Live data from Hacker News

Honda Civics and the Evil Valet

juniperspring.org

71–80 of 105 posts

Re: Honda Civics and the Evil Valet

#72

I wish other car makers were as reasonable as Honda here. No "evil valet" with half a brain cell would waste time hacking the head unit if they have physical access to the car. They would simply hide a spying device somewhere in the car. Not to mention that people with Civics are never targets of three letter agencies.

You think there isn’t some boring scientist or engineer with classified access who doesn’t drive a boring civic to work?

[flagged]

Re: Honda Civics and the Evil Valet

#77

In one thread people fighting the ever decreasing amount of hw ownership of most devices in our lives and when we have one that is more open, the crowds come to attack that too. The theat model with tech has always been that if an attacker has physical access to the device and time then it's game over.

That doesn’t mean you don’t bother to secure the local device. I strongly suspect you have login security in your physical devices. Maybe even full disk encryption.

Just because a sufficiently advanced and determined attacker can own any device with physical access doesn’t mean we might as well make it easy for anyone.

Re: Honda Civics and the Evil Valet

#78
post #22

IMHO this is a good sign(!?) that they didn't even think about locking down their systems against the owner.

It's not good that they allow anyone that happens to be in your car briefly root access. It'd be live having an always-on laptop in your office with a open shell on it. They should have provided some mechanism for the real owner to approve updates if the updates aren't all trusted by default.

How do you validate “the real owner” if having the keys isn’t enough? That sufficient to steal the car.

You could do a PIN/password, but if it is never used during operation, nobody will know it. Ask anyone who’s had a head unit that needed a PIN after losing power.

Re: Honda Civics and the Evil Valet

#80

Most (if not all) cars on the road are terrible in terms of the security of the infotainment system and other onboard electronics. What makes this even worse is the sensors they have onboard these days; the microphones, cameras, GNSS receivers, wifi and BT radios make them into mobile surveillance platforms. In March 2026, a bunch of controls were added to the Australian Government Information Security Manual[0] basi…

They’re fine. It’s a car radio, not a critical system.

The people who are vulnerable to this type of attack have procedures and trusted equipment to conduct their business (or not). US police agencies have had rules like this for rental cars since OnStar came out.

Most of the dangerous telematics information for the average person is offered for sale anyway.

Post reply on HN