Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

51–60 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#51
post #7

Earlier quoted context omitted.

I think even in the EU, VW group is "too big to fail".

Too big to fail and too much of it is state owned, either directly, or through government-owned retirement funds. The government will investigate itself and find no wrongdoings, let's go after the journalists who committed the ultimate crime: Embarassing Officials.

Oh yea, that big gubmint is the one to blame!

Never mind that it's a for-profit company that does the surveiling, and wrote the faulty IT structure.

Neoliberal religion runs deep...

Re: VW breach exposes location of 800k electric vehicles

#52
post #47

Earlier quoted context omitted.

Apple knows how to allow one to find one’s devices without Apple knowing where they are. It’s not that hard.

Ackhually, it is that hard, unless your method relies on millions of your devices out in the wild acting as sensors in a mesh network, as Apple does.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags.

There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, which decrypts it. But VW can’t decrypt the report itself, so they don’t know the location of the car. Also, it’s forward secure in the sense that a leak of VW’s database is entirely useless after a day.

Re: VW breach exposes location of 800k electric vehicles

#53
post #8
post #5

Why is nobody talking about the fact that this should not be possible? There is precisely zero reason for them to have this location data. Give the CEO one year of jail per person whose location was illegally tracked.

On the contrary it's relatively simple to understand how it got there trivially. Most modern cars, especially ones that fit into more "luxury" brands have an app. That app gives you telemetry and location data for a price. It's rather convenient to be able to pre-condition your car, or figure out where you parked in a massive unlabeled parking lot, etc. This is all consented to, but regardless the data is tracked any…

[deleted]

Re: VW breach exposes location of 800k electric vehicles

#54
post #45

Earlier quoted context omitted.

I’d love to see that implemented, yes, but it would be even better if all cars' speed were automatically limited to the speed limit of each road.

That would risk unintended consequences. For example, suddenly slowing cars on the highway down to 30 kph because a small road with that speed limit runs right next to the highway.

This becomes a thing and I'll have a 25mph sign hanging off the back of my truck. I eagerly await starting a youtube channel of new cars losing their shit on jammed tailgating attempts.

Re: VW breach exposes location of 800k electric vehicles

#55
post #21

That could be a nail in the coffin to end VW, the EU GDPR is quite a sharp weapon.

The EU won't do much, because this is a car company. Car companies run the EU, basically, especially German ones.

Not surprisingly as the EU grew out of post war coal and steel association

Re: VW breach exposes location of 800k electric vehicles

#56

Why the sideways fuck did they even have location data to begin with? It's like the checklist for buying a new car starts with figuring out what circuit drives the cell modem and pop that fuse out before taking a test drive to confirm it doesn't brick anything critical. Fucking ridiculous.

Most new cars have features that require it such as onboard GPS, speed limits on the dash, OnStar and similar features.

Re: VW breach exposes location of 800k electric vehicles

#57
post #56

Why the sideways fuck did they even have location data to begin with? It's like the checklist for buying a new car starts with figuring out what circuit drives the cell modem and pop that fuse out before taking a test drive to confirm it doesn't brick anything critical. Fucking ridiculous.

Most new cars have features that require it such as onboard GPS, speed limits on the dash, OnStar and similar features.

All bullshit my car shouldn't do in the first place.

Re: VW breach exposes location of 800k electric vehicles

#58

Earlier quoted context omitted.

More like automated ticketing for speeding.

I’d love to see that implemented, yes, but it would be even better if all cars' speed were automatically limited to the speed limit of each road.

Dangerous as hell. Imagine there’s a runaway truck behind you and you can’t speed up to avoid or at least soften the collision because of some government enforced handicap.

It would also give local governments a power they never had before: To directly control your behavior in the moment, with no judicial control or oversight.

No, thank you.

Re: VW breach exposes location of 800k electric vehicles

#59
post #52

Earlier quoted context omitted.

Ackhually, it is that hard, unless your method relies on millions of your devices out in the wild acting as sensors in a mesh network, as Apple does.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags. There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, w…

This would require a key per app installation, my SO has the app installed too for example.

It would also introduce a lot of additional failure modes.

Doable but not exactly trivial.

Post reply on HN