Live data from Hacker News

VW Has Spent Two Years Trying to Hide a Big Security Flaw

bloomberg.com

31–40 of 226 posts

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#31

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

It's not possible. Make sure your car is well insured. The insurance companies have traditionally put pressure on manufacturers to add better security. In the UK, the car insurers set up this respected research institute which has steadily improved car security:

http://www.thatcham.org/about

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#32

ITT: nobody so far advocating "responsible disclosure", because this is the sort of vendor abusiveness that made "full disclosure" clearly a good idea, and an essential protection for the interests of the end user . The Internet of Things will recapitulate all the painful experience of how this stuff works out we just spent twenty years getting sorted out in the software field.

Even though these cars aren't a part of the internet of things (yet), situations like these are the exact reasons why I'm not enthusiastic about it. Honestly, I hate it.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#33
post #28

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Theft of newer-model cars is extremely rare and I don't think vulnerabilities will change that much. Anything that requires computers at all is going to be beyond the average car thief. If you're worried about safety, buy a car with a good crash safety rating. You're far more likely to get into a normal crash due to bad human drivers or mechanical failures than you are to be hacked. If you're worried about the financ…

> Anything that requires computers at all is going to be beyond the average car thief.

Not for long.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#34
post #28

Earlier quoted context omitted.

Theft of newer-model cars is extremely rare and I don't think vulnerabilities will change that much. Anything that requires computers at all is going to be beyond the average car thief. If you're worried about safety, buy a car with a good crash safety rating. You're far more likely to get into a normal crash due to bad human drivers or mechanical failures than you are to be hacked. If you're worried about the financ…

> Anything that requires computers at all is going to be beyond the average car thief. Not for long.

Well sure, pretty much by definition. Car thieves who can't handle technology will eventually have to stop stealing cars. There are only so many late 90s Honda Accords out there to be stolen, after all, and they aren't making any more.

But I really doubt that all the thieves out there will learn fancy technology so they can steal newer cars. A few will, but most will find other things to steal.

Right now, popular new cars are stolen in amounts of hundreds per year in the US. Older cars (like the Honda Accord) are stolen by the tens of thousands. That's not because older cars are more valuable, it's just because it's a lot easier.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#35
post #27

The "new" (actually 2 years old) thing is the UK courts granting injunctions preventing the publication of security research from a well known UK university. WTF. http://www.theguardian.com/technology/2013/jul/30/car-hackin...

Right, the money quote in the article is:

> The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper - arguing that its vehicles would be placed at risk of theft - and was awarded an injunction in the U.K.'s High Court.

But then they don't detail the legal situation that led to the two years of litigation and the eventual release, so I don't know who to be mad at..

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#36

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

Don't buy a high end car that has a high theft rate. Research theft rates like you would reliability and resale. Buy a plain vanilla mid-level toyota, honda or the like. Insure your car.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#38

"There's no quick fix for the problem - the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs." What a nightmare. Car manufacturers have to design more resilient systems. Based on the difficulty to secure hardware systems after deployment, they will be for sure trying to put more and more features on the software-side. If so, they will also have to think about…

As noted in the conversation about the Jeep hacking thread, This is an example of "better" security by not making the security system reprogammable (its read only). But it does incur this huge cost when you find a problem with it.

I'm sure the time to fix is also made more problematic by the need to fab new chips.

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#39
Non issue to me. Typical media and security professionals hyperbole.

I have car insurance for my Porsche. According to the list it's vulnerable.

Chance of getting stolen? Quite small. If it does insurance pays in my case the full value not the depreciated value (age of car as only one reason). Not something I am worrying about.

How many cars are actually stolen as a result of this flaw?

Just another example of the security industrial complex fanning the flames...

Re: VW Has Spent Two Years Trying to Hide a Big Security Flaw

#40
post #31

So what manufacturers do seem to care about security? If I wanted to buy a car made in the last few years, who is least likely to be cracked?

It's not possible. Make sure your car is well insured. The insurance companies have traditionally put pressure on manufacturers to add better security. In the UK, the car insurers set up this respected research institute which has steadily improved car security: http://www.thatcham.org/about

That Thatcham rating might not be as good as you think; we used to have massive problems with Thatcham certified motorbike chains and locks, eg: https://www.youtube.com/watch?v=VC3hFr8p2ck

Pro-Tip: If you're chaining your bike up, make sure the chain can't touch the floor.

Post reply on HN