5 ms·
An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repa
by jxurueydyys 6y ago
An easy solution would be to not allow self driving or remotely updated cars until there's a reliable solution to this. People already go to auto-shops for repairs, certified auto-shops could easily double as places to update software and the certification requirements can be tailored to require an external oversight agent come and evaluate their security practices.
- freeopinion 6y agoCertified autoshops are a solution in the same way that Norton is a solution for PC malware. Problem solved?
- jxurueydyys 6y agoThe difference is that the pc is exposed to everything it interacts with including the internet while the car would only be interacting with shops that were meeting their certification obligations. Tying updates to physical locations also reduces the severity of a successful bad actor since most people in a city don't all go to the same auto-shop. A problem like a nation-wide cyber attack on vehicles is only possible if we allow personal vehicles to support the attack vector.
- throwaway0a5e 6y agoI don't see how certification solves anything that just not doing OTA updates doesn't also solve.
- jxurueydyys 6y agoIt reduces the attack surface to places that have been verified to be following security obligations. Otherwise a physical attack becomes much easier because you just need to work at an auto-shop that doesn't pay much attention to you. The same sort of attack is still possible with certs but it's more difficult because it would require compromising both the shop and the person who vets their practices.
- est31 6y agoPeople still want regular map updates, live updating traffic information, and play back stuff from their phone on the in-car entertainment system. All this exposes cars to data communication outside of the car repair shop. Yes, the entertainment system is different from the system that runs the car, but there is some level of communication between the two.
- tsimionescu 6y agoThere is some level of communication, but there really shouldn't be.
- Silhouette 6y agoThe problem is that total separation is difficult to achieve with the requirements being placed on these vehicles. Sure, whatever is playing your favourite music tracks over the speakers probably doesn't need to know anything about steering and acceleration. However, your self-driving software is going to have a tough time getting your car to a location it doesn't know exists because its onboard navigation maps predate the existence of that building, or planning a route that avoids an accident it doesn't know about because it has no real-time information about road closures.
- tsimionescu 6y agoAs others have pointed out, self driving software is inherently unsafe at this moment - we don't know how to make safe network-connected software yet. Anyway, this is moot in most cars, as they don't have sold driving software anyway.
- Silhouette 6y agoIf you read my comments elsewhere in this discussion, you'll see that I've been one of those people. In this thread, I'm simply observing that there can't be a clear separation between control systems and information systems if we're going to achieve these kinds of autonomous functionality. We need a more nuanced solution.
- slg 6y agoI definitely think Tesla can be over aggressive with their updates. However that doesn't mean that the basic idea of remote updating cars is inherently flawed or unsafe when compared with the alternative. It is all about trade-offs. Both the Prius[1] and the Model 3[2] had similar software bugs related to their anti-lock brakes. Both companies had a software fix a few days after the bugs were discovered. Tesla's fix was pushed out immediately to every vehicle. Toyota couldn't push out a fix. They had to issue a recall and have a technician update the software whenever that car ended up being serviced. How many months or more likely years did it take for every Prius to be updated with the software? How many miles were driven in cars that were known to have faulty brake software because it was hard to update them? You have to consider situations like this when discuss banning remote updating. [1] - https://www.networkworld.com/article/2245704/toyota-to-recall-prius-hybrids-over-abs-software.html https://www.networkworld.com/article/2245704/toyota-to-recal... [2] - https://www.wired.com/story/tesla-model3-braking-software-update-consumer-reports/ https://www.wired.com/story/tesla-model3-braking-software-up...
- Aeolun 6y ago> You have to consider situations like this when discuss banning remote updating. Isn't that exactly what we're doing? If someone pushes out a malicious change, do you know how long it would take for that change to propagate to the entire Toyota fleet? It wouldn't.
- user234683 6y ago> Toyota couldn't push out a fix. They had to issue a recall and have a technician update the software whenever that car ended up being serviced. This gives all the more incentive to get the software correct in the first place. The model of "get the software as bug-free as possible upfront using stringent processes, testing, formal methods, and not using software in the first place when it's not actually needed" is better than the model of "put software into as many components as possible to make it shiny and get the software good enough to release before our competitors and play whack-a-mole on the bugs later through updates". Instantaneous updates make it easier for an attacker to take control of the update infrastructure and push an update that will trigger a mass-crash of cars during rush hour. When people have to asynchronously take the car to dealerships over many months, it makes this attack harder to go undetected.
- dmix 6y agoInfosec is a worse gov regulation than drug prohibition. It will do little than make naive people feel better.
- r77ruuddj 6y agoI disagree. I think in an ideal world this is true but the reality is that the bar for security is exceptionally low for industries that aren't traditionally software industries (not that software is excluded). When the stakes are just accounts and transactions that can be reversed the situation is different, when the stakes are life and death, in the real way, I don't think it's unwise to exercise caution. Let someone else take the risk of cyber terrorism and if they go a decade without any hiccups then leapfrog them. There's no reason to expose consumers to these sorts of risks just because it gets the futurists hard.