Researcher Hacks Self-Driving Car Sensors
An anonymous reader writes: Jonathan Petit, security researcher at Security Innovation, has created an electronics kit that costs only $60, which can flood LiDAR sensors on self-driving cars with a laser beam that contains fake data, making them think they have objects in front of them. This forces the self-driving car to slow down and sometimes abruptly stop. Affected cars include all manufacturers that deploy LiDAR sensors. As of now, Google and Apple are affected. According to this article, so may be Toyota's upcoming car.
Throwing a puppy in front of the car will also achieve the same result.
Nearly all of them (from sonar, radar, lidar...) all are susceptible to various interference techniques.
The only ones that exist that I'm sure are NOT directly affected are used by whales, dolphins, bats... They can be overpowered causing problems... but at the operational strength none seem affected even though they are using the same frequencies.
Even normal drivers are affected by having lights shined into their eyes... (which happens to be why it is illegal to aim laser pointers at aircraft or cars).
Great. I now know that a company called ‘security innovations’ is basically a front for a bunch of marketing and PR muppets who will sell you some snake oil attached to whatever is the latest media feeding frenzy using fear and misinformation.
I could go down to my local motorway junction with a pocket full of laser pointers right now and cause a whole lot of human-driven cars to have to slow down and enter a safety mode. I'm pretty sure I would get arrested for doing this, and I doubt the outcome for someone doing this to driverless cars will be any different. No doubt it will be drones with lasers next week.
Shine with a laser pointer or strong flash light into the windshield of driving cars.
You can buy a simple point laser for less, for hacking the visual systems of the human driverâ"hopefully making the driver stop, but maybe at times not.
But the attack itself seems interesting, though it seems it is possible to fix the issue with new hardware. Good research!
[citation needed]
At this point, Apple's auto project is still officially rumor and the idea of it being self-driving, and using LIDAR technology, has not been confirmed either.
You are using the wrong laser!
Hopefully not with puppies! But you can just imagine kids pissing about pushing stuff in front of self driving cars and watching them do an emergency stop then just standing in front so it won't move and giving the occupants the finger. And to anyone who says they won't - kids already play chicken with human driven cars.
News flash, if you aim a laser at an airplane, you can crash it.
News flash, if you aim a laser at an automobile driver, you can crash it.
News flash, if you aim a magnetron at a cold meal, you can heat it! brah! did you know that?
Hack your ass, use toilet paper to conceal the fact you just went to the bathroom.
So LiDAR sends out a laser beam, then looks at reflections. It makes sense this can be flooded - just pick up the signal and send it back amplified, and it seems there's something really close. I assume at least they're looking for brightness rather than timing (distance travelled is very short and light is very fast) to determine the distance of an object.
This makes me wonder. Would it be possible for cars to pick up signals from other cars, and react to them?
Anything to prevent this from happening - and so also prevent such a disturbance attack from working?
These are no reason to stop for this confused signal, while a puppy is a real reason. The two situations are thus not comparable.
To be clear why, what if the signal is not of malicious intent? What if its a laser from another self driving car? What if its a laser used for other purposes? Like 3D mapping, lights shows or games?
So they have to encode their signals so they can tell their signals from others signals.
It's possible to stop trains with even cheaper kits, and this hasn't been a major problem.
This sounds less dangerous than throwing a rock off a bridge.
So he floods the sensors with bad data, and the car stops safely...what is the issue here exactly?
Guy wastes his time developing a high tech way of making the car stop, when much simpler and cheaper ways are available?
So shining a laser in someone's eyes is now "carrying out a denial of service attack"?
This seems less like "hacking self-driving car sensors" and more like what we technically call "being a dick."
For those of you not worried about this...You've not been spending enough time in your evil mastermind lair.
10 years time, with convoys of self driving cars taking up lanes of motorways and highways, how can you be the one to get that all important one car length ahead?
You've spent all that money on an expensive brand car, with the lux pack, drivers pack, safety pack, metallic paint, de-badged, surely you're more entitled to be in front than the guy in the basic no-name drone car?
Now you CAN! With the new 'LIDAR-TRAP-ATRON' Simply place this solar powered, self contained LIDAR trap at the side of the road. By sending out a constant stream of false LIDAR echos all the self-driving cars will be forced to slow down or stop. You in your prestige drivers car, fully under your control can sail past those sheeple in the their drone boxes. The open road can be yours!
It's a tech-specific site, could we at least use tech-specific jargon correctly?
Hacking implies breaking into or somehow achieving a level of control. He didn't do that at all, he merely confused the sensors with a false-positive return, something long-since know in the elint world as "spoofing".
This researcher "hacked" nothing, he "spoofed" them.
-Styopa
http://i.imgur.com/Fb6MHw5.jpg
In other news, screaming into someone's ear when they're not expecting it might just make them jump.
We're headed towards the age of "push-button pile-ups". (There, I coined a new phrase. Now go viral).
Ordinary engineering and typical engineers assume a friendly environment, i.e. the absence of intentional sabotage and hacking. This state of affairs is not true with globally networked infrastructure and sensors operating outside of protected spaces. What these people lack is what Bruce Schneier calls "the security mind-set". It involves not only thinking about how things can be made to work, but also how they can be intentionally broken and subverted. Having it is critical. That most people designing software and software-driven systems these days do not have it the main reason why IT security is in such an abysmally bad state these days.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
You can also distract airplane and helicopter pilots by shining lasers on their cockpits, but that's very much illegal. It would probably be easy to detect afterwards from built-in telemetry data if someone disrupted the sensors with something. If the worst happens, the person responsible for interfering with the sensors might be, depending on the level of intentionality, charged with manslaughter or murder.
You can jam GPS, radars and just about every other sensor relying on external input, but people don't do this because it carries heavy penalties.
They forced a self driving car to stop, wow. Is it any harder to blind a human driver causing him to hit the breaks?
Use a search light or lasers, or a pretty woman flashing her breasts.
This is hardly a "hack" and definitely not a weakness of self driving cars compared to the human variant.
Just put tinfoil over your sensors. Problem solved.
You can buy those to flood the front of your car to screw with police LIDAR so they cant get a reading on you or they only read 0. Except mine has a 1 mile range.
for $60, is he doing it from 1 mile down the road? I bet his only works from a hundred feet away.
Do not look at laser with remaining good eye.
It would be trivial and cheap to halt these cars - a box, a trash bag, or a bit of carpet would probably do the trick for $0. A fact which I'm sure criminals would soon figure out, assuming such vehicles ever see the light of day.
Any vehicle with an OnStar system provides the means to remotely disable it.
A puppy is a real reason to stop, or swerve, only if you can do so safely. That means nobody following too close behind and nobody in lanes to either side of you (or oncoming).
You do always keep enough situational awareness to know this, right?
Otherwise it's the puppy's tough luck. Cute doesn't beat over 88,000 foot-pounds per second of momentum (2000 lb car moving 30mph (44 fps). Whether that's your car or the car behind/beside you is up to you.
First of all this isn't "hacking"
If I shine a spotlight or laser in your face while you are driving am I hacking into you? If I rip the security cameras off your house, am I hacking into your house? Or even better, if I spray paint your windshield, am I hacking into your car?
For only a few dollars I can pick up a laser pointer (or rip a laser diode out of the many products they are in) and point it at a "real" driver. This will not only make them slow down or abruptly stop but also cause accidents due to their spontaneous reactions and possibly blind the driver. So I don't see why this matters. Especially since I would assume that these navigation systems have certain backups like cameras, RADAR and ultrasonic sensors. No one in their right mid would buy (or even sell) a self driving car that doesn't have systems that work in multiple scenarios. This is just a simple test case of a small problem that needs to be fixed. It is not hacking and it is not a security issue.
Now if they were able to communicate with an on-board computer via the LIDAR system, that would be cool.
I can imagine if for some reason you are under attack and need to get away fast.
Then one of the assailant just step in front of the vehicle, the vehicle stops, and you're dead or captured.
What a marvelous system.
Manual car sensors can also be hacked! Shining bright lights at the windshield, especially in nighttime driving conditions, incapacitates the optical sensor of a manually-driven car. Worse, unlike self-driving cars, manual cars behave erratically or unpredictably in these conditions. Even worse, all cars are equipped with hardware that can generate these bright lights, meaning that any car can attack any other manual car in vision range.
Cars are doomed!
Comment removed based on user account deletion
Its the standard business versus technology model: Rush to market THEN consider the security and privacy implications.
Not sure how affected Google is going to be given Ray already knows about this,
http://www.kurzweilai.net/new-...
http://www.nature.com/articles...
Throw a basketball at LiDAR -based car, or even a "traditional" human-operated one, and they both will see an object coming at them at a high rate of speed. If I write an article about it, will Slashdot post that, too?
* Fire a sufficiently high-powered laser back at the interfering source.
* Document the incident (photo/video and LiDar measurements) and alert the cops automatically. Messing with infrastructure is a criminal act, right?