Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

71–80 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#71
post #28

EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion…

I hate touchscreen buttons too and unfortunately all EVs I've seen have adopted that. I wonder if there are EVs with good old fashioned mechanical buttons.

Many EVs have a sensible amount of buttons, and you generally don’t need the touchscreen for driving or much else for that matter.

I can even keep driving while the whole system is rebooting. Around here (where we have many immigrants and some odd practices) I’ve seen people with a towel hanging over their screen while driving, to protect it like a dust cover I guess.

The one thing you might argue I do need from my screen is the speed, which is very easy to see and usually not needed in the flow of traffic.

The outcry against screens is just misinformed imho. My car has plenty of mechanical buttons.

Re: VW breach exposes location of 800k electric vehicles

#72
post #52

Earlier quoted context omitted.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags. There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, w…

This would require a key per app installation, my SO has the app installed too for example. It would also introduce a lot of additional failure modes. Doable but not exactly trivial.

It would work exactly like how you can send an encrypted email to multiple recipients and each of them can decrypt it despite having different private keys. That part isn’t rocket science.

Re: VW breach exposes location of 800k electric vehicles

#73
post #12

Hey EU, maybe mandate an opt out for all vehicle telemetry? Then maybe the rest of the world will follow suit. I know, I know, I am kidding myself.

VW do use opt-in. In fact it is so annoying that you get asked every time when you start your car. So basically every time your car start it says „do you want to use the profile connected with the vw service“ if you do not accept it than the car will be in a dumb mode. One of my coworkers was annoyed by it and „reset“ the car to use a non connected profile which does not do that.

I’m a owner of a id.4 (or rather a user of it, since my company owns it)

Re: VW breach exposes location of 800k electric vehicles

#74
post #52

Earlier quoted context omitted.

Ackhually, it is that hard, unless your method relies on millions of your devices out in the wild acting as sensors in a mesh network, as Apple does.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags. There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, w…

You cannot establish a private channel between app and car if you don’t already have either a pre-shared secret, or pre-shared trusted certification authority keys (such as to allow TLS-like tamper-resistant encrypted communication between app and car) that VW can’t replace.

Otherwise, if there is no pre-existing private channel, the key (which by the way would have to be the public key, not the private key) could be switched out by VW acting as a man-in-the-middle, allowing it to access all encrypted content going through it.

The same is true for Apple. There are parts of the protocol or the pairing where you have to trust Apple, either their servers, or if the establishment happens locally via bluetooth or similar, their software that runs on the local devices.

Re: VW breach exposes location of 800k electric vehicles

#75
post #28

EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion…

One person’s useless extra is another person’s collision avoidance system, AC, music system… I like extras when they make sense.

Re: VW breach exposes location of 800k electric vehicles

#76

Earlier quoted context omitted.

It's opt-out on my Renault Megane e-Tech. It was a very clear prompt during initial setup, and it shows me a very unambiguous notification that it's enabled every time I start the car. If I click on that it takes me to the setting. edit: might even have been opt-in during initial setup, now that I think about it. I do recall it being a very deliberate thing during setup. Of course I'll have to trust that turning it o…

The opt-out should be pulling the telematics fuse. Unless you can audit the source code, you can't, and shouldn't, trust the software.

That might be impossible with mandatory eCall: https://en.wikipedia.org/wiki/ECall

Re: VW breach exposes location of 800k electric vehicles

#77
I wonder if they were all petrol vehicles, or all diesel if that would be so prominent in the headline. The drive train has nothing to do with an unsecured s3 bucket, and if you think that electric vehicles are the only “connected” cars in 2024, you’re in for a shock.

Re: VW breach exposes location of 800k electric vehicles

#78
post #73
post #12

Hey EU, maybe mandate an opt out for all vehicle telemetry? Then maybe the rest of the world will follow suit. I know, I know, I am kidding myself.

VW do use opt-in. In fact it is so annoying that you get asked every time when you start your car. So basically every time your car start it says „do you want to use the profile connected with the vw service“ if you do not accept it than the car will be in a dumb mode. One of my coworkers was annoyed by it and „reset“ the car to use a non connected profile which does not do that. I’m a owner of a id.4 (or rather a us…

Reminds me of cookie banners. Annoy you into submission

(I know the EU doesn't mandate annoying cookie banners but unintended consequences etc)

Re: VW breach exposes location of 800k electric vehicles

#79

Earlier quoted context omitted.

> The data is collected even if you don't use the app or hit agree It’s irrelevant. The matter of the discussion is “cannot drive a car without hitting I agree button”.

The post you were responding to is specifically about the lack of consent, not whether the button is necessary.

[deleted]

Re: VW breach exposes location of 800k electric vehicles

#80

Earlier quoted context omitted.

> The data is collected even if you don't use the app or hit agree It’s irrelevant. The matter of the discussion is “cannot drive a car without hitting I agree button”.

The post you were responding to is specifically about the lack of consent, not whether the button is necessary.

I don’t think so. They even double down on the button: https://news.ycombinator.com/item?id=42525040.
Post reply on HN