Skip to main content
  1. Home
  2. Cars
  3. News

Latest Jeep hack reminds us why we should keep our cars’ software updated

Add as a preferred source on Google

Last year, security researchers Charlie Miller and Chris Valasek demonstrated the threat of car hacking in a dramatic way, by taking control of a Jeep Cherokee’s transmission and brakes while the car was moving. Now they’re back with new hacks that seem more sinister, but may not pose an actual threat in the real world.

Miller and Valasek can now mess with more than the transmission and brakes. They can activate the parking brake, tamper with the cruise control, and use the Cherokee’s automated parking system to jerk the steering wheel 180 degrees while the car is in motion, according to Engadget. That doesn’t sound good.

Recommended Videos

However, that ability to sow mayhem comes with an asterisk. After Miller and Valasek revealed their first Jeep hack, Fiat Chrysler Automobiles (FCA) initiated a recall of 1.4 million cars to update software and eliminate the weak point the two security researchers exploited. For this second demonstration, though, Miller and Valasek used the same 2014 Cherokee as before. FCA claims the vehicle did receive the software update as part of last year’s recall, but that it had been “altered back to an older level of software.”

Read more: Worried about car hacking? FBI and DOT offer safety tips

Unlike the previous hack, this one also required a physical connection: a laptop was plugged into the Cherokee’s OBD-II diagnostic port the whole time. Miller and Valasek also had to install their own firmware, which disabled some of the car’s built security features, before they could gain control of the steering and other systems. Given that, it’s unlikely someone would be able to execute this hack in the real world without the target’s knowledge.

It’s worth noting that, as The Verge points out, hackers could gain access to a car’s OBD-II port through diagnostic devices like the Verizon Hum and Automatic Adapter, or the devices issued by insurance companies to track driver behavior in exchange for the possibility of rate discounts. The proliferation of these devices further erodes the wall that used to separate car systems from the world at large.

Updated on 08-03-2016 by Stephen Edelstein: FCA issued a statement in response to the latest Miller and Valasek hack. The carmaker noted that accomplishing the hack required “extensive technical knowledge” and physical access to the OBD-11 port. FCA also said that the Jeep Cherokee used in the demonstration had been updated to address the security issue exposed last year, but that its had been “altered back to an older level of software.”

“Based on the material provided, while we admire their creativity, it appears that the researchers have not identified any new remote way to compromise a 2014 Jeep Cherokee or other FCA U.S. vehicles,” the company said.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
China’s latest budget EV costs under $7,000, and it’s basically a four-seat electric go-kart
A $6,540 electric car with a giant rear wing? Yes, I'll take it.
Geely Panda Mini Featured

I have a soft spot for tiny cars, and China has a bunch of them. Geely’s latest Panda Mini takes that form and puts an electric engine into it. The updated Panda Mini Karting Edition launched in China earlier today with a CATL battery, four seats, and a rear wing that makes it look pretty sporty for its size.

Its limited-time subsidized price is 43,900 yuan, or around $6,540, compared with a regular listed price of 49,900 yuan, or approximately $7,435. The promotional offer runs through September 30, with additional purchase incentives subject to eligibility. Budget EVs come in many different shapes, but this one has enough personality to make you look twice.

Read more
Order an Uber and a self-driving Mustang might show up
Electronics, Phone, Mobile Phone

Ordering an Uber in London could come with a surprise today. Instead of a conventional car and driver pulling up, you might find a Ford Mustang Mach-E that can drive itself. Uber has launched London's first public robotaxi service in partnership with British autonomous driving company Wayve. The service is available through the Uber app, meaning you don't need to download anything new or book a special type of ride to try it.

There is one important caveat. Although the cars will handle the driving themselves, a trained safety operator will initially sit behind the wheel, ready to intervene if necessary. Fully driverless rides are planned for a later stage. The launch fleet consists of electric Mustang Mach-Es equipped with cameras, radar, and Wayve's AI Driver technology. These systems give the vehicle a 360-degree view of what's happening around it. And if anywhere can put that technology through its paces, London seems like a pretty good candidate.

Read more
Range Rover Electric arrives with 543hp, 600km range, and a starting price of the moon
The electric Range Rover is here, and your wallet may need CPR
Range Rover EV

The Range Rover has never been shy about luxury, size or price, and its first fully electric version is carrying that tradition into the EV era. Jaguar Land Rover’s (JLR) first battery-electric Range Rover is now open for orders, starting at £154,070, or about $208,420. That makes it one of the most expensive electric SUVs on the market.

The electric model costs almost £50,000 more than the standard combustion-engine Range Rover. It is priced in the same territory as the electric Mercedes-Benz G 580 and not far from ultra-luxury gasoline SUVs such as the Bentley Bentayga.

Read more