vinman
International Playboy
     
Posts: 3,310
Joined: Dec 2010
Reputation: 65
|
Hackers Remotely Kill a Jeep on the Highway—With Me in It
This is something that we should all keep a watchful eye on. A writer volunteered to have a vehicle he was driving exploited by hackers. It's kind of long, but I'll post the link, and highlight some relevant parts.
Quote:I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.
Though I hadn’t touched the dashboard, the vents in the Jeep Cherokee started blasting cold air at the maximum setting, chilling the sweat on my back through the in-seat climate control system. Next the radio switched to the local hip hop station and began blaring Skee-lo at full volume. I spun the control knob left and hit the power button, to no avail. Then the windshield wipers turned on, and wiper fluid blurred the glass.
Just imagine what could happen if you weren't expecting this, and the hacker had eyes on you in traffic.
Quote: Their code is an automaker’s nightmare: software that lets hackers send commands through the Jeep’s entertainment system to its dashboard functions, steering, brakes, and transmission, all from a laptop that may be across the country.
Wasn't Michael Hastings, the writer killed in a single vehicle collision?
Quote:As the two hackers remotely toyed with the air-conditioning, radio, and windshield wipers, I mentally congratulated myself on my courage under pressure. That’s when they cut the transmission.
Immediately my accelerator stopped working. As I frantically pressed the pedal and watched the RPMs climb, the Jeep lost half its speed, then slowed to a crawl. This occurred just as I reached a long overpass, with no shoulder to offer an escape. The experiment had ceased to be fun.
At that point, the interstate began to slope upward, so the Jeep lost more momentum and barely crept forward. Cars lined up behind my bumper before passing me, honking. I could see an 18-wheeler approaching in my rearview mirror. I hoped its driver saw me, too, and could tell I was paralyzed on the highway.
Miller and Valasek’s full arsenal includes functions that at lower speeds fully kill the engine, abruptly engage the brakes, or disable them altogether. The most disturbing maneuver came when they cut the Jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch. The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the Jeep is in reverse. Their hack enables surveillance too: They can track a targeted Jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.
Miller attempts to rescue the Jeep after its brakes were remotely disabled, sending it into a ditch. Click to Open Overlay Gallery
Miller attempts to rescue the Jeep after its brakes were remotely disabled, sending it into a ditch. Andy Greenberg/WIRED
The two researchers say that even if their code makes it easier for malicious hackers to attack unpatched Jeeps, the release is nonetheless warranted because it allows their work to be proven through peer review. It also sends a message: Automakers need to be held accountable for their vehicles’ digital security. “If consumers don’t realize this is an issue, they should, and they should start complaining to carmakers,” Miller says. “This might be the kind of software bug most likely to kill someone.”
There's more to the article that you can read for yourselves. But just imagine a pissed off ex getting with someone that can do this stuff.
http://www.wired.com/2015/07/hackers-rem...p-highway/
"Feminism is a trade union for ugly women"- Peregrine
(This post was last modified: 07-28-2015 08:51 AM by vinman.)
|
|
| 07-28-2015 08:44 AM |
|
The following 10 users Like vinman's post:10 users Like vinman's post
Deepdiver, Handsome Creepy Eel, captain_shane, h3ltrsk3ltr, Troll King, Atlanta Man, Fast Eddie, FlyBoy, NovaVirtu, Snowplow
|
Deepdiver
True Player
    
Posts: 2,335
Joined: Mar 2013
Reputation: 79
|
RE: Hackers Remotely Kill a Jeep on the Highway—With Me in It
(07-28-2015 08:44 AM)vinman Wrote: This is something that we should all keep a watchful eye on. A writer volunteered to have a vehicle he was driving exploited by hackers. It's kind of long, but I'll post the link, and highlight some relevant parts.
Quote:I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.
Though I hadn’t touched the dashboard, the vents in the Jeep Cherokee started blasting cold air at the maximum setting, chilling the sweat on my back through the in-seat climate control system. Next the radio switched to the local hip hop station and began blaring Skee-lo at full volume. I spun the control knob left and hit the power button, to no avail. Then the windshield wipers turned on, and wiper fluid blurred the glass.
Just imagine what could happen if you weren't expecting this, and the hacker had eyes on you in traffic.
Quote: Their code is an automaker’s nightmare: software that lets hackers send commands through the Jeep’s entertainment system to its dashboard functions, steering, brakes, and transmission, all from a laptop that may be across the country.
Wasn't Michael Hastings, the writer killed in a single vehicle collision? 
Quote:As the two hackers remotely toyed with the air-conditioning, radio, and windshield wipers, I mentally congratulated myself on my courage under pressure. That’s when they cut the transmission.
Immediately my accelerator stopped working. As I frantically pressed the pedal and watched the RPMs climb, the Jeep lost half its speed, then slowed to a crawl. This occurred just as I reached a long overpass, with no shoulder to offer an escape. The experiment had ceased to be fun.
At that point, the interstate began to slope upward, so the Jeep lost more momentum and barely crept forward. Cars lined up behind my bumper before passing me, honking. I could see an 18-wheeler approaching in my rearview mirror. I hoped its driver saw me, too, and could tell I was paralyzed on the highway.
Miller and Valasek’s full arsenal includes functions that at lower speeds fully kill the engine, abruptly engage the brakes, or disable them altogether. The most disturbing maneuver came when they cut the Jeep’s brakes, leaving me frantically pumping the pedal as the 2-ton SUV slid uncontrollably into a ditch. The researchers say they’re working on perfecting their steering control—for now they can only hijack the wheel when the Jeep is in reverse. Their hack enables surveillance too: They can track a targeted Jeep’s GPS coordinates, measure its speed, and even drop pins on a map to trace its route.
Miller attempts to rescue the Jeep after its brakes were remotely disabled, sending it into a ditch. Click to Open Overlay Gallery
Miller attempts to rescue the Jeep after its brakes were remotely disabled, sending it into a ditch. Andy Greenberg/WIRED
The two researchers say that even if their code makes it easier for malicious hackers to attack unpatched Jeeps, the release is nonetheless warranted because it allows their work to be proven through peer review. It also sends a message: Automakers need to be held accountable for their vehicles’ digital security. “If consumers don’t realize this is an issue, they should, and they should start complaining to carmakers,” Miller says. “This might be the kind of software bug most likely to kill someone.”
There's more to the article that you can read for yourselves. But just imagine a pissed off ex getting with someone that can do this stuff.
http://www.wired.com/2015/07/hackers-rem...p-highway/
[quote] I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.
The fact that they began their hack experiment at high speed on a public highway showed severe lack of good judgement as they put other motorists at risk even to the point of slowing to a crawl on a highway with a Tractor Trailer rig behind the driver then running into a ditch. Dumb really Dumb - but - important to test and make facts public - would have been better to test at a huge parking lot etc on a no traffic day and not at 70mph... I will not be buying any FCA products too soon however i am sure Ford and GM as well as Toyota etc., scrambling to test their vehicles as well.
|
|
| 07-28-2015 09:02 AM |
|
The following 6 users Like Deepdiver's post:6 users Like Deepdiver's post
JoyStick, vinman, eradicator, Suits, Troll King, FlyBoy
|
heavy
True Player
    
Posts: 1,979
Joined: Sep 2013
Reputation: 31
|
RE: Hackers Remotely Kill a Jeep on the Highway—With Me in It
I'm thinking I might go back to my 1992 Mercury Grand Marquis. Rear wheel drive is fun in the snow, with the added benefit of not being able to be hacked into.
|
|
| 07-28-2015 09:05 AM |
|
The following 11 users Like heavy's post:11 users Like heavy's post
JoyStick, vinman, Kingsley Davis, eradicator, scotian, h3ltrsk3ltr, teh_skeeze, Akula, MiscBrah, Fast Eddie, Snowplow
|
Handsome Creepy Eel
Innovative Casanova
      
Posts: 9,575
Joined: Apr 2011
Reputation: 149
|
|
| 07-28-2015 10:23 AM |
|
The following 22 users Like Handsome Creepy Eel's post:22 users Like Handsome Creepy Eel's post
Menace, vinman, Pontifex Maximus, Xntrik, Kingsley Davis, Vacancier Permanent, Jukes, Mentavious, WalterBlack, eradicator, DJ-Matt, Gmac, Huey, Seth_Rose, Atlanta Man, Excelsior, Akula, kruger41, MiscBrah, Fast Eddie, Onto, coverdoc
|
el mechanico
Innovative Casanova
      
Posts: 11,003
Joined: Mar 2011
Reputation: 152
|
RE: Hackers Remotely Kill a Jeep on the Highway—With Me in It
(07-28-2015 10:33 AM)The Beast1 Wrote: American car makers are among the dumbest of dumb. Seriously allowing an entertainment console full duplex with the ECM (engine control module) is retarded. Once the vehicle leaves the factory the ECM should only report engine stats to the entertainment console.
I have no desire to ever own an American car. I have nothing but disdain for most cartainment consoles, especially since most of them lock out features while driving.
And on that note, car computers ECM/Entertainemnt or otherwise are the worst thing to ever hit an automobile.
What you're trying to refer to is this..
https://en.wikipedia.org/wiki/CAN_bus
The computers talk to eachother. A regular ECM in like a 1995 civic can't be shut off but hackers.
Quote: American car makers are among the dumbest of dumb.
They all have it. Euro car electrics are the worst Japanese being the best.
(This post was last modified: 07-28-2015 12:37 PM by el mechanico.)
|
|
| 07-28-2015 12:35 PM |
|
The following 9 users Like el mechanico's post:9 users Like el mechanico's post
The Beast1, Kingsley Davis, vinman, Hotwheels, kaotic, scotian, tarquin, DJ-Matt, SupaDorkLooza
|
AneroidOcean
True Player
    
Posts: 2,711
Joined: Feb 2013
Reputation: 50
|
RE: Hackers Remotely Kill a Jeep on the Highway—With Me in It
(07-28-2015 10:15 AM)Menace Wrote: The article makes it seem like this is a general problem in any modern car. However, this totally wireless remote exploit appears to be limited to the 2013, 2014, and 2015 Jeep Cherokee. The article states that if you know the IP address of the Jeep, you can execute this remote exploit. On the great scale of things, this is pretty low on my list of things to worry about.
Are you reading the same article? Please point out where it states that. Relevant quotes (bold emphasis is mine):
Quote:All of this is possible only because Chrysler, like practically all carmakers, is doing its best to turn the modern automobile into a smartphone. Uconnect, an Internet-connected computer feature in hundreds of thousands of Fiat Chrysler cars, SUVs, and trucks, controls the vehicle’s entertainment and navigation, enables phone calls, and even offers a Wi-Fi hot spot. And thanks to one vulnerable element, which Miller and Valasek won’t identify until their Black Hat talk, Uconnect’s cellular connection also lets anyone who knows the car’s IP address gain access from anywhere in the country. “From an attacker’s perspective, it’s a super nice vulnerability,” Miller says.
Quote:Miller and Valasek say the attack on the entertainment system seems to work on any Chrysler vehicle with Uconnect from late 2013, all of 2014, and early 2015. They’ve only tested their full set of physical hacks, including ones targeting transmission and braking systems, on a Jeep Cherokee, though they believe that most of their attacks could be tweaked to work on any Chrysler vehicle with the vulnerable Uconnect head unit. They have yet to try remotely hacking into other makes and models of cars.
The fact that even the most basic of strong security measures hasn't been taken by automakers to this point is indicative of how many huge vulnerabilities like this are bound to exist.
Read My Old Blog - Subscribe To My Old Blog
Top Posts - Fake Rape? - Sex With A Tranny? - Rich MILF - What is a 9?
"Failure is just practice for success"
|
|
| 07-28-2015 01:50 PM |
|
The following 2 users Like AneroidOcean's post:2 users Like AneroidOcean's post
TheWastelander, eradicator
|
Dr. Howard
International Playboy
     
Posts: 5,729
Joined: Oct 2011
Reputation: 69
|
RE: Hackers Remotely Kill a Jeep on the Highway—With Me in It
(07-28-2015 10:23 AM)Handsome Creepy Eel Wrote: Fortunately, my favorite transport method is immune to hacking:
![[Image: 13763-walking_news.jpg]](http://news.stanford.edu/news/2014/april/images/13763-walking_news.jpg)
Your legs are not immune to hacking, specifically the old fashioned kind.
looking for a new signature.
|
|
| 07-28-2015 06:25 PM |
|
The following 19 users Like Dr. Howard's post:19 users Like Dr. Howard's post
vinman, Nalka, Goldfinger, Paracelsus, h3ltrsk3ltr, redbeard, StrikeBack, Mr. Cameltoe, African.horn, DJ-Matt, Goldin Boy, Excelsior, kruger41, Shrodax, MiscBrah, Onto, SupaDorkLooza, NovaVirtu, Snowplow
|