Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

21–30 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#22

That could be a nail in the coffin to end VW, the EU GDPR is quite a sharp weapon.

The problem was caused by Cariad, not VW directly. Cariad will be held responsible for, not VW.

CARIAD is a 100%-owned subsidiary of the Volkswagen group.

Re: VW breach exposes location of 800k electric vehicles

#23
post #12

Hey EU, maybe mandate an opt out for all vehicle telemetry? Then maybe the rest of the world will follow suit. I know, I know, I am kidding myself.

The reason for all that telemetry is the legislation. How do you think they are going to implement the full “intelligent” speed assistant in 2027?

More like automated ticketing for speeding.

Re: VW breach exposes location of 800k electric vehicles

#24

Earlier quoted context omitted.

Opt in you mean, like the cookie banners? Oh no that'll never happen because VW are a European company and the money is in fining US tech companies!

European companies get fined the same as any other companies.

Well within the constraints they set out which exclude a hell of a lot of European companies.

(I am in Europe for reference, this is not an external perspective)

Re: VW breach exposes location of 800k electric vehicles

#25

Earlier quoted context omitted.

Eh, "consented to" is rather weak when you are forced to hit the "I agree" button to be able to drive the car you bought. That and forced arbitration need to die posthaste.

I refuse to believe that it’s not possible to drive the car without the app.

And I'm skeptical that it is. Happy Friday.

Re: VW breach exposes location of 800k electric vehicles

#26

If it so bad there is actually a whistleblower then how do they pass their ISO27001 audits? Bit too friendly with TUV Nord? https://cariad.technology/content/dam/digitalmindofmobility/... EDIT: Just noticed this is an ISO9001 certificate. Though on their job offer site they do ask for "Foundational understanding of security related regulations and standards preferred (e.g. ISO21434, ISO27001, NIST-800)". Unclear if t…

The fact that you have passed audits isn't a guarantee (or even an indication) that you don't have major security vulnerabilities.

Re: VW breach exposes location of 800k electric vehicles

#27

Earlier quoted context omitted.

Eh, "consented to" is rather weak when you are forced to hit the "I agree" button to be able to drive the car you bought. That and forced arbitration need to die posthaste.

I refuse to believe that it’s not possible to drive the car without the app.

Back in the day, during the original Browser Wars, when the US Department Of Justice was trying to force Microsoft to detach Internet Explorer from Windows, Microsoft argued that it was impossible for Windows to operate without IE baked in. Well, it took a couple of "hackers" about a day to prove them wrong. I ran Windows XP without IE for years just fine. So yeah, cars can run without the app.

Re: VW breach exposes location of 800k electric vehicles

#28
EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion ...

Re: VW breach exposes location of 800k electric vehicles

#29

Earlier quoted context omitted.

The problem was caused by Cariad, not VW directly. Cariad will be held responsible for, not VW.

CARIAD is a 100%-owned subsidiary of the Volkswagen group.

It’s their bad software bank.

Re: VW breach exposes location of 800k electric vehicles

#30
post #12

Hey EU, maybe mandate an opt out for all vehicle telemetry? Then maybe the rest of the world will follow suit. I know, I know, I am kidding myself.

It's opt-out on my Renault Megane e-Tech.

It was a very clear prompt during initial setup, and it shows me a very unambiguous notification that it's enabled every time I start the car. If I click on that it takes me to the setting.

edit: might even have been opt-in during initial setup, now that I think about it. I do recall it being a very deliberate thing during setup.

Of course I'll have to trust that turning it off actually turns it off, no way for me to verify that.

The reason I keep it on is because my SO is a bit absent minded to where she parks the car, and I value not having to run around in the streets trying to find it when I'm in a hurry over the potential privacy loss.

edit: Renault was found[1][2] to be the "least problematic" with respect to privacy by Mozilla last year.

[1]: https://foundation.mozilla.org/en/blog/privacy-nightmare-on-...

[2]: https://news.ycombinator.com/item?id=37443644

Post reply on HN