Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


DeepBlueSky

549 posts

Ultimate Geek
+1 received by user: 67


#177097 22-Jul-2015 12:30
Send private message

Read this from Wired; Its a bit of a worry as we dive further into the connected world the security of any critical system is going to have to be factored at the beginning of development not as an after though, especially devices like cars, medical equipment. Wi-Fi enabled pace makers and insulin pumps have already been hacked now cars and maybe aircraft.

http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3
surfisup1000
5288 posts

Uber Geek
+1 received by user: 2159


  #1349757 22-Jul-2015 12:36
Send private message

My personal opinion is that punishments for hackers need to be exponentially increased. 

The USA has the right idea. 

Make the very idea of hacking so scary it is just not worth going there.

Problem is the russians / chinese / middle eastern countries are only too happy to hack western countries and cause damage. 



macuser
2120 posts

Uber Geek
+1 received by user: 506


  #1349761 22-Jul-2015 12:46
Send private message

I wonder how many foreign rides have been bugged by the CIA in this manner.

#no-tinfoil-hat-necessary



DeepBlueSky

549 posts

Ultimate Geek
+1 received by user: 67


  #1349763 22-Jul-2015 12:53
Send private message

macuser: I wonder how many foreign rides have been bugged by the CIA in this manner.

#no-tinfoil-hat-necessary




It had crossed my mind that certain groups may not be happy that this information has been outed.  Having a car crash, could just be an accident or maybe not ??



Dratsab
3964 posts

Uber Geek
+1 received by user: 1728

Trusted
Lifetime subscriber

  #1349764 22-Jul-2015 12:54
Send private message

surfisup1000: My personal opinion is that punishments for hackers need to be exponentially increased. 

The USA has the right idea. 

Make the very idea of hacking so scary it is just not worth going there.

Problem is the russians / chinese / middle eastern countries are only too happy to hack western countries and cause damage. 

My emphasis added.

The problem is most people who commit crimes do not factor punishment into their thought patterns. The real deterrent is centered around what's called the capable guardian - which, if you have them, brings about the fear of getting caught.

wasabi2k
2102 posts

Uber Geek
+1 received by user: 860


  #1349767 22-Jul-2015 12:58
Send private message

surfisup1000: My personal opinion is that punishments for hackers need to be exponentially increased. 

The USA has the right idea. 

Make the very idea of hacking so scary it is just not worth going there.
 


Nope - I entirely disagree. You will ALWAYS have people willing to do stuff regardless of punishments.

This would effectively be security through scare tactics.

Companies/Governments providing external access to any technology need to take responsibility for their own security and build systems that are secure. They have responsibilities and if they aren't living up to them under self regulation then maybe it is time for a big stick.

Punishments for hacking should be in line with their non computer equivalents - and there needs to be allowances for responsible disclosure.

Edit: After reading that article - HOLY hell. In what universe does it make sense to have driving systems controllable from ANY external system? This is rampant stupidity. This is not the hacker's fault - this is a major screw up from the car vendor!



pdath
253 posts

Ultimate Geek
+1 received by user: 116


  #1349768 22-Jul-2015 13:01
Send private message

This is nothing new.  Still could be worse, you could own a Ford or a Toyota.  There vulnerabilities are bad enough that a hacker could kill you.

http://www.independent.co.uk/life-style/gadgets-and-tech/researchers-hack-cars-to-remotely-control-steering-and-brakes-8733723.html




Try my latest project, a Cisco type 5 enable secret password cracker written in javascript!

 
 
 
 

Shop now on Samsung phones, tablets, TVs and more (affiliate link).
wasabi2k
2102 posts

Uber Geek
+1 received by user: 860


  #1349769 22-Jul-2015 13:02
Send private message

pdath: This is nothing new.  Still could be worse, you could own a Ford or a Toyota.  There vulnerabilities are bad enough that a hacker could kill you.

http://www.independent.co.uk/life-style/gadgets-and-tech/researchers-hack-cars-to-remotely-control-steering-and-brakes-8733723.html


via OBD port IN the car - so significantly less of a risk. Same guy if I read correctly?

JWR

JWR
821 posts

Ultimate Geek
+1 received by user: 272


  #1349776 22-Jul-2015 13:23

surfisup1000: My personal opinion is that punishments for hackers need to be exponentially increased. 

The USA has the right idea. 

Make the very idea of hacking so scary it is just not worth going there.

Problem is the russians / chinese / middle eastern countries are only too happy to hack western countries and cause damage. 


You have given a good reason not to have insane penalties.

If people from foreign countries can hack with immunity, then you need good security.

So, you rely, to an extent, on local hackers uncovering the security holes.

Penalties for hacking should relate to any damage done and we have other laws to cover virtually any situation.

Lias
5655 posts

Uber Geek
+1 received by user: 3978

ID Verified
Trusted
Lifetime subscriber

  #1349786 22-Jul-2015 13:40
Send private message

How about instead of penalising hackers**, not all of whom have nefarious intent, we insist that companies actually develop SECURE products. 
Every single piece of software needs to be written from the ground up with security as a primary goal. Instead most of them are written with security not even considered, or considered as an after thought.
I don't blame hackers for Flash or Java patching every 5 minutes, I blame the people who wrote poorly coded insecure software and then distributed it to billions of devices.

Disclaimer: I've spent quite a few years working in enterprise deployment/application packaging and my experiences have left me wanting to have large numbers of software authors dragged into the town square and flogged or worse.

**Without getting into the entire hacker/cracker debate, I'm using this in the popular sense.








I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup. Opinions are my own and not the views of my employer.


MikeB4
MikeB4
18775 posts

Uber Geek
+1 received by user: 12765

ID Verified
Trusted
Subscriber

  #1349789 22-Jul-2015 13:44
Send private message

Like everything in life if its built it will the victim of crime be it cars, computers, houses, food, animals, trees..........




Here is a crazy notion, lets give peace a chance.


kiwigeek1
637 posts

Ultimate Geek
+1 received by user: 12
Inactive user


  #1349799 22-Jul-2015 13:56
Send private message

this might of happened to that reporter who has a major leak about the wrong doings of USA gov and drones.. some say his car computer was hacked so breaks failed and power steering etc

anything is possible. so do you throw black ops and gov people in jail if they hack your car to silence you :)

http://www.huffingtonpost.com/2013/06/24/michael-hastings-car-hacked_n_3492339.html

 
 
 

Support Geekzone with one-off or recurring donations Donate via PressPatron.
DeepBlueSky

549 posts

Ultimate Geek
+1 received by user: 67


  #1349826 22-Jul-2015 14:39
Send private message

I'm sure some execs will be bewildered by this information, too much emphasis on quick development turn around and sales the boring stuff like security generally takes a back seat to features.  Unfortunately when the lawyers get involved and they will that boring stuff will be the only thing saving some of these execs / company bottom lines from taking a major hit I suspect.

frankv
5705 posts

Uber Geek
+1 received by user: 3666

Lifetime subscriber

  #1349830 22-Jul-2015 14:55
Send private message

wasabi2k:
pdath: This is nothing new.  Still could be worse, you could own a Ford or a Toyota.  There vulnerabilities are bad enough that a hacker could kill you.

http://www.independent.co.uk/life-style/gadgets-and-tech/researchers-hack-cars-to-remotely-control-steering-and-brakes-8733723.html


via OBD port IN the car - so significantly less of a risk. Same guy if I read correctly?


But if you have access to the car, you could add a device to connect the OBD port to the Internet via cellphone.


nakedmolerat
4631 posts

Uber Geek
+1 received by user: 874

Trusted
Lifetime subscriber

  #1349861 22-Jul-2015 15:32
Send private message

frankv:
wasabi2k:
pdath: This is nothing new.  Still could be worse, you could own a Ford or a Toyota.  There vulnerabilities are bad enough that a hacker could kill you.

http://www.independent.co.uk/life-style/gadgets-and-tech/researchers-hack-cars-to-remotely-control-steering-and-brakes-8733723.html


via OBD port IN the car - so significantly less of a risk. Same guy if I read correctly?


But if you have access to the car, you could add a device to connect the OBD port to the Internet via cellphone.



For Ford & Hyundai, if you were to attach anything, it will be super obvious as there is a cap over it (it will need to be left open).



wasabi2k
2102 posts

Uber Geek
+1 received by user: 860


  #1349864 22-Jul-2015 15:39
Send private message

DeepBlueSky: I'm sure some execs will be bewildered by this information, too much emphasis on quick development turn around and sales the boring stuff like security generally takes a back seat to features.  Unfortunately when the lawyers get involved and they will that boring stuff will be the only thing saving some of these execs / company bottom lines from taking a major hit I suspect.


So if self regulation doesn't work - you regulate or legislate. While very had to do well, it might be necessary.

Security standards for vehicle systems seems a good start - with penalties for releasing systems that don't meet them.

Security might not be of interest to an executive - but financial penalties and bad press should be.

 1 | 2 | 3
View this topic in a long page with up to 500 replies per page Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.