33 ms·
Hackers Remotely Attack a Jeep on the Highway
- uptown 11y ago"...whether the Internet-connected computers were properly isolated from critical driving systems, and whether those critical systems had “cyberphysical” components—whether digital commands could trigger physical actions like turning the wheel or activating brakes." Shouldn't this be the most basic design consideration for any company building autos? The liability from litigation should bankrupt any company that doesn't prioritize this.
- marak830 11y agoHell i thought an airgap would have been the first thing to occur. Why would you need wireless access to non entertainment systems? It honestly beggars belief in my opinion.
- maxerickson 11y agoRemote start via cell phone is a very marketable feature. Once you get there, doing things like turning on the heat or AC are nice tack ons.
- jon-wood 11y agoRemote start I can see the reasoning for, but remote stop just seems to be asking for trouble.
- marak830 11y agoI cant really see the need. If your already in the vehicle. . . . Seems to be completly asking for trouble.
- blawson 11y agoI can see law enforcement agencies loving this feature. Way easier than high-speed pursuits down busy city roads. [edit] Though remote control would probably be sufficient, but they seem equally dangerous to me from the driver's perspective.
- ceejayoz 11y agoIt's been long pitched as a safety measure to prevent high-speed car chases and car thefts.
- maxerickson 11y agoI was addressing the question of wireless access to vehicle systems, not trying to justify any particular feature that might be included in such an implementation.
- cameldrv 11y agoThe obvious but security-oblivious way to do this is to just connect the entertainment system that has the internet connection to one of the car's microcontroller busses. Even if it just needs to send a single command, it's easier than adding another pin and another wire to the appropriate microcontroller on the other end. The problem is that everything on these busses is completely trusted, and there's no authentication. The window motor can't tell whether the signal to roll down the window came from a switch or from the entertainment system. The simple solution is just to have a separate wire for everything, and source devices that aren't supposed to control destination devices don't get those wires connected. The problem is that the automakers went to microcontroller busses because this creates a rats nest of wires. The level 2 solution is have some sort of low-level filtering on the commands that are going out from a controller on the bus, so any command that the entertainment system sends to turn off the transmission doesn't make it onto the bus. The level 3 solution is to have some sort of cryptographic authentication of entities on the bus, so that the endpoint can decide what commands it's going to accept from what source. As you go from level 1 to level 2 to level 3, the system is more flexible, adaptable, and upgradable, but it's more complex, and thus more brittle to attack. Sorting out how to handle this sort of thing is going to be a big challenge as IoT pushes into more devices.
- quonn 11y agoEncrypted and authenticated data on the bus won't happen anytime soon for cost reasons. Filtering the commands the controller can put on the bus seams reasonable, but would only be useful, if implemented on a second controller (probably won't happen, either). I think the best approach is to secure the internet connection properly. Don't permit incoming connections at all and just permit a single outgoing TLS connection to the server of the manufacturer, define a very simple protocol and spend enough time to be sure the client is secure and validates everything.
- nitrogen 11y agoGiven the risks to safety, it's necessary to use defense in depth and secure every layer by air gaps where possible, and a strict message whitelist where not. This might add $100 to the cost of each car, which is a ton of money when multiplied by millions of cars, but it simply has to be done.
- logfromblammo 11y agoAbsolutely. But I can think of one very easy check that would solve many potentially serious problems. Disable remote operation of car hardware when a conscious human is detected at the manual controls. For some reason, this reminds me of Star Trek episodes where the crew has to transfer operation control of the Enterprise from the bridge down to engineering, or to another Starfleet ship. Even on a sci-fi television show, whenever that happened, it seems like they always had to enter a secret security code or have multiple bridge officers give their authorization codes. It speaks poorly of your product design when writers for a television show give more thought to security than you.
- maxerickson 11y agoIt's usually convenient to a plot to have characters do things. In real life, people generally prefer not doing things. Which isn't meant to excuse a problematic implementation like is seen in this article, I'm just not sure the writers were actually sweating the system details when they did that stuff.
- logfromblammo 11y agoWhile I don't think the original writers paid much attention to any of that, by the time Star Trek: the Next Generation began, computer security cracking was present in the popular culture. That's how the invading Borg were defeated, after all. At some point, when the plot for a current episode demands that it be possible for a ship to be controlled remotely, they then have to ask the continuity expert how to fix it so that the newly introduced thing doesn't significantly impact previous canon. That burden adds up across multiple seasons of multiple spinoffs. The plot solution didn't even have to make sense. All they need is some technobabble, ready to spout for any fan wearing plastic ears who might stand up at a con and ask, "If Enterprise had capability X in episode Y, why wasn't that used in episode Z?" In this case, it is very reasonable that someone, somewhere, might have asked, "What should we do if this command is used while the owner is driving along a busy highway at 70 mph, and executing it would stall out the engine?" This is a question that would provoke a stop-and-assess moment in even the most dysfunctional software company I have ever worked in. From the architectures we typically see for in-car computer networks, it looks like no one is asking these questions.
- gress 11y agoWhat if you change your mind?
- dec0dedab0de 11y agowireless updates are cheaper than recalls.
- Shivetya 11y agoWell self driving cars should be a load of fun. There will be calls to isolate critical components as well as demands they are accessible to the likes of Law Enforcement so they can disable cars remotely. So it will take legislation to sort out as liability concerns needs to addressed as well as the demands of law enforcement. Don't think for one minute they will accept self driving cars they cannot disable all of them for "safety reasons". Similar how they excuse options to black out cell service in areas
- rhino369 11y agoIt probably depends on how the exploit works. If you can OTA update a firmware that allows wireless control, that is a huge flaw. But this article doesn't really talk about how the exploit is triggered. This is pure speculation, but I bet it requires some physical access to install. And then the wireless control works. Why do I suspect that? Why else would the journalist have to travel all the way to St. Louis to test it. Imagine how huge the story would be if these guys disabled a car they never got within 1000 miles of over the internet. There is probably some CPU in the Navigation/Entertainment display that needs access to the CANBUS for stuff like warnings, speed, airpressures, etc. and also is connected to the UConnect thing for entertainment purposes. You can't airgap because you need the car data. So the lazy solution is to just firewall it. Make sure the CANBus controller for the entertainment system only sends data and doesn't receive any. Maybe you encrypt all data transfers on the bus for good measure. But with temp physical access you can reflash that controller to allow it to give commands it receives from the internet connected entertainment system.
- adamgravitis 11y agoSo, it's becoming abundantly clear that vehicle companies (autos, jets...) have approximately zero knowledge how to hire software engineers. Presumably they're somewhat more successful hiring mechanical engineers because that's always been their "thing". It's all well and good for us to chuckle at the terrifying software/systems decisions being made by these teams, but how do we address the root of the problem? It's very clear that entire meta-categories of horrific errors are being made at a very fundamental level. Is this a problem of outsourcing? Of confusing "coders" with engineers? And how do we solve it? Shame the software team such that they can never get hired in a serious role again anywhere? Professionalize the job into a strictly licensed regime like other branches of engineering? Whenever I read these types of articles, my main thought has always been, "so who, the hell, wrote the code?" It'd be interesting to know their story.
- lmm 11y agoPeople, and businesses, respond to incentives. The company probably did the economically rational thing here - the money they make from their remote-access features is more than the money they will lose for the insecurity. Companies in industries that need to find ways to make secure software; it's not a hard problem if you're willing to throw enough money at it. But as long as customers don't care whether their products or data are secure, we'll get the security we pay for.
- Lawtonfogle 11y agoPeople do care if it makes the news. But the current official ways of doing the testing doesn't make the news and testing that is news worth gets the cops called on you. How convenient that testing a security flaw is viewed as more negligent than allowing them in the first place as a cost saving measure.
- lmm 11y agoAllowing the flaw was negligent. This test was reckless. The law treats knowingly ignoring a risk as worse than unknowingly allowing one.
- a3n 11y agoI think a basic idea should be: panic stops disconnect all wireless access. Which will probably result in lots of calls from people after they avoid hitting a dog. But still.
- alandarev 11y agoDisconnecting will not restore corrupted firmware. Once virus is there, disconnecting just prevents data transfer.
- a3n 11y agoExactly. But at least you'd break the current control link and possibly/hopefully be able to stop and steer. Maybe in addition to breaking a link on a panic stop, stopping and steering would be set to a non-commanded mode that relies less or not at all (maybe impossible with current design?) on software commands.
- maxerickson 11y agoThe malicious firmware could just omit all that stuff. I guess the disconnect could be physical/mechanical and require physical intervention to reconnect (but cost, etc.).
- mojoB 11y agoIsn't the car calling their service center / 911 one of the major selling points of the service? The root problem is that they were able to flash an ECU with custom code. From there they are 'trusted' on the vehicle network and can trigger or emulate any other component. Requiring the firmware image to be signed, or not accepting a bootload from the physical interface that's connected to the internet would be a more comprehensive solution.
- tombrossman 11y agoSome questions for the researchers, or anyone else who thinks this was okay: 1) Were public roadways and speeds of 70mph absolutely necessary to demo this? 2) What was the plan if the trucker approaching at 70mph hadn't seen the Jeep stalled early and had to swerve or panic stop, possibly crashing and injuring themselves or others? 3) Anyone notify the Missouri State Highway Patrol about this? They may be contacting the researchers with questions about this demo if they weren't consulted in advance. 4) What's the plan if they trigger a bug in the car software of the people they had tested this with earlier? The article mentions them tracking people remotely as they attempt to learn more about the exploit. I could go on but why bother? In case any of you think this was cool or even remotely (no pun intended) ethical, I'd like to know if you have a problem with letting these two test this on a loved one's car. How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything? If I ever learned this had been tested on a vehicle I was in, I'd make sure this cost the researchers dearly. EDIT: I've just phoned 'Troop C' of the Highway Patrol at their main number, +1-636-300-2800 and they seemed pretty keen to follow up. The fact that the vehicle was disabled where there was no shoulder, was impeding traffic, and the demo not cleared with them in advance has them concerned. I'm all for testing exploits and security research, but this isn't the right way to do it. And to film it and post it to a high traffic site is nuts.
- alistairSH 11y agoI had the same thoughts. Testing the exploits on a open highway, at full speed, strikes me as needlessly reckless. There is no excuse for this when there are plenty of lower speed locations available. They should have used a large parking lot or similar.
- callesgg 11y agoThey are not testing it, they are showing it. Reckless yes and still probably not enough.... I believe people will need to be killed, or get their cars destroys before the rest of the population takes enough of a stance against "neglecting" security.
- ak217 11y ago"Toyota, in particular, argued that its systems were “robust and secure” against wireless attacks." That's what they said about unintended acceleration. It turned out they were lying. http://www.edn.com/design/automotive/4423428/Toyota-s-killer-firmware--Bad-design-and-its-consequences http://www.edn.com/design/automotive/4423428/Toyota-s-killer...
- ianhawes 11y agoI own a 2015 Jeep Cherokee and have poked around with Uconnect and the API services it exposes. Theres a whole new world of exploitation (and eventually modding) that is coming.
- hoopism 11y agoWow. Just because you are savvy enough to do the research does not make you a researcher. These two really need to rethink the way they are "testing" this and perhaps educate themselves on ethics in research. Their judgement collectively was worse than a pack of 5th graders with high grade fireworks.
- shkkmo 11y agoThey could certainly have done a much better job of demoing this safely. On the other hand, I'd rather that they be doing this work with the way they did it than not at all...
- hoopism 11y ago"On the other hand, I'd rather that they be doing this work with the way they did it than not at all..." That's such a stupid tradeoff. Putting it as an either/or is silly. Doing this safely and demonstrating the alarming conclusion are not mutually exclusive. I'd go as far as to say that the way they demonstrated this actually diminishes the message of the danger of this exploit and put's the focus on their stupidity.
- shkkmo 11y ago> I'd go as far as to say that the way they demonstrated this actually diminishes the message of the danger of this exploit and put's the focus on their stupidity. Doing it the way they did clearly increases the impact of their message. To believe otherwise belies ignorance of the way information gets spread in our culture. The question is only if the increased impact was properly balanced against the increased risk.
- jblow 11y agoI don't think you understand. Anyone in the world can do this. Right now. Any time.
- hoopism 11y ago
- yodon 11y agoHopefully people selling armored cars and armored trucks have good pen testers on their teams. Run flat tires and armor-plated doors don't help much if an attacker can shut down the engine and open the doors remotely.
- spaceisballer 11y agoWell luckily my Chrysler despite only being a year old does not have this connectivity. It does have Uconnect which I despise, I keep contacting Chrysler to demand that they offer the ability to use Apple Carplay or the Google equivalent. To be fair there has yet to be a vehicle that has a nice easy to use controls for radio or media.
- basseq 11y agoSame situation, same sentiment. Chrysler is apparently "on the list" for CarPlay compatibility, but across all marquees, there are only two cars you can buy today that have it installed, and both are Ferraris. (The 2015 Volvo XC90 may have some form of CarPlay "preparation".) Don't hold your breath for backwards compatibility. All I really want is two things: 1. The Voice button on my steering wheel to activate Siri. (Not the horrible UConnect voice assist.) 2. Waze maps on screen. (UConnect navigation is shit and not worth the price.)
- Kliment 11y agoSo if I'm understanding this correctly, the initial vulnerability is remote-exploitable and relies on a firmware patch. Why wouldn't the manufacturer use the same exploit to patch all affected vehicles rather than calling them in for service?
- maxerickson 11y agoPresumably they lack permission to do such a thing. The researchers only experimented on a car they owned/controlled.
- Kliment 11y agoThe manufacturer presumably has permission to do so. As for the attackers patching vulnerable vehicles, I hadn't thought of that, but of course that's a possibility as well. Pretty much the definition of white hat. :)
- maxerickson 11y agoYeah, it appears they do: http://www.driveuconnect.com/terms/ http://www.driveuconnect.com/terms/ (term 17)
- jblow 11y agoGiven that cars get recalled all the time for "this one part is kind of flimsy and might break 3% of the time", I am not sure why "some guy in China can drive your car off a cliff" is not grounds for an immediate and full recall. If you talk to auto manufacturers in a way that they understand, they will understand.
- userbinator 11y agoAll of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. I think this is the biggest problem. Stop making "smart" cars with all these unnecessary features. Even if you can't resist adding entertainment or navigation, don't ever physically connect those systems to the critical systems like engine and transmission computers except through a one-way (to display information) link, like it's done on airplanes. I'm happy to have a much older vehicle with none of these "enhancements". It has a physical throttle, hydraulic brakes, and steering linkage for which remote hijacking is physically impossible. I can add navigation and entertainment with a smartphone mounted on the dash. It may not be as fuel-efficient or safe(?) as the cars today, but maybe the tradeoff is worth it. That also suggests there could be a market for new "dumb" cars which have all the modern improvements to engines and safety, but none of these "smart" exploitable features. (I'm not so paranoid as to get a mechanical EMP-proof diesel though...)
- deleted 11y ago[deleted]
- KeytarHero 11y agoIt amazes me that while more and more jurisdictions are banning cell phone use while driving, vehicle makers are increasingly resorting to touch screens for things like stereo and climate control. When using a smartphone while driving is illegal, how are in-vehicle touch screen controls meant to be operated by the driver not banned? As much as I love Tesla and what they are trying to do to the car industry, they are the worst offenders in this. Hopefully by the time I can afford one, there will be legislation making entirely touch-screen dashes illegal and they'll have the usual 3 dials for climate control, that you can operate without having to take your eyes off the road.
- vvanders 11y agoAll the controls on the Tesla are 1.5" or larger which makes them easy to use out of your FoV while keeping your eyes on the road. Cellphones are a much smaller surface area and require a lot more focus.
- daveloyall 11y agoSo, a HN commentator apparently called the cops on these guys after reading the Wired article. Several commentators more or less agree, arguing that performing these tests on the I-40 was criminally negligent. Stop right there. Grow some balls. These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason. And wtf you called the cops? head in hand
- vvanders 11y agoBecause the did it on public road, intentionally causing him to lose control of the vehicle. Bunch of idiots if you ask me, no better than the clueless people you see talking on their cellphones distracted. A 1 ton vehicle is deadly in the wrong situation. Like many other people mentioned, there's many ways to demonstrate this is a safe, controlled manner rather than out in the wild.
- daveloyall 11y agoAt least now they'll face charges of reckless driving, rather than unauthorized access to the vin+gps+etc of various vehicles. ....... ... .... ....
- Someone1234 11y ago> These guys are elite, their demo was badass, and I've done stupider things on I-40 for no reason. "Elite," seriously? Is it 1995? Is the movie "Hackers" some type of inspiration to you? I'm almost surprised you didn't go all l33t speak. They endangered people's lives. It is as simple as that. If you too endanger people's lives "for no reason" on I-40 I hope they get you too.
- daveloyall 11y agoThey demonstrated that hackers can take lives using a laptop and a cell phone. And they displayed their own picture on the dashboard screen while doing it. Yes, elite. I'm not bringing it back; they already did.
- hoopism 11y agoTo recap the facts: - Man drives car on public highway @ speeds of up to 70mph - Hackers turn on windshield wipers and fluid to blur view - Hackers Blare music and obscure any comms link to driver - Hackers disable vehicle on Highway at location with no shoulder And there are people who are not only ok with type of experiment but think there should be more of it. I understand that these exploits need to get attention... but I really can't stop thinking about my wife and kids being behind this guy while he shows how dangerous this can be. I applaud the person who notified the police.
- danielweber 11y agohttps://en.wikipedia.org/wiki/Institutional_review_board https://en.wikipedia.org/wiki/Institutional_review_board is how normal people deal with this.
- kbenson 11y agoNo, I think notifying the police, who then notify the IRB is how normal people would deal with this. I don't expect the normal person knows about the IRB (I'm not surprised it exists, but I was unaware of it). In a similar vein, if you notified your local police about a kidnapping they would notify the FBI, because kidnapping is the FBI's jurisdiction.
- danielweber 11y agoBy "deal with this" I meant "deal with the fact that researchers have giant blind spots about the ethical impacts of their research." I don't expect Joe Random to know to contact these guys' IRB, when they likely don't have one at all.
- kbenson 11y agoAh, fair enough. I interpreted it as you saying people should have contacted the IRB, not the police, regarding this breach of ethics in research.
- 11y ago
- deleted 11y ago[deleted]
- joncfoo7 11y agoDid anyone bother to read the full article? If so, you would find out that it was a [somewhat] controlled experiment. > To better simulate the experience of driving a vehicle while it’s being hijacked by an invisible, virtual force, Miller and Valasek refused to tell me ahead of time what kinds of attacks they planned to launch from Miller’s laptop in his house 10 miles west. > Instead, they merely assured me that they wouldn’t do anything life-threatening. > Then they told me to drive the Jeep onto the highway. “Remember, Andy,” Miller had said through my iPhone’s speaker just before I pulled onto the Interstate 64 on-ramp, “no matter what happens, don’t panic.”
- scott_karana 11y agoHow in the world is "don't panic on public roads when we attack you without warning" a controlled experiment, in any sense of the word? ;)
- bengali3 11y agobe sure to check out the video http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005/9aca04ce-083b-4756-bda9-a37a148bf90flow.webm http://dp8hsntg6do36.cloudfront.net/55ad80d461646d4db7000005...
- joncfoo7 11y agoAll right, I concede. I did not watch the video but only read the article - that was a bit insane of them. When I read the article, in my mind, I pictured them driving the car on an empty-ish highway/road. That was clearly not the case.
- bluedino 11y ago>> The attacker’s PC had been wired into the vehicles’ onboard diagnostic port, a feature that normally gives repair technicians access to information about the car’s electronically controlled systems. Is this even really considered an issue?
- Zikes 11y agoA bit of Arduino magic and a few minutes alone with an unlocked car (or locked but otherwise vulnerable) and that wired port could become wireless.
- maxerickson 11y agoHere's the context: Back then, however, their hacks had a comforting limitation: The attacker’s PC had been wired into the vehicles’ onboard diagnostic port, a feature that normally gives repair technicians access to information about the car’s electronically controlled systems. A mere two years later, that carjacking has gone wireless. So the issue is right there in the surrounding text.
- linkregister 11y agoThat was a previous demonstration; this one was done solely wirelessly.
- innguest 11y agoIf Myth Busters tested some wacky car on a public road at 70mph without telling anyone, we'd all be freaking out. But because they were "researchers" (i.e. the same tribe as most leftist people here) from a university (leftist church) then they get a pass and all sorts of justification for why what they did was OK. EDIT: Leftists go by label. They will heart any "researcher" thinking they must be their peer in their religion. They're not the sort of people that do some research before forming an opinion. EDIT 2: There's no irony because most people defending the researchers are indeed leftists. This is like saying that there would be irony if I mistakenly thought that a politician said something (and hence argued based on that false knowledge that leftists attach themselves to politicians too quickly) when in fact it wasn't a politician but a celebrity. The point is, leftists defend people not on principles but based on how close they think they are to them - and reading "researchers" dings the "good people" bell in the leftist brain. EDIT 3: The real irony here is that when free marketers say NASA should be shut down, leftists complain there's no way a private company can fund research, and here we are with leftists trying to shame me for mistakenly thinking a researcher was working for public money, when in fact I'm wrong and these researchers are actually the kind of researcher that leftists say can never exist: private researchers. Amazing. Do you at least now understand why NASA is a waste of taxpayer money (I don't care if it's 70c per person) or is the next excuse going to be that rockets are more expensive than cars?
- maxerickson 11y agoThe researchers in question are employed in industry. As your sibling comment points out, the review board at a university would not sanction doing the test in the article.
- danielweber 11y agoWere they really at a university? It looks like they were "inspired" by researchers at universities, which universally have review boards that stop idiots from disabling cars on an open road to see what happens.
- maxerickson 11y agoDo you see the searing irony in your edit? Edit: The irony I see is not political, it is in saying They're not the sort of people that do some research before forming an opinion. while making a declaration that was not especially well researched. I also probably disagree with your characterization of the people defending the researchers (but who knows what your definition of "leftists" encompasses).
- jkot 11y ago> The most disturbing maneuver came when they cut the Jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch I was in that situation. No brakes, high rocks on one side, 100 meters cliff on other side, 20km of downhill in front off me. I guess I will not be buying Jeep anytime soon.
- jerf 11y agoIf you think that "drive-by-wire" is a specifically-Jeep problem, I've got some bad news for you.... It is a safe assumption that these guys just happened to use a Jeep, and with some work almost any modern car could have this done to it.
- upofadown 11y agoThat was a lot of uninformative text to plow though... Apparently someone has found a remote exploit that affects some model of Jeep. It requires an attacker to find the IP address of the Jeep. Which implies that a Jeep has an IP address. The communication between the Jeep and the world is something called Uconnect.
- Miner49er 11y agoThey've also found a way to scan the Sprint network for cars connected to Uconnect and retrieve the cars' VIN and location.
- XorNot 11y agoI'm still curious if this can be done without physical access to the car in advance. The last time one of these showed up, it was very understated that all the remote access stuff involved reprogramming an ECU and plugging in a phone you control. The article doesn't provide any clear information on whether this works purely remotely. EDIT: Scrap that, seems it does - weird that the article doesn't lead with that more prominently. In which case wow - pinging the network and grabbing GPS coordinates for cars?
- adamtj 11y agoShould hackers actually kill somebody, I struggle to find a reason why the relevant automotive engineers and their managers shouldn't be charged and convicted of negligent homicide, or worse. After all, somebody had to make the decision to connect a radio receiver to the CAN bus. Others are aware of the wireless and choose not to remove it. To be a professional is to have a duty to refuse to do stupid stuff like this, even if it's legal and even if your job depends on it. But is it legal? Why would we need any new laws for this? Connecting a wireless receiver to the same network that controls a car's brakes and steering seems to me like reckless endangerment. No need to wait for innocent people to die. If history has shown us anything, it's that we cannot rely on software to separate two systems sharing a network. Only physics can do that. If we must have wireless for entertainment, then the entertainment and vehicle control networks must be air-gapped. This seems blindingly obvious to me. What am I missing?
- chrisdbaldwin 11y ago>What am I missing? The bottom line - a cost/benefit analysis from a corporation.
- rhino369 11y agoCriminal negligence is a high bar. We don't want to send people to jail for mistakes, accidents and miscalculations. Civil liability is a lower bar. Regular negligence is essentially not using reasonable care. Whether air-gaping a cars computer is reasonable car would be up for debate. But I think you'd have a good case. Product liability is similar to negligence. It holds the builder, designers, sellers, etc. liable for design defects. But I'm not familiar with caselaw about how hacking vulnerabilities intersect with design flaws. >If history has shown us anything, it's that we cannot rely on software to separate two systems sharing a network. Only physics can do that. Yet, a shocking number of critical systems are exposed to the internet.
- dsuth 11y agoWhen it comes to industrial safety, the main question when facing accusation of negligence is "what would a reasonable person have done in that situation". It takes into account things like: - would a reasonable person have identified this feature as having an exploitable vulnerability? - was it reasonably practicable to protect against it? In this case, the manufacturer could argue that, in their review of the risks associated with their remote connection system, it was not reasonable to expect that it could be compromised and lead to a hazard. Obviously, now that it has been demonstrated, there will be a much greater expectation that car manufacturers secure their remote access pathways.
- gortok 11y agoAll the researchers and the journalist had to do was to talk to the Highway Patrol and say, "We'd like to test this on a highway; what do we need to do to make that happen?" That's it. Maybe the State Patrol would say, "Sorry, there's nothing you can do to test this here legally", or maybe they would have said, "Pay for overtime for 10 troopers and you can do it." The point is, we don't know. We can speculate, but we don't know. The 'researchers' and journalist elected instead to conduct this experiment on a state highway, in "real world" conditions, without any safety mechanisms in place. Not only is this unethical and dangerous, it is (and should be) illegal. No one should stop these experiments from taking place; and the CFAA should be amended to allow security researchers to research issues; but the problem I have is the inherent danger in this experiment. What would we be saying if the journalist had been killed, or a mother and her two kids because of this? Do you think public sentiment would support security researchers if this had turned out differently? If anyone had gotten hurt, you'd be looking at legislation that strengthens penalties for security researchers; not at legislation that takes security research more seriously. This was an extremely childish move that had the propensity to hurt our industry more than help it. It is incumbent upon us take safety seriously in conducting these experiments. We can't count on level heads from outside the tech industry if we aren't willing to show that we care about people's lives and their safety when we're conducting these experiments.
- nhf 11y ago> This was an extremely childish move that had the propensity to hurt our industry more than help it. It is incumbent upon us take safety seriously in conducting these experiments. We can't count on level heads from outside the tech industry if we aren't willing to show that we care about people's lives and their safety when we're conducting these experiments. Agreed. I would have no problems with them doing this on a test track, closed highway, or even a quiet road at low speeds. Even if we take the best possible negative scenario—say, the car is disabled going at 25 miles an hour, the driver can't handle manual steering, and then runs into someone's fence—the insurance companies are going to throw the book at the driver when they learn that they purposefully disabled their car and engaged in dangerous behavior on a public street. I'm all for pushing the boundaries of security research (there are people in the labs all around me right now doing crazy stuff), but at least we in the academic world get our crazy stuff signed off on by a panel of competent experts.
- asd 11y agoI'm willing to bet FCA wil recall all of these "UConnect" enabled vehicles within a month to patch this. This will blow up fast.
- mzs 11y agoYou might lose some money: http://www.detroitnews.com/story/business/autos/chrysler/2015/05/18/nhtsa-fiat-chrysler/27531693/ http://www.detroitnews.com/story/business/autos/chrysler/201... There is a patch available, but that is not a recall. A recall takes some time under the best circumstances and FCA pushes back hard on expensive ones.
- asd 11y agoThe feds have been breathing down their necks lately due to too many defects. I'm sure they brought the hammer down hard (behind the scenes) on this one, thus forcing them to announce the recall this morning.
- mzs 11y agoI just saw the news and came here to say you would have made a great bet, cheers!
- jblow 11y agoThis discussion is going insane. I see lots of people arguing about the safety of how these guys conducted the hack. Okay, sure, there is probably an issue there of some degree. But it's a very small issue compared to the fact that hundreds of thousands of vehicles are arbitrarily hackable right now, with more rolling off the assembly line all the time, and people are driving these around right now. Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place.
- phaylon 11y ago> Why is most of the discussion here about the minor issue? Why is everyone so eager to derail discussion from the major issue? I thought HN was trying to be a reasonable place. I find these criticisms _extremely_ reasonable. Plus, the big discussion is not about them doing something illegal, the big discussion is about people here being totally fine with it. And given that the topic you (I assume) want to discuss is something along the lines of "negligent behavior in technology", I also find it very relevant that negligence is countered with more negligence.
- jblow 11y agoThey might be reasonable in isolation but are not being levied remotely in proportion. I just realized what the problem is: this is bikeshedding. Everyone knows about people driving around and feels qualified to have moral indignation in that area, whereas few people know anything about actual cars.
- phaylon 11y agoNo, when people's lives are at stake, I extremely disagree about calling that "bikeshedding".
- jblow 11y agoPlease make an effort to read and understand my point. Yeah, maybe there was a case when a couple peoples' lives were at stake but nothing happened. The real issue is that tens of thousands or hundreds of thousands of peoples' lives are at stake RIGHT NOW, under conditions that are much less controlled than what people are deriding as uncontrolled conditions. But people are griping about the 1-2 instead of the 10,000-400,000. How is this not dead simple to understand? I don't get it.
- peeters 11y agoI feel like, public safety aside, people should be mad at these researchers because they give credibility to every ignorant politician, prosecutor, or journalist out there who says that all hackers threaten the public good. How are you supposed to draw a line between blackhat and ethical hackers when the "ethical" ones endanger public safety all the same?
- tantalor 11y agoLot of comments here are accusing the "hackers" of negligence, but do not forget the writer, camera crew, and editors of WIRED were fully in control of the demonstration. This happened in the context of journalism, not security research. Blame WIRED if you think they screwed up, not the folks behind the computer. It was up to WIRED to ensure the safety of the demonstration, and evidently they failed given this passage, After narrowly averting death by semi-trailer, I managed to roll the lame Jeep down an exit ramp Seems to me they should have at the very least had a chase car trailing the demo car with a sign, flashing lights, or flags to alert nearby drivers.
- peeters 11y agoI think people are quick to single out the researchers because there is more at stake when researchers act recklessly. When a journalist does something reckless, it's a problem with that journalist. The Constitution protects other journalists continuing to do what they do. When a hacker does something reckless, it's usually painted as a problem with all hackers. Which then fuels calls for draconian laws which would hinder future research.
- ripter 11y agoI think it's because the article clearly names the two researchers, while WIRED is a faceless organization. It's a lot easier to get mad and blame the one with a face.
- joeldg 11y agoThis is wired, they sensationalize their stories.
- laacz 11y agoI'm baffled (reporting ethics aside). One would think that car industry would be the one which has learnt about road safety the hard way. That experience should have manifested into extreme caution when adopting and implementing anything new, open and complex. Sadly it is starting to look that everything they learn, they do by trial and error. Not by doing those things we take for granted from engineering and IT perspective.
- siliconc0w 11y agoLast wired on this was kinda bullshit - they let the researchers install a system on the CAN bus. Was this a legit wireless takeover?
- tzs 11y agoDARPA researchers demonstrated this stuff on a "60 Minutes" segment a few months ago [1]. The main difference is that they were in a large empty parking lot so as to not unethically put non-participants in danger. That work and earlier work (including that shown in the 2014 Black Hat presentation by the researchers in the present article) drew interest of the Senate [2]. Senator Markey's office produced a detailed report, and has called for the NHTSA and the FTC to develop standards to deal with these issues (and also the numerous privacy issues modern cars raise) [3]. [1] http://www.cbsnews.com/news/car-hacked-on-60-minutes/ http://www.cbsnews.com/news/car-hacked-on-60-minutes/ [2] http://www.cbsnews.com/news/sen-ed-markey-on-safety-privacy-concerns-for-cars-vulnerable-to-remote-hacking/ http://www.cbsnews.com/news/sen-ed-markey-on-safety-privacy-... [3] http://www.markey.senate.gov/imo/media/doc/2015-02-06_MarkeyReport-Tracking_Hacking_CarSecurity%202.pdf http://www.markey.senate.gov/imo/media/doc/2015-02-06_Markey...
- metafunctor 11y agoThere's a patch available for this already: http://www.wired.com/2015/07/patch-chrysler-vehicle-now-wireless-hacking-technique/ http://www.wired.com/2015/07/patch-chrysler-vehicle-now-wire...
- AustinDizzy 11y agoDoes Wired really wonder why so many of their readers have ad blocking software? [1] I can't even read the article on their website because every ad I see is covering up some sort of text of the article. None of the ads have a close, hide, or dismiss button either so I can't just go and hide them. [1]: http://i.imgur.com/IZymUKm.png http://i.imgur.com/IZymUKm.png [2]: http://i.imgur.com/C7LiA60.png http://i.imgur.com/C7LiA60.png
- tdicola 11y agoSomething is wrong with your browser or screen resolution. The page renders fine in Chrome with no artifacts like that, etc.
- otikik 11y agoWhen I studied real time systems, it was clear that critical systems (in this case the brakes, accelerator, wheel) needed to be in a physically separate network from non-critical ones (music, air conditioning). I guess it must be cheaper to build all in a single network, but it sounds irresponsible. Also, this test should not have been done in a public road. That was irresponsible.
- mzs 11y agoThere often are multiple CAN buses (though there is a push to a single high speed bus) and the ECU (or BCM and so on) are supposed to make sure the commands are safe. In practice they often communicate with one another (manufactures want to sell features like remote start or use cheaper system such as electric parking brake) and the module does not do as much verification as it should.
- eam 11y agoAnything connected on the internet is hackable. We've seen this time after time, so I'm not surprised.
- superuser2 11y agoEvery single highway crash involving a loss of control is now potentially a high-end assassination, including those that have taken place in the last few years. How many people do you think will be murdered this way before investigators and the justice system catch up?
- tdicola 11y agoHah, I found it really funny as I scrolled down there's a big ad for a Fiat in the article: http://i.imgur.com/rSyYPO4.png http://i.imgur.com/rSyYPO4.png Fiat owns Chrysler who owns Jeep... maybe not the best marketing idea to advertise your cars in an article about exploiting them with potentially catastrophic results.
- godgod 11y agoMichael Hastings. Look into it.
- cromulent 11y agoPrevious research on this topic from 2010: http://www.autosec.org/pubs/cars-oakland2010.pdf6 http://www.autosec.org/pubs/cars-oakland2010.pdf6 Experimental Security Analysis of a Modern Automobile "Even at speeds of up to 40 MPH on the runway, the attack packets had their intended effect, whether it was honking the horn, killing the engine, preventing the car from restarting, or blasting the heat. ... In particular, we were able to release the brakes and actually prevent our driver from braking; no amount of pressure on the brake pedal was able to activate the brakes. Even though we expected this effect, reversed it quickly, and had a safety mechanism in place, it was still a frightening experience for our driver."
- mzs 11y agoThere is an extraneous "6" at the end of the paper url, it should instead be: http://www.autosec.org/pubs/cars-oakland2010.pdf http://www.autosec.org/pubs/cars-oakland2010.pdf
- mfukar 11y agoSurprising the comments critical of how the test was performed publicly equate exploitation with guns: > How about they remotely poke around your husband or wife's car and explore, as long as they promise not to intentionally trigger anything? > Calling the cops on a loud neighbor might not be acceptable, but calling the cops on a neighbor firing a gun in the general direction of your house certainly would be. > Anyone could shoot up a public place... should amateur researches be showing up in malls with firearms to test preparedness? The lack of sound judgement _and_ arguments is astounding.
- floatingatoll 11y agoPlease take a moment to write the NHTSA about this hack and ask them to issue a recall for the affected vehicles. http://www.nhtsa.gov/Contact http://www.nhtsa.gov/Contact
- mzs 11y agoI don't know if it will do much good, even if it did eventually lead to a recall, FCA (parent of Jeep) is under investigation by the NHTSA for allegedly poor handling of recalls. http://www.detroitnews.com/story/business/autos/chrysler/2015/05/18/nhtsa-fiat-chrysler/27531693/ http://www.detroitnews.com/story/business/autos/chrysler/201...
- Animats 11y agoThis is very serious, because it can be used on a large scale and has terrorism potential. This could be used to kill people or disrupt an entire city. Where's Homeland Security on this? This is their job. Meanwhile, do not buy a Chrysler product with the "connectivity group". It's an option that costs about $500-$600.
- jbombadil 11y agoGood luck trying to hack my 1971 Volskwagen.
- davesque 11y agoIt's weird that they said the demonstration wouldn't be life threatening when it actually was.
- a-dub 11y agomeh. cars stall all the time. if they hadn't gone for the freakout factor with the reporter, there wouldn't be high profile press, embarrassed automotive executives and politicians scrambling to get a handle on the issue. the real issue is that the automakers are producing fundamentally dangerous vehicles and the federal government is allowing it. these vehicles could be exploited maliciously to cause serious physical harm or death. this is actually a problem. not some onetime stall of a jeep on the highway.
- anfedorov 11y agoThe two researchers say that even if their code makes it easier for malicious hackers to attack unpatched Jeeps, the release is nonetheless warranted because it allows their work to be proven through peer review. Huh? If they have a video of their turning a care off remotely, do they really need peer review of the details?
- mzs 11y agoYes, there have been numerous times when security researchers show video and then the peanut gallery argues if it was staged or not. There is just no way to be sure otherwise.
- anfedorov 11y agoOK. Then you put a journalist in the video, who makes sure it wasn't staged, and we trust them because their careers depend on their integrity.
- toolsadmin 11y agoThe amount of statist pu$$ies in the comment section is astounding. Props to the guys for the demo, that was exactly what was needed to bring attention to this.
- bluecalm 11y agoThis is scary. Malice or incompetence I think it's unacceptable for systems handling the breaks and other crucial functions of the car to be anywhere close to interacting with internet connection. I am going to stick to old style cars for a while. This is really scary.
- keso_77 11y agoI don't get it. Everyone seems to be either upset at the researchers for their test or defending them. Why is no one upset at car companies putting tech in our cars that allows for remote shutdown of said car. Is this what we bailed them out for?
- Tekker 11y agoI'm not going to comment on the question of whether or not the highway patrol should have been called or not - just say I understand where poster tombrossman was coming from. However, I fully agree this was a ridiculous stunt. They could have gotten the same results by demonstrating (on the highway, if they insisted) the air conditioner going full blast, the radio, and the picture of the hackers on the screen. Anything else (cutting transmission, obscuring visibility) should have been saved for a safer environment. The point still would have been made. And it's got nothing to do with the vehicle and driver itself (though I wonder how the hackers knew the exact driving situation - was it plastered with cameras?) - what if two unrelated vehicles got in an accident for some reason and the test driver had to get out of the way, but couldn't? And to make it worse, the cranked radio made it hard for the tester to communicate with the hackers. Very dangerous stunt. Also, and I know it was unrelated to this particular hack, but if the UConnect recognizes voice commands (I assume so), and sends it back for processing, then might it not also be able to bug (eavesdrop) on the car's interior? Many disturbing revelations came out of this, and I applaud them for making it known, but I criticize them harshly for the cavalier way they endangered public safety.
- thetruthseeker1 11y agoResearch can be done to drive a point without making that into a drama. you can demonstrate the science without the hollywood so to speak. I think what was done here could have been demonstrated without the risk that was taken. I think the risk that was taken was poor judgement.
- Wonderdonkey 11y agoITT: Pussies call the police on their peers, shame-defend their pussy actions as "responsibility," display fear-aggression against people defending the researchers' actions. > 40 MPH = dead stop > Blasting the radio = life-threatening > Enjoying the test by laughing about it = black hat > 4 years of inaction by car makers = no need for drastic action It's one thing to be against what these researchers did. It's another to call the police on them. Pussies. Also ITT: Wonderdonkey is downvoted into oblivion. > I regret nothing!
- rebootthesystem 11y agoI revisited this thread and thought: How would I go about running these tests and creating awareness for this issue? A dynamometer would cover the vast majority of what they wanted to show. There was no need to create the danger they created with this vehicle. They really didn't know how the driver would react, "don't freak out" guarantees nothing. A professional driver (like a stunt driver) would have been far more appropriate. The business about disabling the breaks should have been done a pile of hay bundles or something like that in front of the car. For exposure they could have contacted any number of TV stations or networks who would have jumped on this immediately. In all, the choices they made were reckless, stupid, dangerous and potentially criminal. I don't doubt their tech credentials at all. They are tech-smart people, no question about that. However, they have proven, beyond a reasonable doubt, that they are poster children for that stereotype of socially clueless engineers and/or the other stereotype of scientists/engineers who are so into what they are doing that they are completely blind to the idea that they could seriously harm people through their careless actions or inaction.
- themgt 11y agoAs big of dicks as these researchers are, I just have to say, to anyone out there working on software to run cars, airplanes, robots, other mobile vehicles ... some day, within the next 5 or 25 years, it's pretty likely some nut job is going to use an exploit take control of one or more of these vehicles and crash them/use them as remote-controlled / swarm weapons, possibly killing lots of people. If you're writing that software, make sure you do a really, really good job on security. Because no one wants to be the guy 'git blame' shows wrote the exploitable feature that led to ??? deaths. The industry really should have stringent standards that prevent ridiculous breaches like this, I would say as well as simulators (or physical demo vehicles) available online/open source that people can pen-test against and win prize money. And maybe write all the code in Rust?
- MikeNomad 11y agoGood research by the hackers, stupid execution. Calling the police was indeed the right thing to do. Maybe next time, the hackers can test on the vehicles driven by the car executives, while they are driving, have their family in the car with them, etc. Can't wait to see that comment thread...
- gregpilling 11y agoOk, so if the Dodge Dart and the Alfa Romeo Giulietta are built on the same platform , do they share the same vulnerability in the computer systems? or is it more about the Uconnect than anything else ?
- andrey-g 11y agoI recall that last time they used a piece of hardware to connect to the CAN bus via cellular. Are they now able to control the CAN bus via the infotainment system? Does it have it's own cellular transmitter?