Car Chat General discussion about Lexus, other auto manufacturers and automotive news.

Hackers Remotely Kill a Jeep on the Highway

Thread Tools
 
Search this Thread
 
Old 07-23-15, 10:11 AM
  #16  
4TehNguyen
Lexus Fanatic
iTrader: (1)
 
4TehNguyen's Avatar
 
Join Date: Jan 2006
Location: Houston, Texas
Posts: 26,033
Received 51 Likes on 46 Posts
Default

why the heck would any company tie in the vehicle controls into the infotainment, those should physically be kept seperate
4TehNguyen is offline  
Old 07-23-15, 07:14 PM
  #17  
bitkahuna
Lexus Fanatic
iTrader: (20)
 
bitkahuna's Avatar
 
Join Date: Feb 2001
Location: Present
Posts: 73,770
Received 2,127 Likes on 1,379 Posts
Default

Originally Posted by 4TehNguyen
why the heck would any company tie in the vehicle controls into the infotainment, those should physically be kept seperate
because from the phone app you can start/stop the car, lock/unlock, so the cell connection has to reach into the main drive train and security controls.

fwiw, when i tried the app to lock or start the car (don't remember which) it was pathetic - took about 5 minutes between pressing the app and the action occurring. go sprint 3G network.
bitkahuna is offline  
Old 07-23-15, 07:43 PM
  #18  
mmarshall
Lexus Fanatic
 
mmarshall's Avatar
 
Join Date: Oct 2003
Location: Virginia/D.C. suburbs
Posts: 90,585
Received 83 Likes on 82 Posts
Default

Originally Posted by bitkahuna
fwiw, when i tried the app to lock or start the car (don't remember which) it was pathetic - took about 5 minutes between pressing the app and the action occurring. go sprint 3G network.
Just a pure guess on my part (not necessarily fact), but I wonder if, when remote-starting the engine, at least part of that 5 minutes is security-related...to make sure that it is actually YOU that wants to make the remote start, and not some potential car thief or carjacker just waiting for a chance to jump into it and drive off.
mmarshall is offline  
Old 07-23-15, 08:21 PM
  #19  
n00g7
Driver School Candidate
 
n00g7's Avatar
 
Join Date: May 2015
Location: Lone Star State
Posts: 24
Likes: 0
Received 0 Likes on 0 Posts
Default

Wait... Where do I find the UConnect on my XJ Cherokee?
n00g7 is offline  
Old 07-24-15, 11:37 AM
  #20  
bitkahuna
Lexus Fanatic
iTrader: (20)
 
bitkahuna's Avatar
 
Join Date: Feb 2001
Location: Present
Posts: 73,770
Received 2,127 Likes on 1,379 Posts
Default

Originally Posted by mmarshall
Just a pure guess on my part (not necessarily fact), but I wonder if, when remote-starting the engine, at least part of that 5 minutes is security-related...to make sure that it is actually YOU that wants to make the remote start, and not some potential car thief or carjacker just waiting for a chance to jump into it and drive off.
why would 5 minutes make it safer and what do you think is going on during that 5 minutes?
bitkahuna is offline  
Old 07-24-15, 11:38 AM
  #21  
bitkahuna
Lexus Fanatic
iTrader: (20)
 
bitkahuna's Avatar
 
Join Date: Feb 2001
Location: Present
Posts: 73,770
Received 2,127 Likes on 1,379 Posts
Default

Originally Posted by n00g7
Wait... Where do I find the UConnect on my XJ Cherokee?
https://www.driveuconnect.com/software-update/
bitkahuna is offline  
Old 07-24-15, 12:46 PM
  #22  
n00g7
Driver School Candidate
 
n00g7's Avatar
 
Join Date: May 2015
Location: Lone Star State
Posts: 24
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by bitkahuna
It was a joke. Mine's a '98, a REAL CHEROKEE.
n00g7 is offline  
Old 08-11-15, 01:19 PM
  #23  
geko29
Super Moderator

 
geko29's Avatar
 
Join Date: Feb 2007
Location: IL
Posts: 7,479
Received 211 Likes on 161 Posts
Default

Right on the heels of the record $105 Million consent order levied against FCA for failing to recall vehicles with safety defects, comes the revelation that they were notified of the Uconnect vulnerability in January 2014, a full 18 months before the story broke that actually triggered the recall.

Originally Posted by Bloomberg Business
The company’s description of events leading up to the July recall says it knew in January 2014 that radio communications ports had been left open unintentionally, allowing them to “listen to and accept commands from unauthenticated sources.” It doesn’t mention the possibility that such access might lead to a hacker taking control of steering, braking or other functions that could cause a car to crash.

Fiat Chrysler said in a statement it advised NHTSA of the security issue “in a reasonable and timely manner.” The company said it’s “conducting a remedial campaign as a safety recall in the interest of protecting its customers” out of “an abundance of caution.”

The company said it contacted NHTSA after the hackers informed Fiat Chrysler of their plan to publicize the security flaw at Black Hat, including information to facilitate unauthorized and unlawful access to the automaker’s vehicles.
Originally Posted by Bloomberg Business
Documents Fiat Chrysler filed with NHTSA note that it didn’t consider the software issue, identified by a third party in January 2014, to be a safety defect under U.S. law. Under the Motor Vehicle Safety Act, which governs how and when recalls are conducted, automakers must notify NHTSA within five days of discovering a flaw that presents an unreasonable risk to public safety.
And naturally, this means that a Class action lawsuit is in the works.

Think they'll learn their lesson this time? Me either.
geko29 is offline  
Old 08-11-15, 07:40 PM
  #24  
bitkahuna
Lexus Fanatic
iTrader: (20)
 
bitkahuna's Avatar
 
Join Date: Feb 2001
Location: Present
Posts: 73,770
Received 2,127 Likes on 1,379 Posts
Default

corporations don't take security seriously.
bitkahuna is offline  
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Butchie
ES - 5th Gen (2007-2012)
3
12-22-11 03:59 PM
mikesblkgs
GS - 2nd Gen (1998-2005)
7
03-07-09 12:37 AM
pmonag
RX - 1st Gen (1999-2003)
1
10-26-04 02:24 PM
Redwood
ES - 1st to 4th Gen (1990-2006)
2
05-24-03 09:57 PM



Quick Reply: Hackers Remotely Kill a Jeep on the Highway



All times are GMT -7. The time now is 09:11 AM.