Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

171–180 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#172
post #114

Earlier quoted context omitted.

Wait, so VW has an RFID immobilizer and a physical key? I've only ever seen cars having one or the other.

All European cars since 1998 will have both, because immobilizers are required by law in most of Western Europe. On most cars, you'll never notice the immobilizer as it's RFID based, passive, and requires no batteries. The only way you'd find it is if you take apart the key fob or have to service the ignition lock, at which point you'll find the RFID antenna ring around it, or if you try to get the key replaced.

> All European cars since 1998 will have both, because immobilizers are required by law in most of Western Europe.

So will some cars produced before 1998. The Audi S2 (listed in the article) is one of those, and was built from 1990 to 1995.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#173
post #8

My question is if VW has switched the affected stuff in newer models since they found out about the issues?

Yes, as people mentioned above. It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all.

> It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all.

Some of the models on the list feature neither keyless entry, nor are high-end (the Audi A2, for example). While the Audi S2 may be considered high-end, it certainly wasn't available with keyless entry, and I wouldn't be suprised if the Audi 80/90 (which the S2 is based on) were affected, too.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#174
post #152
post #142

Earlier quoted context omitted.

True. stop-start might have not been the best example in this case. But still, i would be quite apprehensive of buying a 10-year old european car that has stop-start built in - Much more than an equivalent toyota. Japanese are quite slow to follow in implementing new features and as a result (IMO) their implementations seem to be more reliable. I have experienced European cars to develop serious electrical issues ove…

The continuous start-stop wears out the engine faster, so it won't last as long as an identical model with the same engine that hasn't that feature. It's like switching a traditional light bulb on and off in a continuous way - it won't last years (some 100+ old light bulbs still work fine, but the were powered-off just a handful times).

Do you have a reference for that? Cold engine starts cause a lot of wear, but warm engine starts should cause very little wear, especially in an engine designed for start stop.

http://www.autocar.co.uk/car-news/new-cars/stop-start-long-t...

While a home light bulb may not stand up to continuous on/off cycles, a bulb that's designed to do so (like a low-voltage bulb with a heavy filament) can last for a very long time.

So I wouldn't retrofit an existing car with a start-stop system, but I wouldn't have any qualms about purchasing a car with a start-stop engine as it would have been designed for the purpose.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#175

Earlier quoted context omitted.

The Thai finance minister, apparently: http://www.smh.com.au/articles/2003/05/13/1052591776195.html "Suchart said he was on his way to give a speech to central bank officials from 17 countries when his ministry-assigned BMW car stalled on a road, not far from his house. The engine stopped, the air conditioning shut down, the doors got locked and the windows wouldn't roll down, he said, adding that he was trapped for…

Within of to minutes no air? That sounds weird.

Depends on the food eaten. Intestinal gases are poisonous.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#176

Earlier quoted context omitted.

One might, if one had purchased a VW during the years this paper was censored.

Except that VW at somepoint quit using the transponder in question because of this issue so new cars made are no longer susceptible.

Not everyone buys only new cars. Besides, in a world in which research was not censored, do you really expect that VW would have been slower to fix the issue?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#177

Earlier quoted context omitted.

I don't know anything about the protocols involved, but it would be possible for the first message to be "I'm a key that would like to unlock the vehicle with VIN# 123abc...". In that case there would be no mistaken protocol runs.

There is no key as such. The fob for my Hyundai never leaves my pocket. Just by standing next to the car, the unlock button on the door is enabled. So if I walk up and push the button, it unlocks. If I'm not around, the button does nothing. So there's no discernible event from the fob, as far as I can see. It's just a "this is me" signal.

I guess the Hyundais I've driven were different, in that the unlock button was on the fob rather than on the car door. Could you say, if you have multiple cars, does the fob work with all of them? I doubt that's the case, so I don't see why your "this is me" signal couldn't actually be a "this is me, fob 123ABC..., and I can authenticate with the vehicle with VIN# 123abc...".

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#178

So why were the researchers willing to publish a redacted version now, but were not willing to publish the redacted version 3 years ago when they were researching the issue? I am actually curious because this is the only part of this whole thing that does not make sense to me. Even if I disagree with Volkswagon's decision to not notify existing owners that there was a vulnerability known or eventually provide them wi…

Is it the same redacted version? Maybe Volkswagen asked more more extensive redactions back then, and they now reached a compromise?

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#179

Earlier quoted context omitted.

Wait until Teslas become cheaper. Until then, buy a Lada Niva. No one will want to steal it and it doesn't have anything complicated in it that can be hacked.

1993 Corolla with decayed paint. Utterly, utterly, reliable. Appears undesirable. It will also guarantee that you'll never get laid.

I know someone bought 1988 Honda. Made a sharp turn - front wheel fell off.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#180
post #170

Articles like this make me love my 2000 Subaru even more. I'm gonna hate getting a newer car one day, but maybe by then manufacturers will better secure their cars.

You should look at crash tests results of your 2000 Subaru and a car more modern than 2013 and decide which you'd rather be in in the result of a crash. I'm less scared of a potential hacker cutting power to my car than I am of the millions of poor drivers cutting lanes and changing lanes without signals (or even looking) resulting in an auto accident. Things started improving in the 90's (falling from 143m to 115m).…

Newer safety regulations definitely help, but at the same time, I almost feel like we're reaching a point where we're at pendulum overswing to some degree.

That biggest change since 2012 has been increased roof strength requirements. This was driven at least in part due to the popularity of top-heavy, rollover prone vehicles.

Meeting these requirements have required cars to get heavier and incorporate massive roof pillars. This negatively impacts gas mileage (relatively minor concern), but, far more importantly IMO, means that nearly every new car out there has awful rear visibility. So we've bandaided that by requiring backup cameras, but those don't help when you're moving in traffic. We've created a situation where most new cars on the road have huge, terrible blindspots by trying to make the cars safer.

Again, better safety is a good thing, i just think that we just need to do a better job of balancing it with the usability of the vehicles.

Post reply on HN