Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

221–226 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#221

Earlier quoted context omitted.

Wait until Teslas become cheaper. Until then, buy a Lada Niva. No one will want to steal it and it doesn't have anything complicated in it that can be hacked.

1993 Corolla with decayed paint. Utterly, utterly, reliable. Appears undesirable. It will also guarantee that you'll never get laid.

Nope. 90s Toyotas have eminently resalable parts and no immobilizer, making them far and away the most-stolen cars in America.

There are very high-end car thieves who want flashy cars, but the vast majority of car theft is about 1) ease and 2) what the parts are worth.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#222
post #170

Earlier quoted context omitted.

You should look at crash tests results of your 2000 Subaru and a car more modern than 2013 and decide which you'd rather be in in the result of a crash. I'm less scared of a potential hacker cutting power to my car than I am of the millions of poor drivers cutting lanes and changing lanes without signals (or even looking) resulting in an auto accident. Things started improving in the 90's (falling from 143m to 115m).…

Newer safety regulations definitely help, but at the same time, I almost feel like we're reaching a point where we're at pendulum overswing to some degree. That biggest change since 2012 has been increased roof strength requirements. This was driven at least in part due to the popularity of top-heavy, rollover prone vehicles. Meeting these requirements have required cars to get heavier and incorporate massive roof pi…

Perhaps - but the numbers don't indicate the pendulum swinging back. It looks to be a net gain, even despite that.

Interesting, though. I had noticed this trend - coming from a 2002 Outback, most of the ZipCars I drove seemed to have terrible rear visibility. Now I know why.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#223
post #134

Earlier quoted context omitted.

I'm not familiar with the current state of physical security exploitation, but I get the sense that it would take more than 30 minutes and pushing the button on a black box someone built for me to compromise. Unlike this. The issue with electronic exploitation is that the know-how component is relatively trivially automated. Script kiddies, etc. If I bought an $80k Porche, I'd be bit miffed that it could be stolen fr…

It takes 10 seconds to bypass a window. Alarm systems are a deterrant, not prevention.

That's the whole point of an immobilizer. To prevent the typical physical methods (break window, hotwire ignition) from being accepted unless the security token is also present.

I don't think Porche et al are under any illusions their windows are rock-proof. ;)

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#224

So why were the researchers willing to publish a redacted version now, but were not willing to publish the redacted version 3 years ago when they were researching the issue? I am actually curious because this is the only part of this whole thing that does not make sense to me. Even if I disagree with Volkswagon's decision to not notify existing owners that there was a vulnerability known or eventually provide them wi…

Is it the same redacted version? Maybe Volkswagen asked more more extensive redactions back then, and they now reached a compromise?

It sounds like the same thing was redacted from this version that they asked be redacted from that version as this one doesn't have the specific codes necessary to make it work.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#225

Earlier quoted context omitted.

Except that VW at somepoint quit using the transponder in question because of this issue so new cars made are no longer susceptible.

Not everyone buys only new cars. Besides, in a world in which research was not censored, do you really expect that VW would have been slower to fix the issue?

No but I don't think they would of been faster either was my point.

Hence, to answer to the question posed "So how many vulnerable cars are on the roads of the world right now because the UK High Court wanted to "protect consumers""

I would answer 'possibly zero, BECAUSE of that' and once they are manufactured and sold they exist regardless of the owner, till they are destroyed.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#226

Earlier quoted context omitted.

Not everyone buys only new cars. Besides, in a world in which research was not censored, do you really expect that VW would have been slower to fix the issue?

No but I don't think they would of been faster either was my point. Hence, to answer to the question posed "So how many vulnerable cars are on the roads of the world right now because the UK High Court wanted to "protect consumers"" I would answer 'possibly zero, BECAUSE of that' and once they are manufactured and sold they exist regardless of the owner, till they are destroyed.

I never posed that question. (hint: sibling did)

I merely countered the plight of old VW owners with that of new VW owners.

Post reply on HN