Skip to main content

Latest Jeep hack reminds us why we should keep our cars’ software updated

Jeep Cherokee
Image used with permission by copyright holder
Last year, security researchers Charlie Miller and Chris Valasek demonstrated the threat of car hacking in a dramatic way, by taking control of a Jeep Cherokee’s transmission and brakes while the car was moving. Now they’re back with new hacks that seem more sinister, but may not pose an actual threat in the real world.

Miller and Valasek can now mess with more than the transmission and brakes. They can activate the parking brake, tamper with the cruise control, and use the Cherokee’s automated parking system to jerk the steering wheel 180 degrees while the car is in motion, according to Engadget. That doesn’t sound good.

However, that ability to sow mayhem comes with an asterisk. After Miller and Valasek revealed their first Jeep hack, Fiat Chrysler Automobiles (FCA) initiated a recall of 1.4 million cars to update software and eliminate the weak point the two security researchers exploited. For this second demonstration, though, Miller and Valasek used the same 2014 Cherokee as before. FCA claims the vehicle did receive the software update as part of last year’s recall, but that it had been “altered back to an older level of software.”

Read more: Worried about car hacking? FBI and DOT offer safety tips

Unlike the previous hack, this one also required a physical connection: a laptop was plugged into the Cherokee’s OBD-II diagnostic port the whole time. Miller and Valasek also had to install their own firmware, which disabled some of the car’s built security features, before they could gain control of the steering and other systems. Given that, it’s unlikely someone would be able to execute this hack in the real world without the target’s knowledge.

It’s worth noting that, as The Verge points out, hackers could gain access to a car’s OBD-II port through diagnostic devices like the Verizon Hum and Automatic Adapter, or the devices issued by insurance companies to track driver behavior in exchange for the possibility of rate discounts. The proliferation of these devices further erodes the wall that used to separate car systems from the world at large.

Updated on 08-03-2016 by Stephen Edelstein: FCA issued a statement in response to the latest Miller and Valasek hack. The carmaker noted that accomplishing the hack required “extensive technical knowledge” and physical access to the OBD-11 port. FCA also said that the Jeep Cherokee used in the demonstration had been updated to address the security issue exposed last year, but that its had been “altered back to an older level of software.”

“Based on the material provided, while we admire their creativity, it appears that the researchers have not identified any new remote way to compromise a 2014 Jeep Cherokee or other FCA U.S. vehicles,” the company said.

Stephen Edelstein
Stephen is a freelance automotive journalist covering all things cars. He likes anything with four wheels, from classic cars…
Mercedes-Benz G580 first drive: old-school off-roader goes electric
2025 Mercedes-Benz G580 from three quarter view.

American car buyers mostly know Mercedes-Benz as a luxury brand. But for decades, the automaker has also produced the tough, rugged G-Class (also known as the Geländewagen or G-Wagen), an SUV not afraid to get its leather upholstery muddy. And now, this iconic Mercedes is going electric.

The 2025 Mercedes-Benz G580 with EQ Technology — the final name of the SUV previously known as the EQG — isn’t the first electric off-roader. The Rivian R1S and R1T and GMC Hummer EV have proven that electric powertrains and off-roading are a great combination. But the electric G-Wagen is different because it’s based on an internal-combustion model — and a very traditional one at that.

Read more
Honda believes hydrogen semi trucks will make the case for fuel cells
Honda hydrogen fuel-cell semi truck.

Honda remains committed to hydrogen fuel-cell vehicles, but the market for those vehicles remains limited. So Honda is looking at other uses for fuel cells -- including commercial trucks.

To show how that could work, Honda converted a semi truck to fuel-cell power, replacing its diesel engine with three fuel-cell modules. Together, the three modules produce a combined 321 horsepower, and can propel the truck to a top speed of 70 mph. There's enough onboard hydrogen storage capacity for a 400-mile range with a full load, Honda claims.

Read more
Mercedes-Benz G580 vs Rivian R2: Is the much cheaper Rivian actually better?
2025 Mercedes-Benz G580 from three quarter view.

Mercedes-Benz has finally taken the wraps off of the new "Mercedes-Benz G580 with EQ Technology." Yeah, it's a mouthful, but it's basically a new electric G-Wagon. It looks a lot like the G-Wagon you know and love, but with an electric powertrain and a battery. It's not the only electric SUV out there, however, and there are some great ones -- like the Rivian R2.

Both the Mercedes G580 and the Rivian R2 have a lot going for them, but they also approach the electric SUV slightly differently. Is one better than the other? I put the two head-to-head to find out.
Design
The approach that the two vehicles take to design is quite different -- and you might like one better than the other.

Read more