Live data from Hacker News

Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

neowin.net

191–200 of 225 posts

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#191
post #117

Earlier quoted context omitted.

Slate [0] say differently... [0] https://www.slate.auto/en

Slate has not shipped yet.

I'm hopeful but pessimistic about Slate. There is still time for them to A.) raise prices because of "unforeseen" issues, B.) enshittify with tech or wacky pricing structures.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#192
post #116

I don't get why companies don't understand how offensive it is to the customer to nickel and dime them, especially after they're already a converted customer. They could easily eat the $60 cost and spin it as positive PR, Apple-style. It's particularly bad because customers see it as a defect. No one wants to pay full price for defective equipment. The only thing that would make it worse is if this "hack" were reprod…

[dead]

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#193

This is a violation of UN regulation 155/156 where the vendor must provide free fixes and updates in case of safety or cybersecurity violations. I'm mentioning this specifically because the CAN bus is involved, which is mandatory to be safety conform and has to be ASIL-C/D conform. If you cannot guarantee that, you will lose the license. Without conformance to UN Regulation 155/156, the car manufacturer might lose it…

The UN has regulations? Who does it have authority over? Who enforces its regulations?

The vast majority of countries have into their laws that road vehicles must adhere to UN vehicle regulations. That's how enforcement happens - by whatever regulatory authority of the country the vehicle is to be used in. Canada and the US are among the exceptions in that they have their own standards.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#194

Earlier quoted context omitted.

Hyundai has car factories in 10 countries. The car in question is made in at least 2 countries. The defect being fixed applies to cars sold by a British subsidiary in Britain to Britons with the promise that it meets British market standards. It’s not even clear to me that these cars were manufactured in Korea, if they were, they couldn’t be sold there due to the right hand drive. The cars in question were very much…

Absurd. McDonald chose to participate in Korean market and I see no kimchi burgs there?

That’s because you didn’t check.

McDonald’s, famously, adapts their menu to the location. Here’s a bulgogi burger they only sell in Korea: https://www.mcdonalds.co.kr/eng/menu/detail.do

Here’s another menu item exclusive to Korea https://www.mcdonalds.co.kr/eng/menu/detail.do

It is one of many local menu items available exclusively in Korea. What is absurd is that you make false assertions that can be checked faster than you can write your comment.

Do you genuinely think that Hyundai does not adapt the car to the market (did they accidentally put the steering wheel on the right, and just happen to send those cars to the UK?)? Every car company HAS to do this, if only because different markets have contradictory rules. E.g. Lights that are legal in North America do not meet the standards of other countries. The car HAS to be adapted to the market.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#195
post #111

I don't know about the Hyundai Ioniq, but the Kia Niro has no way to permanently disable keyless entry, which would be the obvious, super easy s/w fix. You can disable it each time you lock your car by holding extra buttons on the fob for a few secs, but it's auto re-enabled next time you unlock. It's everything you need to know before you make your smart decision not to buy a Kia. Cheap(er) for a reason. But looks f…

Also be aware that homologation means there is no one-sized-fits-all, canonical vehicle for all markets but many variations for different markets with variations in security and safety features. Some markets get proper security measures while others get screwed.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#196

I want a dumb EV. No infotainment system. Just speakers and a way to plug my device into them. Anything critical to the car should be completely air gapped and require an absolute minimum amount of software, preferably zero.

That’s illegal in the EU, 911 eCall requires an always-on cellular connection with an attached device that records your location. Would you please think of the children?

Which wire to snip?

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#197
post #191

Earlier quoted context omitted.

Slate has not shipped yet.

I'm hopeful but pessimistic about Slate. There is still time for them to A.) raise prices because of "unforeseen" issues, B.) enshittify with tech or wacky pricing structures.

I'm hopeful but pessimistic as well.

I'm just tired of hearing about Slate. A relatively small amount of people want a product and they use a company that hasn't shipped as validation of their imaginary market size (this company exists, so tons of people want it!)

I hope they're successful.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#198
post #86

Earlier quoted context omitted.

The Kia Boys stuff, child labor, and ICCU failures weren't enough? The Ioniq 5 absolutely looks like a compelling car but from my POV Hyundai seems hell bent on snatching defeat from the jaws of victory.

I once ordered Kia EV6, but after a year I canceled the order. I am now glad I canceled it. Bi-yearly inspections and coolant change for 600€ are ridiculous ripoffs. ICCU failures are handled really badly in Germany. I really like the EV6 and EV3 cars, but the manufacturer isn’t that attractive anymore

  > Of course I'm in California so EVs are more expensive to run than ICE cars so it's all moot.
Does California have an oil industry that I'm not familiar with?

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#199

Earlier quoted context omitted.

We don't actually know how to build the CPU that would replace your vulnerable one. New CPUs are largely immune to the specific attacks that were published before they were designed. But we aren't gonna get a fast CPU without sidechannels and IMO it's not possible in theory to build a branch predictor that never makes potentially exploitable mispredictions. In a sense this doesn't change your point but I wanted to ta…

> IMO it's not possible in theory to build a branch predictor that never makes potentially exploitable mispredictions. I believe the Mill hardware design would be immune by design because the hardware is in-order (relying on other trickery for its performance). Of course, it's still vaporware, but the noises made have been fairly competent. So in some ways, yes, but in other ways, what if you didn't need a branch pre…

> I believe the Mill hardware design would be immune by design because the hardware is in-order

Well yes you can dodge this problem by not having a branch predictor but note the way I formulated my claim ;)

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#200
post #28

Earlier quoted context omitted.

> I know the locks on my car are easily picked They aren't actually. Which is why theives just smash your windows. In either case the alarm is going to go off so there's no advantage to them learning a complex attack on your lock cylinder when a piece of concrete will do. Further there often were additional ignition interlock mechanisms that required the correct key code or a key with the correct additional hardware…

It's not ease, it's efficiency: opening a locked car door is 1-2 minutes for an experienced person. Smashing the window is 2 seconds (though you also need some experience, as modern car side windows are also laminated).

opening a locked car door is 1-2 minutes for an experienced person

Look up LockPickingLawyer on YouTube. Less than a minute with the right tool.

Post reply on HN