3 ms·
While I agree with the author about the undervalued risks of autonomous vehicles in the light of careless security practices his proposed solution is just insan
by schlowmo 9y ago
While I agree with the author about the undervalued risks of autonomous vehicles in the light of careless security practices his proposed solution is just insane.
In my opinion the demand for a government controlled kill switch in every piece of hardware that is somehow able to harm people is much more threatening in so many ways than the insecurity the author is trying to reduce. Just a few:
1. Based on the asumption, that ones current government/state is for the good of all people, what gives him the confidence that this will stay that way? What if your beloved government goes rogue? That's a lot power for an autocratic regime.
2. Why even trust the government in the first place with that kill switch? They are the same people which are careless about infrastructure critical ITSec since decades.
3. An univervsal security module which is highly standardized is a very profitable target. While the author is aware that finding an attack vector of one particular vehicle can mean that all vehicles of that type can be compromised, he doesn't come to the conclusion that the same logic applies to his security module.
- 3pt14159 9y agoI’m the author. I was nodding in agreement with you for your first two points. I don’t think I’ve come to a perfect solution, but I want you to know that I actually have many of the same reservations that you have and that I’m open to changing my mind. Here is where I still sit, however: the government had predator drones and will soon have killbots able to take out individuals based on facial recognition software. If we can’t trust them to turn off our cars we’re fucked anyway.
- nickodell 9y agoThese safety modules sound really complicated. Let's say a security vulnerability has been discovered. An attacker has wormed their way into as many cars as they can. They send a 'go' signal from their command and control servers. Across the world, cars start looking for opportunities to kill their passengers and bystanders. We send the shutdown signal. The safety modules wake up and take over from the compromised computers. What do they do? They could brake. However, the car might be in a turn, on a rainy day. Braking could send the car into a skid and kill its passengers. Maybe they brake, but slowly. However, the car might be behind someone who just suddenly changed lanes and slammed on the brakes. Braking hard might be the right move in that circumstance. Maybe they do something conditional on the sensor input they get. However, if the control computer can do something to 'blind' the safety computer, that doesn't help. For example, can the control computer issue firmware updates to the camera sensors? Can the control computer fill a sensor's bus line until it can't respond? I can't think of any solution to this that doesn't involve duplicating a substantial part of the control computer.
- vntok 9y ago1. Have an emergency break button somewhere in the car that the user could press at any time to have the vehicle break. Note that we already have those in all trains, buses etc. 2. Have a warning light up next to the button asking the user to press the break button as soon as they feel safe to do so. Note that we already have those service lights in all regular cars. Simply add a buzzer as well for people asleep etc. 3. Have the circuit that breaks upon button activation be sealed off from the internet (make it hydraulic). The only action of the "good C&C" is to turn a light on.
- schlowmo 9y agoThanks for sharing your concerns. But regarding your last two sentences, I'm sorry that I've to tell you that I think we are already fucked. I don't think it's a good idea to speed up the process of being fucked even more.