1 View
Life in Prison for Car Hacking? Michigan Takes the First Steps

by Steph Willems
(IC: employee)
April 29th, 2016 9:56 AM
Share

Hoping to access and remotely take charge of a vehicle’s operating system via your laptop? Expect to shower with strange men in a place where the Wi-Fi sucks.Life behind bars is the penalty proposed by two Michigan senators seeking to regulate the state’s connected and autonomous vehicle industry, Automotive News reports.The bills introduced yesterday make it a super-duper felony to intentionally access a vehicle’s electronic system for the purpose of damaging it or gaining control of the vehicle. As a demonstration, two computer experts did just that to a Jeep Cherokee travelling on a St. Louis highway last summer, leading to the recall of 1.4 million Fiat-Chrysler vehicles equipped with the hack-prone Uconnect system.It’s expected that more bills will follow yesterday’s Senate Bill 927 and 928, as lawmakers generally lean towards comprehensive regulation of an emerging industry, rather than piecemeal legislation.Senators Mike Kowall (R) and Ken Horn (R) claim the legislation is proactive, with Kowall saying he hopes the legislation, if passed, is never used.“That’s why the penalties are what they are,” he said. “The potential for severe injury and death are pretty high.”The hackers behind the Cherokee stunt were able to control the Jeep’s steering and braking systems, as well as its transmission.Infotainment and GPS systems are the keyholes that hackers use to enter and access a vehicle’s primary functions. FCA installed a patch on its software during last year’s recall, but some companies are now developing a beefier vehicle firewall.The two Michigan bills were sent to the Senate judiciary committee, so there’s little time left for the state’s hackers to get their kicks. After that, it’s back to the well-paying job, community work and recurrent carnal relations they’re best known for.[Image: SalFalco/Flickr ( CC BY-SA 2.0)]
Published April 29th, 2016 10:30 AM
Latest Car Reviews
Read moreLatest Product Reviews
Read moreRecent Comments
- Surferjoe Still have a 2013 RDX, naturally aspirated V6, just can't get behind a 4 banger turbo.Also gloriously absent, ESS, lane departure warnings, etc.
- ToolGuy Is it a genuine Top Hand? Oh, I forgot, I don't care. 🙂
- ToolGuy I did truck things with my truck this past week, twenty-odd miles from home (farther than usual). Recall that the interior bed space of my (modified) truck is 98" x 74". On the ride home yesterday the bed carried a 20 foot extension ladder (10 feet long, flagged 14 inches past the rear bumper), two other ladders, a smallish air compressor, a largish shop vac, three large bins, some materials, some scrap, and a slew of tool cases/bags. It was pretty full, is what I'm saying.The range of the Cybertruck would have been just fine. Nothing I carried had any substantial weight to it, in truck terms. The frunk would have been extremely useful (lock the tool cases there, out of the way of the Bed Stuff, away from prying eyes and grasping fingers -- you say I can charge my cordless tools there? bonus). Stainless steel plus no paint is a plus.Apparently the Cybertruck bed will be 78" long (but over 96" with the tailgate folded down) and 60-65" wide. And then Tesla promises "100 cubic feet of exterior, lockable storage — including the under-bed, frunk and sail pillars." Underbed storage requires the bed to be clear of other stuff, but bottom line everything would have fit, especially when we consider the second row of seats (tools and some materials out of the weather).Some days I was hauling mostly air on one leg of the trip. There were several store runs involved, some for 8-foot stock. One day I bummed a ride in a Roush Mustang. Three separate times other drivers tried to run into my truck (stainless steel panels, yes please). The fuel savings would be large enough for me to notice and to care.TL;DR: This truck would work for me, as a truck. Sample size = 1.
- Ed That has to be a joke.
- SCE to AUX One data point: my rental '23 Model 3 had good build quality, but still not as good as my Hyundais.Test mule aside, perhaps the build quality of the CT will be good in 2027.
Comments
Join the conversation
Well gee whiz, aren't murder, reckless homicide, reckless endangerment and computer hacking already illegal? Oh right, but they can't use those crimes to terrify anyone who even thinks about modifying their car.
Allow me to state up front that I have only skimmed the text of the proposed acts in question; my understanding of them is likely not what could exactly be referred to as 'comprehensive'. With that out of the way: I am wondering how Michigan's lawmakers are going to reconcile the provisions of these proposed acts with the existing ones at a Federal level in the Digital Millennium Copyright Act which permit reverse engineering (including circumvention of encryption, encoding, and other methods of protection) for the purposes of security research. Note that I am not stating an opposition to third-party research into automotive control systems: I'll put my bias out in the open and state that I am entirely in favour of it. But it does appear as though Michigan's proposed laws run afoul of at least a couple of DMCA provisions which could ultimately put this law into contention with existing Federal ones. If anything, the onus should be on the manufacturers to design inherently more-secure control systems which have been reviewed by third-party auditors and testers prior to placing them in production vehicles. Given both the potential for risk to human life and property as well as the liabilities involved with not doing so, one would think that if for no other reason than due diligence manufacturers would require this to be a mandatory part of their software development processes. It would be interesting to know who (if anyone) is backing these pieces of legislation beyond the Senators involved. They appear to be a handy way to - in Michigan, at least - criminalise exposing automobile manufacturers' shortcomings in securing their in-the-marketplace vehicle control systems while simultaneously silencing publication of the efforts of that research.