I'm not really worried about that. Thanks to the recent release of a comprehensive hacker toolkit I'm able to plug into the IoT and block any self driving car attacks with my flying drone squad.
I agree with the danger of networked cars but most other things are already possible now. Leaving a bag with explosives in a train is easy, equipping a drone with explosives and flying it into a parade as well. Manipulating the traffic light system, etc. Self-driving cars may be another possibility in terrorist attacks but most of the things described are not really a problem of self-driving vehicles but rather problems inherent of mass transportation or the internet of things.
> equipping a drone with explosives and flying it into a parade as well
Ever since at least last year I keep waiting for the news to break out: drone + computer vision + navigation system + some kind of weapon (maybe a gun, maybe a poison dart) - all that stuff sent to seek someone out and "deal" with them. Totally doable.
I wonder how they protect the important people (president, VP) from something like that. Modern drones are crazy fast. RC jet planes are insanely fast.
Explosives require someone somewhat near the target. Making a significant proportion of self-driving cars malfunction could be done from anywhere, in theory. Even if it didn't kill many people, it would hurt the economy for a while.
“We have big firewalls, really strict firewalls to make sure no one can operate the airbags and take over the car."
That's not very comforting. We're just getting to the point where it's becoming mainstream for corporate IT to understand that "the firewall" is not some magic line of security demarcation where "evil" stays firmly on "its side".
What benefit could possibly come about by connecting the airbag system (intertial sensor(s), the airbag, and the explosive device) to the v2v or any other electrical system other than power?
Why does there even need to be a firewall. It should be air-gapped in the truest sense.
True, I recall now that cars automatically turn on hazard flashers and some attempt to connect to OnStar and the like. IMO, that should all be a separate inertial sensor...
It reminds me of a situation I ran into w/ a Customer who wanted to monitor manufacturing process parameters from a production line. The line already had PLCs controlling the processes. Their PLC vendor advised them to just attach the PLC network to the rest of the LAN with a "firewall" to restrict access to "approved computers". I argued very strongly for independent PLCs connected only to sensors measuring the process parameters. There was no requirement to make modifications to the control PLCs from less-trusted networks anyway. I didn't win the battle, but I stand by my position and feel much the same way about cars.
>Picture hackers employed by a hostile nation finding a way to command large numbers of cars on U.S. roads. Picture those hackers ordering the vehicles to suddenly accelerate and turn hard to the right, flipping them over, killing many passengers and clogging freeways with junked cars.
Car only needs a computer - not a network. Modern cars already have computers. Picture hackers employed by a yadda yadda remotely disabling power-steering on cars across the nation or disabling ABS and you have the same disaster scenario in an already-existing attack vector.
>Or envision a lone-wolf terrorist loading explosives into a car and programming it to drive to a targeted building or public space.
Already possible. Even Mythbusters sets up "life size" RC cars for some of their crash-related myths.
> Already possible. Even Mythbusters sets up "life size" RC cars for some of their crash-related myths.
It's already possible, but it takes a lot of work, and (AFAIK), you don't end up with a vehicle that can be programmed with destination coordinates tens or hundreds of kilometers away and then left to its own devices.
There's always the possibility of a lone-wolf, obsessed Unabomber-style terrorist who has their own machine shop and whatnot, but that's an edge case. The potential danger here (IMO) is the terrorist who can steal a few autonomous cars from parking lots (or call up a few autonomous taxis), load them up with cellphone-detonated explosives, and be all set. That scenario doesn't require anything really technically-challenging, and IMO is very likely to occur.
The random "crash a bunch of cars on the freeway" scenario is not as likely, IMO, because the number of people who are interested in killing tens or hundreds of random people is lower than the number who are interested in killing a few very specific people, or destroying a very specific building/piece of infrastructure.
I don't think this is a reason to disallow autonomous vehicles, but I don't have a good answer for how to address it, either.
> What of the lone-wolf terrorist, placing explosives in a programmable car? At a National Highway Transportation Safety Administration hearing in April, one speaker urged the government to require sensors inside autonomous cars to sniff out hazardous materials and disable the cars if necessary.
How does that make sense? They are talking about "hackers" seizing millions of cars remotely in one paragraph, on the next we have perfect technology that can sniff dangerous chemicals and disable a car. But wait, aren't those people supposed to be hackers? Why can't they disable the sensors then?
Also, what's preventing them from retrofitting a car to be remote controlled, if they are so skilled? Newer cars are almost "fly-by-wire" anyway already.
<sarcasm>But no one could ever cover or electronically bypass a sensor</sarcasm>
Also, if we could do that might as well also have it call the police with the exact GPS location and drive the perp to a remote bomb disposal location.
Committing acts of terror is REALLY EASY already. Because most people are basically decent, and intelligence agencies are largely capable of preventing most threats at the current rate; we don't see a huge number of problems.
But if you have more people ready to accept the guilt tripping and ideological shame it takes to make a radical, I'm guessing those capabilities will dry up. We really ought to be focusing on the intent rather than the means, because the means is obviously already common.
Sensationalist, Alarmist Journalistic masturbation.
First of all there are plenty of volunteers to wear vests and self sacrifice, so the point is nearly moot.
This complete LOSER of a journalist has created Fear, Uncertainty and Doubt, riding on ignorance of both his editor and his readers.
Great fodder for a return of John McClaine though. Somebody call my agent!
31 comments
[ 2.8 ms ] story [ 66.3 ms ] thread&
https://www.amazon.com/Freedom-TM-Daniel-Suarez/dp/045123189...
fun reads.
Alternatives are cheaper, already available and you can't stop someone who really does want to spread terror.
Ever since at least last year I keep waiting for the news to break out: drone + computer vision + navigation system + some kind of weapon (maybe a gun, maybe a poison dart) - all that stuff sent to seek someone out and "deal" with them. Totally doable.
Just a matter of time.
Holy JC on a bicycle, I didn't even think of that.
Yeah, good point. Forgot about those.
Coat the explosive material with a (hemi)sphere of ball bearings, and you have a flying claymore mine.
The Finnish military has a nickname for large claymore mines: Refugee TV. I can't imagine what they would call a swarm of drone variants.
That's not very comforting. We're just getting to the point where it's becoming mainstream for corporate IT to understand that "the firewall" is not some magic line of security demarcation where "evil" stays firmly on "its side".
"Firewalls are like seat belts, not magic force fields."
Seems like an apt analogy for this one.
Why does there even need to be a firewall. It should be air-gapped in the truest sense.
Not defending this behavior, but that's a reason..
Car only needs a computer - not a network. Modern cars already have computers. Picture hackers employed by a yadda yadda remotely disabling power-steering on cars across the nation or disabling ABS and you have the same disaster scenario in an already-existing attack vector.
>Or envision a lone-wolf terrorist loading explosives into a car and programming it to drive to a targeted building or public space.
Already possible. Even Mythbusters sets up "life size" RC cars for some of their crash-related myths.
I really hate puff scare pieces.
It's already possible, but it takes a lot of work, and (AFAIK), you don't end up with a vehicle that can be programmed with destination coordinates tens or hundreds of kilometers away and then left to its own devices.
There's always the possibility of a lone-wolf, obsessed Unabomber-style terrorist who has their own machine shop and whatnot, but that's an edge case. The potential danger here (IMO) is the terrorist who can steal a few autonomous cars from parking lots (or call up a few autonomous taxis), load them up with cellphone-detonated explosives, and be all set. That scenario doesn't require anything really technically-challenging, and IMO is very likely to occur.
The random "crash a bunch of cars on the freeway" scenario is not as likely, IMO, because the number of people who are interested in killing tens or hundreds of random people is lower than the number who are interested in killing a few very specific people, or destroying a very specific building/piece of infrastructure.
I don't think this is a reason to disallow autonomous vehicles, but I don't have a good answer for how to address it, either.
How does that make sense? They are talking about "hackers" seizing millions of cars remotely in one paragraph, on the next we have perfect technology that can sniff dangerous chemicals and disable a car. But wait, aren't those people supposed to be hackers? Why can't they disable the sensors then?
Also, what's preventing them from retrofitting a car to be remote controlled, if they are so skilled? Newer cars are almost "fly-by-wire" anyway already.
Also, if we could do that might as well also have it call the police with the exact GPS location and drive the perp to a remote bomb disposal location.
But if you have more people ready to accept the guilt tripping and ideological shame it takes to make a radical, I'm guessing those capabilities will dry up. We really ought to be focusing on the intent rather than the means, because the means is obviously already common.
This complete LOSER of a journalist has created Fear, Uncertainty and Doubt, riding on ignorance of both his editor and his readers.
Great fodder for a return of John McClaine though. Somebody call my agent!
(Also "Demon Seed")