4 ms·
When I see news about self-driving cars I can't help but think about car DoS, ransomware and hijacking. Not that this doesn't apply to "normal" cars, but I susp
by kenoph 10y ago
When I see news about self-driving cars I can't help but think about car DoS, ransomware and hijacking. Not that this doesn't apply to "normal" cars, but I suspect that "intelligent" cars will have Internet connection and, at some point in the near future, inter-vehicle communication in order to cooperate better. We already have a PoC smartlight worm.
- user5994461 10y agoPut a physical button to enable/disable the network connectivity. That will limit the damages. Add a hard firmware reset button as well.
- mille562 10y agoPlaying devils advocate: - If the hack/virus was already installed, a network shutoff won't help much. - If a car is 10 years old with 10 years of safety updates/patches, resetting to the original firmware might not be a viable solution. But there needs to be a failsafe way of knowing the running software has not been tampered with.
- jjawssd 10y ago> - If the hack/virus was already installed, a network shutoff won't help much. Master battery disconnect which auto locks all brakes > - If a car is 10 years old with 10 years of safety updates/patches, resetting to the original firmware might not be a viable solution. But there needs to be a failsafe way of knowing the running software has not been tampered with. Plug and play ROM modules?
- niels_olson 10y ago> Master battery disconnect which auto locks all brakes probably want to separate those. Kill the engine at 80 mph, you can coast to stop. If you lock the brakes at 80 mph, you immediately lose most of your control, and, since you killed the battery, you lost traction control and probably ABS. And you risk blowing the tires.
- jjawssd 10y agoMaybe one day the OS will go rouge and we will have to start pulling out memory modules to save ourselves Relevant: https://www.youtube.com/watch?v=UgkyrW2NiwM https://www.youtube.com/watch?v=UgkyrW2NiwM
- niels_olson 10y agoInteresting. Instead of just an emergency brake, you want a second emergency handle: a mechanical linkage to a circuit-breaker on the mains.
- Diederich 10y agoI concur with your overall points. Rather than a firmware 'reset', a 'firmware safe mode' control. This loads a super simple and infrequently updated image that lets the car just be a dumb car, and nothing else.
- iainmerrick 10y ago"Super simple" would be nice, but as I understand it, even "dumb car" software is incredibly huge and complicated. (It's very unclear to me why that needs to be so)
- Someone 10y agoIf self-driving cars really take of, "just be a dumb car" won't help in a few decades. The 'driver' may not know how to drive his car, and even if he did, the car may not have a steering wheel. Also, I guess one would press this 'I want to take control' button in an emergency. That means the persons suddenly finding themselves driving this vehicle have to be above-average drivers.
- kenoph 10y agoThis would partially solve the issues but it would also limit the usage of cars as a service (as in, autonomous taxis vs owning a car). From my point of view car-sharing is one of the main selling points of self-driving cars. As for the inter-vehicle communication, if it proves to be effective in improving security, I guess it will eventually be mandatory or at least "encouraged" by making your insurance more expensive if you disable them.
- 31reasons 10y agoI haven't paid attention to the exploits in many years. But are they still using the Stack buffer overflow to execute the malicious code or are there other techniques modern exploits use?
- kenoph 10y agoIf you are referring to the smart lights, if I recall correctly they used a side-channel attack to extract the keys used to decrypt/verify new firmwares in various models. So they basically abused OTA firmware updates to take control of the lights. Assuming that devices don't have cryptographic issues, IoT security is still a mess. So yes firmwares are probably full of BO vulnerabilities. As for more recent techniques, I'm aware of some of them but I'm no expert so I can't comment properly :)
- Balgair 10y agoHa! Why kill the gold egg laying goose? Look at the bot-nets that are already in your daughter's talking Barbie. They don't interrupt the functionality of the device/car, they only take the extra clock cycles there are when the processor is not in use and then use them to try to sell you Viagra. The same will be true of real cars. If they get too bold, then legislators will orbitally lazer your bots and the small spaces that the bot makers exist in. Sure, some mafia guys will pay to get it figured out how to lock you in your car (or your kid on a really hot day) until you pay up/brick your Tesla from Outer Bongostan, but if they do it too much, it'll kill the whole enterprise. Yeah, hackers are stupid, but they more greedy than that.