Fiat Chrysler recalls 1.4M cars after Jeep hack
bbc.com
bbc.com
The real fix will require much more intervention than just a firmware flash at the garage.
We'll see at Def Con how much Chrysler really screwed up.
It's the only one available to them. They can't just refit all existing cars with a new design on a short timeline. Hardware has permanence.
With that in mind, how would you fix the issue for existing vehicles?
The problem is access to the CAN bus is necessary to change various vehicle settings from the infotainment system. I know for a fact that changing the door lock settings in my car requires the infotainment system to access the CAN bus to apply settings to that system.
This is not an unsolvable problem; this is basic software engineering. Processes should be isolated from each other. I imagine everything in the infotainment system effectively runs as "root" because they consider the whole thing a singular black box.
There is little genuine need to send commands from low-importance networks to high-importance networks. Yes, you would have to live without single uber-control touchscreen, but it's not really that big of a limitation: you simply need separate controls for low-importance and high-importance things.
Last car I had (Kia Forte) was actually very pleasurable... they had a very helpful digital display but all the adjustment could be done w/real buttons.
The direct control interfaces in a car that tend to be very well designed and implemented are the basic movement controls like the steering wheel and pedals. These are distinctive and immediately recognisable. They work predictably and after proper driver training they become very intuitive. Drivers in an emergency can often still manage to swerve or brake to avoid a collision, and that is the level of user friendliness you want when you're in control of multiple tonnes of fast-moving death machine.
Other parts of the interface that modern cars tend to do very well are all the subtle behaviours behind those controls: the power steering that adjusts so it "feels right" at any speed, the independent driving and braking of different wheels so the simple pedal controls don't unnecessarily spin the wheels if you try to move off with too much gas but do retain control without skidding unnecessarily if you brake and steer at the same time in an emergency.
And of course there are a raft of safety systems in modern cars, some fully automatic, but some giving subtle cues to the driver to help them predict and hopefully avoid dangerous situations earlier.
But these so-called infotainment systems, and radios, and communications systems, and satnavs, and fancy environmental controls... Most of these are just awful, and sneering at them is entirely fair and justified right now, so separating them from the essential controls that keep the vehicle operating properly and safely should really be no problem at all.
Yes, the info system needs SOME access to the CAN network. But it shouldn't be unrestricted access. Instead the info system should be treated as "untrusted" and only specific things should be permissible over a well documented set of APIs.
I'd almost be tempted to say that while the car is moving, ALL access to the CAN network should be disabled. Since let's name some things the info system needs on the CAN network:
- Reconfigure car (e.g. daylight running lights, auto-locking door, etc).
- Start car remotely.
- Set AC remotely.
- Diagnostics.
The only one on that list which MIGHT be useful to have while the car is in motion is diagnostics. And that could be delivered via a read only interface.
It's not really about RO v RW, CAN is about sending commands. The head unit could say, it's the brakes, so that has to be protected against.
When there is not a physical layer doing that protection (separate bus, a filter, and so on) there are two other layers. One is the thing sending can reject it from going out, but that takes resources that might not be there. The other the receiver does some sanity checking on it, like "you want me to go in P but I'm going at 65, yeah I don't think so" to even it's gotten common place for messages involving the brakes include a shared code back and forth.
Really I think this boils down to there are untrusted channels (wifi, cellular, DAB) that should be locked down better. I mean the DAB thing, likely it's a buffer over flow in the head unit. Even if that has a cpu that is running FW that is making sure the CAN messages it is sending are sane, the exploit just makes it stop doing that. There's such a pressure to save cost and so many OEMs involved that ease of integration motivates the rest.
Yeah it sucks, but it is what it is.
"Yeah it sucks, but it is what it is."
This attitude might work with some other things, but the automotive industry will have to deal with security in a reasonable fashion. This is potentially life-and-death stuff and consumers actually have choice here. Not everyone understands the full implication of someone tracking their cellphone or hacking their email, but everyone can imagine what will happen if your car will get out of your control.
I've been trying to describe two things. One, the way that CAN bus operates, so some of the technical solutions people have been making just are impossible. People should imagine that CAN bus is something like RS-485 or the old systems that had some mix of ISA and PCI, not like switched ethernet. The second item is a bit of how these things happen in business world, for good or bad, not that I agree with it or anything.
But wouldn't those likely be one-way commands TO the infotainment system? They would still work even if it was receive only.
Basically there is no notion of to or from really. When you push the vol+ button on the steering wheel there is a controller that sends a message trying over and over again until there is no collision. That message has an ID in it early on. In this case it will be like I dunno $412 okay. That means audio controls or something. A bit later is some length and then the data, say the data is $C.
The infotainment unit is listening to everything just as the controller for the steering wheel controls is and everything else on the bus (it has to, because of how collision detection works). When the controller in the steering wheel sees that $412 ... $C it goes, well isn't that nice, me or someone else sent the vol+ message out finally, cool, I'll stop sending that now. When the radio sees that message with an ID of $412 it goes, oh that's an audio control message command, I should pay attention to that. Then it looks at the length and data and sees $C. It goes oh that means someone pressed vol+, I'll make it louder.
But here's the thing, there might be a knob too for volume and there really is just one board doing the infotainment. It's not like the old days where it's a potentiometer, it's not even wired directly into the board that handles infotainment. All the IO pins that board has are already used-up handling the screen, CAN bus, and other things. When you twist it, it also sends the same $412 ... $C over CAN from it's controller! The radio did not know what sent it, and that's by design in CAN bus.
There might be mobile phone integration, it can do CAN too, say also a $412 with with a different payload (and possibly length) that might mute on call. Also there may be a touch screen, but that will not do a thing over CAN if you press the vol+ there, just do it's normal IO from screen to SoC on the board.
Am I doing a better job of explaining? The take away is lots of things can send the same message and lots of things might be interested in that message and that is how it is intended. To some extent you can mitigate this in hardware. You can make long runs or some shorter star shaped topologies as long as you get the termination right. For the star shaped topologies you can stick gateways in there. The controllers can be setup to filter on certain conditions and the bus is the limit for filtering if you are using a programmable part. What I mean by bus is the limit is things like there is no notion of to and from.
That's what you get in CAN bus cause that's how it works. You can thank Bosch for that.
It seems like a good design in a very noisy environment and it does allow the car manufacturer to easily add in new controls ( volume up for example ) in different locations that do the same thing.
CAN is great for its purpose, but handling untrusted actors is not part of that purpose.
What should happen is a non-CAN hardware gateway that only passes valid commands to CAN buses.
Other cars have climate controls built into the info unit.
Then, there are cars like Tesla where nearly everything comes from the info unit...
Totally doable, but it is unbelievable to me the lack of forethought in things like this.
I think that's a good idea, but I think it would be better if it was a small hardware firewall than a program in the infotainment system.
I would think something like that could even be entirely formally verified.
So we're in complete agreement.
It's not just security - you can't have bugs in one system causing other systems to go down. You can't tolerate a bug in the radio causing the car to crash (didn't anyone learn anything from the demise of the Death Star?)
The Fukushima disaster and the Deepwater Horizon disaster, from what I read about them, all suffered from easily preventable "zipper effect" of cascading failures.
Every industry apparently has to relearn the hard way what the aviation industry learned decades ago (and what the Navy learned even earlier).
That's vitally important to understand. The systems are mingled but they don't have to be and in fact shouldn't be.
Also, not all isolation is the same. Consider the scope of isolation between multiple sandboxed apps (some accessing the raw internet) on a single computer and two separate computers connected via a specialized protocol-aware data diode.
So often though a designer will say "We really want to help people who call in for roadside assistance, we just want to read the CAN bus, we don't need to write it." And some complex function will be created that only "reads" but then a overflow attack or some other exploit lets arbitrary code get run and since its possible to write code with a write function your security is toast.
So what actually will happen (I hope) is that a bunch of things will no longer be possible from the infotainment system because that system doesn't have access to the CAN bus at all. And any UI that does have access to the CAN bus won't have any wireless access to it at all. Which will make some car features, less featurefull.
I definitely agree though they need to take this to the level that's usually seen in avionics with a read only gap between the third entertainment system bus. Without that you really can't hope to secure it. The only real problem I can see is how would you let the roadside assistance stuff unlock the doors? Maybe an authenticated write only to the low speed bus that you don't get to control the message, just "unlock all doors".
http://www.lakecountrynow.com/opinion/blogs/communityblogs/1...
After more investigation they ended up suspecting a different failure mode, but it speaks to the danger of even pedestrian functionality. Most people are shit drivers who are unsafe to be around in the best of times, "minor" things like stereo control, windshield washing, etc are certainly enough to distract them let alone being physically moved out of the reach of the controls. Particularly in combination, let alone in rush hour traffic or bad weather.
Analogy: is it worth the time making a pick-proof lock for the front door when someone can just break a window?
(I'm not saying we should let car manufacturers off the hook, just offering a perspective on the realism of the threat.)
>Analogy: is it worth the time making a pick-proof lock for the front door when someone can just break a window?
Yes, because not everyone can throw a rock from their house to yours, be nearly everyone can be connected to the internet.
Attribution. Mechanical attacks are easier to attribute than something that can be done from across the world over the Internet.
It could be it's own CAN bus completely separated but you probably also have the CC on the wheel too. So do you put the CC on the same one? But wait, there's the SRS there too, oh man that plays ball with the self diagnostics.
Hmm looks like we need a high priority CAN in the wheel, might as well use it for everything.
That's how it goes...
It's the infosystem that shouldn't be able to broadcast on that bus. There should be a very limited set of messages that will be accepted from it and there should be a dedicated circuit that drops everything else.
So one reason the infotainment might want to send commands is to that station/song information appears in the instrument cluster.
Now I agree it would be really smart if there was another module sitting between the the radio and the IPC with two sides and it filters both ways. Also that gateway has logic like, I have power but it's been less than a minute, this packet has the right code, sure I will let this reflash happen. In fact such devices exist (except they are more trusting).
The thing is though that the radio tends to have the most impressive CPU of all in the car, so there is pressure to add that in there (I mean there was one manufacturer that had tried to merge BCM, TCM, telematics, and DIC all into the head unit with a roughly 400MHz cpu, so that gives oyu an idea), logic like 'yeah maybe, we won't be sending that in fact.' But once it is hacked, all bets are off, it can even DOS the bus. The other aspect is you just want they crap from Delco to work with the stuff from TRW and the gateway is getting in the way and yo don't want to expend the resources to figure-out why.
When it was all a wired network, it did not really matter so much.
I get that. And if it did, the attack would by spoofing that.
Which is why the solution needs to filter what goes onto the bus - at the only point the source is known.
> When it was all a wired network, it did not really matter so much.
Well, consider if I told you there was a way to "cut the brakes" (at a future date, when the car is at speed, etc) on any car you've been in, without any tools needed or evidence left. Untraceable murder.
It's only the scope of the current attack that makes that look minor.
No, it's the only easy option they have.
Take all the vulnerable vehicles off the road. That's another option they have.
> How would you fix the issue for existing vehicles?
Have dealers yank the cellular connection in every vehicle and refund the customers something for removing a feature the product sold with.
Nothing else will fix it in a short timeline.
We recommend layered security to protect people's cat pictures – doesn't it seem like a good idea for something which could literally result in casualties?
If they were yanking the cellular connection that'd be pretty good... If they're just patching one or two obvious holes it'll likely be broken again by Blackhat.
But:
https://twitter.com/0xcharlie/status/624608184485851136
So the vehicle connection is not as visible as it used to be.
But that's the least useful way to protect us. Literally. If the vehicles remained visible they'd have to fix the bugs - this way they'll simply pretend they did.
That automobiles are recalled for reasons other than hardware replacement is a recent phenomenon.
However a software patch would keep Def Con busy while replacement hardware is developed.
Sure, but how often are they doing major surgery vs. replacing a part / doing a patch? It sounds to me like properly fixing this issue would be a fairly sizable undertaking.
We need to communicate that this isn't a decent half-measure, this is specifically a worthless measure intended to keep vulnerable cars on the street where they can kill people because a real fix is seen as being too expensive.
You are absolutely correct. Unfortunately, so is "jacquesm":
> > They have to be seen to do something to counter all the bad press.
To me, Fiat Chrysler is doing classic PR damage control that the automotive industry knows far too well. It wouldn't surprise me to find out that Fiat Chrysler has threat analysis reports regarding this and other vulnerabilities within their organization.
Sadly, this is not uncommon in the automotive industry[1]:
GM has been heavily critiqued after the
company admitted that engineers were aware of
the issues that caused this recall as early as
2004. Yet it took nearly 10 years later for GM
to finally issue a recall ...
1 - http://www.bcoonlaw.com/general_motors_recall_lawsuitThat thing here is a big fucking warning to all other car manufactures for the future.
http://www.wired.com/2015/07/jeep-hack-chrysler-recalls-1-4m...
> Chrysler says it’s also taken steps to block the digital attack Miller and Valasek demonstrated with “network-level security measures”—presumably security tools that detect and block the attack on Sprint’s network, the cellular carrier that connect Chrysler’s vehicles to the Internet.
Oh great, they'll install an antivirus and think they've fixed the problem.
So, if I'm in someone's Fiat Chryslermobile, and they're pumping gas, I can flash the vehicle's firmware from the passenger seat?
This seems a lot easier than rooting it over the air.
This is a super strange thing to say after your first quote. They've blocked it on the cell network AND are sending out updates to car owners.
So how you ignore your own first quote to criticise them for "only" blocking it at the network level is bizarre, it is like you didn't read your own post...
Any network fix is useless smoke and mirrors.
Regardless it's the only and correct decision they can make at this time. It's honestly not terrible at all. What would be terrible, and valid of the comment "a terrible decision" would be doing nothing at all.
We all acknowledged the issue is architecture, and that can't be fixed by flashing firmware.
Ignoring direct violence? DoS PSAPs so small things like reporting burglaries or helping heart-attack patients fails. Or shit, have you seen the cabling at many datacentres? Take a few of those out and the US Internet would be off for what, weeks? (And that one you can even do remotely.)
My point is that you cannot harden the entire US infrastructure. Saying this car issue "has terrorism implications" is either a tautology or fearmongering.
I don't think that's the case, but I still commend them for doing a recall this quick.
Shooting the messenger seems to still be quite a strong reflex for corporations faced with bad news. The way to look at it should be that these guys did Fiat-Chrysler a service. After all, it's not only security researchers that have the ability to write code and that have prolonged access to a vehicle to test.
They seem to be mistaken about the time to write the code, after all, you can write the code and test it on a different vehicle than the one you intend to crash.
Law enforcement typically won't analyze the firmware of all the computers in a car after a single vehicle accident (and it would probably be quite possible to erase the evidence once the car has been given a command sufficient to kill the occupants).
You know that engineers on the ground were well aware of this vulnerability. You know they tried to warn. But what happened to the warnings? They didn't make it up to the executive levels necessary, because several layers in between feared for their jobs and careers if they said something like "This new feature you're demanding could be used to brick every single Fiat-Chrysler vehicle we make, or even murder people". So the executives were asking for features but flying blind on danger.
And ultimately, this is a failure of the executive structure and the corporate structure (and it's an inherent antipattern in large organizations). Since the nature of hierarchy is for subordinates to hide unpleasant truths from superiors, they should have been actively asking about the hazards. They could have hired outside security reviewers. But they didn't.
The recall aligns with an ongoing software distribution that insulates connected vehicles from remote manipulation, which, if unauthorized, constitutes criminal action.
So through the process of extensive journalism, unauthorized remote manipulation got turned into hacking vehicles.
> The recall aligns with an ongoing software distribution that insulates connected vehicles from remote manipulation[...]
Assuming that's not a lie, were they working on that because the 'researcher' (quotes due irresponsible 'testing') had been sending FCA what they found instead of their own internal decision to improve things and they knew this (specifically) was coming at some point?
I'm not quibbling about that. I replied to this statement:
> The company added that hacking its vehicles was a "criminal action".
I don't think that's the case, but I still commend them for doing a recall this quick.
Which characterizes the statement in the article to be about hacking the vehicle at all. So my reply points out that the manufacturer was probably not putting forth that characterization when they talked about criminal action, they were likely talking about unauthorized remote manipulation (which should be and quite likely is criminal).
So my argument is that the manufacturer statement about criminality is narrower in scope than the BBC translation of it.
The software update release is obviously in response to the research:
https://twitter.com/0xcharlie/status/623492229714313216
Upgrading it to a recall is probably in response to bad press.
> I don't think that's the case, but I still commend them for doing a recall this quick.
It is illegal under existing laws. Basically, it falls under the same set of laws as cutting someone break line. You are, at a minimum, in the "Reckless endangerment" category.
It doesn't take new laws, the old ones have seen enough people doing stupid things to other people's cars.
"if you manage to provably put the public in danger"
Watching the video, they did it on a public highway with other cars. They killed his engine when he was on the highway. He is damn lucky he wasn't rear-ended and killed someone. Yes, that is illegal and definitely endangerment.
This is crap stunt journalism.
The only crap stunts here are by the car company pretending to fix the issue and knowingly leaving everyone vulnerable.
Some traffic may have backed up for a minute until he restarted the car.
The issue is what the extra risk is compared to the baseline risk.
There's no doubt that driving is inherently a terribly risky activity. But I also don't think that pretending that taking your foot off the gas on a highway is a risk-free activity is particularly helpful.
Then combine that with the recall it spurs. The value of a live highway hack is very high. It got all the media to pay attention and got a commitment to a fix. You're freaked out about one car slowing down in traffic. Imagine many of the 500,000 vulnerable cars simultaneously accelerating wildly all across the nation if this was actually exploited.
What's the risk of doing nothing? Or of wasting years more with ignorable private disclosure?
No, I'm pointing out an idiot reporter endangered his fellow citizens to create hype instead of doing the reporting in a safe environment. Your the one who seems to be trying to justify endangering people to report someone else is endangering people.
The demonstration could have been done safely and effectively on a rented race track. It happens all the time when you want to test something around motor vehicles. Instead he went for cheap and sensational.
Doesn't the DMCA make that illegal? Isn't that the big fuss about John Deere tractor fixing and the like?
Should they be criminally charged, no, not for the hack itself, perhaps for the highway theatrics. But they deserve to sweat and hire some lawyers, and perhaps face a civil case for the irresponsible way they disclosed it.
The surest way to get legislative pressure put forward to regulate the info sec industry and put red tape that hampers or outright outlaws security research and activity is to have guys like this being so irresponsible with research that affects people's lives as to give them cause to.
[0] https://twitter.com/0xcharlie/status/623492229714313216
[1] https://twitter.com/daviottenheimer/status/62351634451271270...
They deserve to be charged/locked up for that portion of it.
Not something that I would do, at least not on that stretch of road. But, nobody was actually harmed, nor was anyone even inconvenienced beyond perhaps having to make a lane-change. It could have caused a pile-up accident, but to give some perspective, I commuted into Houston on that same day and counted half a dozen disabled vehicles on my route, and two police officers trying to catch speeders; both of which add at least the same magnitude of risk to other motorists.
>They deserve to be charged/locked up for that portion of it.
"They" the two that did the risky road demo, or "they" the ones who waited 9 months to mitigate the safety defect in thousands of cars? Locking one of those groups up makes us more safe, and the other less.
That's ends-justifies the means. I'm not arguing someone was hurt, I'm arguing they put people in a situation with a higher than necessary risk.
> I commuted into Houston on that same day and counted half a dozen disabled vehicles on my route, and two police officers trying to catch speeders; both of which add at least the same magnitude of risk to other motorists.
You can't control what other drivers around you do to cause road hazards, but in this case that's exactly what the hackers did. By cutting the transmission they caused a possibly dangerous situation.
They could have done this test safely in numbers ways. On a rig designed for testing horsepower, an abandoned parking lot, a private track, or asked some police to close a section of road.
Instead they did it in about the most dangerous way possible: live on uncontrolled roads with other traffic.
> "They" the two that did the risky road demo, or "they" the ones who waited 9 months to mitigate the safety defect in thousands of cars?
The 'researchers'/hackers. They directly put people's lives at risk to have a stunt to prove their point.
FCA screwed up big, and deserve some sort of penalty from the government. This shouldn't have been possible in the first place. But they didn't modify a running vehicle at 70mph surrounded by unsuspecting motorists.
If the hackers had done this reasonably safely, I'd have no issue at all. But they don't deserve the title 'researcher' after behaving like that.
I don't like it either, but it's a common philosophy that we experience in our daily lives, whether we want it to be that way or not.
>Instead they did it in about the most dangerous way possible: live on uncontrolled roads with other traffic.
There are a number of ways they could have made it worse.
>The 'researchers'/hackers. They directly put people's lives at risk to have a stunt to prove their point.
We tolerate the same kinds of risks daily by allowing police to conduct traffic stops on busy roadways. We do so ostensibly because safety, but the reality is that it is mostly for some pretty dubious financial reasons. That's ends justify the means, and in this case ends are traffic fines collected, and the means are lives of police officers and motorists and man-decades of time lost in traffic every day.
>FCA screwed up big, and deserve some sort of penalty from the government.
But not jail, like for the evil hackers-not-researchers?
>This shouldn't have been possible in the first place.
Another uncomfortable reality for you. Software verification is a huge challenge which nobody has gotten right yet. There will be more of these vulnerabilities. We have to get this disclosure/update process right. The best thing that automakers can do to prevent disclosure stunts like this is to fix vulnerabilities ASAP when they're discovered.
>But they didn't modify a running vehicle at 70mph surrounded by unsuspecting motorists.
What they did/do (months worth of nothing) is far worse, and endangers far more lives. Imagine if someone/somegroup/somegov't had managed to bundle this vuln with a popular cell-phone app, or mobile website, and decided to activate it one day at rush hour.
>If the hackers had done this reasonably safely, I'd have no issue at all. But they don't deserve the title 'researcher' after behaving like that.
That's just petty, and nobody really cares what you call them. It does nothing to move the discussion in a fruitful direction; but it does make you appear a bit shallow in your reasoning.
We've chosen to accept that risk, and have control over it though government. People could choose to make it illegal.
Also note that when the police do it they take precautions such as having bright multi-colored lights on the car to draw attention.
It also bothers me that the Wired guy didn't know what was going to happen, so he couldn't prepare as well. Even that would have helped (though I still think the stunt was dangerous enough for someone to go to jail).
> But not jail, like for the evil hackers-not-researchers?
We can't put a company in jail and we don't usually do it with the CEO for much bigger crimes. I doubt the CEO had any idea this could happen.
I imagine this is one of those things where dozens of people in different departments (and even companies due to auto parts suppliers) all made small but not terrible bad decisions that added up to a huge problem. I doubt there is a smoking gun email someone where a manager says 'I know someone could disable the car on the freeway but it will save us millions!'
And while this is happening to FCA there are other cars with cell connected systems (VW, BMW, Audi, others). I imagine if we had enoug time we'd find at least 2 or 3 other companies with vulnerable systems in other car brands's 2015 models.
I just don't see how we could jail anyone in FCA. That's why I didn't call for it. On the other hand the hackers seems like a pretty cut and try case.
> That's just petty, and nobody really cares what you call them.
The words you use to describe something matter. Having taken such a stupid risk I don't see why they should ask to be acknowledged on the same level as security professionals who don't put people in danger for headlines.
Frankly the number of people in these threads defending the overly dangerous demo scares me, as does the number of people who seem to tacitly encourage such behavior.
I'll expect to see you down at the legislature lobbying for reform and threatening jail for the opposition.
>Also note that when the police do it they take precautions such as having bright multi-colored lights on the car to draw attention.
It's hard not to notice something so distracting! That's another argument against the practice, isn't it?
>We can't put a company in jail and we don't usually do it with the CEO for much bigger crimes. I doubt the CEO had any idea this could happen.
It's a funny thing. We can never seem to find anyone in a company who knows anything or has any responsibility. We just have to satisfy ourselves that if popular opinion moves against a company strongly enough, or the gov't gets shamed into prosecuting them, that maybe then they might address some problem, usually after it actually kills people, so long as nobody has to admit fault. It's almost like a huge stunt is needed to get peoples' attention sometimes!
>I imagine this is one of those things where dozens of people in different departments...
Yeah, we all know about how corporate structures insulate decision-makers from the consequences of their decisions.
>cut and try
"Cut and dry" So, because it's easy to prosecute these two, and hard to prosecute the others, justice should take the easy route, even though one may have endangered tens of people on one occasion, and the other endangers tens of thousands of people for months? I see a different value proposition here than you.
>Frankly the number of people in these threads defending the overly dangerous demo scares me
I guess it would surprise you to learn that I feel the same way about you after this conversation?
I dont know another way to say 'this is not acceptable'. To literally just say it but not punish... I do t think that would be heard and someone else would take a stupid risk.
They certainly don't need 5 years or something like that. Just a very noticeable slap on the hand.
When are you going to start discussing the criminal implications of the company in ignoring that disclosure?
> a way that isn't quite so expensive or rushed.
Since when is the company's expense our problem?
The fix is trivial. Yank the cellular connection. The company is refusing to do the simple, easy, and quick fix. They're the ones making it a painful process. They're the ones choosing to leave everyone vulnerable while they hide the problem with a bandaid.
> legislative pressure put forward to regulate the info sec industry
Your country's laws are your problem. That would be disastrously dumb, but it's your responsibility to forbid your politicians from shooting the country in the foot.
If you blame this on hackers you'll only ensure that a foreign hacker will start a campaign of trying to get you to pass broken laws.
If your system ALLOWS other assholes to take over my car, it's DEFINITELY a safety issue.
Now, for a civil action, it is always fuzzy. Whether or not it is negligent is going to be based on many things, a big one being whether it was "reasonable". Shipping cars before this event may have been reasonable, but continuing to do so many be negligent. But at least in the US, that needs to be decided in court, not on the internet.
I'm pointing all this out because you said "Certainly". That word really has no place in the US legal system.
You can replay this story 10's of times over the next couple of years and lets hope it's only the nice guys finding them.
Ain't America's laws wonderful?
Is it? I thought the encryption has to be "effective", which would not be the case for ROT13. I would even argue that ROT13 is merely an encoding.
No, the exemption is this:
Encryption Research. The DMCA exempts encryption research from its circumvention and trafficking bans. Circumvention of access controls by one who has lawfully obtained the encrypted copy is permitted if the circumvention is done in the course of "an act of good faith encryption research." The researcher must first have made a good faith effort to obtain authorization before the circumvention, and the circumvention itself must not constitute infringement. The researcher may also develop and employ tools to circumvent the access controls for the sole purpose of carrying out the research, and may share those tools with collaborative researchers. The DMCA lists several factors to be used in determining whether the exemption for good faith research should apply in a particular situation, including whether and how the research results were disseminated, whether the researcher is engaged in a course of study or is trained or experienced, and whether the researcher provides the copyright owner with the results of the research.
Effective would probably have more to do with covering all the routes of ingress rather than doing so strongly.
But when it comes to politicians trying to ban encryption and automakers trying to ban me from editing bits on a memory chip that I got as a part of purchasing one of their cars, I really am unapologetic when I say I really don't understand them. I completely and utterly lack an ability to get into their heads. It would be fascinating to lose my knowledge of everything I know about computers for a day and give these issues thought. To have computers be mystical voodoo magic would be an amazingly different world.
If I had to give it a guess, that's probably what I'd say. Politicians and automakers and middle aged Edward Snowden haters all lack an idea of what is possible and what is unpractical when it comes to computers. They lack an appreciation for just how much commonality there is between the computer running a McDonald's register and the one making sure their car doesn't kill them.
Politicians think we can just "ban" encryption, as if this isn't some mathematical concept with freely-available professionally made implementations. They think Apple has gone to great lengths just to implement their end-to-end iMessage encryption... when in reality they almost certainly took the path of least resistance and merely stand on the shoulders of giants that collectively implemented encryption for them. PR reps for automakers think of code in such an abstract way that they think modifying it must be terribly difficult and thus inherently malicious, when in reality their programmers stood on the shoulders of giants and used the same common interfaces that every programmer uses. Hacking their car was probably done by a curious man decompiling the firmware which they pulled off via JTAG or a test clip. They think Edward Snowden must have been sneaking around in underground tunnels with a ski mask and plugging his laptop into servers, when in reality this was just a drive that was mounted on a machine he used.
Tl;dr: Programmers all pretty much follow the path of least resistance. The general populations lack of background makes them think that things are much more difficult and thus deliberate than they really are.
Plenty of the Edward Snowden haters are <= 30 and plenty of the people that applaud him are > 40 so let's not add age into that discussion.
Whether you are pro/against Snowden probably has more to do with your life experience to date and your general views on what a government should be able to get away with.
> Whether you are pro/against Snowden probably has more to do with your life experience to date and your general views on what a government should be able to get away with.
I only said, "middle aged" for exactly that reason: you might hate Edward Snowden and be a totally technically literate person. Age doesn't necessarily shape your view on Snowden, but age almost certainly correlates with technical literacy, and I think technical literacy definitely plays into your perception of how much effort Snowden went to in order to gain access to the files he leaked. If you think that he went to great lengths to gain access to the files, you might think his actions were more malicious / that he was looking for trouble.
Law enforcement won't try to analyze the firmware, but class-action lawyers certainly could. Won't do any good if the bad actors have erased their tracks of course.
We're all used to the idea that if you put a computer on the internet, it will come under attack. People will try to snoop on the data it handles, or subvert it to use it for their own purposes. So why do we then move on to assume that, if such a system is attached to something safety critical, that those same people who will attack the computer to get at its data or processing power will now move on to attacking the brakes, or the engine, and try to kill people?
Most vehicular crime isn't homicide, it's acquisitive - people will attack vehicle security systems to steal the car, or get access to valuable contents. Sabotaging the vehicle to kill the driver is way down the list.
As a society we tend to assume that physical security is not the only thing that stops random strangers from trying to kill us. We do not all drive around in armored cars in case someone decides to shoot at us from an overpass. We don't all sweep under our car with a mirror for bombs before we get in and start the engine.
And it's certainly not a failing of Chrysler's engineers to adequately consider customer safety that they sell Jeeps which are not bulletproof and which have exposed frameworks on the underside where bombs can be attached.
So why is it that we're so quick to assume that because a safety-critical computer system is exposed to the internet, that this is the worst thing ever?
Is it that as far as physical security of your Jeep goes you only have to trust the people in your neighborhood, but for internet security we have to trust the whole world?
Because of the Greater Internet Fuckwad Theory (or, more nicely put, the "online disinhibition effect"[1]).
We don't worry as much about random strangers harming us in person because most people are generally well-behaved when they are face to face with someone in real physical space.
On the Internet, where all you see is a screen and all you do is click your mouse, "reality" gets a lot more tenuous. In that environment, people act worse.
If you were walking over an overpass and saw someone left a cinder block up there with a note attached saying "Throw me!" how likely would you be to lumber it up off the ground, carry it to the edge, and heave it over onto to a car you can see passing below, whose occupants are visible to you?
Now imagine you stumble onto a random web page with a button labeled "Click to drop cinder block off overpass". Tempting?
The way our behavior differs in these two circumstances is a big part of why Internet security is so different from physical security. (The other big difference is how data can be replicated for free. It takes 50x as much effort to steal 50 cars. It often takes no more effort to apply the same have 50, or a million times.)
[1]: https://en.wikipedia.org/wiki/Online_disinhibition_effect
Your assessment of risk has to change when the cost of scanning and attacking your machine from afar in a hard-to-trace manner is dirt cheap.
The Chrysler exploit, by contrast, allows you to silently take control of the vehicle in ways that don't reveal your position until much later (if at all), due to the sound system not being firewalled from the brakes.
That seems fundamentally different from "hey, gangbangers might shoot at you while driving".
[1] http://www.quora.com/Is-cutting-someones-brake-line-prior-to...
I'm asking because I'm genuinely not sure. I agree it seems different. It does feel like chrysler should be responsible for securing the system from remote exploitation. But are they? And why?
Also, the US gov has been using these entertainment systems to spy on people for more than a decade...it's already been happening. Unfortunately, I can't find the link now, but it was a post from 2001 or 2003 on NYT and I think they were using Ford Sync to do it.
But to be clear, drug cartels, spy agencies and criminal organizations have been able to do that for quite some time. They've just had to send a person to plant the bomb or the bug or the location tracker in person. And it's not generally regarded as the car manufacturer's problem to deal with that threat.
So yes, there's a question of scale, which makes a difference here. Traceability can maybe be handled at the network level - who knows what information Sprint captures about traffic to these car systems?
But the way most people are talking about this you'd think that as soon as the method for doing this hits the internet, script-kiddies are going to start randomly crashing Jeeps into bridge pylons.
But those sorts of methods require orders of magnitude less plausible deniability.
When people hear on the news that some controversial political activist (in any country) died during an armed robbery, from a propane explosion, suicide or a car crash which one do you think they'll question the least?
You're a fool if you think intelligence agencies (around the world) haven't been weaponizing these sorts of vulnerabilities (and they're fools if they haven't been). The major hurdle I see is that the people they'd risk exposing this sort of capability on, don't ride around in cars with the required features or live somewhere where it's more sensible to get them some other way.
Yes, the main remote exploit you're exposed to driving round Yemen in a Grand Cherokee is probably a Reaper-launched Maverick strike, rather than having your transmission remotely cut :)
You mean the same script kiddies who think it's hilarious to sic a SWAT team on someone's house? It's not like script kiddies everywhere would start doing this - but all it takes is 1 before you've got a problem, and I'm sure that if it was easy enough for any script kiddie to do, at least one of them would.
Say the car manufacturer made no attempt at security whatsoever - all you had to do to take control of the car's critical systems was know its IP address and guess its 8 character max admin password. Would that really not be on the manufacturer?
It's not the car manufacturer's responsibility to protect their customers from that.
Make the same thing possible for someone to do from their basement, and sure: people will die; people will go to prison.
Look, I'm not actually trying to absolve Chrysler of responsibility here, I'm trying to get to the bottom of why when virtual meets physical, we act like the nature of the internet fundamentally changes things. I'm interested in what it is about this threat to car owners which is in a difference from existing threats.
Plus, the anonymous nature of the internet makes it much easier to become detached from the real-life consequences of your actions. Just look at all the examples of online harassment from people who would never say things like that in real life. Look at people who go and grief kids' minecraft servers, yet wouldn't go and kick over their sand castles in real life. Look at morons who swat people.
Actually, come to think of it, maybe it's not so different - if it was found that a big car manufacturer had a problem with their door locks and you could open it just by sticking a toothpick in, you can bet they would take the blame once they started getting stolen.
I'm not saying the responsibility is solely on the manufacturer, but they definitely bear a major part of it. When you buy a car, you expect a reasonable amount of security. I guess the question is where we draw the line as to what counts as reasonable.
Yes, exactly. And I think a lot of people, including me, would say that anything that can be done entirely in software is reasonable.
Hmm. Does this mean that anyone doing safety-critical embedded software should be compelled to formally verify every line of their code? I'll have to think about that. That might be going a bit too far given the present state of verification technology. On the other hand, it would be a great thing.
Yes?
If you connect a system to the internet, you have to consider attempts to attack that system (automated and not) to be part of typical operating conditions.
These are all true to a greater or lesser extent (often to a lesser extent than people think). But it makes for a pretty weird threat model, trying to protect your customers from high-tech murderers, anarchists, and three-letter-government agencies. This isn't like trying to stop someone steal a credit-card-number.
1. Ability of attackers to probe many systems for vulnerabilities safely. Someone walking down the street pulling handles to check for unlocked cars can only get at so many cars.
2. Physical distance of the attacker from the victim and their property. Specifically, they can be in a different legal jurisdiction, making it very hard to prosecute them, and therefore reducing the deterrent effect of law enforcement.
3. Abstract nature of the act from the criminal's perspective. The decision to commit a crime, and the processes that deter it, are not entirely rational, and have to do with things like social anxiety, perceived safety of the environment, etc. Just like trolls say things online that they would never say I'm person, some online attackers do things they would never have the nerve to do on person, even with the same level of actual risk.
As to motives, these are fairly well-studied, and some are very applicable to this class of vulnerabilities.
1. Direct acquisition of valuable goods/information. Doable with this vuln, but not for someone sitting in Russia. Strike it off the list.
2. Extortion. Most DDoS attacks are aimed at this. You can't get anything directly by causing someone harm, but you can (and many people do) perform a "demonstration" attack to show capability, then call you up and make demands. Very doable with these attacks.
3. Ideological motives. This tends to lead people to want to hurt others in particularly visible ways, so I can see the psychological appeal of using this kind of vulnerability for a terrorist attack. A bit out there in terms of probability, but possible.
4. Nation-state action. Not many consumers worry about this too much, but I think the appeal of this vulnerability to an intelligence agency is pretty clear.
In a sense, yes. The risk to the attacker is reduced so significantly, and the consequences are so remote, that people on the internet will do something horrible just for fun. Basically, distance, anonymity, and lack of consequences seems to turn a lot of people into sociopaths.
People develop in a society, face to face, where your actions have consequences to you and to others around you, and ultimately to your relationships with people you interact with directly. I think the internet provides some evidence that if we didn't have that, a lot more people would act horribly to one another.
Granted, that's not Chrysler's fault. But providing a "crash my car over the internet" button is handing those people a very powerful tool, and that seems like negligence to me.
Let's put it this way: would you drive a car you know someone could hijack and crash over the internet at any time? Wouldn't you like a reasonable assurance that your car has been designed to prevent that?
So maybe instead of using this to kill people, someone decides to cause small accidents for the insurance money. Or there's a way to use it to listen to people through the voice recognition software and people spy on their exes or employees with it. Or just load a trojan onto people's smartphones when they dock it into the onboard charger that gives them root access to the thing they use to check their bank statements, or who knows what? Don't think of it as just a car, rather think of it as an exploitable network with the added benefit of potential collision damage.
Precisely. And you said one of the reasons it must remain that way:
> It crosses borders
The alternative is for any connection to the network to require a real-world identity, and to bear liability for information they transit if they can't identify who it came from. This is politicians' wet dream (more control/power), but it is utterly impractical as it simply can't scale, cross jurisdictional boundaries, or actually stop bad actors (who just steal someone else's credentials). Never mind the inevitable effects on free speech and cementing the idea that individuals cannot opt out being tracked and recorded.
It's a long-held design principle to assume that the Internet is full of malicious intelligences, and that your software should act accordingly. Even if everybody in the world were completely benevolent, this would still be a prudent assumption for robustness against weird coincidences between context domains. Putting one's fingers in their ears and then crying to influential friends about "hackers" doesn't absolve one of responsibility for adhering to this principle.
I'm not sure, but a large number of vehicles turning into bricks during rush hour would probably be a big enough problem for one of the many catch-all "things that undermine national security" (criminal) laws to be relevant.
> Sabotaging the vehicle to kill the driver is way down the list.
But if it can be done remotely and untraceably...?
If Greedy Greg knew public CEO Huge McChecks was driving an exposed vehicle, Greedy Greg could short sale Huge McCheck's company and cause a multi-million dollar crash with Huge McChecks inside... all with a couple strokes on a keyboard from thousands of miles away.
That might be a valid complaint if this attack required physical access, but it's a remote exploit. It is computer security, except the target is many times more interesting because it can kill people.
Of course.. there's some room for them to screw up, but I would argue that that's set off by the risk of having buggy vehicle control firmware killing people. Especially with a new vehicle like the Tesla.
I'd prefer it if my car didn't have any connection between a public network and it's control systems, but if it does I want it to be able to automatically install patches ;)
But to be honest people are taking their specification and dooms-day-ism to stupid extremes. Soon we'll be talking about "it is only as secure as the CPU, what if you find a CPU bug and bypass all security?!"
I would argue otherwise, plenty of signature schemes give you enough rope to hang yourself. The Playstation 3 example springs to mind!
Here's another page which is describing the steps: http://www.areacellphone.com/2009/12/motorola-droid-rooted-h...
Here is the commit with a bug fix: http://review.source.android.com/12807
and actual diff: https://android-review.googlesource.com/#/c/12807/1/verifier...
The car manufacturers who do OTA updates for their cars are sitting on time-bombs. The clock is ticking for them until people get killed this way (regardless of them using HTTPS or signed updates - which some manufacturers don't even use now).
http://www.theregister.co.uk/2014/07/21/chinese_uni_students...
Yeah, no. Auto mfr.'s want to reduce the display count to make cars cheaper to make and the interiors simpler to build. I've never ever spoken to or heard form anyone who 'wants' or even kinda likes having their climate controls on the same screen as their maps, pandora, etc. It's confusing, usually cluttered, and complicates things unnecessarily.
Customers want things, it's not their responsibility, it's the manufacturer's responsibility to not ship something unsafe
One problem is that there is no limitation in the CAN protocol to prevent a node from impersonating the master node. Another is the mutability of a node's firmware.
Security is about degrees and nuances. These kind of black & white statements are unhelpful and unrealistic.
Have you /been/ on the internet, lately? ;)
"Climate control system" is an abstraction over belt driven moving parts.
http://www.gpo.gov/fdsys/pkg/FR-2014-06-06/pdf/2014-13245.pd...
If a compromised device can talk on the CAN bus it's game over since (pretty much) everything listens on that bus so you can't (without a lot of time and effort, implement a way to) pick and choose systems to segregate while maintaining wireless connectivity to those critical system.
Vehicle manufactures get a huge data set sent back to them by vehicles. They use this for stuff like correlating part failures to operational conditions, determining which intermittent wiper setting people use as well as improving the logic for the operation of critical systems (e.g. if my last inputs were $stuff then don't upshift). I wouldn't be surprised if they sold the data as well. McDonalds would love to know where and when people start looking for food. insurance companies would love to have more variables to correlate to risk trivial (e.g. $color cars with $trivial_feature get in accident that cost $really_small_percent $more_or_less than $other_color
To segregate systems you need to be able to pitch to the bean-counters that the cost/benefit of whatever degree of segregation you're proposing beats the cost/benefit of whatever plan the next guy is proposing. These data sets are incredibly valuable to many different parts of the company. The people doing marketing and customer facing stuff would be at a severe competitive disadvantage if they had to wait months (first oil change) o get real world data on feature usage after a re-design.
Sure you could download it at service time..."but we already have a system that does it in near real time, can't we just secure that?"...
TL;DR: Segregating systems involves more than having the engineers wait a few months to figure out if their new tune solved the problem.
If necessary, consider that security is a feature you can sell, when your competitors are following the path of least resistance and paying out their settlements.
You might fix it just to have a similarly obscure zero day be discovered (unknown to you) and exploited in a different place. Then not only were all those resources spent in vain, but you've got to deal with the opportunity cost of not having thrown those resources behind current of future safety and security tech.
People accept the risk of driving vehicles with legacy safety equipment, why should software be any different from hardware or legacy software in non-embedded applications. At some point you have to let stuff go. Just ask Microsoft.
And in this case, these vehicles were manufactured pretty recently, so even conceding your point, I don't think we've passed the 'let stuff go' point in this case.
That is creepy. Is there a way to disable this phoning home (or know it even exists) if I ever buy a new vehicle? That's an unlikely situation for me, but maybe there are others who would like the new features but not the privacy aspects of it.
Even so, the manufacturers are only receiving data, so a one-way link from critical systems to others would be fine. That's how airplane avionics have been designed.
"No defect has been found. FCA US is conducting this campaign out of an abundance of caution."
What the hell?
http://www-odi.nhtsa.dot.gov/recalls/recallprocess.cfm
I guess it isn't that big a stretch to use such defensive language, there are a lot of things that can be tampered with on a vehicle that arise out of engineering trade offs.
I don't mean to dismiss the problem at hand, but it is only an issue if someone makes an effort to tamper with a vehicle, which is different than a critical part failing prematurely or whatever.
But also the hackers haven't demo'd the exploit in an untampered with car. I still wonder if you need physical access to do this.
The WIRED story's hackers presumably were authorized by the vehicle's owner or operator, so the demo did not "constitute criminal action."
They were probably authorized by the driver, but car companies have argued that the driver does not "own" the software in the car, so I assume their claim of unauthorized access is predicated on the assumption that the car company still owns the software and that the car company did not authorize the access.
I do not agree with the car company's stance on ownership, but that may be the origin of their claim.
http://www.wired.com/2015/04/dmca-ownership-john-deere/
Supposedly the US Copyright Office will decide this month.
That paragraph is there to make it clear that the tampering is a significant action to take.
[edit: viewing the video - yes they did - they should be charged with endangerment - someone could have been hurt rear ending the jeep]
https://news.ycombinator.com/item?id=9921557
Also related:
Maybe IIHS needs to include "remote hackability" as a criterion in their testing?
I think so but just include hacking in general. Remote hacking is the worst but if someone can get physical access to some part of your car for a brief period of time (maybe the door's are unlocked and they plug something in or maybe they get under the hood and mess with the car's computer) you still have a major problem on your hands.
Granted it's far harder to secure a device when someone has physical access to it but they need to test and harder for this the best they can as well. In my opinion anyway.
I guess you could engage in other antics but none of them would be all that effective since the car is towed by a cable until it's a few feet from whatever it's hitting.
I'll tell you why: because insurance companies are a rent-seeking oligopoly with an enormous barrier to entry. They just sit there and make a fortune doing jack shit.
I have zero sympathy for the manufacturers. I only hope that, if they decide to go on a witch hunt, they actually seek and punish the morons in power who, most likely for self-serving purposes, let this slide.
This also should raise a ringing cry to rein in DMCA et al. uses that seek to outlaw such research. In this case, the manufacturer has obviated their authority in the matter.
screw that attitude.
I hope government will make the equivalent of whistleblower protection for security researchers that report exploitable flaws, because it's the only way to increase security over time.
i.e. I'm scared as hell that planes are allegedly hackable but researchers aren't really talking about it nor testing it properly because fear of lawsuits.
http://blog.caranddriver.com/fiat-chrysler-quality-chief-res...
http://www.autonews.com/article/20141028/OEM02/141029851/bet...
http://www.techtimes.com/articles/70582/20150721/apple-hires...
because nothing screams quality like a 'decided to leave one day after yet another drop in Consumer Report rankings' and 1.4m car recall!
I know this is supposed to be The Magic Kingdom where people are only supposed to say positive things and eat happy pills all day, but would it kill people to at least try to read up about the things they so willingly share their "insights" on before posting here?
At the very least, try to understand how CAN works before spouting nonsense grounded in uninformed assumption. Uninformed opinions are not helpful. They just pollute the discussion.
I know I'll get down voted, but it has to be asked.
But, consumers expect a infotainment user experience at least as good as hanging an iPad in the car, and if your car doesn't provide that, they will rate it poorly in surveys.
Source / Disclaimer - I work for GM.
Often the board that handles the radio acts like a bridge in modern cars. It tends to be the beefiest computer hardware in the vehicle. So it is on the high speed CAN bus and a node on the more star shaped low speed bus.
When they updated the FW, they removed the bit of code that prevented dangerous messages IDs from leaving the controllers on the radio board and possibly added code that could put arbitrary CAN bus messages on the buses as relay from the sprint network.
I am very eagerly awaiting the talk.
Ever the enduring question
In terms of comparing two different vehicles...
If the $year base model $carA has a suspension system closer in performance to the sport model of $year $carB but for $year+1 they put a much softer suspension in the base model of $carA in response to customer feedback then the results go out the window. Alternatively, if the OE tires are particularly expensive then you can bet that most owners will replace them with cheaper one. Additionally, particular trims are often incredibly rare or almost always have a particular option added. So testing a $trim without $package will be of little meaning when the vast majority of $trim that make it to dealer lots will have $package. In either case the results go out the window because there's a handful of large variables that are uncontrolled for. It's little better than the comparisons you see in car commercials.
If you actually want to grill Jeep over something I suggest you read up on 90s XJ gas tank fires.