5 ms·
The difference is in how easy it is to scale an attack. Once an attacker can remotely hack a single car, they can hack all cars that have an identical configur
by scribu 9y ago
The difference is in how easy it is to scale an attack.
Once an attacker can remotely hack a single car, they can hack all cars that have an identical configuration, with little additional cost.
What happens then? Even if insurance companies could replace all affected cars simultaneously (very unlikely), they’d have to replace them with a model that isn’t affected.
- aetherson 9y agoPassive keyless entry is not remotely hackable, it's locally hackable, that's not scalable and besides which cars sold today (with very few exceptions) can not self drive, so even if you could remotely unlock it you'd still need someone local to drive away with it.
- LinuxBender 9y agoNumerous internet connected cars are remotely hackable and you can take over engine controls, steering, breaking. This was performed on live highways multiple times. DOT investigated at least one of the incidents involving some SUV's.
- scribu 9y agoYou’re of course right about passive keyless entry and perhaps the GP has that confused with other features that do require an internet connection. Anyway, even if it isn’t autonomous, suppose a car has a smartphone app that allows you to turn on the heating before getting in. And then someone exploits that and gains control over the heating. They could then proceed to drain the batteries or the fuel tank by leaving it on over night, let’s say. Not exactly a threat to national security, but still a major inconvenience.
- newman8r 9y agoif you did it on the day of an election and only targeted your opposition, it could have an impact. It's far-fetched, but just another scenario.
- socialist_coder 9y agoGenius!
- currymj 9y agoNot sure it was confusion, but rather intended as an example of how "high end" features spread to the bottom of the market quickly, such that in a few years nearly all new cars may be internet-connected.
- Slansitartop 9y ago> You’re of course right about passive keyless entry and perhaps the GP has that confused with other features that do require an internet connection. I did not confuse anything. I only mentioned passive keyless entry in a footnote, as an example of an insecure technology that you can't really avoid anymore. You still have a chance to avoid "connected car" features, but in my estimation the days are numbered for that.
- jonknee 9y ago> Once an attacker can remotely hack a single car, they can hack all cars that have an identical configuration, with little additional cost. And do what with them? It's decently difficult to fence a single car, it's impossible to make millions of cars disappear.
- trsse 9y agoIf you'd read the article you'd see several examples. Drive them at 120mph into gas stations, for starters.
- dovdovdov 9y agoLet's get rid of gas stations, for starters! Btw, the truck attack in the German market would've been a much larger scale if the truck's safety mechanism didn't trigger the emergency break. Regardless, that Jeep hack sure proved a clusterf*ck of system design, and should be a cautionary tale.
- WillReplyfFood 9y agoThe system design clusterfuck is what you always get, when you cram as much software as possible on as few ecus as possible. You wouldnt buy a car that is safe- because bad security does not smell.