Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

101–110 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#101

Earlier quoted context omitted.

A recall for what? There's no safety issue here. There's no functional loss. Unless they advertised the car as being unstealable or anything close there's not even a marketing point that's not working as one could reasonably expect. Carmakers call this a theft-deterrant feature, they don't even call it anti-theft or similar. The immobilizer is not as secure as one would hope, but nobody ever promised you anything her…

It's obviously not a safety recall, but that doesn't mean it isn't serious. Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind? "It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#102
post #8

My question is if VW has switched the affected stuff in newer models since they found out about the issues?

Yes, as people mentioned above. It’s long fixed, and only a tiny set of cars (only high-end models with keyless entry) were even affected at all.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#103
post #11

[deleted]

The Thai finance minister, apparently: http://www.smh.com.au/articles/2003/05/13/1052591776195.html "Suchart said he was on his way to give a speech to central bank officials from 17 countries when his ministry-assigned BMW car stalled on a road, not far from his house. The engine stopped, the air conditioning shut down, the doors got locked and the windows wouldn't roll down, he said, adding that he was trapped for…

Within of to minutes no air? That sounds weird.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#104
post #82

Earlier quoted context omitted.

At least in Germany, yes. Usually the key is also secured with multiple other techniques and has a 3-dimensional unique pattern, plus additionally magnetic safety features. And the fact that the car has a steering wheel lock (the steering wheel is locked in the right-most position) is also standard.

Interesting, that seems like a pretty reasonable way to do it. Another case of convenience taking precedence over security, I guess.

The above mentioned vulnerability only applies to very few models, on the North American market, which have the (very costly) extra of keyless entry.

According to my knowledge, keyless entry is even illegal in Germany. (But I am not a lawyer, so I do not know if that applies at all, or if the legal situation just ends up stating that drunk people owning a car with keyless entry may not be close enough to their car that the immobilizer is deactivated)

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#105
post #83
post #74

Earlier quoted context omitted.

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

I doubt you'd say that if you owned one of the affected VWs.

That's the problem, that the judges making the decisions usually don't have skin in the game.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#106
post #98
post #58

Earlier quoted context omitted.

Fair, but only on cars which have only passive security (that is - where you don't need to use the fob to unlock the car and you don't need to use a physical key to turn the ignition).

Which is of course the stock configuration on most modern luxury vehicles.

Most new cars which have keyless systems work exactly like that, nothing to do with luxury cars.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#107
post #100

I have a Passat from late 2013 -- it cannot be remotely started but doors are keyless. Twice in the last 16 months, somebody rummaged through it overnight, without breaking anything. We religiously close the car every night, especially after the first occurrence, but still it happened again. After it happened to my next-door neighbor's 2013 Golf as well, I reported it to VW and they never even bothered getting back t…

I saw a report a while back that if you put your car keys in the freezer or something it blocks enough of the signal from your keys so that someone can't use this signal repeater to unlock your car, it's supposed to act like a Faraday cage (somewhat).

I know it sounds stupid but I remember seeing it on HackerNews a while back. I'm not sure if it was debunked or not.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#108

Earlier quoted context omitted.

It's obviously not a safety recall, but that doesn't mean it isn't serious. Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind? "It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

> It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

It wouldn't fill me with warm and fuzzies if I were sold a high-end door lock / alarm system / safe that was only exploitable with 'special gear and know-how far outside the realm of the typical thief.'

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#109
post #74

Earlier quoted context omitted.

People are usually bad understanding counter intuitive notions such as the fact that making security flaws public actually makes consumers more secure, not less.

Detailing how this works publicly makes nobody more secure. Public release of the general problem is still worthwhile as information, but there is a net "security" loss here.

I disagree. Making a security flaw known forces manufacturers to fix it. As the article states, they went "to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013". Two years later the problem hasn't been fixed, because a recall would be too labor intensive. Meanwhile VWs are still being stolen using this exploit. Now that the exploit is out there VW is forced to act.

And it's not like regular people are going to turn into car thieves because this exploit has been made public. Not even house burglars will turn into car thieves. I would guess that car thieves are very specialized due to the seemingly complicated logistics behind these operations, so it's unlikely that they weren't aware of this exploit.

I'm far from being an expert on the subject, but I don't see how this is a net loss. I see very little potential for a spike in thefts and a high probability of VW finally facing the problem.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#110

Earlier quoted context omitted.

It's obviously not a safety recall, but that doesn't mean it isn't serious. Other companies have been known to do voluntary recalls defective locks, why is VAG exempted in your mind? "It barely can even be considered an immobiliser" is almost certainly contrary to reasonable consumer expectations, and it wouldn't surprise me if the EU, at least, had laws regarding this kind of issue.

It's not serious. It still requires someone to specifically target you & your car with special gear and know-how far outside the realm of the typical car thief.

IDK about "far outside the realm of the typical car thief". Not that the typical car thief is going to be trailblazing the research, but once the research is done, it just takes someone putting a black box VW keyless unlocker together, and then it's in the realm of the typical car thief. In fact, at that point you're talking about the break in being the simplest part of the theft, with fencing being much more difficult.
Post reply on HN