Live data from Hacker News

Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

neowin.net

171–180 of 225 posts

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#171

Earlier quoted context omitted.

There will always be at least a basic screen in new cars in the US because of backup camera requirements.

Yeah, a basic screen with Android Auto + Carplay (just the video passthrough, not the OS with installable apps) would be perfect.

I work at an ewaste recycling company. Last week, I was testing a projector, and was using a USBC to DVI cable (one of the most cursed cables I've come across). I said "LOL this won't work" and plugged it into my phone. Sure enough, my phone recognized that a display was connected, and once confirmed, showed what I expected it to!

Plugging a car into a phone should work like that: just a dumb display with maybe a keyboard or touchscreen input device.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#172
post #92

Earlier quoted context omitted.

Nobody will sell you one for cheaper than a whole package. See also ‘smart’ tvs vs digital signage displays aka dumb tvs.

While this is partially true, digital signage displays are also designed to run 24/7, which also makes them more expensive than regular TVs.

Vertical digital signage products should also have their polarization filter flipped 90° so you can view them with polarized sunglasses, adding another SKU and cost.

Stockholms Länstrafik didn't figure this out so all our timetable displays are pitch black when viewed with polarized sunglasses.

I've noticed that all but iPhones exhibit this behavior at some angle too and they're apparently using "circular polarization" (expensive) which is another one of these "we do it better" things nobody knows about from Apple (or displays in general)

(https://claude.ai/share/e462247c-0ecd-4a07-8ec1-36a4f3c86597)

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#173

This is a violation of UN regulation 155/156 where the vendor must provide free fixes and updates in case of safety or cybersecurity violations. I'm mentioning this specifically because the CAN bus is involved, which is mandatory to be safety conform and has to be ASIL-C/D conform. If you cannot guarantee that, you will lose the license. Without conformance to UN Regulation 155/156, the car manufacturer might lose it…

The UN has regulations? Who does it have authority over? Who enforces its regulations?

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#174

Earlier quoted context omitted.

The line between software and hardware is hard to distinguish when we talk about ASICs and FPGAs, but they still should be responsible for core functionality (i.e. locks) as they shipped insecure software.

But why? Locks are working. They perfectly fulfill requirements for the lock. Open/close with a key, stay closed if tried to be opened without a key. There is no such thing as secure lock. Any lock could be open without original key. The difference is in the amount of effort. Still baffles me that KIA sold cars which can be driven away using screwdriver and USB cable.

> There is no such thing as secure lock.

These in fact do exist, but they have properties unsuitable for many use cases, such as taking 8-24 hours to open if you lose the key/combination or a mechanical fault occurs, and being part of a system so heavy the floor beneath them have to be constructed to support the weight. (A friend of mine was a master locksmith for many years and worked on such locks, mostly for government contracts.)

In case of a lockout often the easiest way to open them is a brute force attack using a device called an autodialer.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#175

Earlier quoted context omitted.

While this is partially true, digital signage displays are also designed to run 24/7, which also makes them more expensive than regular TVs.

Vertical digital signage products should also have their polarization filter flipped 90° so you can view them with polarized sunglasses, adding another SKU and cost. Stockholms Länstrafik didn't figure this out so all our timetable displays are pitch black when viewed with polarized sunglasses. I've noticed that all but iPhones exhibit this behavior at some angle too and they're apparently using "circular polarizatio…

On the other hand, it would be great for sunglasses to automatically change their polarization angle to block street ads...

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#176

Earlier quoted context omitted.

Yeah, a basic screen with Android Auto + Carplay (just the video passthrough, not the OS with installable apps) would be perfect.

I work at an ewaste recycling company. Last week, I was testing a projector, and was using a USBC to DVI cable (one of the most cursed cables I've come across). I said "LOL this won't work" and plugged it into my phone. Sure enough, my phone recognized that a display was connected, and once confirmed, showed what I expected it to! Plugging a car into a phone should work like that: just a dumb display with maybe a key…

Isn't that essentially what Carplay and Android Auto are? Just over USB?

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#177

Earlier quoted context omitted.

Even in McDonalds if what they give you is defective they will replace it without question once you bring it to their attention. If it turned out the door locks on the car were defective you'd expect them to be replaced under warranty. If the warranty had expired the situation would, admittedly, be a bit murkier - but you could still make a case that since the locks had always been faulty they'd be the manufacturer's…

> if what they give you is defective they will replace it without question once you bring it to their attention Go there and request a rare steak or idk steak with kimchi, let is know how it goes! This is a Korean car and probably secure enough in korea where you usually don't lock your bike and/or house. If it not secure if you park it on the street in SF/London/Magadan/Capetown/Kabul are you sure they owe you a fre…

Hyundai has car factories in 10 countries. The car in question is made in at least 2 countries. The defect being fixed applies to cars sold by a British subsidiary in Britain to Britons with the promise that it meets British market standards. It’s not even clear to me that these cars were manufactured in Korea, if they were, they couldn’t be sold there due to the right hand drive. The cars in question were very much NOT made to be driven in Korean conditions.

If these people had bought a Korean market car in Korea and personally shipped it to the UK, yours would be a more compelling argument.

As it is, it makes no sense. If you choose to participate in a foreign market you do not get to abdicate responsibility for problems because they don’t exist in your home market.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#178

Earlier quoted context omitted.

The line between software and hardware is hard to distinguish when we talk about ASICs and FPGAs, but they still should be responsible for core functionality (i.e. locks) as they shipped insecure software.

But why? Locks are working. They perfectly fulfill requirements for the lock. Open/close with a key, stay closed if tried to be opened without a key. There is no such thing as secure lock. Any lock could be open without original key. The difference is in the amount of effort. Still baffles me that KIA sold cars which can be driven away using screwdriver and USB cable.

There are some locks that cannot be opened without the correct key. Abloy and BiLock are two examples.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#179
post #76

Earlier quoted context omitted.

It doesn't matter. If a customer buys faulty hardware, it's the seller's responsibility to replace it with working hardware. If the breaks had a manufacturing defect, you wouldn't expect the customer to pay for the replacement.

There is nothing faulty in the hardware, why they should replace it? Following the same logic: old phones, even iphones can be hacked. Should manufacturers replace the hardware?

They should open up the specs, so that the community could update the software.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#180

Earlier quoted context omitted.

Agree the title is a bit misleading, but addressing what sounds like an exploit still feels like a patch of sorts. But yeah, “patch” usually implies software vs. hardware. Either way, agree with other comments that Hyundai should just eat the costs if it prevents theft due to an exploit. Having said that, given what the car costs, the fee doesn’t seem completely unreasonable.

Given what the car costs, you'd think they'd do this out of courtesy.

Yeah, definitely.

I have a Kia EV6, and just saying that if the same “patch” is offered for it, I won’t think twice about paying $65 for it.

I’d also not be super happy they didn’t cover it, but I saw a comment about never buying a Hyundai because of this, and not sure I’d be that upset about it.

There’s a line, for sure, but $65 wouldn’t be it, for me.

Post reply on HN