Live data from Hacker News

Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

neowin.net

31–40 of 225 posts

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#32
post #7

Earlier quoted context omitted.

I didn't know Hyundai corporate defenders were so unrealistic and childish.

I don't even like Hyundai. What's "unrealistic and childish" is expecting free labour.

Well if your car had a seat belt defect and people were dying you know they absolutely would recall the car and pay for the defect.

The defect that allows the car to be stolen in seconds is absolutely a serious problem. I hope Hyundai changes course and decides to provide it for free. We have already seen reports of the trend where people were stealing Hyundai/Kia vehicles and going on joy rides driving extremely dangerously. This has lead to deaths in several instances. So they have a flaw that has lead to people dying. IANAL but I would say leaving this flaw unpatched may even leave them liable if anyone else were to be hurt. As a recent example of something similar is the Sig Sauer P320. They are in the middle of fighting some lawsuits over their faulty product. So it would not be a far stretch if Hyundai/Kia were held responsible for a know flaw in their product.

Anyways it is just my opinion that they should just eat the cost to provide this for free as a show of standing behind their product. Just seems like such bad PR to now make people pay.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#33
post #22

They're swapping out hardware, which is why they're asking money for this to compensate the labor costs. Not saying this justifies it, but the title is misleading.

Agree the title is a bit misleading, but addressing what sounds like an exploit still feels like a patch of sorts.

But yeah, “patch” usually implies software vs. hardware.

Either way, agree with other comments that Hyundai should just eat the costs if it prevents theft due to an exploit.

Having said that, given what the car costs, the fee doesn’t seem completely unreasonable.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#34
post #8

Earlier quoted context omitted.

Sure, that could be a decent legal regime. The first step to enabling it would be releasing the source code and system documentation for the product they've sold, so that it's even possible for anyone else besides themselves to fix it. Until then it's a black box the company has chosen to retain responsibility for. And frankly regulators should be making sure they support the 20-40 years of useful life we generally e…

I think you significantly overestimate people’s expectations for automobiles.

I'm not talking about individuals' expectations for how long they personally will use a given vehicle, but rather societal expectations for how long a given vehicle will live across all tiers of the market. The cell phone made-to-be-ewaste model shouldn't be allowed to infect capital assets costing 100x as much.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#35

[flagged]

This isn't about normal wear-and-tear but a fundamental security design flaw that allows thieves to steal these cars with a $25 device exploiting the CAN bus - more akin to GM shipping cars with a master key hidden under the floor mat than a pickable lock.

Except even more egregious, because if your GM car had a master key under the floor mat, you could just remove it yourself and throw it down a handy storm sewer.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#36
post #32

Earlier quoted context omitted.

I don't even like Hyundai. What's "unrealistic and childish" is expecting free labour.

Well if your car had a seat belt defect and people were dying you know they absolutely would recall the car and pay for the defect. The defect that allows the car to be stolen in seconds is absolutely a serious problem. I hope Hyundai changes course and decides to provide it for free. We have already seen reports of the trend where people were stealing Hyundai/Kia vehicles and going on joy rides driving extremely dan…

I think the deaths might qualify the cars as an attractive nuisance at this point. Although The Club is only about $50.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#39
post #2

Maybe a better link: https://www.theverge.com/news/757205/hyundai-ioniq-5-securit...

Also frustrating but for different reasons: > in 2023 over the “Kia Boyz” attacks that allowed thieves to bypass a vehicle’s security system using a USB cable. The USB cable happened to have the right size to engage the starter mechanism. Any physical object with similar dimensions could have been used. It really undercuts how absolutely terrible the Kia security design was around that component.

In some vehicles, their "software fix" literally did nothing but move thieves from smashing a window to screwdriver'ing the driver door lock.

More work for the thieves, but hardly a fix to inspire confidence.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#40
post #14

This seems like a clickbait title because I’ve never hear of a hardware upgrade being called a “patch”.

I don't think the patch is hardware. The hardware they're talking about is the "Gameboy like device" that runs the exploit.

> The Verge now reports that Hyundai is offering a security patch for this issue through software and hardware upgrades to Ioniq 5 customers.

You do a hardware upgrade on the car to patch the vulnerability.

Post reply on HN