Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

111–120 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#111
post #85
post #74

Earlier quoted context omitted.

You cannot establish a private channel between app and car if you don’t already have either a pre-shared secret, or pre-shared trusted certification authority keys (such as to allow TLS-like tamper-resistant encrypted communication between app and car) that VW can’t replace. Otherwise, if there is no pre-existing private channel, the key (which by the way would have to be the public key, not the private key) could be…

This argument seems like a fairly extreme example of the perfect being the enemy of the good. Sure, it would require a more advanced system for VW to prevent themselves from silently compromising their own system to learn everyone’s location. But the design I outlined will prevent a passive compromise of VW, and even possibly a court order, from learned everyone’s location, and it prevents even an active and highly m…

I was triggered by the argument “Apple knows how to allow one to find one’s devices without Apple knowing where they are. It’s not that hard.” People misunderstand this as Apple having no possibility to learn the location if they wanted to. And that’s just not the case.

Re: VW breach exposes location of 800k electric vehicles

#112
post #86

Earlier quoted context omitted.

This is not hard. App login sets up a session with VW (which is surely already does), except the session needs a database entry and not just a JWT-like token. (Many auth frameworks do this anyway.) The database row needs to add a public key, and the server needs to send all the key changes to the car. And that’s about it.

Again, that's the easy part. The hard part is making it work reliably in the real world.

[deleted]

Re: VW breach exposes location of 800k electric vehicles

#113
post #9

Find the guys who usually park at expensive family homes, but occasionally visit a known brothel, then blackmail them. We all just let surveillance haplen to us, in fact we paid for most of it

I once worked for a firm that had access to credit card transaction data and came across almost this exact scenario.

Kindergarten transactions one day, escort payments on another.

It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.

Re: VW breach exposes location of 800k electric vehicles

#114

Earlier quoted context omitted.

European companies get fined the same as any other companies.

Well within the constraints they set out which exclude a hell of a lot of European companies. (I am in Europe for reference, this is not an external perspective)

https://www.enforcementtracker.com/?insights shows breakdown by country, type, industry sector. "Highest fines: individual" top 10 list is all international companies (Meta, Amazon, TikTok, LinkedIn, Uber) and those make the news. Smaller European companies hardly make the news.

Re: VW breach exposes location of 800k electric vehicles

#115

We need a way to disable vehicle telemetry. No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely) Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay

Instead, US senators will rail about the security risk of Chinese vehicles while refusing to provide competitive alternatives.

Re: VW breach exposes location of 800k electric vehicles

#117
post #111
post #85

Earlier quoted context omitted.

This argument seems like a fairly extreme example of the perfect being the enemy of the good. Sure, it would require a more advanced system for VW to prevent themselves from silently compromising their own system to learn everyone’s location. But the design I outlined will prevent a passive compromise of VW, and even possibly a court order, from learned everyone’s location, and it prevents even an active and highly m…

I was triggered by the argument “Apple knows how to allow one to find one’s devices without Apple knowing where they are. It’s not that hard.” People misunderstand this as Apple having no possibility to learn the location if they wanted to. And that’s just not the case.

Of course Apple could do this. But Apple is the one major company that actually goes out of its way not to.

Re: VW breach exposes location of 800k electric vehicles

#118

Ah, here's my daily reminder to treat my 2005 Honda like a princess and hope it never, ever dies.

I plan to buy old used cars forever when I can no longer keep my 2013 Subie going.

why not have whatever dies replaced? I will probably do that with my crappy small truck from 2006.

Re: VW breach exposes location of 800k electric vehicles

#119

I'm curious if the breach is from the German core Cariad or the Swedish subsidiary/joint-venture, WirelessCar? Based on what sort of data was exposed, it seems plausible that it is one of the services from WirelessCar.

According to the article, Cariad

Re: VW breach exposes location of 800k electric vehicles

#120

I wonder if they were all petrol vehicles, or all diesel if that would be so prominent in the headline. The drive train has nothing to do with an unsecured s3 bucket, and if you think that electric vehicles are the only “connected” cars in 2024, you’re in for a shock.

Because EVs are new-ish and so mentioning them specifically is aproximate shorthand for "consumers of a certain tax bracket" so it's useful for getting those people to click on the article, hand wring, re-tweet and do all those other things that make money.
Post reply on HN