Earlier quoted context omitted.
You cannot establish a private channel between app and car if you don’t already have either a pre-shared secret, or pre-shared trusted certification authority keys (such as to allow TLS-like tamper-resistant encrypted communication between app and car) that VW can’t replace. Otherwise, if there is no pre-existing private channel, the key (which by the way would have to be the public key, not the private key) could be…
This argument seems like a fairly extreme example of the perfect being the enemy of the good. Sure, it would require a more advanced system for VW to prevent themselves from silently compromising their own system to learn everyone’s location. But the design I outlined will prevent a passive compromise of VW, and even possibly a court order, from learned everyone’s location, and it prevents even an active and highly m…
VW breach exposes location of 800k electric vehicles
111–120 of 317 posts
Re: VW breach exposes location of 800k electric vehicles
#112Earlier quoted context omitted.
This is not hard. App login sets up a session with VW (which is surely already does), except the session needs a database entry and not just a JWT-like token. (Many auth frameworks do this anyway.) The database row needs to add a public key, and the server needs to send all the key changes to the car. And that’s about it.
Again, that's the easy part. The hard part is making it work reliably in the real world.
Re: VW breach exposes location of 800k electric vehicles
#113Find the guys who usually park at expensive family homes, but occasionally visit a known brothel, then blackmail them. We all just let surveillance haplen to us, in fact we paid for most of it
Kindergarten transactions one day, escort payments on another.
It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.
Re: VW breach exposes location of 800k electric vehicles
#114Earlier quoted context omitted.
European companies get fined the same as any other companies.
Well within the constraints they set out which exclude a hell of a lot of European companies. (I am in Europe for reference, this is not an external perspective)
Re: VW breach exposes location of 800k electric vehicles
#115We need a way to disable vehicle telemetry. No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely) Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay
Re: VW breach exposes location of 800k electric vehicles
#116Maybe legal needs to have a talk with marketing.
Re: VW breach exposes location of 800k electric vehicles
#117Earlier quoted context omitted.
This argument seems like a fairly extreme example of the perfect being the enemy of the good. Sure, it would require a more advanced system for VW to prevent themselves from silently compromising their own system to learn everyone’s location. But the design I outlined will prevent a passive compromise of VW, and even possibly a court order, from learned everyone’s location, and it prevents even an active and highly m…
I was triggered by the argument “Apple knows how to allow one to find one’s devices without Apple knowing where they are. It’s not that hard.” People misunderstand this as Apple having no possibility to learn the location if they wanted to. And that’s just not the case.
Re: VW breach exposes location of 800k electric vehicles
#118Re: VW breach exposes location of 800k electric vehicles
#119I'm curious if the breach is from the German core Cariad or the Swedish subsidiary/joint-venture, WirelessCar? Based on what sort of data was exposed, it seems plausible that it is one of the services from WirelessCar.
Re: VW breach exposes location of 800k electric vehicles
#120I wonder if they were all petrol vehicles, or all diesel if that would be so prominent in the headline. The drive train has nothing to do with an unsecured s3 bucket, and if you think that electric vehicles are the only “connected” cars in 2024, you’re in for a shock.