Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

131–140 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#131
post #86

Earlier quoted context omitted.

This is not hard. App login sets up a session with VW (which is surely already does), except the session needs a database entry and not just a JWT-like token. (Many auth frameworks do this anyway.) The database row needs to add a public key, and the server needs to send all the key changes to the car. And that’s about it.

Again, that's the easy part. The hard part is making it work reliably in the real world.

What, exactly, makes it hard to get this to work reliably in the real world? The app already won’t work without a valid login session. The car is already sending a little blob of data to the mothership containing a location. If the communication to the mothership changes to having the mothership send a list of keys and the car encrypt its blob, that’s basically it. The total increase in communication needed is one round trip to revalidate keys.

I realize that modern development has layers and layers of documents and teams and overcomplicated interfaces, but this is the kind of thing that could be done by one developer, using two servers and a load balancer (or a more creative HA scheme with client assistance that can easily survive complete loss of a datacenter or two), that can handle the entire fleet.

Re: VW breach exposes location of 800k electric vehicles

#132

We need a way to disable vehicle telemetry. No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely) Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay

No device should be allowed to be sold without the ability to function without telemetry or sale of data to third parties. And telemetry and any data sharing should be opt in, as part of configuring the thing the first time. With a one click opt out of all.

Re: VW breach exposes location of 800k electric vehicles

#133
post #9

Find the guys who usually park at expensive family homes, but occasionally visit a known brothel, then blackmail them. We all just let surveillance haplen to us, in fact we paid for most of it

I once worked for a firm that had access to credit card transaction data and came across almost this exact scenario. Kindergarten transactions one day, escort payments on another. It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.

> An average Joe like me shouldn't be able to

The average joe is merely a side effect of the government collecting all that data. The government is also why your car reports its location.

Re: VW breach exposes location of 800k electric vehicles

#134

We need a way to disable vehicle telemetry. No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely) Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay

No device should be allowed to be sold without the ability to function without telemetry or sale of data to third parties. And telemetry and any data sharing should be opt in, as part of configuring the thing the first time. With a one click opt out of all.

Default Opted Out

Opt In should NOT be required to enable features.

Features should not be rented, and should be delivered as purchased with the car. Shipped but disabled features that take up additional vehicle weight (relative to lacking the feature) should not be allowed. (This phrasing is precise, to allow for silicon and software enhancements which are not a material change to vehicle manufacturing / design.)

Setup processes should always empower the user. If there are multiple choices or paths a default may be indicated, but alternatives MUST NOT be in other locations, and MUST be displayed with equal prominence in a logically adjacent section of the dialog.

Example from a website: 'Paperless' should not be force enabled by default; the ability to have paper or paperless billing should be radio boxes next to each other. Additional benefits (E.G. higher account interest rates) should not be tied to either selection.

Re: VW breach exposes location of 800k electric vehicles

#135

Earlier quoted context omitted.

I once worked for a firm that had access to credit card transaction data and came across almost this exact scenario. Kindergarten transactions one day, escort payments on another. It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.

That's just bad opsec. I would have thought rule number one of soliciting was to be cash only. Ignoring of course that the amount of aggregated surveillance makes it impossible to escape monitoring. Credit cards, license plate scanners, phone GPS, airtags, doorbell cameras, "Eye in the Sky" spy planes, etc

The exact example IS bad opsec... however assume some example fuzzing for good opsec.

Trip to McD's with a price of exactly happy meal + tax one day, and a recurring payment for XXX website OnlyFans access the next. Adjust the values to taste/theory. Sometimes a credit card is just a credit card.

Re: VW breach exposes location of 800k electric vehicles

#136

We need a way to disable vehicle telemetry. No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely) Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay

No device should be allowed to be sold without the ability to function without telemetry or sale of data to third parties. And telemetry and any data sharing should be opt in, as part of configuring the thing the first time. With a one click opt out of all.

Expand this to any product. I should be able to use ANY product fully, without maintaining some kind of communication channel to and/or from the product's manufacturer. When I buy a hammer from Home Depot, I take it home and hammer with it. The manufacturer doesn't know I have it, doesn't know how many nails per month I hammer with it, how many swings it takes on average for me to drive in a nail, how often I use the claw side. They don't know if I use it for other purposes besides hammering nails. They don't know if I lend it to my neighbor. I can sell it to someone else without the manufacturer's permission.

Somehow hammer manufacturers can live with this. Why can't automakers, tech device manufacturers, and software developers live with this?

Re: VW breach exposes location of 800k electric vehicles

#137
post #28

EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion…

In a lot of cars you can pull the fuse that powers the cellular modem without any side effects

Re: VW breach exposes location of 800k electric vehicles

#138
post #9

Find the guys who usually park at expensive family homes, but occasionally visit a known brothel, then blackmail them. We all just let surveillance haplen to us, in fact we paid for most of it

I once worked for a firm that had access to credit card transaction data and came across almost this exact scenario. Kindergarten transactions one day, escort payments on another. It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.

[flagged]

Re: VW breach exposes location of 800k electric vehicles

#139

The answer is simple: No matter the reason, if you have a data breach you must pay each person 100$ min with higher amounts depending on the information lost. Additionally, if that information is used in a crime then you are liable for further damages. Car companies, and other data vacuums, will just stop collecting it if they are liable for what happens to it. I will not buy a car that does this. I am starting to tu…

The $100 thing is kind of a standard that a European court just established in a Facebook data leak case!

In the case of full location data, it would need to be a lot more though. Yes, that might bankrupt the company. They should have thought about that before they illegally stalked nearly a million people then put their highly sensitive data on the Internet.

If I did this to one person, I'd probably (and rightfully) go to jail. I'd like the same standard applied here.

Re: VW breach exposes location of 800k electric vehicles

#140
post #28

EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion…

In a lot of cars you can pull the fuse that powers the cellular modem without any side effects

you're taking to a bunch of old men shouting (literally) at clouds
Post reply on HN