Live data from Hacker News

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

eaton-works.com

41–50 of 64 posts

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#41
post #39
post #2

> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.

reminder, Volvo is Chinese.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#42
post #39
post #2

> November 3, 2025: Reported. > November 10, 2025: No response, followed up. > November 17, 2025: No response, followed up and copied some additional people on the thread. > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed. > July 27, 2026: Published Quite the generous timeline on this person's behalf.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.

I don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity.

Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#43

Earlier quoted context omitted.

>modern cars Tesla doesn't have this problem. It just works. No cloud needed, other than at the time of purchase.

That's only because they were all designed before the always-on spyware madness began.

They send over-the-air updates all the time. If they project that it'll be profitable, they'll switch everybody over as soon as you can say the words.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#44
post #41
post #39

Earlier quoted context omitted.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.

reminder, Volvo is Chinese.

How so? Sources?

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#45
post #41

Earlier quoted context omitted.

reminder, Volvo is Chinese.

How so? Sources?

Geely bought it from Ford in 2010.

https://www.reuters.com/article/business/geely-signs-18-bill...

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#46

Earlier quoted context omitted.

How so? Sources?

Geely bought it from Ford in 2010. https://www.reuters.com/article/business/geely-signs-18-bill...

That would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#47

Earlier quoted context omitted.

Geely bought it from Ford in 2010. https://www.reuters.com/article/business/geely-signs-18-bill...

That would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)

Oh, fair. I assumed this was consumer cars.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#48
post #28

Earlier quoted context omitted.

Rivian let's you disable all connectivity. https://news.ycombinator.com/item?id=47967786

You can disable connectivity in any car by pulling fuses.

Not without consequences.

You could be sacrificing other features, increasing your increase premiums (or get claims denied) or potentially breaking the law.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#49
post #5

This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car. Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy. On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home becaus…

Should honestly be a matter of national security. A bad actor could brick and entire county's vehicles

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#50
post #48
post #28

Earlier quoted context omitted.

You can disable connectivity in any car by pulling fuses.

Not without consequences. You could be sacrificing other features, increasing your increase premiums (or get claims denied) or potentially breaking the law.

Telematics systems for insurance are not even lawful in my state.
Post reply on HN