Slashdot Mirror


Remote Exploit On a Production Chrysler To Be Presented At BlackHat

Matt_Bennett writes: A scary remote exploit is going to be published that enables someone connected to the the same wireless (mobile data) network to take over many [automobile] systems, including braking. This is an exploit in Chrysler's Uconnect system. Charlie Miller and Chris Valasek also demonstrated exploits in 2013 that could be done via a direct connection to the system, but this is vastly expanded in scope. The pair convinced Wired writer Andy Greenberg to drive around near St. Louis while they picked apart the car's systems from 10 miles away, killing the radio controls before moving on to things like the transmission.

173 comments

  1. Valasek and Miller are assholes and should be asha by suso · · Score: 5, Insightful

    As I felt with their first video, these "security researchers" play with the steering on a car moving 40mph on a public road. Now they've gone and done this. Playing with the driving controls on a 2 ton vehicle moving at 70 mph on a busy road.

    In this video they said "it wouldn't be anything life threatening" which shows that they don't have a clear view of reality in the situation. A seat belt won't
    you have a 70mph head on collision with a semi. The driver wasn't informed beforehand that he could bail out of the test by restarting the car, they waiting
    until he was panicing to try to tell him that.

    What if they made a mistake and turned the car into oncoming traffic? What if their computers were remotely controlled?

    Is the situation with car's vulnerabilities serious? Yes of course.

    Will this video help to drive home the problem to the public? Maybe, but probably not.

    Should they have done this demo on a public road? Absolutely not.

    Bottom line, when you are doing a test where there is physical risk, you need to be in control of the environment and not putting the public in harms way.

    This isn't your home computer and your email account. This is real life.

  2. All driving software should be private functions by Anonymous Coward · · Score: 0

    Who's all getting fired at Chrysler for this? Right now I mean, eventually everyone when Chrysler inevitably goes under for being the worst car company standing.

  3. Tailpipes by Anonymous Coward · · Score: 1

    Now if they could only shut off the blue smoke that I see coming out of most Chrysler tailpipes...

  4. Chrysler by Anonymous Coward · · Score: 0

    People still buy that brand?

    1. Re:Chrysler by Eosi · · Score: 3, Funny

      Well, other than Fiat, not that I know of.......

    2. Re:Chrysler by cayenne8 · · Score: 1

      People still buy that brand?

      Well, the Viper is quite nice....

      --
      Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  5. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 5, Insightful

    Bravo gentlemen. The only way this will get the full and due attention of the media and the car companies is by demonstrating life-threatening risk in the UConnect system. If this were a track test, it would be dismissed by the car companies as contrived, and the media would rather talk about Trump. This will now assuredly end up on the front page unless killed by Chrysler via influence peddling. It's time digital security was a real concern when it comes to my family hurtling down the highway at 75mph in what can now be convincingly argued is a very real digital death trap.

  6. Re:Valasek and Miller are assholes and should be a by xxxJonBoyxxx · · Score: 5, Insightful

    Disagree, in fact I'll probably shake their hands at DEFCON (assuming they're there again).

    The fact that they demonstrated vulnerabilities and then showed automakers multiple ways how to avoid such things (#1 firewall or separate networks; #2 technology to detect and kill anomalous signals) and STILL the automakers shipped defective product...is the problem.

    >> Will this video help to drive home the problem to the public?

    No, but I'd expect a few class action lawsuits will get their attention. I've read a few attorneys' periodicals warming up trial lawyers for IoT product liability, and automakers and their big pockets are sure to be some of their first targets (I think I've seen one settlement already happen).

  7. Fix It Again Tony by Bob+the+Super+Hamste · · Score: 1

    As much as I want to lay the blame for this on it being a Chrysler, now Fiat, product it seems that all auto makers are making a mad rush to have these hyper connected cars. My current car has features I couldn't care less about but is still mostly mechanical linkages and not drive by wire, I'm not sure what I will get when I have to replace it as shortly after it was made the silliness of connected cars started taking off. Maybe I'll just have to get my MG Midget restored before I have to replace my current car and just drive that instead.

    --
    Time to offend someone
    1. Re:Fix It Again Tony by drinkypoo · · Score: 1

      The last full-mechanical car which is vaguely recognizable as "modern" (it featured many firsts we now take for granted) is the Mercedes W126, e.g. 300SE, 300SD, 420SEL... The gassers get pretty poor mileage, though. The diesel will actually continue to operate (in spite of the automatic transmission — which is cable-controlled, and lacks a lockup TC, but does have OD in fourth) if the electrical system goes away completely. It can also be pull-started, in spite of the automatic. Push-starting, however, is not realistic.

      The last full-mechanical, fully-electronically-controlled car I know of which has every modern feature you could reasonably want (like climate control, heated this and that, etc) is the D2 (original) Audi A8. And even it has fully electronic (all-servo) climate controls. The servo connectors tend to break as the vehicle ages... ask me how I know. You can get and swap in a six speed manual. There is an automatic variable intake manifold, but the throttle is a good old cable, so's the parking brake, so's the hood release.

      If you want a bare-bones sports car I still think the best thing around is the 240Z or 240SX depending on what era you like. Pretty safe, nice long hood, swap anything you like. Heater controls still used cables even on the SX.

      New cars are all rolling clusters. The early nineties were the last time that wasn't true. But more modern cars are a whole lot safer...

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Fix It Again Tony by Anonymous Coward · · Score: 0

      Fuck. You understand they have made cars in Detroit for generations, yes?

    3. Re:Fix It Again Tony by Anonymous Coward · · Score: 5, Informative

      I've taken all the sub-systems out of a 2005 Subaru WRX to build another car from the bits. Although there are a lot of electronic modules, very few of them are connected to each other. The cruise control, airbag, ABS, climate control, heating, entertainment, lighting, and engine control systems are all completely independent from one another. I can 100% guarantee that a compromise in any one of the systems cannot be used to control any of the others on this car.

      My experience tells me that it's mostly cars from the past five years or so that are vulnerable to this type of exploit. Anything pre-CANbus has pretty much zero chance of having complex interconnections. Even most early CANbus cars only use the bus for mundane stuff like sending speedo and tach signals to multiple systems. It's a pretty recent trend to start adding things like door locks and brakes to the main bus.

    4. Re:Fix It Again Tony by Anonymous Coward · · Score: 0

      Detroit had been churning out garbage for years before the big two nearly went under and had to beg Uncle Sam for a handout. I don't care much they improved, I'll never buy a domestic car.

    5. Re:Fix It Again Tony by drinkypoo · · Score: 1

      Fuck. You understand they have made cars in Detroit for generations, yes?

      I understand they built a bunch of shitpiles there from about 1973 until... well, they're still building mostly shitpiles, although ironically Ford seems to have a few cars which are built OK. Most of them were designed for Europe. Notably, that 240Z I mentioned would beat the Corvette for half the money, and it was at least twice as reliable. Don't even get me started on how much better-designed in every way the W126 Mercedes is than anything ever produced in the USA. I have plenty of bad things to say about my Audi, though, if you want to hear them.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    6. Re:Fix It Again Tony by Bob+the+Super+Hamste · · Score: 1

      I have been driving BMWs mostly for the last 20 years and they up until recently seem to have stayed away from the excessive electronics at the base trim options. My current car is an 2002 325i (bought used a couple of years ago) with a manual transmission. It doesn't have the fancy infotainment center so when the head unit started flaking out it was just a simple replacement with a ~$100 aftermarket one. It also doesn't have an interment connection or stuff like that. the steering wheel still has a mechanical linkage to the rack, and the brake pedal is still physically connected to the master cylinder. Since I plan on keep the car until it isn't worth fixing I will probably have it for another 10 years at least provided it doesn't get totaled in an accident since it lacks the weak automatic transmission so I may be hard up for something that isn't loaded to the gills with stupid gadgets.

      Unfortunately I am not the type of customer most car companies try to target. I want a car that is fun to drive not something that I can have an interactive conversation with as it reads me the latest twitter posts. In dash navigation I can get that if I wedge my phone between the top of the ashtray and bottom lip of the climate control panel. Seriously it fits perfectly there is out of the way and it isn't going anywhere.

      --
      Time to offend someone
    7. Re:Fix It Again Tony by JaredOfEuropa · · Score: 1

      I've worked for a bit on my girlfriends W126 (a 500 SEL, it was her dad's car, bought in '82). It's a nice mechanic's car and easy to work on even for novices like myself; if you want a "project car" that offers plenty of comfort, and if you don't mind the crappy milage, then I would recommend the Benz. Just check for rust in the usual spots.

      --
      If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
    8. Re:Fix It Again Tony by Bob+the+Super+Hamste · · Score: 1

      Just because they have made cars for ages doesn't mean they have made good cars. Having had the pleasure of owing a mid 80s Oldsmobile in the late 90s when I was in college and after that owning an early 80s BMW it was night and day difference. While the Oldsmobile felt old and worn out as well as begin rusted out (you could roll the windows down and still see the windows) the BMW drove quite nice and wasn't a rusty shit pile. Also the vehicles had fairly similar mileage on them when I disposed of them. The Oldsmobile was gotten rid of because it died on the road, the BMW was gotten rid of because I was stopped at a light and some ass hole rear ended me while going 55 MPH, I walked away uninjured but the trunk of the car was completely under the car and the rear half of the car bowed out so the rear doors popped open and couldn't be shut.

      Every time I see one of those Chrysler commercials about being imported from Detroit I just substitute war torn 3rd world hell hole as it more accurately describes the expected quality. Chrysler use to be a company that made pretty good vehicles and was known for engineering but that was over 40 years ago. I mean when you get to the point of discussing the features of your cup holder as a selling point you really don't have much to offer.

      --
      Time to offend someone
    9. Re:Fix It Again Tony by HornWumpus · · Score: 2

      240Z beat a vette? You are on drugs.

      Perhaps if you put a mouse (American engine, same as in most corvettes) in the Z it would be competitive. But the vette chassis will hold easily twice the power and you are basically talking about putting a vette drivetrain into Z car.

      I owned a 280Z back in the day, they are fun cars, but not even in the vettes class.

      We know you love your old benz, you'd have to get a caprice classic to get similar numbers from an American car.

      Twice as reliable? Tell me that after you get 3 Hitachi side draft carbs to synch perfectly. The advantage of the 240 over the 280 was lighter weight, at the cost of a lower powered and much less reliable engine. The 240 is the Z you want to put a V8 into, not the one you leave stock.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    10. Re:Fix It Again Tony by Anonymous Coward · · Score: 0

      You could probably extend that observation to pre 1996 OBD-II cars in general. Once OBD-II came out, everything was much more connected and cars started using CAN for everything. For instance, my 1997 Maxima had an extensive LAN section in the factory service manual.

      I have a 2006 WRX currently, which is certainly more connected than the 2005, but isn't as integrated as newer cars. The TR that I have has manual HVAC controls, a manual trans and no VDC, but does have drive by wire throttle. The Body Integrated Unit is wired into both the high speed and low speed CAN bus, but doesn't have the ability to control the transmission or actuate the brakes since there's no VDC or TCM. ABS and engine control are on the bus, as well as automatic locking and the combination meter (CAN errors will display on the trip meter). Fortunately, none of that is connected to anything wireless, and I'm highly likely to notice if something is plugged into my diag port since it's right under the steering column and I often plug my AccessPort into it.

    11. Re:Fix It Again Tony by gweilo8888 · · Score: 2

      My experience tells me that it's mostly cars from the past five years or so that are vulnerable to this type of exploit. Anything pre-CANbus has pretty much zero chance of having complex interconnections.

      You do realize that the earliest iterations of the CAN bus date back to the late 1980s, it has been in the majority of US-market vehicles for more than a decade, and by 2008 was a legal requirement in mass-market vehicles, right?

      A heck of a lot more than just the last five years of vehicles use the CAN bus. If your vehicle is made within the last decade it's almost a certainty that it uses the CAN bus.

    12. Re:Fix It Again Tony by mjwx · · Score: 1

      As much as I want to lay the blame for this on it being a Chrysler, now Fiat, product it seems that all auto makers are making a mad rush to have these hyper connected cars. My current car has features I couldn't care less about but is still mostly mechanical linkages and not drive by wire

      Drive by wire is not inherently bad. A lot of very good cars have DBW now.

      The problem is that drive control systems are being connected to entertainment and communications systems that have links to the outside world.

      There should be an air gap or at the very least a one way connection (as in the Tx pairs physically cut) between systems that have access to drive/engine controls and systems that have connections to the outside world. Sadly this wont happen until someone actually dies because of it (and even then they'll use every dirty trick in the book to avoid it) because there are too many vested interests (law enforcement, data miners, "services" like onstar) and auto makers are too lazy to do things properly.

      Paying extra to keep an old mk IV Supra on the road seems like it's becoming a more attractive prospect every day.

      --
      Calling someone a "hater" only means you can not rationally rebut their argument.
    13. Re:Fix It Again Tony by Anonymous Coward · · Score: 0

      I know. The five year mark is the watermark for the stupidity of moving functionality to software and connecting everything together. Ten year old CANbus cars generally have few security holes. My point was that CANbus didn't introduce the exploit vector, but is a prerequisite for it.

      Chronology:

      - Pre OBD-II (early 80's and before) - No problems

      - OBD-II, pre CANbus - No problems

      - Post CANbus, pre "infotainment age" - Few problems

      - Cars with infotainment systems - Security disaster

    14. Re:Fix It Again Tony by ceoyoyo · · Score: 1

      They rated cars on various factors that they thought would predict vulnerability to hacking. The Jeep they hacked rated highest, IIRC, but right up there with it were the Escalade and a Lexus sedan. It's an industry-wide problem. Actually, it's worse than that. These things are really baby SCADA systems, and SCADA security is pretty crappy in all industries.

  8. Re:All driving software should be private function by beelsebob · · Score: 1

    Uhhhh? Do you somehow think that making a function private in the source code means that it's impossible to jump to that location at runtime? That's really not how it works.

  9. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    WHICH IS WHY EXPOSING SUCH BUGS NOW IS IMPORTANT, YES!

    Do you not see that, despite seeing the potential dangers of this? The Uconnect shit has been around for years now!

  10. Re:Valasek and Miller are assholes and should be a by suso · · Score: 4, Insightful

    I'm not really talking about automakers or the vulnerabilities of cars. I'm only saying that Valasek and Miller were irresponsible security researchers for conducting a dangerous test on public road. This is the kind of thing that will give all security research a bad name or at least bring it under heavy scrutiny.

  11. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 1

    Disagree, in fact I'll probably shake their hands at DEFCON (assuming they're there again).

    The fact that they demonstrated vulnerabilities and then showed automakers multiple ways how to avoid such things (#1 firewall or separate networks; #2 technology to detect and kill anomalous signals) and STILL the automakers shipped defective product...is the problem.

    >> Will this video help to drive home the problem to the public?

    No, but I'd expect a few class action lawsuits will get their attention. I've read a few attorneys' periodicals warming up trial lawyers for IoT product liability, and automakers and their big pockets are sure to be some of their first targets (I think I've seen one settlement already happen).

    I guess you are out of touch with reality, too. You don't need to risk an accident on a highway to prove that your remote control works. The flaws in the system needed to be exposed, but risking a car accident on a highway involving people who didn't consent (aka the truck driver) makes them assholes. That was an unneded stunt. At the moment I fell like I'd like to exploit the hand shake with them and get them into a police grip and bump their head on wall to show them the dangers of shaking hands the safe way.

  12. Nobody Pays attention. by Archangel+Michael · · Score: 3, Insightful

    I point you to Admiral Adama of (Battlestar Gallactica) wise words ... "Do not network the ships computers"

    --
    Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    1. Re:Nobody Pays attention. by Anonymous Coward · · Score: 0

      The Cylon's did have to break through like 7 layers of firewalls to get to the main computer. Good work on their part.

    2. Re:Nobody Pays attention. by Archangel+Michael · · Score: 1

      They had Baltar working for them, and I don't blame him. Who wouldn't give up secrets to Six?

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
  13. Re:Valasek and Miller are assholes and should be a by xxxJonBoyxxx · · Score: 1, Insightful

    >> dangerous test on public road

    I'd still rather have them do THIS when the systems aren't too popular than have some random swatter roll a minivan with 5 kids because he mistyped the IP address of the guy who just beat his speedrun. (Where "THIS" is a controlled test.)

  14. the future of car accidents by Gravis+Zero · · Score: 1
    --
    Anons need not reply. Questions end with a question mark.
  15. Re:Valasek and Miller are assholes and should be a by Archangel+Michael · · Score: 1

    They did not ship a defective unit. The unit was shipped worked fine. The problem was it was exploitable, which is not a defect, it is a lack of foresight.

    Any sufficient level of incompetence is indistinguishable from malice.

    --
    Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
  16. Re:Valasek and Miller are assholes and should be a by Mr+D+from+63 · · Score: 3, Insightful

    Doesn't it matter what it takes to make this exploit work? For instance, if you have to physically access the vehicle and do something in order to enable the remote exploit. There is a widely know physical exploit called cutting the brake lines, but manufacturers are in no way responsible for creating hard to access and cut brake lines.

    These articles often are vague on the implementation requirements to achieve the exploit. That matters, IMHO.

    With that said, standard control architecture practices should keep the key controls like steering, braking, acceleration, etc separate from the data monitoring and other systems, and where you can't separate entirely there are methods to manage that as well.

  17. Re:Valasek and Miller are assholes and should be a by Registered+Coward+v2 · · Score: 1

    As I felt with their first video, these "security researchers" play with the steering on a car moving 40mph on a public road. Now they've gone and done this. Playing with the driving controls on a 2 ton vehicle moving at 70 mph on a busy road.

    Excellant points. They could have made just as powerful a statement in a safe environment instead of running a test on an open road where they would endanger the driver and others if something went wrong. Expecting someone "not to panic" when they find themselves slowing down with no escape route and a semi on their tail is stupid at best and criminal at worst.

    They had the ear of some powerful Senators. You want to get things done? Find a safe place to show what you can do, such as a parking lot where the owner will offer to cordon it off while you run your demonstration. Offer to put one of them in the Jeep with the journalist. Partner with a University that has access to a test track.The got a grant and appear to have the credentials to be taken seriously, use them. A stunt like this could very well result in a backlash and articles condemning them for putting people at risk; rather than focusing on the real issues they bring up.

    Frankly, I'm surprised the automakers use the same bus for vehicle control and the entertainment systems that are linked to the internet.It would seem at a minimum it should be air gapped for security and access to the control systems limited to the diagnostic connector. I'm guessing it was cheaper to use 1 bus to carry all the signals with no real thought that someone might exploit the weakness. Oddly enough BMW coders (who change vehicle orders in cars to activate additional features) have apparently been remotely updating the coding for a number of years. Granted, the person doing the update needed information from the owner to do so but the vulnerability would still be there; I say apparently because I have not used a remote coding service but done updates via the OBDC and software myself through a wired connection.

    --
    I'm a consultant - I convert gibberish into cash-flow.
  18. Probably won't stop the auto industry by MikeRT · · Score: 4, Insightful

    Like medical device manufacturers, they seem to be in lala land compared to most fields that use computers when it comes to security. The worst part is that if the federal government mandates security standards, the most likely outcome is that they will likely only target a few bright lines tests and the standards will never keep pace with the evolving threat models.

    1. Re:Probably won't stop the auto industry by lhowaf · · Score: 1

      Security vulnerabilities will get much worse and more impactful as we migrate to driverless vehicles. Government action isn't the answer - laws/regulations only address known flaws - and at the grossest level. Unfortunately, shiny things sell way better than safe things.

    2. Re:Probably won't stop the auto industry by P.+I.+Staker · · Score: 1

      I assure you things are getting, much, much better. Some of the standards being passed down are far more stringent. As much as it's easy to say that they are "in lala land", it's easy to see why security would be an after thought to a system not connected to the outside would. Manufacturers would rather focus on immediate safety concerns. I agree that it's not certain that the standards will keep pace with evolving threat models, but exploits like this should get much tougher. I'll be interested to see details of this exploit, but I bet they weren't doing much (or anything) to secure the CAN bus. There is currently a huge security push in the auto industry, and bus security will certainly improve. Honestly, I don't have any expertise in security, but I imagine that encrypting the traffic on the bus and authentication will make it much harder to decipher and send malicious messages (this appears to be what the attackers are doing). Why anyone would put an infotainment system with access to the internet on a safety critical bus is beyond me and seems pants on head retarded though.

  19. RIP Hastings by Anonymous Coward · · Score: 0

    It also works with foreign cars, as long as they are modern like the Mercedes C250 Coupé

  20. IoT failure by Anonymous Coward · · Score: 0

    It just goes to show that connected systems aren't ready to take on risky endeavors. Unfortunately, most companies keep including more and more connected things, and I'm sure that FCA isn't alone in being completely unprepared for the lawsuits and drop in sales that will result in not taking security seriously. As with any connected system, if there is a way to communicate out, there is the potential for a way to communicate in. In this case, it's lucky that the flaws were discovered and shared by more benign hackers. Others might be much more malicious, especially when the company was initially dismissive of security flaws.

    That's why I prefer to sacrifice the convenience of being connected in order to know that someone else isn't watching me at home or potentially going to take control of something that can kill me. My smartphone is security hole enough, but those games won't play themselves!

    1. Re:IoT failure by Anonymous Coward · · Score: 0

      "As with any connected system, if there is a way to communicate out, there is the potential for a way to communicate in."

      Not necessarily, if they actually put some thought into their designs it would be simplistic to create systems that communicate relevant information out (oil pressure, voltage, RPM, temperature, Heat/AC fan speed, etc) of a non-connected critical system to a networked entertainment/remote monitoring system. As others have routinely mentioned on these kinds of "critical systems security" discussions some cabling systems employ a set of conductors for output and another for input, just physically cut the input ones on the critical system side and set up the software on that end to send out a continuous stream of telemetry to the non-critical system. Properly programed that gives you most of the functionality of a directly connected system with very few if any of the risks.

  21. Re:Valasek and Miller are assholes and should be a by beelsebob · · Score: 3, Insightful

    But anyone sane on the planet would rather have them sit a car in a large, private, open space and demonstrate that they can control all of the controls without endangering anyone's life, especially people who didn't sign up to have their life endangered and were just driving down a public road.

  22. Re:Valasek and Miller are assholes and should be a by beelsebob · · Score: 2

    So you're saying it had a defect (the ability to exploit it), but it wasn't defective?

    In general, companies don't tend to know about significant defects when they actually ship the item. That doesn't mean that they're not defects.

  23. Re:Valasek and Miller are assholes and should be a by Impy+the+Impiuos+Imp · · Score: 1

    It makes them criminals and they should go to jail.

    Proof of concept would involve a test car in a safe area.

    --
    (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
  24. Re:Valasek and Miller are assholes and should be a by fred911 · · Score: 2

    "STILL the automakers shipped defective product...is the problem."

    Chrysler has been doing this for years. Perfect example is the head-gasket on the Neon. They produced an upgrade repair but NEVER upgraded the product.

    --
    09 F9 11 02 9D 74 E3 5B - D8 41 56 C5 63 56 88 C0 45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
  25. Re:All driving software should be private function by DanJ_UK · · Score: 1

    Quite possibly the funniest suggestion evAr.

    --
    - Dan
  26. This doesn't surprise me One bit... by Anonymous Coward · · Score: 4, Interesting

    The Uconnect system is one buggy piece of software. Most of my interactions with the system is working around bugs. It updates without you knowing about it in the middle of the night over the Satellite system. It is very order dependent on things working correctly (even though running an automobile isn't that order dependent. The fact that there are remote issues doesn't surprise me all that much. I had a day where the tire system when bonkers and was reporting all sorts of surprising things. Then it stopped. I have had the car not start in a particular order. I have accidentally had the car started and instead of turning off, grind the starter. And because it is all software driven, there is nothing to do but wait. It is also tied into the Media system and bluetooth where I have a lot of interactions that just do not seem to work all that well. But I have been well trained on how to get it to work, until the fix a bug or add a new one, and my workflows have to change.

    1. Re:This doesn't surprise me One bit... by strikethree · · Score: 1

      I hope you did not buy the vehicle that you are having problems with. If so, I would seriously looking at returning it for a full refund as defective merchandise.

      I am guessing all new cars are off the list now. GM has OnStar, Ford has shit that remembers where you drive, and Chrysler has buggy, remotely exploitable software. All of them have stuff that let's someone else control your vehicle.

      What the fuck? Who would buy something like that? Perhaps the consumer just does not know...

      --
      "Someone needs to talk to the tree of liberty about its ghoulish drinking problem." by ohnocitizen
  27. Re:Valasek and Miller are assholes and should be a by gstoddart · · Score: 4, Insightful

    You know, doing it in a real world setting and demonstrating it is a hell of a lot better than continuing to believe the lie these companies have done an adequate job at security.

    And, once again, we see that consumer electronics are almost completely incompetent at any semblance of security.

    Uconnect, an Internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicleâ(TM)s entertainment and navigation, enables phone calls, and even offers a Wi-Fi hot spot. And thanks to one vulnerable element, which Miller and Valasek wonâ(TM)t identify until their Black Hat talk, Uconnectâ(TM)s cellular connection also lets anyone who knows the carâ(TM)s IP address gain access from anywhere in the country. âoeFrom an attackerâ(TM)s perspective, itâ(TM)s a super nice vulnerability,â Miller says.

    Which is pretty damned unbelievable if you ask me.

    In fact, it sounds like some pretty epic incompetence at security, and reaffirms that corporations need to be held to MUCH higher standards of liability with all of their computers, instead of just saying "oops, we didn't know".

    --
    Lost at C:>. Found at C.
  28. Re:Valasek and Miller are assholes and should be a by Archangel+Michael · · Score: 0

    I don't consider exploits to be defective. Defects require no outside "help"

    This would be the same as saying the Twin Towers were defective because the couldn't withstand airplane crashing into it (extreme example).

    To me, defective is something that breaks all on its own.

    --
    Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
  29. Doesn't affect me by Anonymous Coward · · Score: 0

    I'm safe. All of my vehicles pre-date Firefox.

    1. Re:Doesn't affect me by Anonymous Coward · · Score: 0

      I'm safe. All of my vehicles pre-date Firefox.

      I assume you mean the movie not the browser.

  30. Re:Valasek and Miller are assholes and should be a by bws111 · · Score: 1

    No, he is saying it is NOT A DEFECT. The cars are not designed to stop criminal actions. Is it a 'defect' that the windows can be 'exploited' by not being bullet-proof? Is it a defect that the body is not armored? Is it a defect that brake lines can be cut? Is it a defect that the car can be towed away by a criminal?

  31. Re:Valasek and Miller are assholes and should be a by pixelpusher220 · · Score: 3, Informative

    They aren't vague, it's the defined system by which the car connects to the internet, Uconnect. They accessed that over the internet from 10 miles away and controlled the car. This is no different than them using a buffer overflow exploit to gain remote access to a web server.

    It's a perfect example of why encryption back doors are a fools errand. I'm sure it would be nice to stop a criminal who stole your car by turning off the engine...but that opens up the ability to remotely turn off the engine that could be used by anyone gaining the appropriate access. You can't make remote connections 'secure', only levels of security that come with risks.

    --
    People in cars cause accidents....accidents in cars cause people :-D
  32. Just patch your car .... by bobbied · · Score: 1

    Not an issue, just patch it... It doesn't take that long, nor is it that hard...

    On July 16, owners of vehicles with the Uconnect feature were notified of the patch in a post on Chrysler’s website that didn’t offer any details or acknowledge Miller and Valasek’s research. “[Fiat Chrysler Automobiles] has a program in place to continuously test vehicles systems to identify vulnerabilities and develop solutions,” reads a statement a Chrysler spokesperson sent to WIRED. “FCA is committed to providing customers with the latest software updates to secure vehicles against any potential vulnerability.”

    You can be sure any new vehicles will have the fix too.... Nothing to see here, move along...

    --
    "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    1. Re:Just patch your car .... by Anonymous Coward · · Score: 0

      Not an issue, just patch it... It doesn't take that long, nor is it that hard...

      On July 16, owners of vehicles with the Uconnect feature were notified of the patch in a post on Chrysler’s website that didn’t offer any details or acknowledge Miller and Valasek’s research. “[Fiat Chrysler Automobiles] has a program in place to continuously test vehicles systems to identify vulnerabilities and develop solutions,” reads a statement a Chrysler spokesperson sent to WIRED. “FCA is committed to providing customers with the latest software updates to secure vehicles against any potential vulnerability.”

      You can be sure any new vehicles will have the fix too.... Nothing to see here, move along...

      This is quite an ignorant statement. Windows has been "patching" their security holes for 15+ years. Is Windows now secure? No! Do you think a couple "patches" will eliminate all security issues with the cars? It will fix the currently 1+ day hacks, but new 0 day hacks will continue to be found. I'm stunned that car makers have not taken security more seriously. All it takes are some "script kiddies" who are also wackos to sit on an overpass, and start spinning cars out of control for "fun".

    2. Re:Just patch your car .... by FranTaylor · · Score: 1

      Windows has been "patching" their security holes for 15+ years. Is Windows now secure? No!

      FIAT ==

      Fix
      It
      AGAIN,
      Tony

    3. Re:Just patch your car .... by Jaime2 · · Score: 1

      Just patch your car

      Maybe in this case it's feasible. My Mazda3 cannot be customer patched and the dealership hates to do it because it takes two hours to do, but the factory only pays them for an hour of labor. I have zero trust that the auto industry will figure out patch rollouts in the near future. Also, even if they get patching right, it will just put them in the same shape that computers are now - which is sad shape.

    4. Re:Just patch your car .... by Anonymous Coward · · Score: 0

      "Just patch your car"

      A far more effective and fail proof way would be to simply segregate the entertainment system (except maybe the volume control) from the rest of the cars systems (engine, brakes, transmission, AC/Heat). There is almost NO reason why these systems should be remotely accessible in any way, any updates to these systems that would be necessary should probably be done at a dealer anyway as they could brick your car.

    5. Re:Just patch your car .... by HornWumpus · · Score: 1

      Fucked
      In
      All
      Things

      My Fiat 850 sport is just a shell that sits on a Suzuki chassis with Toyota axles and a weak little mouse for power. The local Fiat club doesn't like me.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    6. Re:Just patch your car .... by ceoyoyo · · Score: 1

      Sure, that worked so well for operating systems. And smartphones. After those had been patched once or twice there were no more exploits ever.

      If your smartphone gets hacked it's annoying. You format it, install the security update, and hope it doesn't happen too often. If your brakes get hacked you've got a bit bigger problem.

  33. Re:Valasek and Miller are assholes and should be a by beelsebob · · Score: 1

    That depends entirely on whether the item was designed to withstand people attacking it.

    A bomb shelter is defective if someone drops a bomb on it (at the designed distance and explosive power) and it collapses.

    A skyscraper is defective if it was designed to withstand a plane impact and it does not.

    A car is defective if it was designed to withstand people trying to hack it, and it doesn't.

    A car's design is defective if it was not designed to withstand people trying to hack it.

  34. Re:Valasek and Miller are assholes and should be a by Isarian · · Score: 2

    Straw man. There's no reason these exploits couldn't have been executed in a parking lot (where, in fact, the rest of the test was performed). They would hold the same impact without endangering the public.

    This is the same reasons that dangerous medical research is performed in negative room pressure clean-rooms and vehicle safety crash tests are performed in controlled environments and not with vehicles on the interstate. You don't expose uninformed, uninvolved, and non-consenting members of the public when performing dangerous work.

    As it was, he stalled out on a bridge in heavy traffic and managed to get to safety. It's not much of a stretch to imagine a worse scenario - there he is in a tight turn in heavy traffic when his vehicle is compromised. Imagine he hits a minivan with 5 kids that then rolls. Now it's not a story of a dedicated journalist and two edgy security researchers - it's a story of murder, or at least manslaughter, and all three are complicit.

  35. Re:Valasek and Miller are assholes and should be a by ultranova · · Score: 2

    The cars are not designed to stop criminal actions.

    Mine has locks.

    --

    Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

  36. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 0

    And then the jury yawns loudly. By doing the test on the highway, everyone who sees the video can suddenly relate.

    Meanwhile, putting it in neutral wasn't THAT dangerous. Cars suddenly quit running on the highway every day and most can't be fixed just by turning it off and then on again.

  37. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    That is what is known as a design defect.

  38. These people already CHOSE Chrysler by NotDrWho · · Score: 0

    If they're already driving a Chrysler by choice, I'm pretty sure that there's nothing more you could do to them that will make things any worse.

    --
    SJW's don't eliminate discrimination. They just expropriate it for themselves.
  39. Re:Valasek and Miller are assholes and should be a by dpidcoe · · Score: 1

    A car is defective if it was designed to withstand people trying to hack it, and it doesn't.

    I think what he's getting at is that the car wasn't designed to withstand people trying to hack it. i.e. security wasn't even a consideration in the design.

  40. Re:Valasek and Miller are assholes and should be a by cayenne8 · · Score: 2
    Is the UConnect system optional or are they trying to make it standard on their cars?

    I had looked awhile back at a new corvette and last I heard you could NOT get the fscking OnStar system out of the car....

    So, wondering if this is another "feature" that isn't optional....

    Why is it so hard to get a car without it being fucking connected to everything? I just want performance, and nice looks...I drive a car, I'm not trying to do a spreadsheet while driving for God's sake.

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  41. Re:Valasek and Miller are assholes and should be a by bws111 · · Score: 1

    The locks are a convenience feature and not actual security.

  42. The Best Part by Anonymous Coward · · Score: 1

    The best part of this is that because they are exploiting a Chrysler product, even the vulnerabilities will prove to be unreliable

    -- Long Time Jeep Wrangler Owner in therapy

    1. Re:The Best Part by KGIII · · Score: 1

      Jeep lost me when they went to rectangle headlights. Sure, they put the round ones back on some models. The round lights worked better and were generally more resistant to damage. My favorite was a '73 Wagoneer. It had a PTO and a Borg-Werner transmission. It had enough torque in 4W-L that it could probably have pulled a house off its foundation. *sighs* Of course, once you got it stuck it was stuck. It was also a horrifically lovely orange color that belonged on absolutely nothing on this planet. I loved it.

      --
      "So long and thanks for all the fish."
  43. Re:Valasek and Miller are assholes and should be a by bws111 · · Score: 1

    A car's design is defective if it was not designed to withstand people trying to hack it.

    Why? Just because you said so? Since when it is a manufacturers responsibility to protect against criminal actions involving his product?

  44. Re:Valasek and Miller are assholes and should be a by StikyPad · · Score: 4, Insightful

    You can't quantify the level of risk by losing control of a vehicle, because you don't have the data. Neither do they. But there IS a level of risk by simply being on a public road with other cars, and that risk DOES rise with distractions, let alone malfunctions affecting braking, acceleration, or steering. Moreover, they were trying to demonstrate how dangerous the hack can be, so on the one hand, they're implicitly admitting that they put the author and the public at risk, but on the other side of their mouth, they're trying to say there was nothing life-threatening? Sorry, I don't buy it. That was willful negligence. It was irresponsible and reckless, and the "only way to get attention" argument doesn't stick when you fail to escalate in a responsible and methodical manner and skip right to the nuclear option. That was the problem with Snowden, and that's the problem with these characters.

  45. Re:Valasek and Miller are assholes and should be a by FranTaylor · · Score: 1

    The locks are a convenience feature and not actual security.

    This is Not true at all, the government has laws on vehicle security, intended to slow the rate of auto theft.

    Automobile locks in the US MUST be certified their security.

    See: "The Anti-Car Theft Act of 1992", "The Anti-Car Theft Improvements Act of 1996"

    Your insurance company would refuse to offer theft insurance on your car if it was easy to steal.

  46. Re:Valasek and Miller are assholes and should be a by FranTaylor · · Score: 1

    Why? Just because you said so? Since when it is a manufacturers responsibility to protect against criminal actions involving his product?

    Crashing your vehicle into another is a violation of the traffic laws, and yet our automakers spend billions and billions of dollars to protect their customers from these criminal actions.

  47. Don't allow remote-control, except... by davidwr · · Score: 2

    If the "car" part of the car were completely disconnected from any "outside" communication, the problem would go away.

    Now, there are times where allowing outside control of the car is useful, such as remote-start of the heating and A/C systems so the car isn't an icebox or oven when you get in, and (perhaps) a remote-slowdown or remote-prevent-engine-start command as part of an anti-theft-system, but if you are going to do this, you have to do it right and you have to assume that even if you do it right, someone will be able to defeat your security. You have to ask yourself, as a manufacturer, is it really worth it to allow my customers the conveniences of remote-control in exchange for the small but very real risk that an adversary could exploit it to kill my customer or someone else?

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
    1. Re:Don't allow remote-control, except... by FranTaylor · · Score: 1

      If the "car" part of the car were completely disconnected from any "outside" communication

      my car has an FM radio

      can you break in through it?

    2. Re:Don't allow remote-control, except... by Anonymous Coward · · Score: 0

      You don't necessarily need to forgo the convenience to have robust security, just don't be an idiot when designing it. Put the critical car systems on one board and the infotainment/networked systems on another. The critical systems board is only connected to the infotainment/networked board through an extremely locked down connection which streams telemetry to the infotainment/network board for display & "neat feature" capabilities and only allows a very few extremely simple commands back through a few dumb relays. For example a remote start capability, a person commands the car to start through their smartphone which through mobile networks (and unfortunately the manufactures systems) commands the infotainment/networked system to trip a relay that instructs the cars critical systems board to remote start. Like any remote start it has safeguards (and maybe an added few) such as only running for 15 or so minutes unless the key is inserted, touching the brakes shuts the car off, cannot be activated while the car is running, can only be used once every few hours, etc. Even if a hacker gains complete control of the infotainment/networked system they can only see what the car is doing and maybe trip a few non-critical annoyances (starting the car for example) but can never gain direct control over the cars steering, brakes, engine, etc. The further you move the networked systems out of the cars systems the better but this I think is the bare minimum.

  48. Roughly, how did this happen? by ShooterNeo · · Score: 2

    I remember thinking in the 90s "no one would be stupid enough to put safety critical computer systems on a network at all..."

    And, here we are.

    If someone gave me a blank sheet of paper and asked me to sketch out the system for a car's braking controller, I'd slap down a CPLD or microcontroller, and have it use some locked firmware to read the various sensors and send out the control signals.

    Oh, they want networking? I'd isolate or use the inherent properties of a CPLD/FPGA programmed in combinatorial logic style (you can program a CPLD/FPGA to act like a microcontroller instead which is vulnerable)

    In combinatorial logic style, all the processing is through various gates, and is a boolean combination of flip flops and logic gates. So, say they want the ability to read(but not alter) the current state of the vehicle's brakes. A tiny communication processor (a low pin count PIC is one choice) would receive from the vehicle's CAN bus the command to give the vehicle's brake state. The communication processor would toggle high an outpin pin connected to an input pin on the microcontroller/CPLD that actually controls the brakes. That high pin state would mean that every few control loop cycles, the microcontroller/CPLD would blast out the current state on a serial output pin.

    Note that there's no opportunity for a hacker who got into that communication processor to do any worse than toggle a pin on and off. No effect on the steering/braking.

    Ok, maybe now we want to be able to change the "style" of steering and braking. So now there's a finite set of legal states that are stylistically desirable. That's when you'd isolate with the inherent property of an FPGA/CPLD state machine to not be capable of any other states BUT the states you defined. (there's no global memory and no stack, so nothing a hacker can do to affect the machine's behavior)

    1. Re:Roughly, how did this happen? by Jaime2 · · Score: 1

      The answer is easy; no one who really cares about security was at the design table.

      Also, custom circuits seems to be expensive in the auto industry. I recently had to replace a daytime running light controller on a car - it cost about $130. I opened up the old one and it was nothing but about 20 discrete through-hole components on a custom circuit board, mostly transistors and resistors. If you build everything on a programmable general purpose platform, you only pay the hardware costs once.

    2. Re:Roughly, how did this happen? by Anonymous Coward · · Score: 0

      Personally I just protect my car with a modified Host file.

    3. Re:Roughly, how did this happen? by FranTaylor · · Score: 1

      it cost about $130.

      silly silly you, buying new parts to put in a used vehicle. It would have been $15 at a junkyard.

    4. Re:Roughly, how did this happen? by P.+I.+Staker · · Score: 1

      Yes people are that stupid and industries can be very slow to change. The auto industry seems fond of slapping some garbage piece of electronics into their vehicles to make them seem high-tech. Really this isn't brand new, but the fad now days is to try to merge your car with your smartphone. It sounds like this is what they did, and for whatever reason decided their POS infotainment system needed to be on a CAN bus with other critical controllers. Honestly, I'd rather the auto industry keep their hands off these systems and let me buy some aftermarket smartphone remote head unit garbage, or let Apple/Google do it and blend their systems into the interior. In the entire history of auto infotainment it seems like the only benefit of having the manufacture supply the electronics is aesthetics. Every aftermarket product I've used is leaps and bounds better than what was sold with the car, even "premium" systems. Regardless, it should be analogous to powering my phone off the battery and plugging into the sound system. I guess if you really need to send information back and forth, separate the bus and any controller on that separate bus should know that no controls can be sent from the that bus, just basic information. Sorry for the rant, maybe I'm ill informed and this exploit is more complicated, but I'd bet dollars to donuts that a component in the infotainment system, with access to the outside world, is on the same bus with critical components and the engineers just figured "our firmware can't send any commands, so we're good".

    5. Re:Roughly, how did this happen? by P.+I.+Staker · · Score: 1

      You may disagree with me, but personally I don't have a problem with security being an afterthought in the non-connected world cars used to live in. It would require someone with specialized knowledge to have physical access to the vehicle to exploit it. At that point, I'm sure there's a number of nasty things they could do. Cars clearly don't live in an unconnected world anymore, and things need to change. It blows my mind how many engineers are zen with having components, with access to the internet, be connected to safety critical systems (see the recent concerns about Boeing's avionics security)

  49. Re:Valasek and Miller are assholes and should be a by Yunzil · · Score: 1

    The fact that they demonstrated vulnerabilities and then showed automakers multiple ways how to avoid such things (#1 firewall or separate networks; #2 technology to detect and kill anomalous signals)

    Or, I don't know, how about not hooking up the car's controls to any network at all? Why is that even a thing?

  50. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    The finance and insurance companies, and of course, the vast array of law enforcement agencies LOVE being able to locate your vehicle. To opt out, you're stuck with pretty basic cars - and nothing from GM.

  51. Re:Valasek and Miller are assholes and should be a by kheldan · · Score: 2

    At least they're assholes in the public interest. Is what they did borderline criminal? I'll leave that up to public opinion. But what they've done is justify the fears that many may have had, that what they've seen in movies and television shows isn't fiction but reality. They're not be the heroes we need, but perhaps they're the heroes we deserve. Be thankful at least that no one was injured, and that the truth about this was revealed.

    --
    Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
  52. OOP can't stop... apk by Anonymous Coward · · Score: 0

    See subject: Rootkit drivers that can peer into all memory (which is how/why your keyboard works for everything for instance, FAST, & consistently, across all ring 3/usermode/rpl3 applications, right outta ring 0/kernelmode/rpl 0).

    APK

    P.S.=> Just a fact... apk

  53. Re:Valasek and Miller are assholes and should be a by Mr+D+from+63 · · Score: 1

    So, you are certain that they connected to a particular car that they had not accessed at all in any other way prior to hacking? I don't think it is clear at all on that part.

  54. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    There is a corollary:

    Any sufficient level or malice is indistinguishable from incompetence.

  55. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    The "nuclear option would have been to disable the brakes. They didn't do that on the highway. They can only mess with the steering in reverse. Do you claim the jeep was reversing down the highway or would you like to retract that one?

    They DID mess with the brakes at low speed NOT on a public road (picture looked like the edge of a parking lot).

  56. Why no radio kill switch? by kheldan · · Score: 4, Insightful

    Laptops have had hardware power switches for their transceivers for a long time now, if autos are going to have wireless access to their systems then why the hell isn't there a kill switch for that transceiver so the owner of the vehicle can turn it off?

    --
    Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    1. Re:Why no radio kill switch? by Anonymous Coward · · Score: 1

      There certainly should be for doing things like driving through blasting zones (where you should turn off all transceivers) .

    2. Re:Why no radio kill switch? by Anonymous Coward · · Score: 0

      There is! Its called "wire clippers", find the wires that run to the cars phone antenna and clip as close to the circuit-board as you can. Unless you're parked right under a tower it should effectively render your cars external communications inoperable. On some of the earlier OnStar models you could shut down the whole system by pulling a simple fuse, I think you can still do so on newer OnStar systems but it is more involved and may effect some of your factory installed entertainment systems.

    3. Re:Why no radio kill switch? by kheldan · · Score: 1

      Sure, that'll work.. and you'll probably void your car's warranty in the process, and very possibly damage the transceiver(s) using that antenna, if/when they try to transmit and and blow the final amplifier transistor(s) out because there's no antenna. Having a hardwired switch that kills power to the transceiver(s) would be a more elegant and practical solution.

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    4. Re:Why no radio kill switch? by FranTaylor · · Score: 0

      Laptops have had hardware power switches for their transceivers for a long time now,

      you think that switch turns off the radio, but really that switch puts it in the mode that enables secret remote access

      go ahead, prove me wrong

    5. Re:Why no radio kill switch? by BlueStrat · · Score: 2

      Sure, that'll work.. and you'll probably void your car's warranty in the process, and very possibly damage the transceiver(s) using that antenna, if/when they try to transmit and and blow the final amplifier transistor(s) out because there's no antenna. Having a hardwired switch that kills power to the transceiver(s) would be a more elegant and practical solution.

      Unless, as is common with automotive electronics, the circuit board containing the transceiver(s) is potted in epoxy and nearly impossible to physically access in such a way as to successfully perform these modifications without destroying it.

      When US car makers think about their car's electronic security, their focus is on preventing the owners from being able to repair or alter it themselves.

      Strat

      --
      Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
    6. Re:Why no radio kill switch? by Anonymous Coward · · Score: 0

      No doubt it is not a preferable situation, but I think you're significantly overestimating the power sent to the antenna and doubt that you'll blow anything by simply clipping the line. That said however you're right, there SHOULD be built in options to hardware disconnect to the wireless communications systems. But I fear that is going to be a long wait, as the article mentions manufacturers are far more keen on slapping ever more vulnerable systems into the cars instead of hardening the ones they already have.

    7. Re:Why no radio kill switch? by kheldan · · Score: 2

      I used to have CB radios back in the day, and got part of my start in electronics with building amateur radio gear, too. Disconnecting the antenna on a transmitter will reflect power right back into it, and if it's a semiconductor final amp, it'll overheat and blow out in short order. Transmit power really isn't all that relevant. Besides which without knowing for sure how a transmitter will handle it, why take the risk? The 'repair' might be $1000 for the replacement of an entire module that, for one reason or another, isn't repairable. Also, again: Voiding the warranty on your vehicle. At the very least you'd want to disconnect the antenna from the transceiver and substitute a dummy load (preferably a well-shielded one in this case) so nothing gets damaged, but wireless communication still gets disabled.

      --
      Are YOU using the TOOL, or is the TOOL using YOU? Think about it!
    8. Re:Why no radio kill switch? by Web_Teat · · Score: 1

      There is a kill switch. If you watch the video you'll see that the Charlie and Chris told the driver that he could turn off the car and turn it back on in order to reset everything.

      A simple radio kill switch will stop any future instructions from coming in but it won't do anything to get rid of any persistent effects that the hackers have set. How are you then going to turn down the radio? How are you going to tell the brakes to stop bleeding? How will legitimate remote technicians help you to regain control of your cars systems? Turning the car off and then on completely reboots the system to load from firmware. The only way persistent effects will last through that is if manufacturers haven't guarded against remote firmware changes.

      It's mildly dangerous but it's far better than rolling the dice by just turning off the radio. Having a way for people to recover from an ongoing attack is necessary but, OEMs need to do a better job of isolating critical systems from this kind of attack to begin with.

      --
      Per intercessionem Sancti Blasii liberet te Deus a malo gutteris et a quovis alio malo.
  57. Michael Hastings by Anonymous Coward · · Score: 0

    This is how the FBI/CIA killed Michael Hastings

  58. Re:Valasek and Miller are assholes and should be a by pixelpusher220 · · Score: 1

    The video states that there was nothing done to the vehicle prior to the test. It's an internet connected computer, it has a specific address. Whether that's done via hacking the Uconnect servers that then relay commands to the car or by connecting directly to the car is really besides the point.

    Obviously the former is much easier to close, but since the 'fix' is a USB delivered patch me thinks they are directly connecting to the vehicle.

    --
    People in cars cause accidents....accidents in cars cause people :-D
  59. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    StikyPad made a good point. Doing the test on public roads did nothing to reinforce the actual issue.

    As far as I know this whole may just be a montage to get a few more views but it does make them look irresponsible.

  60. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Do you want autonomous cars or driverless cars? Do you want it cheap? What they are probably doing is trying to build in all the capabilities they can do now to see how well it works. Heck, they probably want to put the control/compute in the cloud somewhere where it can be cheap instead of onboard the car.

  61. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    So, given the steering and brakes were NOT messed with, what part do you find so wildly dangerous?

  62. Why? by tompaulco · · Score: 2

    Why does a car have a wireless system, and why is this wireless system accessible from outside the car?

    --
    If you are not allowed to question your government then the government has answered your question.
    1. Re:Why? by jc42 · · Score: 1

      Why does a car have a wireless system, and why is this wireless system accessible from outside the car?

      So that the manufacturer can access the car, collect data on where and how it's been driven, and sell that information to anyone willing to pay for it.

      The idea of sending "data" to the car was an afterthought, when they realized it could be useful for things like disabling a car that's behind on the payments.

      Note that both of these motives contain the string "pay". That's the hint you need to figure out the other intended uses. ;-)

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
  63. Re:Valasek and Miller are assholes and should be a by gtall · · Score: 1

    "You know, doing it in a real world setting and demonstrating it is a hell of a lot better than continuing to believe the lie these companies have done an adequate job at security."

    No, it isn't, and that's a false choice. It is analogous to shooting a gun in crowded room, observing no one was hit, and then claiming it is a good way to show the police are not doing an adequate job of security. You'd better hope they don't pull this stunt again and cause the car's driver to lose control and wipe out half of your family so the other half can grieve.

  64. Re:Valasek and Miller are assholes and should be a by jenningsthecat · · Score: 4, Insightful

    Why is it so hard to get a car without it being fucking connected to everything?

    Never mind that, why is it so hard to find fucking automotive engineers who have enough sense to keep the critical control buses and the frivolous entertainment/external communication buses separate and not connected to each other?

    I don't know whether this is the result of bean counters doing the shit they do, or the hubris of engineers who think, "they won't hack MY system!", but whatever, auto makers need to give their heads a shake and get their shit together. The fact that the exploit outlined in the article is even possible, at all, is just criminal.

    --
    'The Economy' is a giant Ponzi scheme whose most pitiable suckers are the youngest among us and the yet-unborn.
  65. Re:Valasek and Miller are assholes and should be a by tlhIngan · · Score: 1

    I'd still rather have them do THIS when the systems aren't too popular than have some random swatter roll a minivan with 5 kids because he mistyped the IP address of the guy who just beat his speedrun. (Where "THIS" is a controlled test.)

    And what if the random swatter T-boned you in your car?

    Sorry, public roads are not for "testing". There's a reason why car ads all say "Professional drivers on a closed road" - because you can seriously injure someone else.

    Hell, these security researchers not only put themselves at risk, their entire occupation, DEFCON and anyone else a decent lawyer can say was the cause of it (including GM).

    Is it a problem? Yes, a serious one.
    But you don't have to put the general public at risk to demonstrate it.

    You can demonstrate the problem just fine in a closed controlled environment, like say a parking lot. In fact, it may even be more impressive, without scaring the crap out of the driver OR the drivers around him.

    In fact, you can even demonstrate it without a driver - override the brakes so you keep the car stopped, have the driver get out, then drive around. A nice, safe, controlled manner that turns it from "security researchers who put everyone's lives at risk" to "security researchers demonstrate they can take over any GM vehicle...".

    How you tell the story is just as much as important as what you tell. Do it the wrong way and the how can easily overpower the what.

    They're just lucky nothing bad happened, because the message would be quite a bit different if someone got in an accident, and DEFCON would go from "security researchers meeting" to "hackers like Anonymous set to destroy the world" in the mind of the public.

  66. Re:Valasek and Miller are assholes and should be a by Bengie · · Score: 1

    If car manufacturers didn't care about security, they couldn't have installed locks or require keys to drive. Yes, lets just assume everyone in the world is trustworthy.

  67. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Why is it so hard to get a car without it being fucking connected to everything? I just want performance, and nice looks...I drive a car, I'm not trying to do a spreadsheet while driving for God's sake

    A-frigging-men! I'm looking into a Hellcat. Now I just might look for a '70 and put the Hellcat drive train in that.

  68. Re:Valasek and Miller are assholes and should be a by StikyPad · · Score: 2

    First, the nuclear option is a real-world test with unknowing participants -- the other drivers on the road -- which they did. A parking lot would have worked just as well.

    Second, they disabled the transmission. Aside from the fact that acceleration is sometimes necessary to avoid accidents, any significant slowdown below normal speeds on a freeway increases the risk of a collision. Keep in mind that he had music blaring full blast and windshield wipers and fluid obscuring his view at the same time, and no exit strategy since he was on a bridge with no shoulder. That was incredibly irresponsible to put him in that situation.

  69. Re:Valasek and Miller are assholes and should be a by Anonymous+Brave+Guy · · Score: 4, Insightful

    You know, doing it in a real world setting and demonstrating it is a hell of a lot better than continuing to believe the lie these companies have done an adequate job at security.

    Not if it goes wrong and completely innocent third parties pay the price, it's not.

    I am struggling to believe that any rational and normally adjusted person would not see the deep ethical problems with the way this experiment seems to have been conducted, yet there are apparently multiple people in this thread defending it.

    Auto technology is certainly an area that needs a lot more attention and probably heavyweight regulation and laws with real teeth to prevent profits taking priority over safety and privacy. But this isn't the way you do it. In fact, this is the way you get the grown-ups to treat you with contempt and want nothing to do with your research, lest they become contaminated by your methods themselves.

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  70. Re:Valasek and Miller are assholes and should be a by Coren22 · · Score: 1

    The vehicle was put into neutral. How is this any different than the loss of control of....running out of gas? Had this happen to me a couple weeks ago. I managed to merge from the left lane to an exit and eventually on the shoulder without rolling any vans.

    If you are unable to deal with an issue such as this happening, you really shouldn't be a driver as this is a common enough occurrence that they teach you how to deal with it in drivers ed along with what do do when your gas pedal is stuck or breaks fail.

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  71. Re:Valasek and Miller are assholes and should be a by Mr+D+from+63 · · Score: 1

    OK, that helps. Thanks. I just brought it up because it gets overlooked often in these types of articles.

    I guess I'll have to watch the vid, but cant' at work...., will be interesting to see how they knew the address of that particular car......did they find that specific car via owner account/name after hacking Uconnect?

  72. Public IP address by ornil · · Score: 1

    I am not a security expert, but does it strike you as insane that a car apparently has a public IP address? Anyone whatsoever can just portscan your car and look for vulnerabilities. I just have no words.

    1. Re:Public IP address by FranTaylor · · Score: 1

      it is equally shocking that corporations like amazon.com have public IP addresses, anyone whatsoever can portscan them and look for vulnerabilities.

    2. Re:Public IP address by Anonymous Coward · · Score: 0

      How many people die when a vulnerability is found in Amazon?

    3. Re:Public IP address by Anonymous Coward · · Score: 0

      I'm relatively sure Amazon did some risk/reward calculations before they got a public IP address. I'll bet those calculations have not been done for cars.

    4. Re:Public IP address by Anonymous Coward · · Score: 0

      It's not really a public IP address. It's whatever IP address it gets from Cellphone provider. Could be public (IPv6 yay!) or it could not be.
      That's why attacker has to be connected to same network for this to work. That way they could still connect to car even when assigned private IP addresses.

    5. Re:Public IP address by Anonymous Coward · · Score: 0

      Amazon is providing a service to the general public, which necessitates that its systems be publicly-accessible over the internet. My car is not, and does not.

    6. Re:Public IP address by Anonymous Coward · · Score: 0

      it is even more equally shocking that you think that corporations like amazon.com which do have public IP addresses, and anyone whatsoever can just portscan them and look for vulnerabilities, are the same as cars.

    7. Re:Public IP address by cbiltcliffe · · Score: 1

      Amazon.com provides public services over the Internet by design. It would be pointless for them not to, as the whole point of the company existing is to do so.
      A car's purpose is to move its occupants from point A to point B. It has zero need to provide any public Internet services, so why the hell does it need to be publicly accessible over the Internet?

      --
      "City hall" in German is "Rathaus" Kinda explains a few things......
    8. Re:Public IP address by Igloodude · · Score: 1

      Since the researchers had to run the hack explicitly from a Sprint phone, it sounds like it isn't a public IP address, but a private one behind Sprint's internet access point, and Sprint has left peer-to-peer enabled on that private pool of IPs. The cellular access is to provide a wifi hotspot in the car, and I agree with what everyone has said here about not having critical car systems networked with entertainment systems (didn't we just have that discussion about a Boeing aircraft recently?). Why did Sprint leave that Uconnect pool of IPs able to talk to each other when they could disable peer-to-peer in that pool with trivial effort? I'm guessing it's because the Uconnect server's private IP is within that pool, and the architects didn't want to go to the trouble of setting up a VPN or some other mechanism of allowing an IP outside the pool to initiate traffic with the cars' client Uconnect systems. But, that would mean that either the Uconnect server(s) either are talking to all the cars via their own Sprint cellular connection (seems unlikely) or they have plugged the servers directly into the pool, which opens up the mystery again. Bleh, I'd really like to see the exact network architecture here.

      --
      We now return you to your regularly scheduled thread.
  73. Re:Valasek and Miller are assholes and should be a by Anonymous+Brave+Guy · · Score: 1

    Why? Just because you said so?

    No, because people are obviously going to die.

    Since when it is a manufacturers responsibility to protect against criminal actions involving his product?

    Since the manufacturer was making a machine capable of causing serious injury or death and was well aware of the potential risks. At that point, as with any other legal concept of a duty of care, playing the innocent third party doesn't always cut it. I have no problem with passing regulations or laws to reflect that, because otherwise people are obviously going to die.

    Even if the manufacturers get to keep their ability to wash their hands of it legally speaking, they should be required to advertise honestly and with full disclosure. Anyone buying one of these vehicles has to sign to say they've read a clear statement that the manufacturer is aware that anyone may take control of the vehicle from the driver and cause it to behave in unpredictable ways up to and including fatal accidents, the manufacturer has decided not to take any measures to prevent this from happening, and the driver uses the vehicle at their own risk and accepts full legal responsibility for any harm done with it whether or not it was under their control at the time as long as they are still alive to sue. That seems fair, but I don't imagine it would help sales.

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  74. Re:Valasek and Miller are assholes and should be a by Coren22 · · Score: 3, Insightful

    From the nature of the exploits being described:

    They put this system on the CAN-BUS, which is used to control engine and control systems. There is NO REASON for an entertainment system to be on this bus. On-Star has the same issues. If you want these devices to have functionality that is on the CAN-BUS, it should be duplicated outside the CAN-BUS. Security researchers have been trying to explain this to the car industry for 10 years (at least) now, and the car industry keeps being willfully ignorant of the security implications of what they are doing. This is far past defect, it is more like intentionally dangerous and possibly malicious.

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  75. Re:Valasek and Miller are assholes and should be a by cayenne8 · · Score: 1

    Do you want autonomous cars or driverless cars?

    Nope. I do not.

    At least not for me. Hmm...I was looking at the Vipers that do seem to have the Uconnect as standard package.

    I'm wondering if you can disable this without killing functionality in the car?

    Same question about onStar for a Corvette...can you kill it without killing the car, or, are these systems so integrated now that you can turn them off?

    I wonder if you can at least kill the method it uses to "call home" at the very least..?

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  76. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Exactly, the ECU, TCU, stability control computer (which is able to brake individual wheels to stop a skid) and the steering controller (for automatic parking or active lane control) should be on an entirely separate bus from the entertainment and convenience controllers.

    I don't think the article is terribly vague on how they did it. They were able to rewrite the firmware in the head unit over Uconnects cellular connection to allow them to send CAN bus commands to the entire in-car network, which is connected to everything.

  77. Re:Valasek and Miller are assholes and should be a by pixelpusher220 · · Score: 3, Informative

    this link has some more technical details linky

    --
    People in cars cause accidents....accidents in cars cause people :-D
  78. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    I think the thing is that the mechanism that Chrysler has to update Uconnect firmware for end users is USB and they didn't have a routine setup from the factory to allow OTA updates of the firmware. Valasek and Miller have apparently figured out how to do this once they know the IP address of the target cellular modem in the vehicle. They mention that currently, they're only able to do this on the Sprint network with a Sprint phone connected to a laptop, since Uconnect is using Sprint's network.

    FTA - "Uconnect computers are linked to the Internet by Sprint’s cellular network, and only other Sprint devices can talk to them. So Miller has a cheap Kyocera Android phone connected to his battered MacBook. He’s using the burner phone as a Wi-Fi hot spot, scouring for targets using its thin 3G bandwidth.

    A set of GPS coordinates, along with a vehicle identification number, make, model, and IP address, appears on the laptop screen. It’s a Dodge Ram. Miller plugs its GPS coordinates into Google Maps to reveal that it’s cruising down a highway in Texarkana, Texas. He keeps scanning, and the next vehicle to appear on his screen is a Jeep Cherokee driving around a highway cloverleaf between San Diego and Anaheim, California. Then he locates a Dodge Durango, moving along a rural road somewhere in the Upper Peninsula of Michigan. When I ask him to keep scanning, he hesitates. Seeing the actual, mapped locations of these unwitting strangers’ vehicles—and knowing that each one is vulnerable to their remote attack—unsettles him.

    When Miller and Valasek first found the Uconnect flaw, they thought it might only enable attacks over a direct Wi-Fi link, confining its range to a few dozen yards. When they discovered the Uconnect’s cellular vulnerability earlier this summer, they still thought it might work only on vehicles on the same cell tower as their scanning phone, restricting the range of the attack to a few dozen miles. But they quickly found even that wasn’t the limit. “When I saw we could do it anywhere, over the Internet, I freaked out,” Valasek says. “I was frightened. It was like, holy fuck, that’s a vehicle on a highway in the middle of the country. Car hacking got real, right then.”"

  79. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    It is - when these types of exploits first started to be reported almost a decade ago, they did require physical access to the car (like, the laptop running the exploit had to be in the car), and that part was conveniently omitted from all of the mainstream media articles about it. I had to dig up the actual journal paper about it to find that detail.

  80. Re:Nobody Pays attention. apk by Anonymous Coward · · Score: 0

    It's safe to network the computers BUT you must install your own protection. DNS poisoning attacks can cause reckless traffic.

    apk HOSTS editor for Android enables it to maintain name resolutions in memory with no DNS. Reducing network traffic and LESS TRAFFIC means safer roads.

    P.S.=> HOSTS might crash your OS but not your car...

  81. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    Did you watch the video?
    Within the first 2 minutes I can see the following two things I consider dangerous:
    - They reduced his visibility by activating the wipers and windshield washer
    - They cut off the engine while he's on a busy highway

    Here's a sample of what happens when you stop on the highway:
    http://www.citynews.ca/2007/12...

    Just recently there was an emergency vehicle with lights on that was hit while on the shoulder.

  82. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    Like I said, cars stall on the highway all the time. Then they are freewheeling AND they lose power steering and brakes. People use the windshield washer all the time while in motion.

    For real fun, try having your heater core burst at night while at speed. Still manageable.

  83. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    That's not entirely true. I drive a honda civic and I have insurance. Civic is one of the most stolen cars on the road. Great gas mileage though. Seats could be more comfortable.

  84. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    People voluntarily wash their windshield while driving all the time. They also drive in the rain, even heavy rain.

    People's cars stall on the highway all the time. At no point was he in the situation your link talks about. Even if he had been on the shoulder, that too happens all the time and rarely leads to a problem.

  85. IoT may be a good idea for some things by Anonymous Coward · · Score: 0

    but not my bloody car or airplane!

    Chrysler seems focused on converting their customers into money streams.
    This may seem neat and cool, but they seem to be loosing sight of the old fashioned fundamental of making useful products to make happy customers.

    They are probably not the only ones.
    I'd bet the wrong call to a Tesla could bring more spectacular results.

    Having an actual, physical isolation switch seems fundamental.
    It may have to be used sometimes for updates, but leaving it enabled seems begging for trouble.

  86. Re:Valasek and Miller are assholes and should be a by FranTaylor · · Score: 1

    Or, I don't know, how about not hooking up the car's controls to any network at all? Why is that even a thing?

    The brake lights work better when they are connected to the network of wires that connects the front end of the car to the back end of the car.

  87. Re:Valasek and Miller are assholes and should be a by FranTaylor · · Score: 1

    There is NO REASON for an entertainment system to be on this bus.

    My car has precisely one display on the dashboard, used to display all information, from radio frequency to fluid levels to outside temperature. I like having all of this information on one display. The only way to accomplish this is to have the entertainment system connected to the car's bus.

  88. Re:Valasek and Miller are assholes and should be a by Fire_Wraith · · Score: 1

    I'm going to strongly speculate that it's about cost. Why? Because almost everything in business is about cost. Why duplicate things when you can reuse? Why put the wires and routing for two or three networks into a vehicle when you can put in one and run all the devices over them?

    And you'll see it elsewhere too. Those people with an IP routed, internet connected home security system - do you think that's on a separate network from their computer, their internet connected TV, etc? It probably isn't, either. I don't know that I'd call it hubris, so much as underestimating the lengths that some people can and will go to in order to attack the network and the devices on it.

    And more importantly, not only do the designers have to accurately estimate the level of protections necessary for the network, but they also have to be able to sell that to the management, who approves the additional cost.

  89. Re:Valasek and Miller are assholes and should be a by davester666 · · Score: 1

    My understanding is that the best you can do is to find and cut off the antennae that OnStar uses.

    --
    Sleep your way to a whiter smile...date a dentist!
  90. Re:Valasek and Miller are assholes and should be a by Fire_Wraith · · Score: 1

    What do you consider "actual security" then?

    Because there's almost nothing under the sun that will keep out the most determined attacker by itself. Even gigantic safes, vault doors, etc, have a rating based on the number of man hours it's expected to take to breach them. The idea is that you want one that's long enough for the Police/SWAT/QRF to have arrived before the bad guys can breach it.

    The locks on your car doors, alarms, etc are meant to deter and delay the casual intruder, and also to an extent, to establish evidence of a break-in later.

  91. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    But it doesn't have to be two-way.

  92. Re:Valasek and Miller are assholes and should be a by jenningsthecat · · Score: 2

    Thanks - those are all good points. Except the 'underestimating the lengths' part. We have more than a decade's worth of news stories about people who have gone to great lengths to hack hardware and software - sometimes because they want additional features, sometimes out of malice, and sometimes just to prove a point. I figure by this time there's no excuse for underestimating what people will do. I think you hit the nail on the head when you suggested cost as the reason.

    --
    'The Economy' is a giant Ponzi scheme whose most pitiable suckers are the youngest among us and the yet-unborn.
  93. Re:Valasek and Miller are assholes and should be a by Coren22 · · Score: 1

    None of those items are required to be on the CAN-bus. However, if they are CAN-bus sensors, there is no requirement for them to be on the same bus that controls the engine/steering/transmission/brakes/accelerator.

    https://en.wikipedia.org/wiki/...

    This is an operational communications bus used for the engine to comunicate to the computer. There are already several buses in a car, so it isn't like this hasn't been done before. There are also one way communications firewalls like the AC above me suggested could be used to partition the communications from a receive only device.

    Do you use your entertainment system to control the cruise control or something?

    --
    APK likes to ask for responses to the same things over and over. Maybe he just likes the responses?
  94. Re:Valasek and Miller are assholes and should be a by cayenne8 · · Score: 1

    A-frigging-men! I'm looking into a Hellcat. Now I just might look for a '70 and put the Hellcat drive train in that.

    Yeah, I just found out about the Hellcats yesterday and have looked into them today. I like the Hellcat Challenger, not so much the Charger, looks too much like a regular family car.

    But wow...707 HP bone stock....in the $63K price range that is *BANG* for the buck for sure....

    I am trying to calculate how many tires per gallon it gets.

    :D

    Unfortunately, it comes with this unsecure system too and would have to be disabled....

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  95. Depends... by davidwr · · Score: 1

    ... on whether the FM radio receiver can be used - even indirectly - to send control instructions to the engine or other "car" parts of the car.

    One hypothetical example of where this might be an issue is if the car's braking or accelerator systems were voice-activated. If this is the case and there isn't a sure-fire mechanism to prevent the radio's sound from being interpreted as commands from the driver, then, well, the implications are obvious and left as an exercise to the reader.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  96. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Absolutely. Cars should also be designed to be car-jack proof. It's irresponsible to design a car that anyone can walk up to and threaten you to let them take it.

  97. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    You misspelled "Excellent"

  98. Re:Valasek and Miller are assholes and should be a by KGIII · · Score: 1

    How many people DID get hurt by this? I am willing to accept some risk so long as it is minimized. In this case? Yeah, it was a bit risky but nothing untoward happened. All is good in the end and nobody got hurt. I tend to not freak out until after someone gets hurt.

    --
    "So long and thanks for all the fish."
  99. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Something being a frequent occurrence does in no way make it any less dangerous. Your argumentation is ignorant and stupid at best, but looks more disingenuous which is worse. Someone with a four digit account should know better, did you buy it on ebay?

  100. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    Don't worry, when you grow up you'll understand the nuances of what I wrote and it will all become clear to you.

  101. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    Sir, I hope you some day start producing stuff with that attitude. You'll very soon find you'll spend the rest of your life living either in prison or a cardboard box.

  102. Re:Valasek and Miller are assholes and should be a by gl4ss · · Score: 1

    to be fair, the "10 miles away" is arbitrary.

    "anyone who knows the carâ(TM)s IP address gain access from anywhere in the country. âoeFrom an attackerâ(TM)s perspective, itâ(TM)s a super nice vulnerability,â Miller says."

    though, I have to ask, why the car has a public facing IP in the first place? sounds like waste of ip. I assume it's provided cellular provider, which would make most of them sit behind.

    still pretty shitty design though.

    --
    world was created 5 seconds before this post as it is.
  103. Re:Valasek and Miller are assholes and should be a by pixelpusher220 · · Score: 1

    The fact that the decade old exploits needed physical access is irrelevant to this exploit which the article/video clearly states and shows is NOT necessary.

    the video even explains that the first time these guys did this to his car (years ago) they did need physical access - they were in the car with him while they did the hack. They use that point to explicitly note that this time they were miles away.

    --
    People in cars cause accidents....accidents in cars cause people :-D
  104. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 2

    People voluntarily wash their windshield while driving all the time. They also drive in the rain, even heavy rain.

    And they know its going to happen because they either initiate the action or anticipate it. In this case he didn't know it was going to happen.

    People's cars stall on the highway all the time. At no point was he in the situation your link talks about. Even if he had been on the shoulder, that too happens all the time and rarely leads to a problem.

    Would you say it's dangerous to have your car stall on the highway? The answer is yes.
    So why would you intentionally put yourself or someone else in that position of danger?

    Usually people like putting the odds of survival on their side. Test environments are there so we don't have to create unneeded danger.

  105. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    Would you say it's dangerous to have your car stall on the highway? The answer is yes.

    Quit trying to stuff words in my mouth. The answer is "not really".

    So why would you intentionally put yourself or someone else in that position of danger?

    Ask the author of TFA, he wasn't a random victim, he knew what they could do and that they would do it during his drive. He freely chose to drive the car for a demo. That includes washing the windshield and putting the transmission in neutral.

  106. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    Quit trying to stuff words in my mouth. The answer is "not really".

    So 1.8% of interstate accidents in Kentucky involved a stalled vehicle.
    http://uknowledge.uky.edu/ktc_...

    The link is old but it makes the point.

    If you don't live close to a busy highway I can understand why you don't understand the danger of stalling on the road while cars are passing you at 75 MPH

    Ask the author of TFA, he wasn't a random victim

    Who said random? The blame is on all of them. There's a reason testing is done on isolated tracks.

  107. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    So, 1.8% of an unlikely thing involves stalled cars on the side of the road. But he wasn't on the side of the road.

    As someone who drives on the interstate, I frequently see cars on the side long enough to be tagged for impound with no evidence of being hit. I have never seen a car that was hit on the side of the road though I have heard of it.

    There are dumb things you can do on the side of the road that can lead to fatalities like changing a tire with your butt sticking out into traffic, but that wasn't an issue here.

    The police routinely pull people over to the side of the interstate.

  108. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    So, 1.8% of an unlikely thing involves stalled cars

    You didn't read the link did you? 1.8% of highway accidents are stalled vehicle which more often result in fatality. Where I travel there's an average 5 accidents per day. That would mean every 11 days there's an accident involving a stalled car. If you told me it's inconvenient to address the As someone who drives on the interstate, I frequently see cars on the side long enough to be tagged for impound with no evidence of being hit.

    Maybe you travel a stretch that is less dangerous. City stretches tend to be more chaotic and law usually forces vehicles to accept the first tow.

    The police routinely pull people over to the side of the interstate

    Yes, and they follow a protocol to stay safe. They need to do this because highways are dangerous places to stop.

    Even marked vehicles are in danger. 4-5 years ago 3 police officers with vehicles parked 2 feet from the line (on the shoulder) with their lights on got hit. This stretch of highway wasn't even chaotic and you could see for miles ahead.

    More links to show you highway stopping dangers aren't a myth:
    http://www.allenandallen.com/b...
    https://www.aaafoundation.org/...

  109. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    If you told me it's inconvenient to address the As someone who drives on the interstate, I frequently see cars on the side long enough to be tagged for impound with no evidence of being hit.

    I don't even know what that was supposed to mean. Wanna try again?

  110. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 0

    good for them. I support them 100%

  111. Re:Valasek and Miller are assholes and should be a by ZeroWaiteState · · Score: 1

    The system is needed so that law enforcement can remotely shut down the engine if the car is stolen. In other words, as Comey would say, "a front door with really big locks." However, law enforcement has a difficult time working with really big locks, so we make the big locks smaller, more like child-safety locks, so that officers are not inconvenienced and can't accuse the vendor of obstruction.

  112. Re:Valasek and Miller are assholes and should be a by Anonymous Coward · · Score: 1

    The funny thing is that the connected car stuff is planned to be used for the security-critical stuff in the cars, for example, exchange of situational awareness between cars to support assistance systems and the self-driving cars of the future that everyone is working towards.

    If anything, cars are going to become even more hackable. This is definitely going to produce a new kind of murder weapon in the long run: a laptop with a high-gain RF radio in a safe distance and without any traces at the scene of the cime itself.

  113. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    If you told me it's inconvenient to address the issue for a situation that occurs less than 1% of the time I'd agree but because there is no additional cost or inconvenience to do it on a closed circuit it's a no brainer. What they did (all of them) was add unneeded risk to an exercise that didn't gain anything by being done in a "non test" environment. That's the point the previous guy was trying to make and it was very valid.

  114. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    Less than 1% is an understatement. You haven't even shown that it's more likely than a moose related fatality or a deer attack. (look up man killed by moose and see how many hits you get despite the extreme unlikelihood of the event).

    Even when you do see a fatality related to a stalled car, it's a car that wouldn't re-start and where someone got out of the car.

    I will point out that if we're down to the range of inconvenience being enough to justify a risk, we're already far away from the screeching about being extremely irresponsible that started this thread. It's very likely the author accepted a larger risk of an accident in the process of going to see Valasek and Miller than he did during the test.

  115. Re:Valasek and Miller are assholes and should be a by eric_harris_76 · · Score: 1

    Yep. Had the journalist been more skeptical and generally prudent, he would have insisted they do their wireless exploit from the back seat. (Oh, and not on the Interstate.)

    Or at least, have one of them ride along, while the other did his thing remotely. And hope they were good friends.

    Otherwise, you've got yourself a bizarre double-homicide that the forensics team on "CSI: Dogtown" (or "CSI: Creve Coeur" or ...) might not even recognize as a homicide. It would just be a vehicular murder-suicide to them.

    --
    There's no time like the present. Well, the past used to be.
  116. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    You haven't even shown that it's more likely than a moose related fatality or a deer attack

    The moose incident is not avoidable without major inconvenience. That was the point.

    My brother in law who is a trucker has 2 on his record (1 000 000km driven). It's about where you live and when you travel. Up north moose / deer incidents are in weekly news during the summer. Drive at night and you increase your chances of hitting a moose by more than 10 fold. That's very comparable to the test they did. Don't do it and you don't increase chances of an accident and do it and it's an infinite % increase in change of accident.

    It's very likely the author accepted a larger risk of an accident in the process of going to see Valasek and Miller than he did during the test

    That's pretty obvious but it's not the case for the other people on the highway.

    The point is simple. Don't do testing in an uncontrolled environment. It's easily avoided with no impact on the test itself.

    Unneeded risk is just that, unneeded. There are a millions things you do daily to avoid even smaller % of danger and yet you roll your eyes at a completely avoidable scenario.

    If you can admit to facts and common sense there's not much more to say here.

  117. Re:Valasek and Miller are assholes and should be a by sjames · · Score: 1

    Your brother in law was killed by hitting a moose TWICE? Resilient fellow, isn't he? :-)

    We all take 'unnecessary' risks daily. Is the food network horribly irresponsible for encouraging me to use a sharp knife? After all, if I just buy the frozen dinners I need not expose myself to the minuscule risk of a fatal injury. Some of those psychos even suggest a blender! I could order the frozen dinners online to avoid the risk of driving to the grocery store.

  118. Re:Valasek and Miller are assholes and should be a by Ravaldy · · Score: 1

    Your brother in law was killed by hitting a moose TWICE? Resilient fellow, isn't he? :-)

    Wow... I don't need to say anymore. At least I know who I'm dealing with.