best thing. But security people, as a rule, are strongly biased to love things that increase the social standing of security researchers, and chaos does that.
There are other ways of pressuring the car companies. I'd like to see companies failing to fix disclosed security holes in safety critical applications in a certain period of time face monetary damages, even without need to show harm was caused.
But lobbying is boring and getting on the top of HN is fun.
I think the problem is related to core competencies (sorry to throw in the MBA speak).
The old-school car companies are good at making cars, and not secure computer systems.
You can likely say the same about the skill sets of the decision-makers running these companies. Many of them just can't wrap their head around security implications, because they don't fully understand them.
The car companies' failure to patch defects ought to have them facing severe fines. In fact, I would support a bounty system of millions of dollars for researchers who can demonstrate 1) finding a flaw, 2) telling the company, and 3) the company not fixing it in X months. All this finances by fines on the car companies.
The above facts doesn't mean that what these guys did was okay.
You're completely right, but the key phrase in your sentence is "mechanical failure".
I've worked on analytics projects in the automotive industry for analyzing defects before they get into the "campaign" (aka recall) stage. They are incredibly good at that type of analysis. Most mechanical parts "make sense", since they're designed for only a few functions.
An Internet connected computer and software, on the other hand, doesn't always make sense to auto execs because they are significantly more complex.
As it relates to the article, I wouldn't be surprised if the car's computer system was perceived more as just a part having a particular set of features by Chrysler's top executives than as a computer system requiring the same types of security controls as, say, an ATM would.
Maybe, maybe not. All they need to get eyeballs is a linkbaity FUD headline with a few extra scary sentences thrown in.
It's not as if the TV news doesn't already do this with their teasers for "Is eating too much XYZ going to kill you? Find out after the commercial break" only for you to find out that the story about XYZ is overblown and poorly vetted.
PS - Plus due to the flatness of these roads, with large de-facto shoulders you can pull off onto, they're much safer even ignoring traffic levels.
If they had done this in a parking lot at 25 MPH with a couple cops present, the way Mythbusters does things, they would have ONLY had a story about hacking a Jeep to shut it down. And if they played their cards right, they might even be able to start some LEO contracts for car-disabling equipment.
Are we still on Hacker News, or is the transformation to Enablers of Traditional American Power Structure News complete?
Being a security researcher or journalist doesn't give you a license to put the public in physical danger.
I can't wait for the pathetic outrage when "racial profiling" now means harassing white kids with laptops that fit the profile of hacker.
This is a matter for a company like Google to take on politically, not some beat cop in St. Louis of all places.
Why not engage the FBI? This is not an issue specific to St. Louis. Throwing some researchers in jail solves nothing. This is a way bigger deal than some local offense.
You need an agency with the ability to see the bigger picture.
This basically suggests thousands of cars could be driven off the road and deliberately crashed right now. I'd say that's a threat that they need to deal with at the national level on an immediate basis.
Would you rather wait for a malicious actor like North Korea to get involved before the FBI makes a move?
What I'm trying to say is I'd rather the FBI gets involved and works with these researchers to develop an expedient fix for this problem than some beat cop in St. Louis to bust them and throw them in jail where they help nobody and the threat remains extremely grave.
* Cops are under no obligation to go into harms way to protect the public.
* Cops primarily exist to collect evidence for prosecution after the fact.
* Just because criminals and crimes exist doesn't take away from cops' bad behavior.
* If calgoo becomes the victim of a crime, cops are unlikely to be able to make him whole again - for bodily injury, prosecution of the perpretrator can't restore his body or life - for property damage or theft, police usually can't be bothered with the small stuff.
Have you seen what happens to communities when police withdraw? They become overrun by gangs and other less accountable organizations.
Even favelas where cops act paramilitarily, say in Caracas, people still want cops because no cops is usually worse, unless you get a private version of cops, which is essentially cops by another name.
(Of course, even if it's not an exaggeration and even if it reflects the actual probabilities of getting hurt by cops and criminals there, it does not follow that things wouldn't be even worse without a police force.)
I will still call the police in the future, but just so they can fill out a police report for insurance claims or potential law suits. Other than that, I don't expect the police to do anything unless they were on the scene and saw somebody break the law.
And even then, one of the times when my car was vandalized, the cops were there and they filed a police report and told me to try to figure out who will pay between the two dudes that jumped on my car and if that doesn't work, give the officer a call and he will help me with the next steps. Obviously those guys didn't wanna pay so I tried to get in touch with that cop and he was avoiding my calls. I called over 10 times over the course of a couple weeks and he was never there and never returned my calls.
Another time my neighbor was throwing eggs at my motorcycle for 3 nights in a row and I got him on video, call the cops and they come by about 12 hours later and just laughed at the video, and then all of a sudden got a call to something more important and bounced. It may seem funny, but me having to pay someone $300 to clean egg out of all of the fairings and tubing is not funny. At the very least, do your job and file a fucking police report.
Old habits die hard.
Calling the police will not have them go to jail or have their data deleted. It might (rightfully) get them a fine. It will however ensure that their next experiments are done in a safer, more legal way.
Calling the police isn't all about emergency. You can call them to talk about issues that worry you such as this one. They will take care of bringing the issue the the right entities, it's their job.
Or not done at all.
I may not fully agree with their methodology but I'm thankful this work is being done by people with good intentions instead of having these issues come to light when people with malicious intent find the vulnerability and kill or maim countless people.
> Calling the police will not have them go to jail or have their data deleted.
Do we read the same Internet news? Having seen the way the law enforcement + prosecution machine works in cases like Aaron Schwartz, I would be surprised if these researchers did not spend time in jail, and didn't at least face charges of some Serious Nature.If there's a case to be made, the police will build it. If they build it, the DA will prosecute it, and there could be (is going to be?) things like charges under the CFAA, since they could certainly try the perspective that the access needed to be authorized by the auto manufacturer, rather than the owner of the car.
I could totally see how invoking the power of the police on these researchers could, through the kind of progression we've seen many times before, destroy their lives. I really hope that's not the case -- I'd much rather they got some kind of warning like, "Don't you ever do this on a road with other people on it again". Even so, I agree with many others that their actions were pretty reckless, more so than I realized when I first read the article. This is the kind of thing that should have been done on a private test track, and doing it around others was reckless and negligent.
Having considered how dangerous their little stunt was, I'd almost expect them to be sentenced to some gaol time. What they did was pretty darn Serious!
You cannot simply test a car like that on the highway. There are privates road, abandoned airports, big parking lots that are more suited.
If prior HN articles are anything to go by, it's a matter of time before SWAT kicks down their doors, beats them up a bit, and maybe even a few officers "fearing for their own lives" (yeah right) take a couple of shots in "self defense" against unarmed nerds.
You're delusional if you trust in a law enforcement agency to take reasoned and measured action in any situation.
This isn't really engaging with his action. Specifically, because called the cops because he believed that their methods put people in danger of physical harm. This objection isn't coherent without an argument either that:
1) He was unreasonable in his belief that they'd put people in harm's way.
or
2) It is not appropriate to contact law enforcement as a result of observing one person put another in harms way.
I'm guessing you're arguing both, correct?
aside: He contacted the state highway patrol, not the local St. Louis police. aside2: Hi Geofft! How are things going?
My argument is roughly that we don't know for sure that people were put in harm's way, and we have good reason, as hackers, not to trust the legal system to reliably figure these sorts of things out (and they generally fail in the direction of being worse for both individual researchers and society of a whole). If we did empirically find the legal system reliable and fair, I'd be more convinced that the threshold for objecting should be "unreasonable".
The action is also over right now, and I see no indication that they intend to do so again. So this is either about punishment-as-retribution, or about dissuading future researchers from doing similar things. I don't think retribution is particularly justifiable, and I think there are better ways to dissuade future researchers, like having a conversation about it without the police involved. So I guess I'm arguing the specific sub-case of 2 that if they don't intend to put someone in harms' way again, law enforcement isn't necessarily right.
(You're right about the highway patrol thing, btw. I think I had it confused in my head with some other recent public/police conflict where the highway patrol was worse than the local police, but it looks like the opposite was true of the Ferguson protests.)
The researchers could have achieved the exact same results (albeit with fewer clicks) by conducting this experiment in a remote parking lot or a private road. Heck, if the writer had contacted the cops, they could have given him an escort to make sure nothing bad happens.
If you ask me, it is this kind of behavior that makes the work of real researchers harder, as the media is quick to paint all security researchers as clueless nerds who will put people at risk.
According to the article, the researchers already did as early as 2013. Auto manufacturers ignored the reports while continuing to pretend that their vehicles are secure.
If I were an auto manufacturer, I wouldn't wait until someone finds a wireless exploit (at which point it's too late to do anything about it before people die or are maimed unless I'm lucky enough for the zero-day to be found by a white-hat or grey-hat). I'd see those earlier reports, say "holy shit if we have one wireless bug, the whole car could be pwned", and start working on a better isolation of critical systems from internet-connected systems immediately.
Sure you do. This is why large businesses (smart ones, anyway) require employees' smartphones to be locked with a password or PIN. This is why standards like HIPAA require secure data to be encrypted at rest. This is why laptops being stolen from government agencies leads to things like millions of confidential records disclosed (true story).
And you're still missing my point: that the likes of Toyota and Ford are relying on their wireless systems being secure. That's reckless, since now their wireless systems are the single point of security failure. The lack of even basic safeguards, access levels, etc. should a breach occur is the point of this article, more so than the specific UConnect breach. Having only one layer between "secure" and "pwned" is by no measure a good idea.
Calling it a disagreement over methods glosses over the real issue, which is that it was a dangerous exercise and its perpetrators apparently don't have sufficiently good judgement to be left to their own devices.
Was it a stunt? Yes. Was it life threatening? Hardly. The real risk is the early 90s Civic with a torn up clutch and bald tires swerving between lanes.
Uhh what? It seems you cannot go a week without reading about a pile-up on a freeway. Just last week a big-rig lost a wheel, it rolled into the on-coming lane, and drivers swerving and braking to avoid it actually caused a pile up. Stopping even on the shoulder on a freeway is considered "risky" by most police officers and many (like triple digits) have been killed while stopped in the shoulder due to vehicles drifting, failing to pay attention, or otherwise being distracted.
I cannot remotely begin to fathom how anyone can think a car going 0-10 MpH on a freeway ISN'T dangerous. And it is absolutely life threatening. If a car behind didn't notice the change in speed, panicked and either hit you or the concrete barrier(s) that could very easily cost them their life. Or leave them with life-long disabilities. Bigger things like trucks and those "road-trains" are even bigger liabilities.
Honestly I'll defend security research strongly in almost all contexts, but when you put people's actual lives in danger you clearly cross a line. There's no shades of gray there, endangering people's lives and health to effectively show off is absolutely immoral and should be illegal (and likely is).
Saying "well nobody got hurt" completely misses the point. It is the intent that is wrong, not the result. The result could have multiplied the wrongness of the intent and resulting in tens of years of jail time, but luckily for them their only "crime" this time was the intent of their dangerous actions.
And let's be frank here luck is the only reason nobody got hurt. The only reason why these two won't be in jail for many years.
Impeding traffic is a misdemeanor in Missouri, probably rates a maximum 1 year jail sentence (note 6: http://www.nhtsa.gov/people/injury/enforce/stspdlaw/mospeed.... )
Here's a scenario:
Let's say a person is driving a car, when their car engine fails. There's no shoulder for them to drive onto, so they are just slowly decelerating when they are rear-ended by a vehicle behind them. Would you say that the car that had a mechanical failure is at fault, or the person behind them who wasn't paying attention is at fault?
So the people that purposely tried to cause the accident wouldn't be at fault for the accident if it occurred..?
I find it highly amusing that in your scenario you're using an unpredictable failure as an equal for an intentional act.
A better scenario would be:
I open your car bonnet while you go to the bathroom. I half-cut some cables knowing that they will fail when you knock them a few more times. You come out, get in your car, and drive down the freeway. A few miles later your car stops suddenly in the fast lane, and a big rig crashes into you while you sit there stopped going 70 MpH and you die. According to you I am not, at all, responsible for your death.
Or better yet still:
You just stop on the freeway just for fun/see what would happen. Someone drives into the back of you at 70 MpH and THEY die. According to you, you aren't at all responsible for that.
This would be a completely different story if the researchers applied full force to the brakes or accelerator since those are unexpected (to other drivers), sudden, and difficult to react to behaviours.
It isn't that convoluted to hold the driver responsible for the vehicle, they knew prior to driving into the area with a minimum speed that there was some intent to tamper with it.
Legally, you are required to do what you can to avoid accidents.
Ethically, it's all kinds of fucked up when you rationalize with "well, if someone goes wrong I can blame someone else."
What if their proof-of-concept didn't work as predicted and did slam the brakes? This is just a reverse-engineered hack that was unleashed on a highway while the radio was blasting too loud to hear each other on the call.
This test could have easily been done on a closed test track or heck, even a large parking lot.
There are autonomous vehicles being tested on our roads with a failure mode of "coast to a stop". They may not even have a human inside to react to things around them. Do the operators deserve to be jailed?
People modify their cars with various after-market upgrades and take them onto the highway. If the car fails, do they deserve to be imprisoned?
What a slippery slope!
Driving is a risk. The most deadly risk you will take each day. Drive defensively, don't be a statistic.
The people testing self-driving cars had IRBs that go over their test cases. Do these guys even know what IRB stands for?
You might want to review existing laws. See, e.g.:
Georgia: http://law.justia.com/codes/georgia/2010/title-40/chapter-8/...
"O.C.G.A. 40-8-7 (2010) 40-8-7. Driving unsafe or improperly equipped vehicle; punishment for violations of chapter generally; vehicle inspection by law enforcement officer without warrant"
Ohio: http://codes.ohio.gov/orc/4513.02
"(A) No person shall drive or move, or cause or knowingly permit to be driven or moved, on any highway any vehicle or combination of vehicles which is in such unsafe condition as to endanger any person."
California: http://www.leginfo.ca.gov/cgi-bin/displaycode?section=veh&gr...
"24002. (a) It is unlawful to operate any vehicle or combination of vehicles which is in an unsafe condition, or which is not safely loaded, and which presents an immediate safety hazard."
This research appears to have happened in Missouri, where it's harder to find the actual laws on the subject. That said, I did find this: https://www.mshp.dps.missouri.gov/MSHPWeb/PatrolDivisions/MV... which tends to imply that there are laws to this effect that I cannot easily locate via internet searches.
Danger Checklist:
✔ 70mph
✔ Public highway
✔ Driver not in control
I have a 26 mile daily drive, all high-traffic interstate freeways, and I can usually count at least two occurrences per day where I have to take evasive action to avoid a collision – people illegally on their (hand-held) phones, people blowing across three lanes at 75mph and not even bothering to check their mirrors, drivers leaning over in to the back seat on the freeway, people who drift into the wrong lane in a concurrent two-lane left turn, people who tailgate leaving mere inches between them and the car in front of them despite you having nowhere to go, people braking as if their car weighed half of what it actually weighs, et cetera.
I'm honestly not sure what the solution is, but it's (i) legitimately terrifying every single day, and (ii) hard to believe that any other kind of transportation modality would accept the kind of outcomes that humans driving on the US interstate highway system produces.
If we're going to condemn researchers for potential danger, then we might as well extend the same courtesy to car-driving AI and the makers thereof.
You really really don't know this.
If this was done by an actual research lab staffed by adults, it would never have gotten past the ERB.
Back to the article, I think that this type of exploit will become more and more common as vehicles become more connected and automated. We need to know that we can trust the software and firmware running on the devices that literally have the power of life and death over us. Unfortunately, this is a VERY complicated issue, and no one has a solution yet AFAIK.
I watched a talk by Cory Doctorow last year where he suggested validation at the hardware level (a la trusted platform modules), but unlike the typical TPMs that only allow vendor software to be authenticated, these TPMs would allow the user to directly authenticate the firmware. If you know the firmware is good, then each layer can validate the next layer up all the way to the OS.
I have yet to hear of a system that allows the user to directly authenticate software/firmware at the hardware level. Is anybody working on research of this nature? Or are there insurmountable problems with this approach?
Not conducting this demonstration on a public highway would also have been a much less aggressive and thoughtful move, not to mention less dangerous.
Reminds me of people who will call the police on a loud neighbor instead of just, you know, talking to them first.
The driver was clearly distressed and they were just laughing it up.
This has no bearing on the original issue ('Calling police on security researchers'), but I'm just saying that you can't debate nicely with everyone.
I think it's 100% OK to test on a private car on a private track.
Was it a hacker? Nope, just a dumb mechanic that got trash deep into the air intake during a routine oil change.
How many (dumb mechanics)*(routine oil changes) are there in this country? Five-Six orders of magnitude more than auto hackers, which is why I don't see any harm in one more (where the driver knew ahead of time it was going to happen).
Here's the good test: since humans were involved, how did they present this to their ethical review board?
I'm pretty confident the answer would be "what's an ethical review board?".
These people, on the other hand, knowingly and deliberately disabled a car on a highway. Yes, they had a plan, but they are still running their little experiment on other unwitting drivers on the highway. I don't consider the manner in which they ran their test to be ethical; it should have been performed on a closed track.
You can't just waive it away because other risk is more dangerous across the entire nation. Under that standard: One little murder is a rounding error compared to the 2.5 mil who die each year.
I agree with what others have already said: Since nobody was actually hurt he should have contacted the researchers to make his point.
We are here not an intellectual debate club were people take pro and contra sides and points are distributed based on the rigor of the argument, but discussions around here are about real world problems.
And somebody calling the cops on security researchers just because he read an article on the intern is in my view highly questionable behavior for somebody familiar with the tech community.
The right way to do this would have been for the researchers to call the police up front and arrange a demonstration on a closed road with police escort. That would have lent the video more credibility and shielded the researchers from liability, while addressing any concerns about safety or ethics.
There is even a bigger problem. These researchers, even if they were negligent, are far more at risk of legal punishment for creating a small risk for the sake of increasing safety standards overall than the people who choose to cut security funding and put magnitudes more people at risk for the sake of making more money.
Isn't it odd that we have a legal system where the ones attempt to expose and fix the problem for the sake of safety are facing far greater legal trouble than those who knowingly allowed for the problem to first occur due to increasing profits?
But as someone who says the car manufacturer ought to face legal consequences for failing to fix a remotely exploitable stall-out in a timely manner (even without demonstration of anyone being harmed), I also say that people who fuck with moving cars on the road are a menace as well.
Security researchers should only be liable for potential risks if we manage to hold those companies for potential risks.
If we fail to do the latter it's quite unfair to let individuals bear the brunt of legal enforcement.
What about this "experiment" could not be done in controlled environment on a track… or a country road… or an empty parking lot.
I suppose we could just have infectious disease researchers set up shop on a street corner by this logic. Whatever! It's just a small risk! They're doing it for the sake of increasing safety standards!
If these guys want to be regarded as researchers, they need to act like them and be accountable like them. No ethics committee would ever approve a test like this.
WTF are you talking about? There is no the IRB.
Better?
The people who "choose to cut security funding" (I'm assuming you mean congress?) acted within the bounds of the law and within their power as elected officials. They broke no laws and your disagreement with the results does not make them criminals.
I don't know if these researchers broke the law. All that's happening now is they are being investigated. If they did break the law, then it seems to me perfectly logical that they would be in "far greater legal trouble" than someone who didn't.
TL;DR it's not odd that someone who broke the law is in more legal trouble than someone who didn't
But putting many lives in danger is considered acceptable behavior by security researchers? Does it actually matter that it was security researchers? Do security researchers working on banking software need to steal a million dollars in order to prove that they've found an issue? Would calling the police be acceptable in that situation?
Actual outrage is acceptable when there's actual danger. Calling the cops on a loud neighbor might not be acceptable, but calling the cops on a neighbor firing a gun in the general direction of your house certainly would be.
We don't know, for sure, what happened. There might be some creative license in the journalism. There might be some omission of them talking to authorities (even if someone called the highway patrol and they said "oh, we don't know about this," all it proves is there's bureaucracy at the highway patrol). etc.
Calling the cops is invoking a powerful and hard-to-control force. Unless you think that the cops and the legal system are capable of talking to people fairly and understanding security research and making sense of tech journalism and reaching a reliably just outcome, there are better ways to exert your outrage.
For instance, the researchers are very well known in the security community. They're not rogues or mobsters or fugitives. If they recklessly endangered lives, we can pressure them to turn themselves in to the legal system.
I happen to have more faith in the ability of the hacker community to fairly figure out what happened than the legal system to fairly figure out what happened. If I shouldn't, then we have a serious problem as a community.
1. You don't trust the police/legal system.
2. You trust our own community more.
Not saying I agree or disagree, but there are a LOT of people who would really disagree with this, and a lot more who would think that someone saying "why involved the actual people the public has chosen to deal with this, we can deal with it ourselves" would be very wrong.
And tossing chocolate bars into your neighbor's campsite in hopes that the angry bear will wreck their stuff is just not cool.
Unless the unruly bear is these security researchers, the fleeing campers are other security researchers in the same field, and their fleeing is them correctly assessing that some LEA is going to be taking down any bears nearby that even twitch wrong after this.
Bad actors ruin it for everyone.
You seem to think that because the police are theoretically under democratic oversight, that one can safely interact with cops as though the nominal rules of engagement will restrict them, but even if - in the long run - it is possible to rein them in, the law enforcement system we actually have right now is unpredictable, unjust, and unsafe.
If you distrust the police to the degree that you think even if your actions weren't illegal you will still have negative consequences from interacting with them, definitely don't do the above.
When someone's actions extend to endangering the public to the degree we see here (which I think is obvious once you've watched the video), they are past any good will I would have extended them in not contacting the police for fear of an overreaction. Their clear disregard for public safety is reason enough for me.
Additionally, on the chance that it was entirely intentional and they are counting on the media and possibly even law enforcement response to help make this an issue, they they definitely don't need our restraint, and nor do they want it.
It does not matter that we theoretically have democratic oversight. In practice, what we have is a system where cops can do whatever they think fit and expect to get away with it. They are armed and dangerous; it is not safe to interact with them. It is not a good idea to call them, or to talk with them if someone else calls them, because they - the cops - have a clear disregard for public safety when it is counter to their own interests.
If I was robbed, I would call the police. If I saw someone waving a gun around in public, I would call the police. If I saw someone using a car as a weapon, I would call the police. If I see a situation where people are endangering the public and someone might get hurt, I would call the police. Not doing so when I clearly knew I should would make me feel somewhat responsible for any negative outcomes otherwise.
I'm not really interesting in continuing a discussion where the other side's position seems to be "the police are racist scumbags and they will ruin your life with the slightest contact, so don't call them on criminals." You might find that characterization unfair, but then again, you're the one over-generalizing using large media events as evidence instead statistics.
Edit: Removed reference to ad-hominem, which wasn't factually correct.
While I agree with much of the rest of what you right in that comment, this is not accurate: overgeneralizing a negative stereotype of someone other than the other party in a debate isn't "pulling an ad hominem".
I don't like the fact that I trust self-policing by any community (even my own) more than the institution that is supposed to be doing policing. But whether I like it doesn't affect things.
I agree that it is important for us, as a free society, to fix policing. In the meantime, the best way to minimize injustice is not to invoke police when there is no immedate threat that can't be otherwise solved.
The police and judicial system sometimes have conflicting incentives as well, but at least they are aligned more with the public good than ours are. There are laws and they are, for the most part, rewarded for enforcing them.
Of course they do. They can call the highway patrol or 911 and report a disabled vehicle. Let's imagine how that call would go.
911: 911, What's your emergency?
Driver: Hi, there was a vehicle travelling slowly on the freeway with its emergency flashers on, I had to switch lanes.
Pause...
Driver: Hello?
911: Sorry, I was waiting for you to finish. Was there any other information? Did the driver or occupants appear to be in distress?
Driver: I don't think so, he was alone and appeared to be talking to someone, perhaps on hands-free, or maybe On-Star?
911: 911 is for emergencies only, in the future please report events of this type to local authorities' non-emergency number accessible via 411. Goodbye.I would like to think that a call to 911 with more information (which of course a fellow driver wouldn't have) would be handled differently:
911: 911, What's your emergency?
Driver: Hi, someone on the freeway has purposefully disabled their vehicle in a location without shoulders, and is slowing while driving, impeding traffic. I'm not sure if the power brakes or steering are functioning, but the driver is definitely not in full control of the vehicle.
911: We've dispatched an officer to your location. Has there been an accident yet? Has the driver recovered control of the vehicle?The cops can wreck your house, break your stuff, take your money, shoot your dog, deprive you of your liberty, and - if they think they can get away with describing you as a threat - shoot you dead. Even if you spend the time and money it would take to prove in court that all of this activity was illegal and unjustified, most of the time you'll fail, and even if you succeed you'll never get anything back.
I don't trust hackers or cops, but I can sure as hell see which one is the bigger threat.
Meanwhile hackers can break into the control systems for the power grid and shut down electricity, causing major damage. They can open or close hydroelectric dams, causing flooding and death. They can control hospital systems and kill or injure patients. They can control the airplane you're riding on while sitting in their seat. And all of these have been demoed at security conferences I've been to. I've seen these all in person.
There's a lot of physical harm that hackers can do. Sure, with a cop it's more personal since they're standing there in front of you pulling the trigger and a hacker doesn't even have to see your face.
Love them or hate them, both hackers and cops exist for a reason and are not going anywhere any time soon. One of the reason hackers exist is to point out dangerous security flaws like this. One of the reasons cops exist is because sometimes hackers are just as dangerous as the actions they're trying to draw attention to.
It also should be noted (since nobody else has raised this point) that some people within the police force likely read Wired anyway. So complaining about the police involvement for a piece posted to a popular news site is like moaning that your boss reads your Twitter feed.
IMO, the danger to the public caused by the researchers somewhat-controlled exploit is utterly dwarfed by the danger Jeep/uConnect is causing by directly connecting its cars to the internet. If the researchers are successful in getting car manufacturers to remove features like this entirely, the net result will ultimately save lives.
The article claims that the transmission was cut on a section of the freeway with no shoulder, so I'm curious how being stuck in the middle of the freeway translates to "slowing down and eventually driving off onto a grass shoulder." (And just because something "isn't the craziest thing I've seen" doesn't mean it isn't dangerous)
I agree that it probably presented some level of danger to the public, but I maintain that (i) the added danger was small relative to the normal everyday danger of driving with humans; and (ii) the media exposure they've achieved by doing this on a public road has the potential to pressure Chrysler to remove tens of thousands of hazards (read: vulnerable Jeep Cherokees) from the road, which could ultimately reduce danger and save lives. It's not clear-cut when you're dealing with a vendor who chooses to ignore and/or litigate upon an initial disclosure instead of fix their product.
The danger of a car having its transmission crap out on the freeway is non-zero, yes. On the other hand, they explicitly cut a vehicle's transmission on the freeway. The danger for the people in the immediate area of this vehicle was increased because the situation (a cut transmission) went from "maybe it will happen" to "it is definitely happening." At that point, whether or not an accident happened depended entirely on the skill and attention of the drivers around this vehicle something completely out of the control of the researchers.
Not the highway.
People who routinely test things that have the capability for real harm learn to take precautions for as many of the the things you don't think off as you can. For example, the Mythbusters are routinely testing things with cars and other bits of machinery that can cause physical harm if something goes wrong. They also routinely retire to abandoned airforce bases, remote locations, and the salt flats to test things.
But perhaps a little more objectively, there's certainly a moral hazard here; if every security researcher did this on public roads it'd likely be chaos. An appropriate response, IMO, would be for the police to make a phone call and tell them not to do it again.
It's actually not that different than pure software security research. You don't show a POC for your new DNS exploit by doing it against Comcast or AT&T public DNS servers without expecting some blowback. You set up a test environment.
1: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...
With or without shoulder, a stalled automobile is an everyday occurrence that drivers must absolutely watch and be prepared for. It wasn't the safest thing to do, but it isn't outside the normal range of "dangerous" events that one will experience on their commute daily, often more than once daily. IMO it doesn't increase the danger nearly as much as traffic patrol conducting a routine traffic stop on the freeway. If we're prepared to accept traffic patrol on busy freeways, then I don't think it's justified to treat a rare, even if foolish demonstration such as this one as anything more than a nuisance.
What would contacting the researchers achieve? They arbitrarily did the experiment in a public highway "to make the headline more shocking".
As much as I support any kind of security research, and as much as I support getting the attention of people to raise awareness, contacting the authorities was the correct move; a public highway is not a research lab without the proper permission from authorities.
While I strongly support free speech and believe security researchers should be given some extra latitude when appropriate, what I saw was not at all appropriate. I saw two well respected security researchers sitting in a room like Beavis and Butthead laughing and remotely disabling a vehicle on a multi-lane interstate highway, like it was a big joke. The reporter in the Jeep literally says "This is dangerous" and asks urgently for help. This all filmed and posted to Wired for the world to see, like they are proud of it.
Before working with computers I drove tractor-trailers for a while and was lucky to achieve a million-mile safe driving award. I have a pretty good idea of the dangers here and I know that stretch of road well, I've crossed it many times. I know from experience that a car stopped in the middle of a multi-lane interstate is one of the most dangerous situations you can be in. I've had people hit me who didn't see my huge trailer with flashers on and warning triangles out on a sunny day - it happens quite often. I've seen dozens of people killed in situations exactly like this. You see it coming and a random driver just plows into the stopped vehicle.
I exercised my judgement and decided to phone the local Highway Patrol office. I've read the negative comments and I disagree, I still think it was the correct thing to do. If you are a researcher and you do something this dangerous, and are foolish enough to then post it on a high-traffic site like Wired, I think you forfeit any right to a discreet warning and you deserve to have the police show up demanding answers to some tough questions.
Emphasis in too long, because this is the reason why road signs announce dangerous sections of a road with even miles in advance.
I just sat back and tried to estimate (since of course, I don't have a CB in my car and can't follow traffic details like a trucker) but I'd guess I've driven past at least 5 fatalities -- and that's just fatalities I've noticed (body on stretcher, read about it on the news later, etc)
Important research but very poorly tested. Wired and Chrysler (research was funded by Chrysler?) legal teams would not like the contents of this video.
edit: wired's link to video, jump to 2:00: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...
And that was while the security researchers caused the radio to blare so loud that he couldn't hear them on the other end of the phone. The more I see, the more I think they were really negligent in how they planned this out, and I was already firmly in that camp.
What I see is a vehicle slowed considerably, but at least nominally over the legal minimum speed of 40 MPH on highways, and without the driver being able to accelerate on his own. He's travelling in the rightmost lane, explicitly with his hazard lights on. This is not an unusual occurrence on highways. He's then told that to regain control he needs to stop and restart the car, which he does while remaining in motion.
I was surprised, since this is quite different from the way it's being talked about here, as if he was stopped in the middle of the freeway. See GGP comment about "a car stopped in the middle of a multi-lane interstate."
That's not what happened here.
Driver: "It says 43 miles an hour, but it's not really that fast."
[voiceover omitted]
Driver: "Guys, I'm stuck on the highway."
Researcher A: "I think he's panicking."
Researcher A: "He's not going to be able to hear us with that radio. So loud."
Driver: "Guys, I need the accelerator to work again."
Researcher A: "The accelerator..."
Researcher B: "It won't work! You're doomed!"
Driver: "Seriously [beep] dangerous, I need to move."
Researcher A: "You gotta turn the car off!"
Many cars can be seen passing them on the left in the video during the test.This discussion has been distorted and sensationalized, and it has not been based on observable recorded facts.
I don't think this discussion has been distorted. It's based on the information they provided. They put a vehicle on a public highway traveling at the faster end of what's legal in the US on public roads, and then removed a large portion of the drivers ability to control the vehicle. It's unclear whether this affected the steering or brakes, which in a modern vehicle would both be power assisted, generally through the vacuum system of the vehicle. The vacuum is provided by the engine, so if the engine was actually off (which is unknown, but I think it's more likely they just forced the car into neutral), then they removed a large portion of his ability to control the car.
The bottom line is that they put a driver in a situation not only unsafe to himself (which they could have gotten consent to), but unsafe for the other drivers on the road. They did not have consent from the other people on the road to do this (indeed, it's not possible they could have), and if what they purport to happen in the article and video did happen, then they endangered those people. I've seen accidents from stopped cars being hit by others. If the highway is busy enough, the initial accident isn't even necessarily the largest damage, but it moves vehicles into even more obstructing positions and causes follow-on accidents.
https://www.google.com/search?q=stalled+car+accident&tbm=isc...
Without such event present in the footage, car manufacturers can just say "Meh - no big deal". And continue recklessly risking lives by manufacturing unsafe cars without air gap between CAN bus and Internet.
Remember, it's the car manufacturers that are the bad guys here, not the white hats... And just think how hard was this decision. It's a choice between risking lives and having footage that doesn't catch attention and thus allows car manufacturers to continue making unsafe cars with horrible security vulnerabilities. Amazing.
I don't exactly condone the ethics (or lack thereof) of the researchers, either, but if that's the only way to get proper attention (after previous, more polite and reasoned attempts were simply dismissed by manufacturers), then so be it.
Just because automakers are seemingly keen on ignoring security vulnerabilities does not justify putting people's lives at risk. And let's face it – a multi-ton vehicle that is not entirely in its driver's control puts lives at risk in just about any situation. The reason you and others argue that the demo's methodology is effective is precisely because of the risks involved; not in spite of them.
It is the responsibility of researchers to demonstrate risks without exercising the extent of those risks. Imagine if virologists regularly demonstrated communicability risk by injecting humans with disease outside of the lab.
So condemn the auto manufacturers for putting hundreds of thousands - if not millions - of lives at risk instead of yammering about a couple of nerds who put at most 2 vehicles in probably-nonfatal danger in a worst-case scenario.
And as busy as that highway was in the video, it was far more than just 2 vehicles, especially if one of those vehicles was the 18 wheeler.
At the very least they could have done this on a less busy stretch of highway that had a wide shoulder and with control vehicles in front and behind with paramedics at the ready (just like a movie production that is shooting on public streets). Instead the researchers and the journalist chose to be reckless.
Agreed, the researchers deserve some criticism, but let's not lose sight of the forest for these two goofball trees.
Nobody's saying you can't. I certainly do (I strongly disagree with the researchers' obstruction of communication between themselves and their test subject).
My only point is that there's a massive difference in scale between a couple dented fenders and hundreds of thousands of dead/maimed innocents.
We're talking about someone coasting uphill with absolutely no braking whatsoever. There's plenty of reaction time in such situations (as I happen to know firsthand, as was the case when my SUV ran out of gas and I had to coast a quarter-mile over a hill to get to the next offramp while merging from the fast lane to the far right at 70MPH). Even for semis, the reporter's car wouldn't mean having to slam on the brakes. Not to mention that the uphill helps with stopping.
The story would be different if the researchers slammed the car's brakes. If that were the case, then yes, death would be possible. That wasn't the case.
No intellectual dishonesty here. Just thorough examination of the situation as described by the author of the article.
That's mere conjecture. And it's an assertion you could easily test by first doing the remote hack in a controlled environment (e.g. a racetrack) and seeing if automakers respond before trying this on an actual freeway!
The findings before physical tests (identifying cars with a lack of airgapping or other basic security measures) were also reported to Cadillac (as one example among others); said findings were basically dismissed with a "well we've already released a newer Escalade model with some more security features, so whatever".
This isn't to mention that the wired exploits should've been enough to at least spark some level of concern.
First, there's no indication in the article that the researchers or Wired presented the remote windshield wiper hack to the car's manufacturer and that they subsequently ignored it.
Second, there is plenty of indication that the exact opposite is true. The remote windshield wiper hack occurred this June, whereas the article states that they've been working with Chrysler on this for nearly nine months and that Chrysler released a patch prior to the publication of this article.
Third, the Cadillac anecdote isn't really relevant here. For starters, it looks like they were contacted by Wired, not the researchers, so it's unclear whether they were contacted before the dangerous freeway demonstration took place. And while the mention of the newer model is a bit odd, the statement also mentions devoting more resources and hiring a new cyber-security officer, making it unfair to characterize it as a "whatever" response.
Sure, it'd be nice if Cadillac was a little more proactive here, but keep in mind that the researchers hacked a Jeep (made by Chrysler), NOT a Cadillac (made by GM). The researchers think the Cadillac is also vulnerable based on its feature set, but absent a specific flaw to patch and given the short amount of time since the initial demonstration (less than two months), it's unclear what GM is supposed to do here.
Also, it's worth noting that the root flaw here - a hole in UConnect - is not limited to Chrysler. The article mentions tracking and surveilling GM vehicles, too (particularly Dodge), which makes sense, seeing as a lot of recent Dodge vehicles have UConnect as well (per http://www.driveuconnect.com/features/uconnect_access/packag...).
> For starters, it looks like they [Cadillac] were contacted by Wired, not the researchers, so it's unclear whether they were contacted before the dangerous freeway demonstration took place.
The article doesn't actually say that. Infiniti was contacted by Wired according to the article, but the initiator of Cadillac's response isn't specified (as far as I can tell).
If they were contacted in the same manner as Infiniti, then it's implied that said contact happened after the wireless hack, since the Infiniti contact involves a notification that the researchers' predictions were "borne out" in at least one of the three of them (in this case, Chrysler).
Researchers perform controlled experiments. Controlled experiments are ignored. Researchers opt for more damning (though less controlled) experiments to further prove their point, and now they're suddenly the bad guys here.
Much of the commentary here focuses on the recklessness of the highway test and doesn't weigh in too heavily on who the bad guys are.
I think people mostly find the idea of remotely exploitable and controllable cars so terrible that there isn't anything to discuss about that aspect of it, it's nearly universally considered unacceptable (hence the epic thread about the side issue).
Maybe try reading the comments without imputing a side that the writer is taking.
It wouldn't have been difficult to do this right. Cops love drama and publicity. It wouldn't have taken much convincing to get them on board, and the video would gained a lot of credibility.
However, this doesn't change the fact that vulnerabilities were demonstrated, nor does it change the implication that auto manufacturers are excessively sluggish about security patches on things that can and do kill people on a regular basis. Even an imperfectly-conducted demonstration like this particular case is preferable to such a demonstration not occurring at all.
Your argument is ludicrous, because you're attempting to cast the actors as either good or bad. IMHO they are guys with a good idea and motivation who did a bad thing.
edit: as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.".
If optics is your justification for this, then perhaps having these two irresponsible researchers arrested would bring even more attention to this.
>edit: as per the article "researchers already did test these exploits in controlled environments and presented these tests to auto manufacturers. Said tests were dismissed by said manufacturers.".
Where do you see that in the article? Only thing I read was manufacturers downplaying a wired-in attack they demoed.
Yep.
> Where do you see that in the article? Only thing I read was manufacturers downplaying a wired-in attack they demoed.
No "air gap" between "CAN bus and Internet" equals vulnerable.
We know that. Auto manufacturers know that.
Yet they dismiss the possibility of a hack and continue producing unsafe vehicles. And the trend is toward more vulnerabilities.
I was to lazy to search a direct quote, but here it is now: "Miller and Valasek represent the second act in a good-cop/bad-cop routine. Carmakers who failed to heed polite warnings in 2011 now face the possibility of a public dump of their vehicles’ security flaws.".
In this article it mentions how Chrysler is working with them and has developed a patch, indicating that they did not dismiss previously done tests. So basically saying the opposite of what I take your point to be.
> And just think how hard was this decision
Given that they did the easy thing, it wasn't very hard at all.
Oh really, can you point to the responsible tests that were done in the past that proved inconsequential necessitating this reckless alternative? Or are you just inventing that the car manufacturers would ignore this and somehow the story would just go away?
That was rash. You called the police within an hour of reading this article? You didn't think it's possible the writer is embellishing or exaggerating the danger he was in here? As of right now, everything they've done has been done in good faith to try to point out the need for extra security.
Also, if they get arrested, even convicted of a crime, then what? You have two extremely angry researchers who know how to hack your car, and what, you're hoping some jail time might help them see the error of their ways and use more caution in the future? You can't see any potential problems if one of them feels vindictive about being jailed over your phone call when they weren't trying to do anything wrong in the first place?
1: http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...
Making factual statements contrary to how a situation was reported by those involved is fraught with pitfalls you can't anticipate, from things you don't know about. Until there's careful investigation, or the people involved recant or make factually impossible statements, you should be careful about making assumptions.
In any case, their reported actions are what people are upset about. If someone makes false statements about illegal activity and it results in the police showing up, they have only themselves to blame.
I understand it's tempting to see a single bit of evidence and want to use it to invalidate an entire narrative, but is it so hard to accept that while editing could have made a situation less dangerous seem more dangerous, the inverse could be true as well? We really have no authoritative source of what happened other than the story put forth. The story may indeed be fabricated or subject to hyperbole in parts, but unless you have a source beyond what's here, you are not qualified to make that assessment from the little evidence presented.
EDIT: Formatting.
Angry mobs are dangerous and volatile and can push prosecutors to overreact. And prosecutors and politicians love to overreact when it comes to hacking.
Imagine: you're a local and you're trying to call the police. But, you can't, because the number is busy. Or you wait forever on hold, because people on the internet are angry about a reckless driving incident that happened weeks ago and that the police already know about.
OP called the police, that's enough. They know about it now. If you want to express your opinion, write the editor of Wired or, if you're really angry, the local district attorney.
It's a shame because this is an incredible story and the work they did was great, but what a completely reckless stunt they pulled. Totally unnecessary too, the story would have been just as effective if the demo happened on a test track or empty parking lot.
These people did the exact opposite. They put others in potentially mortal danger.
They could have killed someone's daughter, son, mom or dad.
Stop and think about that for 10 minutes before you continue posting with this unreasonable point of view. Would your mom, dad or siblings life be worth this test? Imagine they collided with this car and died. Close your eyes and imagine that for a moment. Imagine receiving that call. Going to the hospital. Seeing the, all torn-up and suffering befor they die due to the injuries.
And then you find out it was due to two fuckers who thought it'd be funny/interesting/whatever to disable a car remotely.
Imagine that.
Although I do agree with you, I modded you down and the GP up in this case because appeals to emotion aren't the answer. Your post is a form of the "If it saves just one child" thought-ending pattern.
Game, set, match.
The fact you have included their phone number seems to me like you are instigating some sort of lynch mob.
If you actually though it was an issue you would have privately contacted them without telling the world.
Very childish.
This is a big story that the appropriate authorities will be looking at anyway.
Demoing it on a test track with no other vehicles and a volunteer driver with helmet and roll cage -- that'd be acceptable, maybe, with suitable safeguards.
But doing it on the open highway with unaware third parties driving past, merely telling the test guinea pig "not to lose control" while being blasted with cold air and loud noise, having the controls disabled, and visibility impaired? That's gross recklessness with public safety. (Here's a clue: you could have put me in that car and given me all the warning in the world and I could not guarantee maintaining control or not causing a potentially fatal accident at 70mph under those conditions.)
You shouldn't run experiments on big powerful machines in public places where you can't keep by-standers out. Gross ethical breach. I just hope the journalist is exaggerating or making things up.
Had someone died you might (in countries which have it) get corporate manslaughter on a company that ignored security warnings. You absolutely would on the researchers and the journalist for their reckless disregard for the lives of others.
(*) without risking lives there wouldn't have been a video documenting these life-threatening vulnerabilities in the cars.
Who cares what their job title is? They deliberately blocked visibility and then cut the transmission of a vehicle being driven on a public road in traffic. That is well into the territory of criminal negligence.
> they cut the transmission. [...] Immediately my accelerator stopped working. As I frantically pressed the pedal and watched the RPMs climb, the Jeep lost half its speed
In what world do we not call the police on this kind of behavior?
Their test-engineers don't say "hey, we're going to do some stuff, but try not to kill anyone".
Gross negligence.
Perhaps you are simply unaware of how dangerous the situation was? Several experts (ex-truckers) have described how they have seen people killed in circumstances like this. If you're being intellectually honest, that should inform your responses.
So, you don't care about the fact that this experiment on public roads could have killed people? Just because it's for security research it's ok to recklessly endanger lives? What Wow's me is your cavalier attitude, I'm glad he informed the police and I hope they face repercussions. What they did needlessly endangered people's lives and public safety to add a sensational bit to a story, I find that way more "aggressive" than informing the proper authorities of those actions.
nothing novel there in terms of having to have some "new" TPM. Just OEMs choose to lock down their boot chain. Probably most secure boots are minimally implemented to only support the use case of secure/trusted boot (device/chip/OEM key) xor untrusted boot (no key).
If both are supported, whatever functionality that relies on OEM firmware or chain of trust would be disabled if it is an untrusted boot (like fastboot oem unlock for some android devices) situation.
May be tricky to enable certain desirable/required features if user wants to run their own firmware.
>I have yet to hear of a system that allows the user to directly authenticate software/firmware at the hardware level. Is anybody working on research of this nature? Or are there insurmountable problems with this approach?
I think chromebooks/chromeOS folks have been looking at this. Not sure of the current state of things.
p.s. TPMs kind of suck if they are not able to be updated OTA.
Even you, the busybody who called the cops because you read an article, said "What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early..." which implies that the trucker would have been following too closely or not paying attention (or both).
It's worth pointing out that the driver was aware of the situation and they didn't do anything dramatic like lock the brakes or throw the car in reverse. They chose a gentle deceleration in a stretch of road that had no shoulder to make it feel dangerous, but, on the spectrum of hazards that most drivers face every time they take the car out of the garage, this is pretty tame.
The fact is, had something happened, it wouldn't have been the disabled car that was at fault.
I think the researchers are in the clear, and for you to have read the article and been bothered enough to call the cops (and post the number for, presumably, the convenience of other hyper-sensitive folk who might otherwise just go back to staring at the neighbor kids from their bedroom window with their phones in their hands and 911 on their speed dial) is nuts.
Say there was a person working at a grown-up lab that deals with traffic safety. Like the University of Michigan Transportation Research Institute http://www.umtri.umich.edu/ .
The person wants to know what happens when someone slams on their brakes on a 70mph road. He says "don't worry, if anyone hits me, it will be their fault, because they were following too close."
What do you suppose the ERB says in response?
I do think that educating them with regards to better choices would be helpful, but they appear to have committed an offense and documented it on camera in the news. I think they were going to end up in trouble one way or another here.
Yes, they created conditions that might have made it possible for a lousy driver to wreck a car, but, no, they did not do anything inherently dangerous. A driver--ANY driver--is expected to be able to handle gently decelerating cars on the highway. They should also be able to pay attention despite big billboards, confusing traffic signs, and attractive people gallivanting on the sidewalks.
The average traffic jam is much more likely to cause an accident, but it typically doesn't and, when it does, we blame the driver that rear ends someone, not the masses of people who have actually stopped on the highway, often NOT gently.
Similarly, the researchers have increased the probability of a crash from the near-zero probabilities that are typical of actuarial tables to close to 100%.
Edit: Actually I've thought it about it, and they could probably be charged with reckless endangerment.
Mature research labs have review boards to govern "researchers" who want to just see what happens when LSD is put in the water supply.
Edit: They could've done it on the parking lot and the article would be put in a pile "some geeks are doing some geeky stuff" and forgotten. 70 MPH on the public highway is like a billboard with ten foot letters saying "PAY ATTENTION" in your face.
I don't entirely agree with the methodology, but nobody was hurt, unlike what would would likely be the case should even less ethically-grounded "researchers" demonstrate similar capability - probably on a larger and more dangerous scale, mind you.
Worst-case scenario, somebody might've been rear-ended. Maybe a bit of whiplash. That's not great, either, but seeing as more-controlled tests by these researchers were outright ignored by auto manufacturers, your priorities have to be incredibly out of whack to villify the researchers over the auto manufacturers - who are willfully endangering hundreds of thousands, if not millions, of Americans every day - in this scenario.
And I wouldn't call this a fight. Just an ethical debate. One that'll probably be a bit heated, of course, given the circumstances, but it's one that needs to be had.
The reporter mentions that this was uphill. Semis generally have a hard time going uphill at an appreciable speed (as I know full well being stuck behind them regularly on the mountain pass highways that connect my town to the rest of the world; lines and lines of trucks at less than 45 MPH with their flashers on); more weight leads to a harder time fighting against gravity. The uphill slope should make it easier for the truck to slow down.
If the reporter had made an abrupt stop (i.e. if the researchers slammed his brakes or something), then yeah, I'd be more concerned. That wasn't the case, though. Rather, it was a gradual deceleration according to the article. Cars can actually coast quite a distance, even uphill, when they start at 70MPH; I know this firsthand from my own SUV running out of gas once on a busy interstate, and on an uphill no less. Even with the uphill, there was enough momentum for me to put on my flashers, merge right from the fast lane, and eventually coast into the next offramp a quarter-mile away. No shoulder, either.
Now, this isn't to say that it couldn't've been safer, nor do I disagree that more safety precautions should've been implemented. For one, the researchers could've - at the very least - told the reporter "hey, if our attack comes at a really bad time and you feel like you're about to die, turn the car off and on again and you'll regain control". However, even with the described scenario as-is, risk of life is quite slim. We're not talking about a driver slamming his brakes and going from 70 to 0 in seconds; we're talking about the equivalent of an engine stall, and thus a rather gradual slowdown - graudal enough for even semis, let alone smaller vehicles, to react to.
> I wonder if your opinions about this would be different
They probably would, yes. Slightly, though; ultimately, one injurious pileup is a drop in the bucket compared to the hundreds of thousands that might actually be prevented by demonstrating precisely why proper security measures on Internet-connected heavy machinery are worth taking seriously. Not that I think the possibility of the former should be dismissed (indeed, I agree that the researchers could've done things more safely while still getting the attention of auto makers), but said possibility needs to be weighed against the possibility of the latter, with the recognition that any demonstration - ideally a totally safe one, but even one with some degree of risk - is necessary to push auto manufacturers toward taking security seriously.
But when I read that you actually called the authorities and encouraged others to do the same by posting the number, a certain somewhat Tao-istic scene in The Big Lebowski [1] came to mind.
You remind me of that general. You should be hanging out on Catch The Hacker News, not Hacker News.
Wasn't hackernews just all up in arms about the US military spreading germs to test bioweapons? Isn't this the same exactly thing?
For example, I have relatives who do fire safety. How people do (or don't!) evacuate from buildings when fire alarms go off is a big area of research.
The ideal way to test this is to set off the fire alarm in a building where people do not know it is happening, along with some smoke and pyrotechnics.
HOWEVER, there are ethical concerns, and a review board would ask questions like:
1. Has anyone else done this study before? If not, why not? How sure are you that no one has done it before?
2. What does the previous research with similar protocols say? What key question are we trying to answer?
3. What is the harm that will be present to people? Are we doing everything we can do to reduce that harm?
4. What more could we do to reduce harm but that might impact the reliability of the research?
5. Quantify how much of a benefit this research would be so we can compare to the risk you are presenting.
6. Demonstrate that you have done all the preliminary work that is necessary to achieve good results, so that we can make sure that the research is used. It would be foolish to put humans at risk and then be unable to use the research because we forgot something we could have taken care of upfront.
These researchers would bomb most of these questions.
The reason for an INDEPENDENT review board is that researchers tend to follow this flow chart:
Have idea. ----> Wait, should I do this? ----> Yes, of course!
I suspect there's also a bit of embellishment going on.
So what should researchers do? Do nothing and keep their hand clean while waiting for the train wreck to happen? Continue in a fruitless effort to warn people on papers only other researchers reads, knowing by historical evidence that no change will come from it. Ask government for permission to do a live test, knowing that it would never be granted. Do a demo test on a demo road, knowing that neither government, industry or public would care.
I don't like this either, but it seems to me as a society we only really give researchers one option and that is to do nothing and wait for the bodies to pile up.
There is a big world between "do nothing" and "put third-parties at risk by stalling a car on a three-lane highway with concrete barriers."
Doing the right thing is often boring and takes lots of work. That's why it's called "doing the right thing" and not "doing the splashy thing" or "doing the easy thing."
They already had the attention of the media. Keep on working with the media to get more and more attention. Is it hard? Then do it some more.
I feel like there's a lot of cargo cult thinking going on here. The situation is _almost_, but not quite, like a lot of other ones where the security researcher is unreasonably blamed. For example, I could easily see some people being up in arms about announcing this exploit at Black Hat.
But that's not the case here. I have a healthy fear and respect of a ton of metal flying down the road at 70mph. And this stunt, done just to generate headlines, was needlessly reckless. It could have just as easily been demoed in a private lot or something.
It was previously demoed in parking lots and other controlled environments by these researchers, according to the article. Said demonstrations were ignored by the auto manufacturers, with some manufacturers - like Toyota - trying to claim that their systems were still "secure".
The public and the manufacturers need a proper wakeup call. My fear is that even a "reckless" test like this one isn't enough of a wakeup call.
If someone had died from this stunt, the total number of deaths from remote hacking of cars would be 1.
NB: I highly favor a bounty system where someone who can demonstrate the ability to take over a car without touching it gets paid lots of money, and if the company fails to fix it they get fined even more money. But "someone else is doing something bad, too" is never a good justification.
If this stunt had never happened, we'd be in a position where some less-scrupulous actor would demonstrate such exploits on a much bigger scale. I can guarantee you that the total number of deaths from remote hacking of cars would be far greater than 1.
If we're going to play the "OH NO THINK OF THE CHILDREN^H^H^H^H^H^H^H^HHYPOTHETICAL DEATHS" game, then let's put this into some goddamn perspective, eh? 1 v. hundreds of thousands (if not millions) that are currently vulnerable to remote hacking right this very instant.
In all actuality, of course, that "1" death was highly unlikely; at most, we'd probably see a few dented bumbers and a couple grand in car repairs. Maybe somebody with whiplash.
And yes, they could've easily done this demonstration with better safety constraints (particularly regarding communication between the researchers and the driver; said communication was seriously impaired), but the implication is that the researchers believed a "live" test to be necessary to actually get that attention. The point is less "this is what happens to your car" than "this is the sort of danger your car poses to the general public".
My fear, of course, is that even this won't be effective. Hopefully proper basic security measures (like, say, not connecting the transmission, brakes, and steering to the bloody Internet) will be taken seriously before some multi-fatality catastrophe happens because of such security flaws.
When they demonstrated a wired-in attack on those vehicles at the DefCon hacker conference in 2013, though, Toyota, Ford, and others in the automotive industry downplayed the significance of their work, pointing out that the hack had required physical access to the vehicles. Toyota, in particular, argued that its systems were “robust and secure” against wireless attacks. “We didn’t have the impact with the manufacturers that we wanted,” Miller says. To get their attention, they’d need to find a way to hack a vehicle remotely.
But you are apparently ignoring this paragraph, which discusses Chrysler responding to the hack, as I read it, prior to the events in the article:
Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference. On July 16, owners of vehicles with the Uconnect feature were notified of the patch in a post on Chrysler’s website that didn’t offer any details or acknowledge Miller and Valasek’s research. “[Fiat Chrysler Automobiles] has a program in place to continuously test vehicles systems to identify vulnerabilities and develop solutions,” reads a statement a Chrysler spokesperson sent to WIRED. “FCA is committed to providing customers with the latest software updates to secure vehicles against any potential vulnerability.”
The way I put the information in those two paragraphs together, it's the fact that the attack can be done without physical access to the car that got the attention of Chrysler, not the publication of a stunt in some web rag.
Basically, folks like Chrysler, Ford, and Toyota (and other mentioned manufacturers, too, like Cadillac) are relying on white hats and grey hats to be the ones finding the zero-day exploits in their wireless systems. And even when those exploits are found, they're being "addressed" with half-assed solutions like requiring an upgrade via USB (never mind that if a remote attacker can hijack the brakes and transmission, of all things, an OTA upgrade should at least be possible).
In other words, I'm not ignoring Chrysler's "response" at all. Rather, I'm noting that their response isn't actually indicative of the attitude shift that's actually necessary to prevent death and maiming of drivers.
[0]: http://www.wired.com/wp-content/uploads/2014/08/Screen-Shot-...
EDIT: Holy moly https://twitter.com/CondeNast/status/623533074865893376 .
"They demonstrated as much on the same day as my traumatic experience on I-64; After narrowly averting death by semi-trailer, I managed to roll the lame Jeep down an exit ramp, re-engaged the transmission by turning the ignition off and on, and found an empty lot where I could safely continue the experiment.
Miller and Valasek’s full arsenal includes functions that at lower speeds fully kill the engine, abruptly engage the brakes, or disable them altogether. The most disturbing maneuver came when they cut the Jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch."
I'm not trying to equivocate the two, but it would seem they both exist somewhere on the same continuum of personal information and police involvement.
How much do you think your decision to make this call was influenced by your perception of what law enforcement does in Europe vs. what law enforcement does here in the United States?
What tombrossman did: "911, I saw a video of researchers shutting down a car on a freeway in the middle of the day with little concern to public safety, can you guys investigate and make sure that nobody's life was in danger for this experiment?"
I don't think there's even a tangential comparison between the two.
In general, I would feel uncomfortable alerting a local law enforcement agency in _another country_ about something I saw on the internet, both because the premise is silly, and because not all cops are loyal public servants dedicated to protecting people. Many just like the power trip they get from having a badge and a gun to wave at us plebs.
That's not how civil court works, as I'm sure you're referring to filing a suit against them, for... some nebulous thing? You have to prove damages to be awarded anything in a civil court.
Theoretically let's say that they tested some remote tracking on your vehicle without your consent. What then? If you can prove there was some damage to your vehicle, great, you'll be reimbursed for it. Otherwise?
Content aside, the self-satisfaction and smug attitude of this comment is disgusting.
We've had 2 MAJOR accidents just recently by my house (I-85 near Atlanta) due to foreign objects and/or stalled vehicles.
Anyone who thinks this isn't unsafe is absolutely delusional. Any unexpected failure is hazardous on the interstate. Especially failures to the drivetrain, suspension, steering, or braking system. Beyond that, I hope everyone can agree spraying the windshield with washer-fluid and thereby completely obscuring the vision of the driver while he was traveling at 70mph is absolutely a hazard (what if the car in front had stopped for some reason).
http://www.detroitnews.com/story/business/autos/chrysler/201...
Here is a choice quote about the culture relating to safety at Fiat - Sergio Marchionne is CEO: >> Marchionne said in January that the auto industry may have “overreacted” to some safety issues, especially the massive air bag recalls, which may have been “overkill,” he said. << This is about the Takata recall in the news where the detonators can produce deadly shrapnel.
So yes the demonstration described in this article was somewhat reckless, but the facts that FCA has not notified owners beyond a posting online about a firmware update (who checks that?), tacitly condemns security researchers' decision to publish some details in their communications with Wired, all the while stonewalling recalls - for example in Jeep vehicles where they catch fire in rear end collisions, killing occupants - that upsets me much more.
In my opinion, when a company is notified of a safety or security issue, they should do all that can be done as quickly as possible, here instead FCA has once again done the minimum plus has the gall to respond in writing, "We appreciate the contributions of cybersecurity advocates to augment the industry’s understanding of potential vulnerabilities. However, we caution advocates that in the pursuit of improved public safety they not, in fact, compromise public safety." I guess I embrace hacker spirit more than anything else I considered here is what it boils down to.
So I would have written to the NHTSA trying to make this yet another recall if I thought it would have done any good, but in that culture of 21%-compliance-is-acceptable, I don't think it would do a lick of good, so I won't bother.
Also, I accidentally clicked on "flag" above when I wanted to click on "parent." I am sorry, that was not my intention, I just wanted to refer back to the Wired article as I was responding, and they are small and right next to each other. Ah, I notice when I refresh there is an unflag option, I have just taken that action, again sorry.
There should be an "unflag" where "flag" used to be.
The guy consented to their experiment and he voluntarily engaged with them. It is not like they set him up for this.
Maybe you could argue that they could have jeopardized the lives of people on the highway with their reckless behavior esp the engine shutdown stunt and I believe that they didn't exercise wise judgement in doing so but didn't they instruct the driver to switch off and back on to regain control of his vehicle and move ahead?
You also claimed that they're boasting of their act by publishing this video when it was Wired that produced and made the whole report and experiment and not them. The reporter himself the subject of this experiment didn't file any report with the authorities so you come and act more royal than the king!
What a mess!
What was that snitching for? This is completely uncalled for.
This is a knee jerk reaction from you and testament of your true character.
You should be ashamed of yourself snitching on your colleagues like this and your phony outrage at this act is not fooling anyone.
Grow up you are not in elementary school anymore!
They could have easily demo'ed it in million other ways.
Kudos for the hack but shame for the demo.
This isn't about security researchers. There's a HUGE GAP between security research and setting up a situation that could kill someone's daughter, son, mom or dad. That incredibly stupid at the least and criminal at worst.
There are levels of this in tech all over. I don't know if it is about social isolation or something else. Things ranging from the kinds of privacy decisions made by people coding social networks to the totalitarian and inhumane approach seen in dealing with various large web players. It's almost like you are dealing with a non-human race (the Borg?) that is almost completely devoid of human feelings, emotion, consideration, respect, a sense of community and simply making decisions that are humane rather than cold and mechanistic.
The other one is morons flying multicopters above people, neighborhoods and around firefighting aircraft. How does a human being go there mentally? I don't know.
I applaud your actions.
What's worst is that it is likely this was not the first time they did this.
WTF is wrong with you?
Well, here you go (search for 'Volkswagen'): http://attrition.org/errata/legal_threats/
How about that - "Fiat Chrysler now says that 10 vehicles from its 2013, 2014 and 2015 model years are vulnerable to hacking, including five 2013-2014 Ram truck models, the 2014 Jeep Cherokee and Grand Cherokee, the 2014 Dodge Durango and 2014 Dodge Viper, and some 2015 Chrysler 200s."
and that - "Miller and his associate, Chris Valasek, director of vehicle security research at the consultancy IOActive, estimates that hundreds of thousands of Fiat Chrysler vehicles on the road today could be vulnerable. That’s unsettling." just read people! 2013 models. And now, this a hole calling police because this guys opened your eyes. Wouldn't it be better if they made "safe" test again, manufacturers ignore it AGAIN & then some sick bastard simply crashed thousand of those?
And yes the main thing I like is - “Customers can either download and install this particular update themselves or, if preferred, their dealer can complete this one-time update at no cost to customers.” DOWNLOAD & INSTALL THEMSELVES? What? but yeah right blame the researches of course.
"In case any of you think this was cool or even remotely (no pun intended) ethical, I'd like to know if you have a problem with letting these two test this on a loved one's car. How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything?"
I would certainly let this guys to check on my car and my wife's car, just to make sure that if it can be hacked then I'd better get rid of that crap and sue a holes which let me drive a car which can be controlled remotely. Cause I would rather trust ex NSA and current director of vehicle security research at the consultancy IOActive, rather than have even a 0,00001% chance that some unknown hacked crew can end my life sipping coffee in starbucks.
- Man drives car on public highway @ speeds of up to 70mph
- Hackers turn on windshield wipers and fluid to blur view
- Hackers Blare music and obscure any comms link to driver
- Hackers disable vehicle on Highway at location with no shoulder
And there are people who are not only ok with type of experiment but think there should be more of it.
I understand that these exploits need to get attention... but I really can't stop thinking about my wife and kids being behind this guy while he shows how dangerous this can be.
I applaud the person who notified the police.
In a similar vein, if you notified your local police about a kidnapping they would notify the FBI, because kidnapping is the FBI's jurisdiction.
I don't expect Joe Random to know to contact these guys' IRB, when they likely don't have one at all.
Indeed. And according to the article, they already did. The manufacturers ignored them.
Still doesn't matter though. There are a million shades between quiet disclosure and outright stupidity that would still make headlines.
1) They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so.
2) They could have ensured constant two-way communication.
3) They could have done it when nobody was on the road.
It was my understanding that the patch was released in response to the live highway test, not the prior tests in controlled environments.
> They could have let the "test dummy" in on what was going to happen, so they could give feedback as to when it was safe to do so.
The article makes it sound like they did.
> They could have ensured constant two-way communication.
Indeed they could've. I agree with you about the recklessness of this particular element of the test.
> They could have done it when nobody was on the road.
Perhaps, and I agree that maybe they should've coordinated with local authorities (if they didn't already). However, between "do the test with vehicles on the road" and "don't do the test at all", I'd certainly pick the former.
Not to mention that the urgency involved with other vehicles on the road factors into the effectiveness of the demonstration.
> Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference.
With respect to letting the driver in on it, it's pretty clear they withheld most information:
> Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch
And with respect to this:
> However, between "do the test with vehicles on the road" and "don't do the test at all", I'd certainly pick the former.
Oh look, another false dilemma. Between those two, I'd pick neither, and do the test responsibly.
The reporter knew there were going to be attacks in the first place. There was also plenty of reason to believe said attacks could severely impair safety.
> Oh look, another false dilemma.
It's a trilemma; the concept of "do the test 'responsibly'" was already implied, so I merely provided the other outcomes. There's "perfect execution of demonstration" and "no demonstration"; between that is a spectrum of perfection, on which this demonstration happens to lie somewhere near the lower-middle.
I don't disagree that the demo could've been done with more safety precautions, but the desire to do a "live" demonstration like this seems pretty reasonable, and even a demonstration lower on the perfection spectrum is preferable to the bottom end of "nothing at all".
Because a dangerous threat exists does not give a researcher license to endanger the public to prove it. This is especially the case when a safer alternative to demonstrate this exploit easily exists.
Robbers could enter your home and hold your family at gunpoint AT ANY TIME. That does not give me the right to prove to you how easy it is by entering your home and scaring the crap out of your family.
1) This is a dangerous exploit
2) This was a dumb way to demonstrate it
Those are not mutually exclusive.
Secondly, nobody would give a fuck about this exploit if it was performed in controlled environment. The researchers knew it because they did this kind of stuff before. Guess what, the cars did not become any safer!
This much should be obvious to anyone with a hacking mindset. The comments in this thread read more like "Moms Against Drunk Driving Bulletin Board" than "Hacker News".
Just because they do it from behind a screen doesn't make it a less culpable crime. Computers don't insulate you from ethics...
We put locks on our doors to prevent people from entering. They have always been exploitable but we use threat of laws to prevent it. Now we put locks in our software to prevent people from entering it (encryption). Somehow this generation believes that these locks are exempt from decency and law. It's sad that people think exposing vulnerabilities at any cost is righteous. There's plenty of people researching security in responsible ways. These two are not in that camp.
Have fun... it's no different than kicking your neighbors door down and tell him to pay you for exposing his security flaw. Still makes you are jerk.
If you read the article, you'd know that said safer alternative was already attempted and presented to auto manufacturers, only to be met with dismissal.
Most of those comments, however, are only clearing up a specific misconception: the belief that the researchers jumped straight to a "live" test before trying tests in closed conditions. My idea of "right" v. "wrong" does not factor into doing my part to ensure that discussions on this matter are based on accurate information.
My "defense" of the researchers is more just identifying a lesser evil. Between the evil of a couple of nerds hacking one car and the evil of auto manufacturers willingly putting hudreds of thousands - if not millions - of innocent people in mortal danger, I'd sooner take the former (assuming that it actually makes a difference re: security priorities of auto manufacturers; in reality, even this particular demonstration is probably insufficient, though perhaps I'm just jaded).
"Second, Miller and Valasek have been sharing their research with Chrysler for nearly nine months, enabling the company to quietly release a patch ahead of the Black Hat conference."
"WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked when Markey took note of Miller and Valasek’s work in 2013."
I did admittedly miss the "nine months" portion of that, but that's still only one company out of many.
> "WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked when Markey took note of Miller and Valasek’s work in 2013."
If you read further, you'll see the paragraphs on Markey's letters to auto makers regarding the 2013 findings; Markey's own findings only reinforce my point further.
Also, note that my point - that auto makers mostly ignored Miller and Valasek, according to the article - would not include senators (unless said senators build cars, of course).
Yes, it's the company that owns Jeep. The company that has a demonstrated the security flaw. How different automakers responded to different security issues isn't related to this article or discussion.
> Also, note that my point - that auto makers mostly ignored Miller and Valasek, according to the article - would not include senators (unless said senators build cars, of course).
Senators may not build cars, but they can (and are trying to) force auto makers to take security seriously.
The argument in this comment chain has been whether this problem could get the attention it needed without such a dangerous publicity stunt. The fact that automaker and lawmakers were convinced to take action by less dangerous demonstrations shows that this stunt was not necessary.
It is related to the article when the article discusses those responses.
> The fact that automaker and lawmakers were convinced to take action by less dangerous demonstrations shows that this stunt was not necessary.
One automaker (even this is dubious; Chrysler seriously expects people to believe that the only way to patch a bug that allows total control over a car's transmission and brakes - let alone the rest of the car - is via a USB stick, and that over-the-air patching isn't an option? Please.) and two senators. There are dozens more automakers and 98 more senators to convince. Hopefully the demo helps make that a better situation.
Meanwhile, a bunch of Dodges and Chryslers are driving around America totally susceptible to UConnect bugs, and a very large number of new cars on the road don't even have the most basic safety precautions (like, you know, not connecting the brakes and transmission to the Internet willy-nilly).
The convincing so far has been negligible. Hopefully that'll change soon, before someone with less-benevolent motives follows in Miller's and Valasek's footsteps.
And when said safer demonstrations are ignored by manufacturers, as was the case here?
What about all those wives and kids that would have been endangered if the flaw had continued to go unfixed and exploited in a more malicious manner?
Can we please not make "BUT THINK OF THE CHILDREN" arguments? Appealing to emotion makes arguments, well, emotional.
I am unwilling to say that. This argument that somehow the ends justify the means when there was a clearly more safe means has to stop. It's just ignorant.
No, he's saying you need a better argument.
The Mythbusters test stuff like this all the time. What do they do? Use an abandoned airforce base or the Utah salt flats. Rule number one, don't endanger the public.
The researchers did many of these things, according to the article. They were ignored by auto makers.
In fact, they may have been counting on that. If they really want to increase the exposure of a story, start a public debate. The easiest way to do that? Get some public outrage going. They called this all out, they'll need to deal with the consequences.
On the other hand, while two wrongs don't make a right, I'm glad that the researchers made that choice, so long as said choice results in manufacturers actually taking car security seriously for once.
I'm reasonably sure that if they had tested in a private track and made a public article it would have the same effect as what they did in their post.
In essence, the publicity factor is the most important, not where they tested it.
"Unlike most previously recorded car hacks, this demonstration was performed wirelessly over cellular networks. The vehicle shown is modified with third-party hardware for demo purposes. In stock form it is not vulnerable to these attacks"
which is quite different from the level of vulnerability showcased in the Wired article.
>Can we please not make "BUT THINK OF THE CHILDREN" arguments
Because, he said anything like that right? What a gratuitous use of a strawman.
It's not appealing to emotions, it's pretty rational to think this experiment could have easily caused an accident and hurt people. We all rationally know that driving is one of the most dangerous forms of travel. Seriously, a car is a dangerous, fast, multi-ton piece of metal, it's not a toy to experiment on when other people's safety is at stake. Respect the vehicle and the damage it could cause.
The exploits can and will be published and reported on quite easily without these reckless theatrics.
I don't agree with the methodology, either, but based on the information in the article, it sounded like the researchers didn't have much of a choice, seeing as how prior demonstrations were casually dismissed by the automakers. The auto manufacturers and the public both need a wakeup call, and this is a much more sane wakeup call than the even worse alternative of outright-malicious crackers breaking into vehicles en masse and reducing highway traffic to shrapnel in ridiculously-large pileups.
All of those things you listed are actual emergency situations that are hard to control. This is one thing where they were in full control of, and still decided to do it anyway. They had a choice, and they chose to endanger the public.
Yes, the researchers could have made better choices. They could have made worse choices, too. The "danger" here is significantly exaggerated given the descriptions of the scenario in the article (gradual slowdowns, contrary to popular belief, aren't that hard to react to in a timely manner), and it certainly does not compare to firing a gun.
It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's very clear that entire meta-categories of horrific errors are being made at a very fundamental level. Is this a problem of outsourcing? Of confusing "coders" with engineers?
And how do we solve it? Shame the software team such that they can never get hired in a serious role again anywhere? Professionalize the job into a strictly licensed regime like other branches of engineering?
Whenever I read these types of articles, my main thought has always been, "so who, the hell, wrote the code?" It'd be interesting to know their story.
Companies in industries that need to find ways to make secure software; it's not a hard problem if you're willing to throw enough money at it. But as long as customers don't care whether their products or data are secure, we'll get the security we pay for.
They might need Internet access for updates, in which case, there should be a physical switch that connects the net and disables the engine.
Better code quality is important too, of course.
I agree with cameldrv that it's going to be a challenge.
Actually, no. Google's Urmson has spoken at "connected vehicle" conferences and indicated they don't need car to car communication.
Thinking that "basic driving functions" will need to rely _heavily_ on internet access is thinking wrongly.
Some would say "this, this is why", but those people are not responsible for selling and maintaining millions of vehicles.
Surely there's a way to make this information read-only. I can see information about my engine on my dashboard via the speedometer and tachometer; it would be ludicrous if I could kill my engine by grabbing the little needles and cranking them down to zero.
There absolutely is a way. Just off the top of my head you could relay the information from the high-sec CAN bus to a low-sec one with a micro-controller. So the low-sec bus can only receive messages from the high-sec one.
Not enabling firmware loading over CAN on the relay is a must as well for obvious reasons, but the key is the code on the relay microcontroller can be kept very simple (easier to audit/secure).
Problem is, most automotive engineers are clueless about security and most "hackers" are clueless about automotive hardware, software and protocols. There is no dialog.
I wish articles like these posted at least some specifics. A lot of these hacks in the past were completely impractical. Yes, yes, they had shown some interesting possibilities, but it was disingenuous to present them as real-life attacks (which many media outlets did).
From a business perspective, security isn't a marketable feature until it becomes a problem—you don't install safety belts, or airbags, or protection against malware until after people start suffering from their absence in a vehicle.
Why? Because while you're busy building a well-secured system, your competitors are busy implementing new features that give them an actual advantage in the marketplace. As unfortunate as it might be, consumers tend to understand things like “remotely start your car with your phone” better than “your ability to brake won't be taken away from you while you're barrelling down the highway at 70 mph.”
It's sad and more than a little scary, but it's also nothing really new. Computer security, at least in the consumer sector, wasn't really a feature until viruses started showing up in the Eighties, and Internet security wasn't really a feature until the average Windows user's PC was getting taken over remotely the moment it was connected to the Net. Even Apple has only been able to tout security and privacy as a feature in its products by juxtaposing it to Google's business model—had the latter not existed and its data grab become part of public discourse, I doubt that Cupertino would have been able to make so much noise about it.
So, it's perfectly possible that every engineer and manager who worked on these systems is really quite competent and perfectly aware of the potential for security flaws (indeed, I doubt that they would have been able to make something so complex work otherwise), and still the sum of all the decisions made and market pressures applied caused the resulting product to be so vulnerable despite everyone's best intentions. It's not because people don't care or don't know, but rather because there are only so many resources available, and the market has pushed them all in a specific direction that happens to be away from security.
But this is also why we need this kind of research. Now that these problems are out in the open, and politicians are starting to take notice, security will become a feature that the public will care about, and, hopefully, car manufacturers will start adopting (or be forced to adopt) better standards.
Even if you disagree, preventing corporate liability is a component of competence in the law's opinion. That is, if the company is found liable, that's saying the employees responsible did something wrong, even if it's not holding them individually accountable.
Parent is 100% correct. It's market-adaptation. Same reason Samsung ships known-vulnerable extensions to Android: features >> security.
> So, it's perfectly possible that every engineer and manager who worked on these systems is really quite competent and perfectly aware of the potential for security flaws [...], and still the sum of all the decisions made and market pressures applied caused the resulting product to be so vulnerable despite everyone's best intentions.
I think this is key. Although I'd lump it more on management given that they allocate technical resources. When you have a lack of technical knowledge in management, you lose the ability to make technically informed decisions.
Sometimes the nuances of a situation can't be summed up in a PowerPoint slide. Especially when it's a slide that someone created to summarize a slide deck from an engineer that they saw.
You think at least some of the OPM vulnerabilities were internally unknown? Even with incompetence, you had to have actual engineers who looked at settings and/or lack of feedback and went "Hunh..."
According to the article, US politicians are looking at introducing legislation to enforce cybersecurity measures. At that point, it will just be another safety rating that manufacturers can and do use to promote their vehicles.
I want all my devices to be as dumb as wires.
Wired technology just works, out-of-the-box, no setup, no maintenance, no nothing .. just make sure the plug fit in both ends, and done!
Wireless technology should work similar, but via the air, like an invisible wire .. not as a open gate to the internet!
..and please let's not add multi-purpose CPU just for the sake of marketing!
This doesn't mean they're doing a good job though. Here's a link to where i previous discuss this: https://news.ycombinator.com/item?id=9801769
a) The developers were this incompetent
b) This "exploit" was a feature requested by the DHS
That's it. Maybe the State Patrol would say, "Sorry, there's nothing you can do to test this here legally", or maybe they would have said, "Pay for overtime for 10 troopers and you can do it."
The point is, we don't know. We can speculate, but we don't know.
The 'researchers' and journalist elected instead to conduct this experiment on a state highway, in "real world" conditions, without any safety mechanisms in place. Not only is this unethical and dangerous, it is (and should be) illegal.
No one should stop these experiments from taking place; and the CFAA should be amended to allow security researchers to research issues; but the problem I have is the inherent danger in this experiment.
What would we be saying if the journalist had been killed, or a mother and her two kids because of this? Do you think public sentiment would support security researchers if this had turned out differently?
If anyone had gotten hurt, you'd be looking at legislation that strengthens penalties for security researchers; not at legislation that takes security research more seriously.
This was an extremely childish move that had the propensity to hurt our industry more than help it. It is incumbent upon us take safety seriously in conducting these experiments.
We can't count on level heads from outside the tech industry if we aren't willing to show that we care about people's lives and their safety when we're conducting these experiments.
Agreed. I would have no problems with them doing this on a test track, closed highway, or even a quiet road at low speeds. Even if we take the best possible negative scenario—say, the car is disabled going at 25 miles an hour, the driver can't handle manual steering, and then runs into someone's fence—the insurance companies are going to throw the book at the driver when they learn that they purposefully disabled their car and engaged in dangerous behavior on a public street.
I'm all for pushing the boundaries of security research (there are people in the labs all around me right now doing crazy stuff), but at least we in the academic world get our crazy stuff signed off on by a panel of competent experts.
I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except through a one-way (to display information) link, like it's done on airplanes.
I'm happy to have a much older vehicle with none of these "enhancements". It has a physical throttle, hydraulic brakes, and steering linkage for which remote hijacking is physically impossible. I can add navigation and entertainment with a smartphone mounted on the dash. It may not be as fuel-efficient or safe(?) as the cars today, but maybe the tradeoff is worth it. That also suggests there could be a market for new "dumb" cars which have all the modern improvements to engines and safety, but none of these "smart" exploitable features.
(I'm not so paranoid as to get a mechanical EMP-proof diesel though...)
As much as I love Tesla and what they are trying to do to the car industry, they are the worst offenders in this. Hopefully by the time I can afford one, there will be legislation making entirely touch-screen dashes illegal and they'll have the usual 3 dials for climate control, that you can operate without having to take your eyes off the road.
Luckily, infotainment screen doesn't really host anything critical. My uses include navigation and phone. Both of those functions should be used while parked anyways. I just cannot imagine changing a/c settings only at stop light.
People have been using cars without touch screens for 50+ years. The UX is a pretty much a solved problem by this point. Yet now car manufacturers seem to want to mess with something that worked great, just so their cars seem cutting-edge.
It's like car manufacturers nowadays want people to crash their cars so that they can sell more of them.
That work and earlier work (including that shown in the 2014 Black Hat presentation by the researchers in the present article) drew interest of the Senate [2]. Senator Markey's office produced a detailed report, and has called for the NHTSA and the FTC to develop standards to deal with these issues (and also the numerous privacy issues modern cars raise) [3].
[1] http://www.cbsnews.com/news/car-hacked-on-60-minutes/
[2] http://www.cbsnews.com/news/sen-ed-markey-on-safety-privacy-...
[3] http://www.markey.senate.gov/imo/media/doc/2015-02-06_Markey...
It was up to WIRED to ensure the safety of the demonstration, and evidently they failed given this passage,
After narrowly averting death by semi-trailer, I managed to roll the lame Jeep down an exit ramp
Seems to me they should have at the very least had a chase car trailing the demo car with a sign, flashing lights, or flags to alert nearby drivers.
When a hacker does something reckless, it's usually painted as a problem with all hackers. Which then fuels calls for draconian laws which would hinder future research.
I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree.
But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now, with more rolling off the assembly line all the time, and people are driving these around right now.
Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place.
I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it.
And given that the topic you (I assume) want to discuss is something along the lines of "negligent behavior in technology", I also find it very relevant that negligence is countered with more negligence.
I just realized what the problem is: this is bikeshedding. Everyone knows about people driving around and feels qualified to have moral indignation in that area, whereas few people know anything about actual cars.
Yeah, maybe there was a case when a couple peoples' lives were at stake but nothing happened.
The real issue is that tens of thousands or hundreds of thousands of peoples' lives are at stake RIGHT NOW, under conditions that are much less controlled than what people are deriding as uncontrolled conditions. But people are griping about the 1-2 instead of the 10,000-400,000.
How is this not dead simple to understand? I don't get it.
Please don't assume disagreement implies I didn't make an effort. I understand your point, I just vehemently disagree with it. Bringing up the word "bikeshedding" when discussing putting people in danger of death is just something I can not agree with.
> Yeah, maybe there was a case when a couple peoples' lives were at stake but nothing happened.
This is exactly why I so vehemently disagree. If we found all the people who were in traffic with them at the time, do you think they'd agree that doing experiments in public traffic next to them is a purely aesthetical issue? Recklessness isn't defined by the outcome, but by the possible outcome.
> The real issue is that tens of thousands or hundreds of thousands of peoples' lives are at stake RIGHT NOW, under conditions that are much less controlled than what people are deriding as uncontrolled conditions. But people are griping about the 1-2 instead of the 10,000-400,000.
Yes, and I'm saying both are very important issues. Experiments on public roads in actual traffic are something that should not ever happen. I'm also not sure I'd put the amount of people they endangered in the 1-2 range, since there was at least one other person in the car, one in the truck behind, and others in the cars that passed them.
I also wouldn't go so far as calling this controlled, since that usually means a controlled setting, safety precautions and such.
> How is this not dead simple to understand? I don't get it.
As said, I do understand, I just disagree. It would also make it much easier to talk about this if you weren't trying to insult me and others.
I agree that the flaw itself is a very big issue. I disagree that the way the experiment was done isn't. And nobody here is arguing that it's good that the cars have that fault, so it's quite natural for the discussion here to be around topics people disagree on.
You know what the perfect location and media would have been for such an experiment? A television car show with a dedicated track and a big audience of people driving cars.
When these guys acted reckless, it hurts all of us. Even if the car company is 1000x worse.
Vulnerabilities in cars is an issue that needs to be fixed. Performing dangerous tests in uncontrolled environments is not a reasonable way to bring about change.
If they HAD caused an accident, how would you go about consoling the victims? "Oh, that sucks for you, but hey maybe your pain/death will convince the car companies to finally do something! Cool right!". It is not acceptable to introduce hazards to the general public to prove a point.
To be a professional is to have a duty to refuse to do stupid stuff like this, even if it's legal and even if your job depends on it. But is it legal? Why would we need any new laws for this? Connecting a wireless receiver to the same network that controls a car's brakes and steering seems to me like reckless endangerment. No need to wait for innocent people to die.
If history has shown us anything, it's that we cannot rely on software to separate two systems sharing a network. Only physics can do that. If we must have wireless for entertainment, then the entertainment and vehicle control networks must be air-gapped.
This seems blindingly obvious to me. What am I missing?
The bottom line - a cost/benefit analysis from a corporation.
Civil liability is a lower bar. Regular negligence is essentially not using reasonable care. Whether air-gaping a cars computer is reasonable car would be up for debate. But I think you'd have a good case.
Product liability is similar to negligence. It holds the builder, designers, sellers, etc. liable for design defects. But I'm not familiar with caselaw about how hacking vulnerabilities intersect with design flaws.
>If history has shown us anything, it's that we cannot rely on software to separate two systems sharing a network. Only physics can do that.
Yet, a shocking number of critical systems are exposed to the internet.
In this case, the manufacturer could argue that, in their review of the risks associated with their remote connection system, it was not reasonable to expect that it could be compromised and lead to a hazard.
Obviously, now that it has been demonstrated, there will be a much greater expectation that car manufacturers secure their remote access pathways.
Shouldn't this be the most basic design consideration for any company building autos? The liability from litigation should bankrupt any company that doesn't prioritize this.
It honestly beggars belief in my opinion.
Once you get there, doing things like turning on the heat or AC are nice tack ons.
[edit] Though remote control would probably be sufficient, but they seem equally dangerous to me from the driver's perspective.
The simple solution is just to have a separate wire for everything, and source devices that aren't supposed to control destination devices don't get those wires connected. The problem is that the automakers went to microcontroller busses because this creates a rats nest of wires.
The level 2 solution is have some sort of low-level filtering on the commands that are going out from a controller on the bus, so any command that the entertainment system sends to turn off the transmission doesn't make it onto the bus.
The level 3 solution is to have some sort of cryptographic authentication of entities on the bus, so that the endpoint can decide what commands it's going to accept from what source.
As you go from level 1 to level 2 to level 3, the system is more flexible, adaptable, and upgradable, but it's more complex, and thus more brittle to attack. Sorting out how to handle this sort of thing is going to be a big challenge as IoT pushes into more devices.
I think the best approach is to secure the internet connection properly. Don't permit incoming connections at all and just permit a single outgoing TLS connection to the server of the manufacturer, define a very simple protocol and spend enough time to be sure the client is secure and validates everything.
That is one of the principles of how Audi's system operates for security reasons.
Disable remote operation of car hardware when a conscious human is detected at the manual controls.
For some reason, this reminds me of Star Trek episodes where the crew has to transfer operation control of the Enterprise from the bridge down to engineering, or to another Starfleet ship. Even on a sci-fi television show, whenever that happened, it seems like they always had to enter a secret security code or have multiple bridge officers give their authorization codes.
It speaks poorly of your product design when writers for a television show give more thought to security than you.
In real life, people generally prefer not doing things.
Which isn't meant to excuse a problematic implementation like is seen in this article, I'm just not sure the writers were actually sweating the system details when they did that stuff.
The plot solution didn't even have to make sense. All they need is some technobabble, ready to spout for any fan wearing plastic ears who might stand up at a con and ask, "If Enterprise had capability X in episode Y, why wasn't that used in episode Z?"
In this case, it is very reasonable that someone, somewhere, might have asked, "What should we do if this command is used while the owner is driving along a busy highway at 70 mph, and executing it would stall out the engine?" This is a question that would provoke a stop-and-assess moment in even the most dysfunctional software company I have ever worked in.
From the architectures we typically see for in-car computer networks, it looks like no one is asking these questions.
So it will take legislation to sort out as liability concerns needs to addressed as well as the demands of law enforcement. Don't think for one minute they will accept self driving cars they cannot disable all of them for "safety reasons". Similar how they excuse options to black out cell service in areas
But this article doesn't really talk about how the exploit is triggered. This is pure speculation, but I bet it requires some physical access to install. And then the wireless control works.
Why do I suspect that? Why else would the journalist have to travel all the way to St. Louis to test it.
Imagine how huge the story would be if these guys disabled a car they never got within 1000 miles of over the internet.
There is probably some CPU in the Navigation/Entertainment display that needs access to the CANBUS for stuff like warnings, speed, airpressures, etc. and also is connected to the UConnect thing for entertainment purposes. You can't airgap because you need the car data.
So the lazy solution is to just firewall it. Make sure the CANBus controller for the entertainment system only sends data and doesn't receive any. Maybe you encrypt all data transfers on the bus for good measure.
But with temp physical access you can reflash that controller to allow it to give commands it receives from the internet connected entertainment system.
If you talk to auto manufacturers in a way that they understand, they will understand.
That's what they said about unintended acceleration. It turned out they were lying. http://www.edn.com/design/automotive/4423428/Toyota-s-killer...
http://www.autosec.org/pubs/cars-oakland2010.pdf6
Experimental Security Analysis of a Modern Automobile
"Even at speeds of up to 40 MPH on the runway, the attack packets had their intended effect, whether it was honking the horn, killing the engine, preventing the car from restarting, or blasting the heat. ... In particular, we were able to release the brakes and actually prevent our driver from braking; no amount of pressure on the brake pedal was able to activate the brakes. Even though we expected this effect, reversed it quickly, and had a safety mechanism in place, it was still a frightening experience for our driver."
http://www.detroitnews.com/story/business/autos/chrysler/201...
A dynamometer would cover the vast majority of what they wanted to show. There was no need to create the danger they created with this vehicle. They really didn't know how the driver would react, "don't freak out" guarantees nothing. A professional driver (like a stunt driver) would have been far more appropriate.
The business about disabling the breaks should have been done a pile of hay bundles or something like that in front of the car.
For exposure they could have contacted any number of TV stations or networks who would have jumped on this immediately.
In all, the choices they made were reckless, stupid, dangerous and potentially criminal. I don't doubt their tech credentials at all. They are tech-smart people, no question about that. However, they have proven, beyond a reasonable doubt, that they are poster children for that stereotype of socially clueless engineers and/or the other stereotype of scientists/engineers who are so into what they are doing that they are completely blind to the idea that they could seriously harm people through their careless actions or inaction.
Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.
On the other hand, I'd rather that they be doing this work with the way they did it than not at all...
That's such a stupid tradeoff. Putting it as an either/or is silly. Doing this safely and demonstrating the alarming conclusion are not mutually exclusive.
I'd go as far as to say that the way they demonstrated this actually diminishes the message of the danger of this exploit and put's the focus on their stupidity.
Doing it the way they did clearly increases the impact of their message. To believe otherwise belies ignorance of the way information gets spread in our culture. The question is only if the increased impact was properly balanced against the increased risk.
This case is even worse the the one I mentioned as there is a really easy way to safely demonstrate this exploit.
This has been their playbook about everything for a long time so I don't know why you think it would be different in this case.
- Contact the police and let them know this experiment will be conducted; and ask for police support
- Conduct this experiment on a closed road
For bonus points, throw in something like: "It's no different than your vehicle's advertisements displaying 'performed on a closed track' -- surely you're not arguing that the vehicle's performance in those advertisements is completely fake and you're deceiving consumers with said non-real-world advertising, are you?"
Meanwhile, do not buy a Chrysler product with the "connectivity group". It's an option that costs about $500-$600.
The researchers only experimented on a car they owned/controlled.
http://www.driveuconnect.com/terms/
(term 17)
One would think that car industry would be the one which has learnt about road safety the hard way. That experience should have manifested into extreme caution when adopting and implementing anything new, open and complex.
Sadly it is starting to look that everything they learn, they do by trial and error. Not by doing those things we take for granted from engineering and IT perspective.
How many people do you think will be murdered this way before investigators and the justice system catch up?
Also, this test should not have been done in a public road. That was irresponsible.
I was in that situation. No brakes, high rocks on one side, 100 meters cliff on other side, 20km of downhill in front off me. I guess I will not be buying Jeep anytime soon.
It is a safe assumption that these guys just happened to use a Jeep, and with some work almost any modern car could have this done to it.
[1]: http://i.imgur.com/IZymUKm.png [2]: http://i.imgur.com/C7LiA60.png
However, I fully agree this was a ridiculous stunt. They could have gotten the same results by demonstrating (on the highway, if they insisted) the air conditioner going full blast, the radio, and the picture of the hackers on the screen. Anything else (cutting transmission, obscuring visibility) should have been saved for a safer environment. The point still would have been made.
And it's got nothing to do with the vehicle and driver itself (though I wonder how the hackers knew the exact driving situation - was it plastered with cameras?) - what if two unrelated vehicles got in an accident for some reason and the test driver had to get out of the way, but couldn't?
And to make it worse, the cranked radio made it hard for the tester to communicate with the hackers. Very dangerous stunt.
Also, and I know it was unrelated to this particular hack, but if the UConnect recognizes voice commands (I assume so), and sends it back for processing, then might it not also be able to bug (eavesdrop) on the car's interior?
Many disturbing revelations came out of this, and I applaud them for making it known, but I criticize them harshly for the cavalier way they endangered public safety.
All I really want is two things:
1. The Voice button on my steering wheel to activate Siri. (Not the horrible UConnect voice assist.)
2. Waze maps on screen. (UConnect navigation is shit and not worth the price.)
If you're writing that software, make sure you do a really, really good job on security. Because no one wants to be the guy 'git blame' shows wrote the exploitable feature that led to ??? deaths.
The industry really should have stringent standards that prevent ridiculous breaches like this, I would say as well as simulators (or physical demo vehicles) available online/open source that people can pen-test against and win prize money. And maybe write all the code in Rust?
Huh? If they have a video of their turning a care off remotely, do they really need peer review of the details?
Which will probably result in lots of calls from people after they avoid hitting a dog. But still.
Maybe in addition to breaking a link on a panic stop, stopping and steering would be set to a non-commanded mode that relies less or not at all (maybe impossible with current design?) on software commands.
I guess the disconnect could be physical/mechanical and require physical intervention to reconnect (but cost, etc.).
The root problem is that they were able to flash an ECU with custom code. From there they are 'trusted' on the vehicle network and can trigger or emulate any other component.
Requiring the firmware image to be signed, or not accepting a bootload from the physical interface that's connected to the internet would be a more comprehensive solution.
http://www.detroitnews.com/story/business/autos/chrysler/201...
There is a patch available, but that is not a recall. A recall takes some time under the best circumstances and FCA pushes back hard on expensive ones.
Apparently someone has found a remote exploit that affects some model of Jeep. It requires an attacker to find the IP address of the Jeep. Which implies that a Jeep has an IP address. The communication between the Jeep and the world is something called Uconnect.
The article doesn't provide any clear information on whether this works purely remotely.
EDIT: Scrap that, seems it does - weird that the article doesn't lead with that more prominently. In which case wow - pinging the network and grabbing GPS coordinates for cars?
Calling the police was indeed the right thing to do.
Maybe next time, the hackers can test on the vehicles driven by the car executives, while they are driving, have their family in the car with them, etc.
Can't wait to see that comment thread...
or is it more about the Uconnect than anything else ?
the real issue is that the automakers are producing fundamentally dangerous vehicles and the federal government is allowing it. these vehicles could be exploited maliciously to cause serious physical harm or death.
this is actually a problem. not some onetime stall of a jeep on the highway.
> To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west.
> Instead, they merely assured me that they wouldn’t do anything life-threatening.
> Then they told me to drive the Jeep onto the highway. “Remember, Andy,” Miller had said through my iPhone’s speaker just before I pulled onto the Interstate 64 on-ramp, “no matter what happens, don’t panic.”
When I read the article, in my mind, I pictured them driving the car on an empty-ish highway/road. That was clearly not the case.
> How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything?
> Calling the cops on a loud neighbor might not be acceptable, but calling the cops on a neighbor firing a gun in the general direction of your house certainly would be.
> Anyone could shoot up a public place... should amateur researches be showing up in malls with firearms to test preparedness?
The lack of sound judgement _and_ arguments is astounding.
Is this even really considered an issue?
Back then, however, their hacks had a comforting limitation: The attacker’s PC had been wired into the vehicles’ onboard diagnostic port, a feature that normally gives repair technicians access to information about the car’s electronically controlled systems.
A mere two years later, that carjacking has gone wireless.
So the issue is right there in the surrounding text.
Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent.
Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason.
And wtf you called the cops? head in hand
Bunch of idiots if you ask me, no better than the clueless people you see talking on their cellphones distracted. A 1 ton vehicle is deadly in the wrong situation.
Like many other people mentioned, there's many ways to demonstrate this is a safe, controlled manner rather than out in the wild.
....... ... .... ....
"Elite," seriously? Is it 1995? Is the movie "Hackers" some type of inspiration to you? I'm almost surprised you didn't go all l33t speak.
They endangered people's lives. It is as simple as that. If you too endanger people's lives "for no reason" on I-40 I hope they get you too.
Yes, elite. I'm not bringing it back; they already did.
That's why every research lab has an ethical review board.
Scientists failing to care about social consequences is nothing groundbreaking.
Okay, okay, I'll admit that they could have done it on an open stretch of road... Which is what I had pictured.
I thought about this thread during my drive home. I thought about hacking my own car's systems while driving...
I immediately realized: no WAY. No, no, no. What if I accidentally BRICK the thing, while driving?
Remember that model of car that lost steering and braking when the ignition key fell out due to a manufacturing defect? What if the Jeep would lose steering when bricked?
It is morally unforgivable to even try to change the radio station while a human is sitting in the "brick" if said brick is moving at 70mph. Especially since the software is known to be faulty.
"Known to be faulty" does bring us back to the manufacturer. I think that much of the anger directed at the hackers should be directed back at the manufacturer.
That being said... Back to the original topic of this particular comment: I apologize. Thanks HN for making me think a little harder.