Live data from Hacker News

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

eaton-works.com

11–20 of 64 posts

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#11
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?

Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#12
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

Agreed that it's absurd. Consumers continue to purchase cars that do this though. BMW doing this, having proprietary bolt heads, and the subscription heated seats fiasco from nearly a decade ago have made it clear that BMW is a make that will try to screw you at every turn, yet people continue to purchase them.

It's a shame. I will continue to purchase vehicles with as internet connected and touch screen features as possible. My 2025 Toyota has knobs and a physical key still. Terrified what will be left on the market when I have to get a new vehicle in (hopefully over) 15 years.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#13
post #11
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed? Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories u…

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time

I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped with phone-as-key.

The phone-as-key shouldn't only work when online and shouldn't require the car to be online, either. And this is a problem trivially solved with proper use of cryptography.

The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. Just like I don't carry two car keys.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#14
post #13
post #11

Earlier quoted context omitted.

>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed? Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories u…

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

It doesn't; BMW use the CCC Digital Key standard for "Digital Key Plus" and there's no Internet required post provisioning. This story really reeks of misunderstanding or "needs more information" as for BMW especially, I don't see any scenario where this could have happened, regardless of physical or phone key use.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#15
post #13
post #11

Earlier quoted context omitted.

>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed? Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories u…

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup.

How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention there are plenty of other ways a phone can fail. It can fall into a toilet, you can drop it and the screen cracks, etc. By not carrying the keys, you're rolling the dice every time.

>Just like I don't carry two car keys.

That all depends on your risk appetite. I normally wouldn't carry money in my socks, but if I'm in a foreign country I very well might. Likewise if I'm going on a road trip where I might be days away from home, I very well might bring a second key, in case i accidentally lock one in the car or whatever.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#16
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

I just want the most basic, no-frills EV truck. I'd even pay a premium over what such a thing _should_ cost. I want no cloud connectivity _at all_ unless I add it myself in some way.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#17
post #15
post #13

Earlier quoted context omitted.

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works

Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable.

Unlocking my car needs me, and my car.

> when the payment terminal randomly decides to not accept apple pay?

I would be justified in being mad if, randomly, my BMW car would decide to not accept a BMW key (virtualized or otherwise).

> Not to mention there are plenty of other ways a phone can fail. It can [...]

"I will not accept this Euro bank note. You could have dropped it into the gutter on your way here, so it's strange for you to be mad at me if you don't have a backup."

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#18
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

I just want the most basic, no-frills EV truck. I'd even pay a premium over what such a thing _should_ cost. I want no cloud connectivity _at all_ unless I add it myself in some way.

You might want to check out Slate:

https://www.slate.auto/en

No embeded modem.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#19
post #15
post #13

Earlier quoted context omitted.

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

It's very different, because you aren't moving from car to car. You're using your car with your digital key. There is no expectation of things changing. Rightly so.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#20
post #2

> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.

And terrible (non-)response from VECV, if they have any interest in receiving timely disclosure from future researchers.
Post reply on HN