Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

81–90 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#81
post #72

Earlier quoted context omitted.

This would require a key per app installation, my SO has the app installed too for example. It would also introduce a lot of additional failure modes. Doable but not exactly trivial.

It would work exactly like how you can send an encrypted email to multiple recipients and each of them can decrypt it despite having different private keys. That part isn’t rocket science.

Indeed, it's making it work reliably and with zero friction given both apps and car will have variable internet access.

Re: VW breach exposes location of 800k electric vehicles

#82
post #58

Earlier quoted context omitted.

I’d love to see that implemented, yes, but it would be even better if all cars' speed were automatically limited to the speed limit of each road.

Dangerous as hell. Imagine there’s a runaway truck behind you and you can’t speed up to avoid or at least soften the collision because of some government enforced handicap. It would also give local governments a power they never had before: To directly control your behavior in the moment, with no judicial control or oversight. No, thank you.

There will always be contrived bogeyman edge cases to scare us from doing something.

The only question that matters is would it result in fewer road deaths? I bet the answer is yes.

In the US every single day 100 families are torn apart by a death on the road. I’m sure you don’t want it to be yours.

Re: VW breach exposes location of 800k electric vehicles

#83
post #82
post #58

Earlier quoted context omitted.

Dangerous as hell. Imagine there’s a runaway truck behind you and you can’t speed up to avoid or at least soften the collision because of some government enforced handicap. It would also give local governments a power they never had before: To directly control your behavior in the moment, with no judicial control or oversight. No, thank you.

There will always be contrived bogeyman edge cases to scare us from doing something. The only question that matters is would it result in fewer road deaths? I bet the answer is yes. In the US every single day 100 families are torn apart by a death on the road. I’m sure you don’t want it to be yours.

That’s a “think of the children” type of an argument. Remind me: how many people die because of guns every day in the US? On a serious note, how many of those road accidents are caused by exceeding the speed by less than 10%? You see, there is a difference between speeding and reckless driving.

Neither you nor me live in the US. They have other options to reduce those deaths. There’s no reason to drive a 4 ton EV truck made out of stainless steel doing 0 to 60 mph in 3 seconds.

Re: VW breach exposes location of 800k electric vehicles

#84
post #56

Why the sideways fuck did they even have location data to begin with? It's like the checklist for buying a new car starts with figuring out what circuit drives the cell modem and pop that fuse out before taking a test drive to confirm it doesn't brick anything critical. Fucking ridiculous.

Most new cars have features that require it such as onboard GPS, speed limits on the dash, OnStar and similar features.

Those are mostly things that require the car to know its location. They don't require that the car share the location with the car's maker except possibly sharing what region the car is in.

The region sharing might be needed to efficiently update things like the map and the speed limits.

Re: VW breach exposes location of 800k electric vehicles

#85
post #74
post #52

Earlier quoted context omitted.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags. There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, w…

You cannot establish a private channel between app and car if you don’t already have either a pre-shared secret, or pre-shared trusted certification authority keys (such as to allow TLS-like tamper-resistant encrypted communication between app and car) that VW can’t replace. Otherwise, if there is no pre-existing private channel, the key (which by the way would have to be the public key, not the private key) could be…

This argument seems like a fairly extreme example of the perfect being the enemy of the good. Sure, it would require a more advanced system for VW to prevent themselves from silently compromising their own system to learn everyone’s location. But the design I outlined will prevent a passive compromise of VW, and even possibly a court order, from learned everyone’s location, and it prevents even an active and highly malicious compromise from learning past locations.

Re: VW breach exposes location of 800k electric vehicles

#86
post #72

Earlier quoted context omitted.

It would work exactly like how you can send an encrypted email to multiple recipients and each of them can decrypt it despite having different private keys. That part isn’t rocket science.

Indeed, it's making it work reliably and with zero friction given both apps and car will have variable internet access.

This is not hard. App login sets up a session with VW (which is surely already does), except the session needs a database entry and not just a JWT-like token. (Many auth frameworks do this anyway.) The database row needs to add a public key, and the server needs to send all the key changes to the car. And that’s about it.

Re: VW breach exposes location of 800k electric vehicles

#87
post #86

Earlier quoted context omitted.

Indeed, it's making it work reliably and with zero friction given both apps and car will have variable internet access.

This is not hard. App login sets up a session with VW (which is surely already does), except the session needs a database entry and not just a JWT-like token. (Many auth frameworks do this anyway.) The database row needs to add a public key, and the server needs to send all the key changes to the car. And that’s about it.

Again, that's the easy part. The hard part is making it work reliably in the real world.

Re: VW breach exposes location of 800k electric vehicles

#88
post #71

Earlier quoted context omitted.

I hate touchscreen buttons too and unfortunately all EVs I've seen have adopted that. I wonder if there are EVs with good old fashioned mechanical buttons.

Many EVs have a sensible amount of buttons, and you generally don’t need the touchscreen for driving or much else for that matter. I can even keep driving while the whole system is rebooting. Around here (where we have many immigrants and some odd practices) I’ve seen people with a towel hanging over their screen while driving, to protect it like a dust cover I guess. The one thing you might argue I do need from my s…

What model is your car?

Re: VW breach exposes location of 800k electric vehicles

#89
Best of from 38th CCC: every three letter secret service of the country seems to be spyied out by this. And a secret VW testing facility in sweden was uncovered.

Also, effects mostly EVs, but not only. (If the EV motor was the group usually logged to the opened AWS bucket, I don't understand how there were ICE or possibly hybrid cars involved in the leak.)

https://streaming.media.ccc.de/38c3/ had a german language video on it, live, but will surely add english translation and permanent video link soon.

Re: VW breach exposes location of 800k electric vehicles

#90

Earlier quoted context omitted.

I’d love to see that implemented, yes, but it would be even better if all cars' speed were automatically limited to the speed limit of each road.

As long as it’s accurate. The current technical implementation is a joke. The car has no idea what the speed limit is. A few examples: 1) drive past the end of town sign in a particular German town, the car thinks it is 30kph, but only during the day because at night it doesn’t see the sign so it thinks it’s 50 where in reality it’s a 100 until the next speed limit, 2) driving between a couple of roundabouts inside o…

> So what is going to happen when that mythical zero casualties is reached and more people will be dying on bicycles than in car accidents?

I don't think anything will need to happen at that point. We wouldn't need to tackle down the top causes of death if the numbers were low, as seems to be the case of bicycle deaths not caused by cars. And when it comes to speeding, it's already against the law, so the technology is only trying to help prevent it. But of course, my enthusiasm is tied to a future where this technology works reliably, so I don't really expect anything like it with all the problems you're describing with current models.

Post reply on HN