I was somewhat surprised to learn about the possibility of taking complete control of a Jeep Cherokee using a laptop and a mobile phone. It seems as if the car makers have added software features to their cars without properly understanding how to make them secure. I work with embedded software that merely has to prevent movies from being copied. If the hacking methods described by Wired are accurate, there are some quite obvious precautions we take that the makers of Jeeps appear not to. I am glad not to be working on life or death software; I expect more from people who do.
Nonetheless, this should all be fixed soon.
Carmakers who failed to heed polite warnings in 2011 now face the possibility of a public dump of their vehicles’ security flaws. The result could be product recalls or even civil suits, says UCSD computer science professor Stefan Savage, who worked on the 2011 study. Earlier this month, in fact, Range Rover issued a recall to fix a software security flaw that could be used to unlock vehicles’ doors. “Imagine going up against a class-action lawyer after Anonymous decides it would be fun to brick all the Jeep Cherokees in California,” Savage says.
Free speech and free markets seem to be working, then. Which makes this seem unnecessary:
It’s the latest in a series of revelations from the two hackers that have spooked the automotive industry and even helped to inspire legislation; WIRED has learned that senators Ed Markey and Richard Blumenthal plan to introduce an automotive security bill today to set new digital security standards for cars and trucks, first sparked when Markey took note of Miller and Valasek’s work in 2013.
As an auto-hacking antidote, the bill couldn’t be timelier.
Meh. It sounds to me more like the government has come along after the problem is already being solved to take the credit. I suspect such a bill will end up protecting car makers from civil suits if they merely have to show they have complied with inevitably flawed regulations.




