it was a real-world attack it wasn’t a proof-of-concept that was done by some white hat hacker and laboratory at or at a security conference these were real individuals who broke into a real world system that had an effect on hundreds of thousands if not millions of motorists over days in one of the most traffic congested areas of the world you I think la has an excellent transportation system we thought of as the center of car culture in the u.s. we have about 6,500 miles of public streets we have about 4,500 signals in the City of Light which is one of the largest signal systems in the world without the at Sac Center it’d be very difficult to manage Kartik Patel in Gabrielle Murillo were to Los Angeles city employees who were accused of illegally accessing the city’s computer system that controls the traffic lights and using it to create day’s long traffic jams in furtherance of protests that their union was was conducting on the surface of it it sounds really really sexy like Italian job right it sounds really really sexy at the time of the August 21st incident I was working in at SAC control center where I was in charge of the engineers I was kind of like the manager of implementing and maintaining that whole system so I I in particular was accused of disconnecting signals and causing some kind of traffic back up we lost communication from our centralized control center to these four signals just by the fact that I was on the system and very few people have remote access that they felt that I got on there to do something kind of fishy my name is James e Blatt I’m a criminal defense attorney in Los Angeles and I was representing mr. Gabriel murió he was the key person of developing at SAC the automated traffic system and control center he was the main troubleshooter the developer the inventor my name is Damien Kamkar I’m a security researcher and computer hacker some of these control systems that are controlling our utilities our traffic are really prone to hacking their current vulnerabilities default passwords they’re on the internet when they shouldn’t be the only pro that I can see from actually these systems being hacked is demonstrating how possible it is if someone presses a wrong keystroke they can put of signals on flash in 30 seconds if we wanted to make say Venice a highway we would go 180 second green we can go Bam Bam Bam Bam and we can do that just from a computer screen it’s a very very very efficient system and it’s one of those where if there was some kind of problem with it ever went down then you really see the value of it because you’d see a lot more gridlock everywhere they have a program called a graphic user interface to monitor and control the traffic light system well that particular program had been shut down four of the major arteries the lights were not working there wasn’t any significant difficulties in this matter but it took three or four days to get the bugs out of the system the hacks that these two individuals are alleged to have carried out is exactly the type of thing that security researchers have been warning about for you know for a better part of the decade I’m not familiar with like all the different firewalls and different things we have but we’re comfortable with the level of security we have here now given that they were able to impact only four intersections and they increased a great deal of aggregate delay on the arterioles affecting only four intersections out of I don’t know roughly forty four hundred or so whatever their message was they weren’t actually trying to bring the system to their knees I think we really dodged a bullet there in the city every signal has its own secure system in such a way where if someone tries to change the signals and it’s beyond that the programming it won’t let it someone may make it inconvenient for the motoring public but it wouldn’t be an unsafe situation you’re creating potentially a dangerous situation where you shut down a particular bridge or access to a freeway where lives could be lost had the individuals responsible been fundamentally malicious and what they were trying to do they could have caused an enormous amount of delays system-wide but it was also a little bit of an inoculation it allowed us to begin to develop the the immunity necessary to protect ourselves against more dramatic infections anytime you use the Internet as a way of communicating between computers and any system the size of El ADOT signalized traffic rate does that to some degree you’re vulnerable our system is not available to the Internet is not out there we really have an old-school hardwired system our CCTV camera system is all analog a lot of our technology and software is just not up to today’s standards so that actually provides a little security that probably a lot of agencies don’t have you know again we’re comfortable with the technology we have I’m one of the few people who had authorized remote access to the traffic control system from home from a laptop those systems controlling our cities should not be on the internet they should not be easily communicated with by anyone who has a phone or laptop it’s actually terrible that there are so many open hardware switches available online that actually anyone could access it they just knew how you could potentially be controlling traffic lights you could be potentially controlling oil refineries you could be controlling water systems or water infrastructure electricity gas pretty much any type of system I definitely think you shouldn’t be so confident that you can’t be hacks I think almost anything is hackable fortunately there are a group of people and definitely a lot of hackers who are looking at this technology on a daily basis and trying to find new ways of exploiting it and then demonstrating it publicly typically in a legal manner but showing that okay some of our cities are not safe and we need to take measures to fix that I did not do anything wrong I did not cause any signal malfunction I believe led ot management made false statements I believe the police created a story when they didn’t even understand something I believe the DA’s office put their foot in their mouth and couldn’t take it out there’s definitely different camps of thinking when it comes to weather or hacking is better for society worse for society one group of people who believe well if you find an exploit you shouldn’t really talk about it you should potentially talk about it privately with who’s in charge and only disclose it to them give them time to let’s say update their systems to patch that vulnerability but if they don’t fix it within some amount of time you should release publicly I think everyone should hack I think everyone should learn how to hack and the more people that know how to hack something the more appreciation there is going to be for the vulnerabilities that come with that technology is a moving target I don’t trust the hackers to teach us a control lesson every time you introduce a new technology you have produced new owner abilities and some miserable son of a bitch out there is going to try to exploit that it’s just human nature securities need desperately to hire outside auditors people that will come in and perform what’s called a penetration test to actually test the limits and the security of the systems the cities are using exposing some of the things that can be hacked and how they can be hacked and really alter anything it really gets other people to work together to sort of rally up and fix some of these issues there are good guy hackers out there and some of the solution can be crowd-sourced if you’re willing to live with the outcome then go ahead and serve the greater good and break the rule I think the insurrectionists among us are healthy elements in society if there weren’t folks out there that were prepared to insist on teaching us some of the important lessons we’d never take delivery on the information packing never ended lives until that day now I’m coming for them you want revenge this phone can turn the city into a weapon we’ve got 40,000 people above us we need a distraction no one can hide from me no one watchdogs pre-order now wait amateur please

