Skip to main content

Jeep hackers return to remotely hack Cherokee’s digital systems

Just a year after they caused Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse. In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. At the Black Hat USA 2016 conference this week the two automot
August 4, 2016 Read time: 2 mins
RSSJust a year after they caused 1958 Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse.

In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

At the Black Hat USA 2016 conference this week the two automotive cybersecurity researchers will outline new methods of cyber attack against the same Jeep Cherokee they hacked last year.

According to Miller and Valasek, hackers usually inject CAN messages on to the vehicle's network. However, there are often many limitations on what actions the vehicle can be forced to perform when injecting CAN messages. While an attacker may be able to easily change the speedometer while the car is driving, he may not be able to disable the brakes or turn the steering wheel unless the car he is driving meets certain prerequisites, such as travelling below a certain speed.

In their presentation, they plan to discuss how physical, safety critical systems react to injected CAN messages and how these systems are often resilient to this type of manipulation.

They will also outline new methods of CAN message injection which can bypass many of these restrictions and demonstrate the results on the braking, steering, and acceleration systems of an automobile. They end by suggesting ways these systems could be made even more robust in future vehicles.

Related Content

  • August 29, 2019
    Don’t drive drunk – or use a hands-free phone
    Despite law changes, drivers’ bad habits have been creeping back in. TRL’s Dr Shaun Helman tells Adam Hill why using a phone at the wheel is just as distracting as driving after a few drinks esearch from as far back as 2002 (see box) suggests that driving while making a phone call – either hands-free or holding a handset to your ear – creates the same amount of distraction as being drunk behind the wheel. While it is notoriously hard to predict how alcohol will affect an individual (due to the speed of
  • May 9, 2014
    Around 420 million connected cars expected on the road in 2018
    According to French think tank IDATE, there will be 420 million connected cars on the road by 2018, compared to 45 million in 2013, an annual growth of 57 per cent. IDATE attributes the development of the market to European safety regulations and manufacturers looking to identify new sources of revenue.
  • March 6, 2015
    Bill introduced in US Senate to extend positive train control deadline
    Four US senators have introduced the bipartisan Railroad Safety and Positive Train Control Extension Act in an effort to extend the deadline for full implementation of positive train control (PTC) on US railroads to 2020. Missouri has 4,400 miles of main rail track that are operated by 19 different railway companies. PTC is a technology designed to automatically stop or slow a train before certain collisions. The Rail Safety Improvement Act of 2008 mandates that PTC must be installed by31 December 2015. PT
  • February 2, 2012
    A carbon free and accident free Europe by 2015?
    By 2050, the Europe Commission aims to make transport in Europe carbon- and accident-free. Between now and then, however, a significant technological development and deployment effort is needed. Here, Neelie Kroes, European Commission Vice-President for the Digital Agenda, talks about what's being done. In many respects, COOPERS, CVIS and SAFESPOT, set up by the European Commission (EC) to explore the potential of cooperative infrastructure systems, are already legacy projects. Between them, the three devel