# Will self-driving cars be dangerous due to computer hackers?

**URL:** <https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940>\
**Category:** Factual Questions\
**Created:** [January 5, 2014, 11:07am UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940 "2014-01-05T11:07:27Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 5, 2014, 7:36pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/21 "2014-01-05T19:36:39Z")

</div>

> [@drachillix](#):
>
> computer can be wiped and reloaded with a fresh load of latest software.

Exactly. And I imagine a support contract/warranty may be a legally compulsory requirement for operating a self-driving car.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 5, 2014, 7:45pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/22 "2014-01-05T19:45:21Z")

</div>

> [@drachillix](#):
>
> A proprietary car computer will be much harder to target. What works on one car will not work on others. Updates can be done by the car checking in with a known server location and pulling updates with no way to force an update manually unless you are physically plugged into a service port in the car.

This, I’m not so sure about - people will want to interface it with their tablets, laptops, smartphones - so they can send a route to it, or download energy efficiency stats, or retrieve journey history data, etc.  
Those are the kind of interfaces that can be open to attack - I’m sure they would be designed with security built in, but nothing is ever perfect - and it’s sometimes possible for an intruder to use what seems like quite a limited interface to inject a command or some such that allows them to gain more control of the system.

---

<div class="post-metadata">

**Author:** ![Dallas\_Jones](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dallas_jones/32/3277_2.png) [@Dallas\_Jones](https://boards.straightdope.com/u/Dallas_Jones)\
**Post date:** [January 5, 2014, 7:56pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/23 "2014-01-05T19:56:44Z")

</div>

> [@Mangetout](#):
>
> This, I’m not so sure about - people will want to interface it with their tablets, laptops, smartphones - so they can send a route to it, or download energy efficiency stats, or retrieve journey history data, etc.  
> Those are the kind of interfaces that can be open to attack - I’m sure they would be designed with security built in, but nothing is ever perfect - and it’s sometimes possible for an intruder to use what seems like quite a limited interface to inject a command or some such that allows them to gain more control of the system.

Yes, like it or not these cars will be available for access through normal internet devices of the time.

People will expect to be able to use their handheld devices for remote starting, to check fuel, to monitor temperature and cool the inside before they get in. Many more things that probably aren’t obvious now.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 5, 2014, 10:53pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/24 "2014-01-05T22:53:27Z")

</div>

> [@Mangetout](#):
>
> This, I’m not so sure about - people will want to interface it with their tablets, laptops, smartphones - so they can send a route to it, or download energy efficiency stats, or retrieve journey history data, etc.  
> Those are the kind of interfaces that can be open to attack - I’m sure they would be designed with security built in, but nothing is ever perfect - and it’s sometimes possible for an intruder to use what seems like quite a limited interface to inject a command or some such that allows them to gain more control of the system.

One of my techs owns a nissan leaf and constantly complains that such interfaces are read only and do not allow him to peforms certain tasks he could do if he had write access. At this point only the dealer does.

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [January 5, 2014, 11:08pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/25 "2014-01-05T23:08:38Z")

</div>

> [@Dallas\_Jones](#):
>
> Yes, like it or not these cars will be available for access through normal internet devices of the time.
> 
> People will expect to be able to use their handheld devices for remote starting, to check fuel, to monitor temperature and cool the inside before they get in. Many more things that probably aren’t obvious now.

And a fairly simple task to key the app to the vehicle much like theft resistant stereo systems are now.

Embedded systems are often built with very tightly restricted write permissions. Like tight to the point of making windows look as secure as a paper bag.

---

<div class="post-metadata">

**Author:** ![PhillyGuy](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@PhillyGuy](https://boards.straightdope.com/u/PhillyGuy)\
**Post date:** [January 5, 2014, 11:25pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/26 "2014-01-05T23:25:32Z")

</div>

> [@chappachula](#):
>
> One day in the future, self-driving cars may become common. Will they be dangerous?

About one million people a year, world-wide, die in vehicle accidents. By that standard, self-driving cars will be relatively safe, if we are allowed to transition to them.

But there still would be a lot of lost lives, with tremendous publicity given to extremely rare accident types that were less likely before – perhaps including software security breaches.

Give the psychology of [illusory superiority](http://en.wikipedia.org/wiki/Illusory_superiority), most people may mistakenly think that they are better drivers than the computer. Getting people to give up the wheel will not be easy, and I think the OP illustrates this.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 6, 2014, 12:27am UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/27 "2014-01-06T00:27:34Z")

</div>

> [@drachillix](#):
>
> One of my techs owns a nissan leaf and constantly complains that such interfaces are read only and do not allow him to peforms certain tasks he could do if he had write access.

Sure, but he’s presumably only trying legitimate methods of access; he’s not deliberately trying to overrun a buffer, or whatever it is that people keep doing that means common desktop operating systems need patching for things that were previously thought secure.

Besides, they won’t be read-only in the future, because people will want to send data to the car - send routes, send custom maps, set preferences for driving style, ride comfort, and so on. These channels of communication can sometimes be broken in a way that opens up a big hole in the security.

---

<div class="post-metadata">

**Author:** ![obbn](https://avatars.discourse-cdn.com/v4/letter/o/d6d6ee/32.png) [@obbn](https://boards.straightdope.com/u/obbn)\
**Post date:** [January 6, 2014, 4:38am UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/28 "2014-01-06T04:38:58Z")

</div>

A bit of topic, but when the idea of self driving cars is a reality will we be able to send them on their way without a human passenger? SayI’m moving and I have more cars than I have people to drive them. Instead of getting a trailer will they be able to just drive themselves to the new location?

And back on topic, if that is possible will a hacker be able to access your car and steal it by having it drive itself to them?

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [January 6, 2014, 2:47pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/29 "2014-01-06T14:47:31Z")

</div>

Even now, hackers have managed to take control of cars.

> **[Can Your Car Be Hacked?](https://www.caranddriver.com/features/a15124906/can-your-car-be-hacked-feature/)**
>
> Hack to the future.

> **[Tampering with a car’s brakes and speed by hacking its computers: A new how-to](https://arstechnica.com/information-technology/2013/07/disabling-a-cars-brakes-and-speed-by-hacking-its-computers-a-new-how-to/)**
>
> The "Internet of automobiles" may hold promise, but it comes with risks, too.

Admittedly, these require physical access to the car, but the MP3 attack vector would be very much like the OP’s concern.

---

<div class="post-metadata">

**Author:** ![Doughbag](https://avatars.discourse-cdn.com/v4/letter/d/aeb1de/32.png) [@Doughbag](https://boards.straightdope.com/u/Doughbag)\
**Post date:** [January 6, 2014, 4:09pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/30 "2014-01-06T16:09:28Z")

</div>

> [@chappachula](#):
>
> One day in the future, self-driving cars may become common. Will they be dangerous?  
> A computer virus is just irritating, but car viruses will be much worse, and possibly dangerous.  
> A computer virus is something we put up with, like a kid who vandalizes your mailbox. We don’t feel traumatized.  
> But a car virus will be like a burglar breaking into your bedroom while you are asleep.That’s traumatizing.
> 
> Am I wrong?

Read up, what is the [Autonomous Car](http://en.wikipedia.org/wiki/Autonomous_car) in the first place.

I am more worried about actual real people driving cars.

Most accidents are due to humans driving the car; drink driving, smoking, texting, speeding, etc….

An extremely small amount of accidents is actually due to mechanical failure.

However, your self-drive car’s internet connection has nothing to do with your browsing the internet.

We already have this [automatic parking](http://en.wikipedia.org/wiki/Automatic_parking) in some cars – its basically your car driving autonomous…… the thing you fear.

---

<div class="post-metadata">

**Author:** ![Diceman](https://avatars.discourse-cdn.com/v4/letter/d/22d042/32.png) [@Diceman](https://boards.straightdope.com/u/Diceman)\
**Post date:** [January 6, 2014, 5:09pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/31 "2014-01-06T17:09:53Z")

</div>

> [@obbn](#):
>
> And back on topic, if that is possible will a hacker be able to access your car and steal it by having it drive itself to them?

I think you’ve just forseen the future of car theft :eek: Why bother smashing windows when you can just order the car to drive itself to the chop shop?

---

<div class="post-metadata">

**Author:** ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)\
**Post date:** [January 6, 2014, 5:29pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/32 "2014-01-06T17:29:58Z")

</div>

> [@Shooby](#):
>
> a) targeted attacks against notable people for political, corporate, personal revenge, or other reasons. For some attackers, an electronic attack against someone’s car will be their easiest or safest option. ’

This gives something like Stuxnet a whole new avenue. Imagine if an Iranian nuclear scientist died in a car accident?

> [@Shooby](#):
>
> b) the lulz. Some people try to take down big websites and such just to leave their mark, troll people, hurt people (financially or otherwise) etc. I suspect some folks will be willing to attack people’s cars as pranks of varying severity, and proof of their own skill.

Another possibility would be anti-corporate warfare. Imagine some eco-warrior causing all Exxon-Mobile tankers to burn in a fiery crash.

That said, I’m totally for self-driving cars because they would still be way safer than human drivers.

> [@PhillyGuy](#):
>
> Give the psychology of [illusory superiority](http://en.wikipedia.org/wiki/Illusory_superiority), most people may mistakenly think that they are better drivers than the computer. Getting people to give up the wheel will not be easy, and I think the OP illustrates this.

This is what worries me. I can imagine some scenario where law suits make it near impossible for companies to create driving software even if it’s shown to make the roads safer. On the other hand the costs could be covered by the insurance companies; i.e. they shift the payouts from the many accidents caused by humans to the few accidents caused by software/hackers/etc. It’s an interesting topic (to me).

---

<div class="post-metadata">

**Author:** ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)\
**Post date:** [January 6, 2014, 5:40pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/33 "2014-01-06T17:40:08Z")

</div>

> [@Mangetout](#):
>
> Besides, they won’t be read-only in the future, because people will want to send data to the car - send routes, send custom maps, set preferences for driving style, ride comfort, and so on. These channels of communication can sometimes be broken in a way that opens up a big hole in the security.

But in a car’s operating system, it is relatively easy to have a separate “code only” memory separate from the routes, maps, &c. There are certain problems that problems for home computers only because they keep code and data in the same memory space.

It’s not perfect, but non-read only car computers _can_ be made to be a lot more secure than desktop PCs.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 6, 2014, 8:12pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/34 "2014-01-06T20:12:30Z")

</div>

> [@leahcim](#):
>
> But in a car’s operating system, it is relatively easy to have a separate “code only” memory separate from the routes, maps, &c. There are certain problems that problems for home computers only because they keep code and data in the same memory space.
> 
> It’s not perfect, but non-read only car computers _can_ be made to be a lot more secure than desktop PCs.

Where you keep the code and data is only part of the picture - exploits don’t necessarily attack things by location or architecture - they’re often based on doing something unexpected that causes the system to malfunction - and to a malfunctioning system, the distinction between code and data may no longer exist.

---

<div class="post-metadata">

**Author:** ![Habeed](https://avatars.discourse-cdn.com/v4/letter/h/a587f6/32.png) [@Habeed](https://boards.straightdope.com/u/Habeed)\
**Post date:** [January 7, 2014, 11:49am UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/35 "2014-01-07T11:49:45Z")

</div>

A good design for an automated car would use isolation. The software for driving the vehicle would use a physically different computer from the one that does the maps. That’s how current cars generally do it : the nav system is a different circuit board than the ECU.

The safest way is to prohibit remote software updates, and to not connect any of the car’s radios to the computers that drive the car. However, in practice, you can be almost as safe by writing the code that handles incoming data very carefully, and not allowing any updates to the car’s software that are not signed by the manufacturer of the car.

Teslas already do all this. There were news articles on how they remotely pushed an update to all the model S vehicles, and the computers in a Tesla control critical driving functions that would allow you to crash the vehicle if you were a hacker.

Security doesn’t have to be perfect. Someone could always cut your brake lines or put a bomb on your current car if they were out to kill you. Computer hacking is just another means, and it just needs to be hard enough to do that it rarely happens.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 7, 2014, 1:30pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/36 "2014-01-07T13:30:34Z")

</div>

> [@Habeed](#):
>
> A good design for an automated car would use isolation. The software for driving the vehicle would use a physically different computer from the one that does the maps. That’s how current cars generally do it : the nav system is a different circuit board than the ECU.

Except in current cars, the nav system is linked to the rest of the car _via the driver_.  
In a self-driving car, the nav system _ **is** _ the driver - it _has_ to be connected, or the thing won’t work.

---

<div class="post-metadata">

**Author:** ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)\
**Post date:** [January 7, 2014, 1:58pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/37 "2014-01-07T13:58:59Z")

</div>

> [@Mangetout](#):
>
> Where you keep the code and data is only part of the picture - exploits don’t necessarily attack things by location or architecture - they’re often based on doing something unexpected that causes the system to malfunction - and to a malfunctioning system, the distinction between code and data may no longer exist.

But the separation of code and data is something that can be done _physically_. Just keep the programs in a ROM. No amount of malicious programming or software bugs can force current the wrong way through a diode.

With special purpose computers, you can do more than rely on the OS for protection of separation.

---

<div class="post-metadata">

**Author:** ![Xema](https://avatars.discourse-cdn.com/v4/letter/x/9de053/32.png) [@Xema](https://boards.straightdope.com/u/Xema)\
**Post date:** [January 7, 2014, 2:14pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/38 "2014-01-07T14:14:05Z")

</div>

> [@leahcim](#):
>
> Just keep the programs in a ROM.

This blocks “in the field” updates - which has the effect of making both hacking and legitimate upgrades more difficult. So if a problem is discovered in firmware the manufacturer has installed, it’s a lot more difficult and expensive to fix it.

The inconvenience this would introduce is so high that it’s hard to imagine this approach being used unless/until hacking is shown to be a significant problem. (Which admittedly could require only a few well-publicized incidents.)

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [January 7, 2014, 2:27pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/39 "2014-01-07T14:27:15Z")

</div>

> [@leahcim](#):
>
> But the separation of code and data is something that can be done _physically_. Just keep the programs in a ROM. No amount of malicious programming or software bugs can force current the wrong way through a diode.

No, but you could conceivably still fall victim to attacks that divert the point of execution somewhere else.

I’m not saying it can’t be designed to be _really secure_; just that today’s notions of ‘really secure’ sometimes turn out to be tomorrow’s surprises - and the very nature of surprise is: something happens that was completely unanticipated, or previously thought impossible (not impossible in the sense of current flowing the wrong way through a diode, but rather, some other exploit or workaround)

---

<div class="post-metadata">

**Author:** ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)\
**Post date:** [January 7, 2014, 2:28pm UTC](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940/40 "2014-01-07T14:28:00Z")

</div>

> [@Xema](#):
>
> This blocks “in the field” updates - which has the effect of making both hacking and legitimate upgrades more difficult. So if a problem is discovered in firmware the manufacturer has installed, it’s a lot more difficult and expensive to fix it.
> 
> The inconvenience this would introduce is so high that it’s hard to imagine this approach being used unless/until hacking is shown to be a significant problem. (Which admittedly could require only a few well-publicized incidents.)

Would this be any more expensive than changing out firmware now? Any updates to the embedded software an ECU require a trip to the dealership to apply, but no one seems to be clamoring for the convenience that being to push updates directly to your garage via wifi would allow.

It is completely possible to make robust, well-tested software that will work for more than a couple of years without an update, and it is routinely done for cases when updating would be onerous. It’s just that for most home PC software the increased development costs are not worth it when you can just push out updates in response to bugs found in the field.

[Previous page](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940.md?page=1)

[Next page](https://boards.straightdope.com/t/will-self-driving-cars-be-dangerous-due-to-computer-hackers/677940.md?page=3)
