[EDIT] Again, I really don't understand why I'd be downvoted for asking a legitimate question like this. It's rather disconcerting. While it's great to think about a future in which this technology is safe and widely available, it seems to me I'm being attacked for simply asking basic security questions that I would ask about any large system that was going through trials prior to mass rollout. And rather than hearing any specific answers, I'm just being attacked and voted down. I think anyone who's spent time in IT would probably ask these things first before they deployed a new system in their company office, so I don't think it's unreasonable to ask them about about a potentially game-changing social innovation.[/EDIT]
That's true. But blowing up a diesel truck is hard to do remotely, and requires someone to actively attack at a specific place and time.
I'm not sure why I got downrated for my post; I'm just asking, doesn't this create a lot of security holes and attack vectors that need to be studied before allowing it? I mean, I haven't heard anything about security, at all. The focus seems to be on a safe driving experience, but where's the white paper on counter-hacking measures? Can you imagine if Google launched Gmail without any kind of plan to mitigate stolen passwords or hijacked accounts? As it is, there are plenty of people who do have their accounts hijacked. Luckily, that doesn't lead to collisions and deaths.
Consider for a moment how many people run Windows and IE, with the latest security updates, who are still vulnerable to zero day exploits. Consider how many don't update their software and get swept up in botnets a few days later. Now imagine each and every compromised PC has physical control over 2-3 tons of rolling aluminum and steel, that can go anywhere on a public highway, with human beings inside it.
An attacker who had taken control over a botnet of compromised autonomous carscould drive swarms of them wherever they wanted by remote control.
Now, rather than downvote me, tell me what security protocols will be in place to prevent the scenarios I've outlined.
> But blowing up a diesel truck is hard to do remotely
It really isn't. Rebels/terrorists/freedom fighters† the world over could tell you how to detonate an explosive using an off-the-shelf prepaid cell phone.
No network access. The computer that controls the car doesn't need to talk to anything other than the car. That eliminates a slew of attack vectors right there.
Is "no network access" going to be part of the legal framework under which the vehicles operate? Presumably they need to download maps from somewhere, along with traffic updates, road hazards, etc. Most new cars have network capabilities as it now stands. So it's unreasonable to assume that they won't have any network access. And as we know, anything with network access can eventually be rooted.
My guess is that the basic systems (keep the car from going off-road or colliding, letting people takeover, etc) will run on an real-time barebones OS on a embedded system and will have a very simple and well defined interface to a full machine that runs all the crap like the UI, navigation systems and such.
I wouldn't discount having your car stolen remotely, but hijacking with humans inside is unlikely to work, and so is crashing into things.
These aren't "dumb" cars. For example, Google's have a high fidelity laser range finder that builds dense 360 point clouds 15 times second. If the car is given a bad map which sends it into a build or other cars, the collision avoidance system will recognize that fact before an accident occurs and stop the vehicle.
It's a lot more complicated than that. The car can't always stop when the map disagrees with the sensor. There are any number of situations where that's a bad idea.
If a cars sensor says there is a wall in front of the car and it goes with the map then some coder some where made a mistake. If the car sensor says there is a cliff in front of the car and it goes with the map some coder some where made a mistake.
replace wall and cliff with obstacle/dangerous environment of your choice and the sentence will always end with some coder some where made a mistake. It's really is as simple as that. sensor wins over map when it comes to avoiding a crash. What possible condition can you come up with that would make it desirable for a car to ignore it's sensors and go with what a map says is supposed to be in front of it?
If the car stops every time the map differs from the sensors, then I just give you a nonsensical map and you go nowhere. Or if the map is outdated, which will of course happen.
If sensors say the road turns and you go with the sensors, what happens to the navigation? Eventually they become irreconcilable. The car will completely lose track of where it actually is, having only local (and perhaps some limited amount of historical) sensor data.
The scenarios aren't just limited to "STOP or CRASH", there's a lot of subtle ways things can go wrong.
>If the car stops every time the map differs from the sensors, then I just give you a nonsensical map and you go nowhere.
..Yeah, as opposed to driving nonsensically? I think I'll take the car that defaults to whatever won't kill everyone around me.
>Or if the map is outdated, which will of course happen.
Assuming the cars download new maps on a regular basis, I'd consider this situation pretty unlikely on any official road or highway (unless we are to accept that in certain locations every car will consistently stop driving).
However, if this situation were to occur, option one: sync with the latest map data; failing that (network issues, etc.), option two: pull to the side of the road, stop, and enter manual mode.
>If sensors say the road turns and you go with the sensors, what happens to the navigation? Eventually they become irreconcilable. The car will completely lose track of where it actually is, having only local (and perhaps some limited amount of historical) sensor data.
What do you mean by this? Google Maps and most GPS navigation systems recalculate routes perfectly fine.
What if someone games the sensor? There are some pretty heinous examples or road rage out there - everything from attacking people's cars with a nine-iron to throwing their poodles into traffic at a stoplight. What happens to that point cloud if someone throws a bunch of silver ball bearings out their window in front of you? What if they aim a laser pointer at the receiver? What's to stop someone from developing a universal remote that you can point at any car to make it think there's a wall 3 feet in front of it? And how do you design a countermeasure against that and still ensure that the car does stop if there is a wall?
* Being possible is not the same as being easy or likely. For example, what if the system only accepts maps digitally signed by the company? You know have to either get the signing cert from the company or break digital cryptography.
* If there's a person inside, the can still take over and drive it themselves or tell it to park and ask for technical support.
Actually I think that the advantages of networked communicating vehicles will outweigh the possible disadvantages related to security. Vehicles that communicate are much safer and more effective.
Not networking vehicles because they might be hacked into a botnet is a little bit like not networking personal computers for the same reason. We could have just decided to not have an internet. Or we could have decided that we wouldn't allow people to print flyers because they might organize a revolution.
We will definitely want communications security though.
Every advance comes with the ability to cause problems (for the record, I didn't downvote). The question is: are we better off without the advance? Personally, I think the answer is rarely (if ever) "yes". Quality of life has gone up over time, and I don't expect this will change that.
Of course, there is the possibility of things going wrong, but, on average, things generally get better, faster, than the alternative. (At least, I hope so ;).
That's true. But blowing up a diesel truck is hard to do remotely, and requires someone to actively attack at a specific place and time.
I'm not sure why I got downrated for my post; I'm just asking, doesn't this create a lot of security holes and attack vectors that need to be studied before allowing it? I mean, I haven't heard anything about security, at all. The focus seems to be on a safe driving experience, but where's the white paper on counter-hacking measures? Can you imagine if Google launched Gmail without any kind of plan to mitigate stolen passwords or hijacked accounts? As it is, there are plenty of people who do have their accounts hijacked. Luckily, that doesn't lead to collisions and deaths.
Consider for a moment how many people run Windows and IE, with the latest security updates, who are still vulnerable to zero day exploits. Consider how many don't update their software and get swept up in botnets a few days later. Now imagine each and every compromised PC has physical control over 2-3 tons of rolling aluminum and steel, that can go anywhere on a public highway, with human beings inside it.
An attacker who had taken control over a botnet of compromised autonomous carscould drive swarms of them wherever they wanted by remote control.
Now, rather than downvote me, tell me what security protocols will be in place to prevent the scenarios I've outlined.