Live data from Hacker News

Volkswagen started blocking GrapheneOS users

discuss.grapheneos.org

381–390 of 497 posts

Re: Volkswagen started blocking GrapheneOS users

#381

I got an iPad as backup with my 2fa stuff, and so I can keep an eye on kids in Apple ecosystem. When my iPhone mini does I'll go for /e/OS or GrapheneOS. And then I'll have the iPad lying at home for all the shenanigans that are nice but I don't even really need. My phone must serve me.

I would recommend Grapheneos over e because it has much better support and is a different class of privacy and security.

Hmm yeah but I’m really eyeballing a FairPhone atm.

Re: Volkswagen started blocking GrapheneOS users

#382

Earlier quoted context omitted.

Car apps, beside Tesla, are universally awful to use. Even Tesla's is not beyond reproach (app size is massive, for one), but at least it doesn't make me want to poke my eyes out. Apple should make a "Cars" app that's like the "Watch" app and let them standardize.

Why does a car even need an app? Don't they have a screen and internet connection on the car itself?

Starting my heating/airco at a distance, checking whether the car is charged so I can continue my trip, exporting charging session for my accountant, ...

Re: Volkswagen started blocking GrapheneOS users

#383
post #291

Earlier quoted context omitted.

N.B. I didn't write /all/ were "broken and dangerous" But some personal examples: - Auto high beam assist saw a car at a side junction, turned off high beam, then turned back on, mimicking a 'flash' to let the car out, which they acted on by pulling out. I had to brake hard to avoid them. I was doing 60 mph - I was on the motorway and a stranded vehicle was on the hard shoulder and the driver decided to exit from the…

PSA: Flashing someone is never a signal that you're giving them priority. That is explicitly forbidden in the highway code and dangerous. Flashing someone, like using the horn, only means "I'm here, just in case you didn't see me". If someone flashes you, you should make your own determination whether it is safe to perform a manoeuvre, making no assumptions about anything that the person who flashed you might be seem…

Yes...but the "feature" is still broken and dangerous

Re: Volkswagen started blocking GrapheneOS users

#385
post #231

Earlier quoted context omitted.

> I got an offer from a dealer three weeks ago and was going to order the car, then the API for the community integration got turned off. I decided to hold back and see what comes from it. Now this, which ultimately - since I am a GrapheneOS user - makes me completely cancel my plans. Make sure that dealers know why you changed your mind.

>Make sure that dealers know why you changed your mind. "Some nerd couldn't use their nerd phone." What incentive does a dealer have to know or care about this?

I wonder what a Venn Diagram of people that use GrapheneOS and people that wish to purchase a Volkswagen vehicle looks like. As of April 2026, the operating system had approximately 400K active users. https://en.wikipedia.org/wiki/GrapheneOS

I wish that Volkswagen would care about this, but I suspect they have little incentive to do so.

Re: Volkswagen started blocking GrapheneOS users

#386

Earlier quoted context omitted.

How else would you build "security" into the app (in the sense of not allowing third-party modifications of it that would open them up to liability), except relying on hardware attestation that the app has not been modified? That attestation necessarily requires the platform provider to be involved.

Volkswagon has no jurisdiction over how I manage my fob, which is the client for the vehicle's unlock and start API. Once you hand a bearer token to me that governs full access to the vehicle, including the accelerator and steering wheel, it's not your job to babysit whether I chose to use it while drunk or hand it over to someone else.

Except it is their job, that is why certain signals on the car are protected from manipulation. Any attempt to circumvent this and succeeding would require direct action from VW. If they cannot prove that they did everything possible to prevent that, then they are legally liable to the authorities.

Same way that banking apps don’t care if you could screw up your account anyway, they will ban rooted phones just to avoid the risk. Because when something happens, what do you think is more likely? That the customer accepts full responsibility for using a rooted device and says that’s on me? Or that they blame the bank for losing all their savings?

Re: Volkswagen started blocking GrapheneOS users

#387

Earlier quoted context omitted.

German companies, especially old school industrial ones like VW, have a very hard time understanding open platforms. The view everything through the lense of liability and compliance first. Their thinking is that if someone runs their app on a custom ROM and uses that to manipulate the app in any way, and that causes some extremely hypothetical damage, that they might be held liable for not having prevented this situ…

VW didn’t seem too concerned with compliance when they were rigging their pollution tests.

And since they saw what it cost them, they are now VERY concerned with compliance.

Re: Volkswagen started blocking GrapheneOS users

#388
post #36

Driving a rental car in Germany almost makes me cheer for the ongoing bankruptcy of their auto industry. It really needs a full reset at this point. Sad thing is EU law mandates for a modem in the car as well as intrusive driving aids that actually make driving less safe by constantly driving your attention away from the road[1]. So there is no hope to get a minimally decent car in Europe in the near future, unless a…

Whoever came up with the idea that the car should beep loudly even close to the speed limit has clearly never driven a car. The best way to silence it is to constantly be over the speed limit or well below.

Wait what brand does that? I need to know what car to not buy.

Re: Volkswagen started blocking GrapheneOS users

#389

Earlier quoted context omitted.

How else would you build "security" into the app (in the sense of not allowing third-party modifications of it that would open them up to liability), except relying on hardware attestation that the app has not been modified? That attestation necessarily requires the platform provider to be involved.

Volkswagon has no jurisdiction over how I manage my fob, which is the client for the vehicle's unlock and start API. Once you hand a bearer token to me that governs full access to the vehicle, including the accelerator and steering wheel, it's not your job to babysit whether I chose to use it while drunk or hand it over to someone else.

So you don't have a VW employee coming by your house in the evening to check if the key fob is still in you possession? Sometimes he even does a testdrive to make sure it still works with the car.

Maybe I have to ask that guy some questions....

Re: Volkswagen started blocking GrapheneOS users

#390
Because I frequently supply to the automotive industry, I fully understand all these issues. No matter how good many open source projects are, companies always have to face lawsuits and liability. That is why, no matter how good Linux servers are, factories use Microsoft servers. Regarding the responsibility for that software, if a problem occurs, the company that signed the contract takes on the liability. Ultimately, they shift the security responsibility to Google. It is unfortunate for open source enthusiasts, but if they do not restrict open source and an accident happens, the possibility of a lawsuit being filed against Volkswagen would be the real problem.
Post reply on HN