1 2 3
JoeyM
JoeyM Mod Squad
7/21/15 7:14 a.m.

Wired is reporting that Jeep Cherokees are vulnerable to the following

Their code is an automaker’s nightmare: software that lets hackers send commands through the Jeep’s entertainment system to its dashboard functions, steering, brakes, and transmission, all from a laptop that may be across the country.

http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/?mbid=social_twitter

I'm sorry if this was already discussed.....I did look, and didn't see a prior thread

classicJackets
classicJackets New Reader
7/21/15 7:27 a.m.

Spooky stuff. Sure, they've spent a lot of time on it, but if a large group of people tried, i bet they could find the problems in significantly less time. I'll take my old car with no computer and no internet connection, but I'll sure as heck be watching all the new Jeep Cherokees drive by with a cautious eye (haha).

JoeyM
JoeyM Mod Squad
7/21/15 7:42 a.m.

The jeep is a proof of concept. If a vehicle has an internet connection, drive by wire, and the onboard computers communicate via CAN, it's possible that it could be vulnerable

So the next year, they signed up for mechanic’s accounts on the websites of every major automaker and downloaded dozens of vehicles’ technical manuals and wiring diagrams. Using those specs, they rated 24 cars, SUVs, and trucks on three factors they thought might determine their vulnerability to hackers: How many and what types of radios connected the vehicle’s systems to the Internet; whether the Internet-connected computers were properly isolated from critical driving systems, and whether those critical systems had “cyberphysical” components—whether digital commands could trigger physical actions like turning the wheel or activating brakes.
Based on that study, they rated Jeep Cherokee the most hackable model. Cadillac’s Escalade and Infiniti’s Q50 didn’t fare much better; Miller and Valasek ranked them second- and third-most vulnerable.

[ .... ]

But the opportunities for real-world car hacking have only grown, as automakers add wireless connections to vehicles’ internal networks. Uconnect is just one of a dozen telematics systems, including GM Onstar, Lexus Enform, Toyota Safety Connect, Hyundai Bluelink, and Infiniti Connection.
N Sperlo
N Sperlo MegaDork
7/21/15 7:47 a.m.

This goes a bit further than the report released a year or so ago. They needed to plug a computer in, but could, in the end, completely control the vehicle's electronic interfaces via computer.

JoeyM
JoeyM Mod Squad
7/21/15 7:56 a.m.

Yup, same people.....they can now do it over the sprint wireless network....all they need is the jeep's IP address. they now remotely upload firmware into one of the computers on the CAN bus, allowing the entertainment system to communicate with other computers

N Sperlo
N Sperlo MegaDork
7/21/15 8:13 a.m.

I knew it was coming. I called it. Now if only they didn't delete all my podcasts.

foxtrapper
foxtrapper UltimaDork
7/21/15 8:38 a.m.

It also frustrates me no end how the automotive/aironautical/marine/etc manufacturers keep their heads in the sand regarding this problem. "Nope, it just can't happen."

N Sperlo
N Sperlo MegaDork
7/21/15 8:43 a.m.

That reminds me. What ever happened to that deal where the guy claimed to have hacked the airplane and control the engine speed. They said it wasn't possible and the story just disappeared.

Grtechguy
Grtechguy UltimaDork
7/21/15 8:44 a.m.

Yep..I'm an IT guy and the last thing I want is a glitchy computer connected to the internet controlling my engine, transmission and brakes.

GameboyRMH
GameboyRMH GRM+ Memberand MegaDork
7/21/15 9:13 a.m.
N Sperlo wrote: That reminds me. What ever happened to that deal where the guy claimed to have hacked the airplane and control the engine speed. They said it wasn't possible and the story just disappeared.

The feds sat him down for a nice chat last time I heard...

It isn't rocket science to keep these things secure, but I guess it might as well be to the big auto manufacturers. These are Idiocracy-level mistakes being made to allow this to happen.

alfadriver
alfadriver UltimaDork
7/21/15 9:25 a.m.

In reply to GameboyRMH:

Lots and lots of opportunities here in Detroit. Come and work.

Giant Purple Snorklewacker
Giant Purple Snorklewacker MegaDork
7/21/15 9:32 a.m.

In reply to alfadriver:

That really isn't a bad idea at all except the Detroit part.

alfadriver
alfadriver UltimaDork
7/21/15 9:44 a.m.

In reply to Giant Purple Snorklewacker:

For this specific example, FCA's HQ is up in Pontiac. 20 min north of that is the middle of nowhere.

Detroit is for the hipsters, anymore.

Still, for all of the complaining and experts out there, come help. Put money in your bank accounts instead of just typing about it.

JoeyM
JoeyM Mod Squad
7/21/15 10:26 a.m.
alfadriver wrote: In reply to Giant Purple Snorklewacker: For this specific example, FCA's HQ is up in Pontiac. 20 min north of that is the middle of nowhere. Detroit is for the hipsters, anymore. Still, for all of the complaining and experts out there, come help. Put money in your bank accounts instead of just typing about it.

It would be easy enough to hire those two to keep doing what they're doing....

HiTempguy
HiTempguy UberDork
7/21/15 10:42 a.m.
GameboyRMH wrote: It isn't rocket science to keep these things secure, but I guess it might as well be to the big auto manufacturers. These are Idiocracy-level mistakes being made to allow this to happen.

Yea, but rather than use an industrial protocol that has been in use for decades, auto-manufacturers decided CANBUS was the way to go. Built in monopoly!

Wally
Wally GRM+ Memberand MegaDork
7/21/15 10:43 a.m.

When we were getting our last round of buses delivered their was a guy running around with a laptop updating software so the would start every morning. He was explaining how many computers were on board and what they controlled. I asked him how long he thought it would be before someone came up with an app that someone could use that would keep the doors open until they got on. I looked excited like maybe there could be another update they could sell us.

madmallard
madmallard Dork
7/21/15 11:24 a.m.

how in the world is a drive by wire system allowed to have 2 way communication with something outside its critical function?

Thats appallingly stupid design.

Curmudgeon
Curmudgeon MegaDork
7/21/15 11:49 a.m.

And people wonder why I abhor the idea of self driving cars...

JoeyM
JoeyM Mod Squad
7/21/15 11:54 a.m.
Curmudgeon wrote: And people wonder why I abhor the idea of self driving cars...

Yup, there's talk of having cars in front "tell" cars behind that they're braking instead of depending on proximity sensors to figure that our. If that is implemented, we'll soon have people working on ways to spoof a signal and activate the braking system.

Keith Tanner
Keith Tanner GRM+ Memberand MegaDork
7/21/15 11:56 a.m.
madmallard wrote: how in the world is a drive by wire system allowed to have 2 way communication with something outside its critical function? Thats appallingly stupid design.

Seems to me an air gap would be reasonable. One system for the powertrain/chassis, one to entertain the meat. Does the throttle really need to know what DVD is playing?

N Sperlo
N Sperlo MegaDork
7/21/15 11:56 a.m.
JoeyM wrote:
Curmudgeon wrote: And people wonder why I abhor the idea of self driving cars...
Yup, there's talk of having cars in front "tell" cars behind that they're braking instead of depending on proximity sensors to figure that our. If that is implemented, we'll soon have people working on ways to spoof a signal and activate the braking system.

This thread is giving me flashbacks. If I only remembered everything I talked about that day. I had this E36 M3 down to the science. It got kinda creepy.

DrBoost
DrBoost UltimaDork
7/21/15 11:59 a.m.

I dunno, cables and linkages worked well enough, and can't be hacked.

Gary
Gary Dork
7/21/15 12:08 p.m.

It's a creepy scenario, and makes one wonder about the possibilities.

I think we might have discussed this a couple years ago:

http://m.nydailynews.com/news/national/conspiracy-theories-abound-michael-hastings-death-article-1.1377392

There were theorists discussing the possibility then. It appears that it's even easier to do now.

oldtin
oldtin UberDork
7/21/15 12:32 p.m.
Keith Tanner wrote:
madmallard wrote: how in the world is a drive by wire system allowed to have 2 way communication with something outside its critical function? Thats appallingly stupid design.
Seems to me an air gap would be reasonable. One system for the powertrain/chassis, one to entertain the meat. Does the throttle really need to know what DVD is playing?

Isn't that sort of the, at least in my mind, the major design flaw of the whole CAN bus architecture - that a malfunctioning radio can give you a non start condition. Everything is interlinked. Good for Bosch on the patent front but not so good for everyone else.

alfadriver
alfadriver UltimaDork
7/21/15 12:36 p.m.

In reply to oldtin:

Bosch supplies most of the industry. Especially the electronic throttles. If they have it, most everyone has it.

1 2 3

You'll need to log in to post.

Our Preferred Partners
e8MuRsqkVQYmxvFnfH6UovSApcUcGwLARNqbRihjBzO8DqDJFVm2DXq9OQGgSqaS