> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
41–50 of 64 posts
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#42> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#43Earlier quoted context omitted.
>modern cars Tesla doesn't have this problem. It just works. No cloud needed, other than at the time of purchase.
That's only because they were all designed before the always-on spyware madness began.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#44Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#45Earlier quoted context omitted.
reminder, Volvo is Chinese.
How so? Sources?
https://www.reuters.com/article/business/geely-signs-18-bill...
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#46Earlier quoted context omitted.
How so? Sources?
Geely bought it from Ford in 2010. https://www.reuters.com/article/business/geely-signs-18-bill...
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#47Earlier quoted context omitted.
Geely bought it from Ford in 2010. https://www.reuters.com/article/business/geely-signs-18-bill...
That would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#48Earlier quoted context omitted.
Rivian let's you disable all connectivity. https://news.ycombinator.com/item?id=47967786
You can disable connectivity in any car by pulling fuses.
You could be sacrificing other features, increasing your increase premiums (or get claims denied) or potentially breaking the law.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#49This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#50Earlier quoted context omitted.
You can disable connectivity in any car by pulling fuses.
Not without consequences. You could be sacrificing other features, increasing your increase premiums (or get claims denied) or potentially breaking the law.