Skip to main content

Jeep hackers return to remotely hack Cherokee’s digital systems

Just a year after they caused Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse. In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. At the Black Hat USA 2016 conference this week the two automot
August 4, 2016 Read time: 2 mins
RSSJust a year after they caused 1958 Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse.

In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt.

At the Black Hat USA 2016 conference this week the two automotive cybersecurity researchers will outline new methods of cyber attack against the same Jeep Cherokee they hacked last year.

According to Miller and Valasek, hackers usually inject CAN messages on to the vehicle's network. However, there are often many limitations on what actions the vehicle can be forced to perform when injecting CAN messages. While an attacker may be able to easily change the speedometer while the car is driving, he may not be able to disable the brakes or turn the steering wheel unless the car he is driving meets certain prerequisites, such as travelling below a certain speed.

In their presentation, they plan to discuss how physical, safety critical systems react to injected CAN messages and how these systems are often resilient to this type of manipulation.

They will also outline new methods of CAN message injection which can bypass many of these restrictions and demonstrate the results on the braking, steering, and acceleration systems of an automobile. They end by suggesting ways these systems could be made even more robust in future vehicles.

Related Content

  • October 3, 2014
    IBTTA commends new report on infrastructure planning
    The International Bridge, Tunnel and Turnpike Association (IBTTA) has responded to the joint report by the Eno Center for Transportation and the American Society of Civil Engineers (ASCE), which highlights the benefits of life cycle cost analysis in planning transportation infrastructure projects. Executive director and CEO Pa trick D. Jones said: “We commend ENO and ASCE for issuing an important report, Maximizing the Value of Investments Using Life Cycle Cost Analysis. This report is especially timely
  • September 26, 2014
    Ford Mondeo – the car that brakes for pedestrians
    The all-new Ford Mondeo will be equipped with a raft of safety features, including technology that is able to detect people in the road ahead and – if the driver does not respond to warning sounds and displays – automatically applies the brakes. Pedestrian Detection is among a raft of new features and improvements detailed by Ford which enhance the Mondeo. The system is part of the Pre-Collision Assist package that also introduces Active Braking, which can autonomously apply braking to help mitigate rear
  • April 11, 2016
    Consumer Watchdog calls on NHTSA to strength rules on autonomous cars
    The US Consumer Watchdog has called on the National Highway Traffic Safety Administration (NHTSA) to require a steering wheel, brake and accelerator so a human driver can take control of a self-driving robot car when necessary in the guidelines it is developing on automated vehicle technology. In comments for a NHTSA public meeting about automated vehicle technology, John M. Simpson, Consumer Watchdog's privacy project director, also listed ten questions he said the agency must ask Google about its self-
  • December 4, 2012
    Assessing the potential of in-vehicle enforcement systems
    Jason Barnes considers the social and ethical ramifications of using in-vehicle safety technologies to fulfil enforcement functions. Although policy documents often imply close correlation between enforcement, compliance and safety – in part, as a counter to accusations that enforcement is rather more concerned with revenue generation – there is a noticeable reluctance among policy makers and auto manufacturers to exploit in-vehicle safety systems for enforcement applications. From a technical perspective t