Live data from Hacker News

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

eaton-works.com

31–40 of 64 posts

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#31

Earlier quoted context omitted.

I just want the most basic, no-frills EV truck. I'd even pay a premium over what such a thing _should_ cost. I want no cloud connectivity _at all_ unless I add it myself in some way.

Rivian let's you disable all connectivity. https://news.ycombinator.com/item?id=47967786

That is admirable, though of course it should be a legal standard, and there should also be legal standards for building features in a way that allows you to use them when your data collection is disabled.

Disabling data collection shouldn’t disable entire major features like lane centering and navigation. Even tech giant spyware companies like Google offer offline maps.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#32
post #17
post #15

Earlier quoted context omitted.

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable. Unlocking my car needs me, and my car. > when the payment terminal randomly decides to not accept apple pay? I would be justified in being mad if, randomly, my BMW car would decide to not accept…

Apple Pay even works if the phone/watch battery is "dead"

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#33
post #4

Earlier quoted context omitted.

In this case, AI wasn't used for anything.

I believe that it was used to generate the post that you replied to.

The person you are replying to wrote that post.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#34
post #4

Earlier quoted context omitted.

In this case, AI wasn't used for anything.

I believe that it was used to generate the post that you replied to.

AI driven/automated farming for kharma will only get worse...

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#35
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

>modern cars

Tesla doesn't have this problem. It just works. No cloud needed, other than at the time of purchase.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#36
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

>modern cars Tesla doesn't have this problem. It just works. No cloud needed, other than at the time of purchase.

That's only because they were all designed before the always-on spyware madness began.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#37
post #15
post #13

Earlier quoted context omitted.

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work.

Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regular EMV contactless cards to communicate, it just happens to be a powered microprocessor instead of a radio-powered microprocessor but that's about the only difference. The smart card standard is really old and covers the exact use case of "what happens if I need to use this thing without the Internet because the Internet wasn't ubiquitous when it was developed.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#38
post #28

Earlier quoted context omitted.

Rivian let's you disable all connectivity. https://news.ycombinator.com/item?id=47967786

You can disable connectivity in any car by pulling fuses.

Yeah but sometimes that disables other things too. Like when I pulled the fuse on my car for the radio, it disabled the power door locks and the door/headlight chime. Not every item gets it's own circuit.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#39
post #2

> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
Post reply on HN