Live data from Hacker News

Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

neowin.net

21–30 of 225 posts

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#21
post #14

This seems like a clickbait title because I’ve never hear of a hardware upgrade being called a “patch”.

I don't think the patch is hardware. The hardware they're talking about is the "Gameboy like device" that runs the exploit.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#23

[flagged]

This isn't about normal wear-and-tear but a fundamental security design flaw that allows thieves to steal these cars with a $25 device exploiting the CAN bus - more akin to GM shipping cars with a master key hidden under the floor mat than a pickable lock.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#25
post #2

Maybe a better link: https://www.theverge.com/news/757205/hyundai-ioniq-5-securit...

Also frustrating but for different reasons:

> in 2023 over the “Kia Boyz” attacks that allowed thieves to bypass a vehicle’s security system using a USB cable.

The USB cable happened to have the right size to engage the starter mechanism. Any physical object with similar dimensions could have been used. It really undercuts how absolutely terrible the Kia security design was around that component.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#26

[flagged]

I think your take makes more sense in a world where you actually own the car fully and have the freedom to do what you want with it. Even if someone was able to write this patch themselves without the source code, distributing it would require owners to root their devices, which isn't legal in all jurisdictions.

You don't expect Microsoft or Adobe to issue fixes any time someone finds a remote exploit that let's attackers gain control of you system though security issue in their software? I 100% expect this of my software vendors even for this purchase in the past. The expectations for software and hardware are certainly very different, but even for hardware we have laws that force companies to fix their hardware in some situations.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#27

[flagged]

> I know the locks on my car are easily picked

They aren't actually. Which is why theives just smash your windows. In either case the alarm is going to go off so there's no advantage to them learning a complex attack on your lock cylinder when a piece of concrete will do.

Further there often were additional ignition interlock mechanisms that required the correct key code or a key with the correct additional hardware to be present for the starter cylinder to actually engage your starter.

> didn't know Hyundai owners were so entitled.

It's called a defect. It should be a recall. We have laws that cover this. They're pretty explicit. I didn't know Hyundai CORPORATION was so entitled as to think they were not subject to them.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#28

[flagged]

> I know the locks on my car are easily picked They aren't actually. Which is why theives just smash your windows. In either case the alarm is going to go off so there's no advantage to them learning a complex attack on your lock cylinder when a piece of concrete will do. Further there often were additional ignition interlock mechanisms that required the correct key code or a key with the correct additional hardware…

It's not ease, it's efficiency: opening a locked car door is 1-2 minutes for an experienced person. Smashing the window is 2 seconds (though you also need some experience, as modern car side windows are also laminated).

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#29

Earlier quoted context omitted.

I don't even like Hyundai. What's "unrealistic and childish" is expecting free labour.

Other manufacturers treat defects in their products by doing a recall and wearing the costs of their mistake. Asking customers to pay for the actually-secure retrofit is certainly a choice. I hope the small amount of money recovered was worth it, Hyundai/Kia just disappeared from my consideration for any future vehicle.

>Other manufacturers treat defects in their products by doing a recall and wearing the costs of their mistake.

No.

Other manufacturers treat defects with recalls after analyzing the fiscal prospect of doing so, and determining whether or not state/regional laws require them to do it.

Here's one of the "not that wrong" scenes from Fight Club to better explain[0].

[0]: https://www.youtube.com/watch?v=SiB8GVMNJkE

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#30

[flagged]

> I know the locks on my car are easily picked They aren't actually. Which is why theives just smash your windows. In either case the alarm is going to go off so there's no advantage to them learning a complex attack on your lock cylinder when a piece of concrete will do. Further there often were additional ignition interlock mechanisms that required the correct key code or a key with the correct additional hardware…

I agree Hyundai should fix this for free (would make up a small portion of the bad PR for having this issue in the first place), but don't forced recalls usually only apply to defects that cause safety issues?

I'm not sure this would fit the definition of a product safety defect.

Post reply on HN