Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

1–10 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#4
post #2

Besides locking your car into a garage, is there anything a VW owner can do to make it more difficult for these types of thefts to occur?

If the article is accurate, avoiding use of the key fob should make it more difficult for the attack to be carried out (which admittedly isn't very useful).

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#5
To anyone with any background at all in computer security, this is such a "duh" moment. If Sony et al can't secure their massively important corporate infrastructure, what are the odds your car's wireless computers are secure in any way? They aren't, they knew it, and you knew it. Sorry.

It'll be interesting to watch the fallout from these obviously-present vulnerabilities. I see three possible outcomes, in decreasing order of likelihood: status quo, where they just "fix" the bugs as they hit the news; some sort of massive push towards real computer security, in this and other industries; or a massive reduction in features to avoid the flaws.

This is really just another symptom of the current state of computer security, best described as "a joke." My guess is in 50 years we'll have decent computer security. There's nothing that precludes it in theory. But it's going to be an ugly, ugly couple of decades while we pay off the wave of computer-security-debt that we have been riding.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#6

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Tesla's at least on top of their software updates, and I believe they designed some more sensible separation of systems than most cars.

For affordable options, I have no idea.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#7

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Something with no wireless features at all(I think the no-feature nissan versa might be that way?). Not because their manufacturer cares about security, but because of less attack vectors.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#9
post #2

Besides locking your car into a garage, is there anything a VW owner can do to make it more difficult for these types of thefts to occur?

If the article is accurate, avoiding use of the key fob should make it more difficult for the attack to be carried out (which admittedly isn't very useful).

As far as my limited understanding goes using the the key fob for remote central locking does not expose any risk, instead its the immobiliser part, so manually opening your door with the physical key provides no extra safety, its when the key is present near the ignition barrel, thats where the immobiliser kicks in and where this venerability exists

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#10

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Just don't opt for the "smart key" option, on most models it's an optional extra.

Radio keys should be OK although they have their own security risk.

Post reply on HN