{"id":8031,"date":"2019-05-13T19:11:58","date_gmt":"2019-05-13T23:11:58","guid":{"rendered":"https:\/\/jolt.richmond.edu\/?p=8031"},"modified":"2019-05-17T10:57:09","modified_gmt":"2019-05-17T14:57:09","slug":"liability-in-hacked-smart-cars-no-smart-solutions-yet","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2019\/05\/13\/liability-in-hacked-smart-cars-no-smart-solutions-yet\/","title":{"rendered":"Liability in Hacked Smart Cars: No \u201cSmart\u201d Solutions Yet"},"content":{"rendered":"<p>By: Zaq Lacy<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/media.threatpost.com\/wp-content\/uploads\/sites\/103\/2019\/02\/25164549\/Automobile-computer.jpg\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In 2015, a pair of security researchers (read that as \u2018hackers\u2019), Chris Valasek and Charlie Miller, conducted an experiment in which they remotely \u2018hijacked\u2019 an internet-connected SUV driven by a volunteer.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> Valasek and Miller gained complete control of the vehicle\u2019s transmission, radio, air conditioning, braking functions, and windshield wipers sprayers, as well as being able to track the vehicle\u2019s exact location.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> In previous experiments, they also were able to mess with braking functions, horn, seat belt, and steering.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> However, in these earlier trials, they were directly wired into the vehicle\u2019s onboard diagnostic interface.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a> That was already particularly eerie, but what made the 2015 trial particularly disconcerting was their ability to do it remotely.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> They were not the first to do so; in 2011, other researchers were able to use cellular connection to locate vehicles via GPS, turn on the lights, and start the car by simply sending files via a telephone call.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> Valasek and Miller were, however, the first to achieve nearly unlimited control over a vast majority of the systems that modern cars rely upon to function and keep the driver and passengers safe \u2013 all from the comfort of their couch.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a> It was this experiment that resulted in 1.4 million vehicles being recalled<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> and was the impetus for legislation regarding digital security standards.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a><\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Scholars estimate that current luxury vehicles have up to seventy Engine Control Units (ECUs), as well as computer control systems that regulate a surprising number of functions we simply take for granted.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a> These are all integrated into the Controller Area Network (CAN), which presents hackers with a potential entry point, granting the hacker access to every system in the vehicle, from the air conditioning and the radio to the air bags and mechanical functions of the engine itself.<a href=\"#_ftn11\" name=\"_ftnref11\">[11]<\/a> Fortunately, less than a handful malicious hacking attack are known to have occurred to date, one of which was a disgruntled dealership employee who activated the vehicle immobilization feature in around 100 vehicles, effectively disabling them all.<a href=\"#_ftn12\" name=\"_ftnref12\">[12]<\/a> Despite that, deep concerns are being raised about cybersecurity with newer internet-connected cars, particularly where it concerns automated \u2018smart\u2019 cars.<a href=\"#_ftn13\" name=\"_ftnref13\">[13]<\/a><\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 There are certainly varying levels of vehicle autonomy in the market, from features like Lane Keep and Auto Brake that still require a driver, to fully automated self-driving cars.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a> Currently, the main focus of the development of such \u2018smart\u2019 cars is ride sharing services, such as Waymo, Uber, and Cruise, rather than the private ownership market.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a> Seeking to appeal to these markets, manufacturers have integrated newer vehicles with heightened multi-layered security that is intended to make remote access more difficult.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> Even so, this past April, a hacker known as L&amp;M was still able to hack around 27,000 accounts of commercial fleets in India and the Philippines and shut down the engines of vehicles moving less than 12 miles per hour.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a><\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 This raises the particularly pointed issue of liability when it concerns driverless vehicles that are hacked when an injury occurs. Traditionally, accident liability falls upon the driver,<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> and it is generally understood that criminal and civil liability arises when a hacker takes control of a vehicle that ultimately injures someone.<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> But, what about when there is no driver and the hacker cannot be located? The question, then, is whether liability should fall to the car manufacturer on the basis of product liability for failing to adequately protect against the possibility of remote tampering, to the software developer similarly for failing to provide sufficient cybersecurity, or to the insurance of the owner\/company whose vehicle was hacked.<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a> Unfortunately, as fully autonomous cars have not yet gained a significant foothold in the U.S. (rollouts are not expected until 2020),<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> there has not yet been cause to explore the issue, and, to date, we are left with little guidance. With the current framework, however, it seems likely that if\/when the first cases arise, a new area of law will need to develop rapidly in order to keep up.<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\">[1]<\/a> <em>See <\/em>Andy Greenberg, <em>Hackers Remotely Kill a Jeep on the Highway \u2014 With Me in It<\/em>, Wired.com (Jul. 21, 2015, 6:00 AM), https:\/\/www.wired.com\/2015\/07\/hackers-remotely-kill-jeep-highway\/ [https:\/\/perma.cc\/2VLH-73W3].<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\">[2]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\">[3]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref4\" name=\"_ftn4\">[4]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref6\" name=\"_ftn6\">[6]<\/a> <em>See <\/em>Scott L. Wenzel, <em>Not Even Remotely Liable: Smart Car Hacking Liability<\/em>, Ill. J.L. Tech. &amp; Pol\u2019y, no. 1, 2017, at 49, 55.<\/p>\n<p><a href=\"#_ftnref7\" name=\"_ftn7\">[7]<\/a> <em>See id.<\/em> at 54.<\/p>\n<p><a href=\"#_ftnref8\" name=\"_ftn8\">[8]<\/a> <em>See Who Is Liable When Your Car Gets Hacked?<\/em>, Botto Gilbert Lancaster Att\u2019y at Law: Car Accidents Blog (Oct. 20, 2015)[hereinafter Botto], https:\/\/www.bgsllaw.com\/mchenry-county-lawyers\/your-car-gets-hacked [https:\/\/perma.cc\/9AG2-2W26].<\/p>\n<p><a href=\"#_ftnref9\" name=\"_ftn9\">[9]<\/a> S. 680, 115th Cong. (2017).<\/p>\n<p><a href=\"#_ftnref10\" name=\"_ftn10\">[10]<\/a> <em>See <\/em>Wenzel, <em>supra <\/em>note 5, at 52.<\/p>\n<p><a href=\"#_ftnref11\" name=\"_ftn11\">[11]<\/a> <em>See id.<\/em> at 53.<\/p>\n<p><a href=\"#_ftnref12\" name=\"_ftn12\">[12]<\/a> <em>See <\/em>Kevin Poulsen, <em>Hacker Disables More than 100 Cars Remotely<\/em>, Wired.com (Mar. 17, 2010, 1:52 PM), https:\/\/www.wired.com\/2010\/03\/hacker-bricks-cars\/ [https:\/\/perma.cc\/6L8X-JBMD].<\/p>\n<p><a href=\"#_ftnref13\" name=\"_ftn13\">[13]<\/a> <em>See <\/em>Fredrick Kunkle, <em>Auto Industry Says Cybersecurity Is a Significant Concern as Cars Become More Automated<\/em>, The Washington Post (Apr. 30, 2019), https:\/\/www.washingtonpost.com\/transportation\/2019\/04\/30\/auto-industry-says-cybersecurity-is-significant-concern-cars-become-more-automated\/?noredirect=on&amp;utm_term=.3f2b1d5ca04a [https:\/\/perma.cc\/XD6Y-Q5BL].<\/p>\n<p><a href=\"#_ftnref14\" name=\"_ftn14\">[14]<\/a> <em>See <\/em>Lindsey O\u2019Donnell, <em>Chris Valasek and Charlie Miller: How to Secure Autonomous Vehicles<\/em>, ThreatPost.com (Aug. 10, 2018), https:\/\/threatpost.com\/chris-valasek-and-charlie-miller-how-to-secure-autonomous-vehicles\/134937\/ [https:\/\/perma.cc\/HF6H-B4U9].<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref16\" name=\"_ftn16\">[16]<\/a> <em>See <\/em>\u00a0Kunkle, <em>supra<\/em> note 13.<\/p>\n<p><a href=\"#_ftnref17\" name=\"_ftn17\">[17]<\/a> <em>See id.<\/em><\/p>\n<p><a href=\"#_ftnref18\" name=\"_ftn18\">[18]<\/a> <em>See <\/em>Christopher Coble, <em>If Your Car Gets Hacked, Are You Liable for a Crash?<\/em>, FindLaw.com (Aug. 24, 2015), https:\/\/blogs.findlaw.com\/injured\/2015\/08\/if-your-car-gets-hacked-are-you-liable-for-a-crash.html [https:\/\/perma.cc\/DJ9C-STWU].<\/p>\n<p><a href=\"#_ftnref19\" name=\"_ftn19\">[19]<\/a> <em>See <\/em>Bradley Thayer, <em>Car Hacking Legislation and Product Liability<\/em>, Wash. Or. Law. (Sept. 24, 2015), https:\/\/www.washingtonoregonlawyers.com\/news\/car-hacking-legislation [https:\/\/perma.cc\/Z6XE-5W5M]<\/p>\n<p><a href=\"#_ftnref20\" name=\"_ftn20\">[20]<\/a> Gilbert Shar, <em>Safety, Liability &amp; Hacking of Self-Driving Connected Cars Are Big Worries for Americans<\/em>, AutoConnectedCar.com (Oct. 3, 2017), http:\/\/www.autoconnectedcar.com\/2017\/10\/safety-liability-hacking-of-self-driving-connected-cars-are-big-worries-for-americans\/ [https:\/\/perma.cc\/E7QG-KJ4M].<\/p>\n<p><a href=\"#_ftnref21\" name=\"_ftn21\">[21]<\/a> Wayne Cohen &amp; Nicole Schneider, <em>Self-Driving Cars and Liability<\/em>, HG.Org, https:\/\/www.hg.org\/legal-articles\/self-driving-cars-and-liability-39591 [https:\/\/perma.cc\/3TH3-QRSP] (last visited May 8, 2019).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By: Zaq Lacy &nbsp; [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In 2015, a pair of security researchers (read that as \u2018hackers\u2019), Chris Valasek and Charlie Miller, conducted an experiment in which they remotely \u2018hijacked\u2019 an internet-connected SUV driven by a volunteer.[1] Valasek and Miller gained complete control of the vehicle\u2019s transmission, radio, air conditioning, braking functions, and windshield wipers sprayers, [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[51366],"tags":[],"class_list":["post-8031","post","type-post","status-publish","format-standard","hentry","category-blog-post"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-25x","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/8031","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=8031"}],"version-history":[{"count":0,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/8031\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=8031"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=8031"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=8031"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}