Live data from Hacker News

Volkswagen started blocking GrapheneOS users

discuss.grapheneos.org

421–430 of 497 posts

Re: Volkswagen started blocking GrapheneOS users

#421

Earlier quoted context omitted.

Volkswagon has no jurisdiction over how I manage my fob, which is the client for the vehicle's unlock and start API. Once you hand a bearer token to me that governs full access to the vehicle, including the accelerator and steering wheel, it's not your job to babysit whether I chose to use it while drunk or hand it over to someone else.

Except it is their job, that is why certain signals on the car are protected from manipulation. Any attempt to circumvent this and succeeding would require direct action from VW. If they cannot prove that they did everything possible to prevent that, then they are legally liable to the authorities. Same way that banking apps don’t care if you could screw up your account anyway, they will ban rooted phones just to avo…

Easy: separate the systems into the safety-critical ones required for driving, and the nice-to-have ones used for things like entertainment. You can now give the car's owner full access to the latter via all sorts of weird 3rd-party apps, as there's no way for that access to cause serious issues.

They should be doing this anyways, or else you end up with your Jeep being crashed via wifi [0], and having the blast radius of a corrupt album image [1] restricted to infotainment is probably a really good idea too.

[0]: https://www.kaspersky.com/blog/blackhat-jeep-cherokee-hack-e...

[1]: https://www.theregister.com/software/2022/02/10/radio-statio...

Re: Volkswagen started blocking GrapheneOS users

#422
post #273

Earlier quoted context omitted.

GrapheneOS requires a locked bootloader and supports using deveice attestation via the generic attestation functionality in the Android Open Source Project. Play integrity is an anticompetitive tool that ignores this, and artificially limits itself on GrapheneOS. It is not due to any incompatibility.

The GrapheneOS supporters are not on our sides, apparently. The seem to actually like remote attestation. They just don't like that they are not in on Play Integrity. But what is won if attestation includes official GrapheneOS releases but would still otherwise be exactly the same evil stuff that takes control of the user's device? I still am hoping that at one point they understand the full consequences of remote at…

GrapheneOS users can hold two opinions at the same time in a consistent way:

- Remote attestation is bad, anti-competitive, and reduces privacy.

- Given in a world where remote attestation exists, GrapheneOS should pass attestation, since there are no security reasons not to.

Both battles should be fought at the same time, because if governments do not want to ban remote attestation, you want to make sure that at least it's not in the hands of companies that abuse it to maintain their duopoly.

Focusing on only one of them can lead to worse outcomes.

Re: Volkswagen started blocking GrapheneOS users

#423

Earlier quoted context omitted.

Unfortunately, due to the nature of these things, you cannot verify an app is unmodified without also verifying the OS running it is also unmodified. So if VW decides that only their unmodified app may access APIs, then they kind of are stuck verifying the OS. They can, given basic competence in SW engineering, also verify against GrapheneOS' published release keys. The reason they don't is the same reason Google clo…

The reason they don't is the same reason Google closed my ticket asking them to include Graphene keys in Play Integrity checks: they don't care. I think the reasons are very different. VW maybe doesn't care. Google does it because it would undermine their stronghold over the platform. If they would allow GrapheneOS, what would block Samsung or another OEM from also sandboxing Play Services and not preinstalling a bun…

Alternatively: don't add inherently-unsafe functionality which requires attestation in order to have a veneer of "safety".

As media piracy and game cheating has shown: no matter how hard you try, there will always be ways around it. You should assume that 3rd-party device you have zero control over is already compromised, so why not use the API as the boundary layer, stop pretending you can secure the app, and open it up to 3rd-party access like it already is in practice?

Re: Volkswagen started blocking GrapheneOS users

#425
post #36

Driving a rental car in Germany almost makes me cheer for the ongoing bankruptcy of their auto industry. It really needs a full reset at this point. Sad thing is EU law mandates for a modem in the car as well as intrusive driving aids that actually make driving less safe by constantly driving your attention away from the road[1]. So there is no hope to get a minimally decent car in Europe in the near future, unless a…

I recently saw a reportage about emergency call-takers. As you watch them work you'll notice they get an automatic call from the crashed car long before any human calls them, presumably from that modem. I'm not arguing that the modem should be mandatory, or that you shouldn't be able to control what it does. But forcing car vendors who want to built in a modem to make this modem do an automatic emergency call by defa…

This is already sorta-kinda the case, and it is leading to a lot of issues right now.

The eCall functionality isn't exactly trivial, and due to its safety use there are probably some rather strict regulations around it. In practice this has led to many car manufacturers opting to use dedicated off-the-shelf modules for them, which are completely separate from all the connected infotainment stuff.

However, early modules were built around 2G/3G cellular technology, and cars with those were still sold well into 2025. Not a huge surprise, because its application doesn't require 4G/5G data speeds. Buuuut many countries are now actively retiring their 2G/3G networks, leaving those cars unable to place emergency calls, and with a functioning eCall module often being legally required it would mean some 2-year-old cars would no longer be road legal...

Re: Volkswagen started blocking GrapheneOS users

#426
post #70

It is amazing how Volkswagen keeps messing up. I am currently in the market for a new car, an EV specifically. Volkswagen brands were at the top of my list for many reasons, among them the excellent driving assist implementation. I got an offer from a dealer three weeks ago and was going to order the car, then the API for the community integration got turned off. I decided to hold back and see what comes from it. Now…

Companies just don't realize how personal computing is.

An analogy is trying to make users wear certain clothes when they use your product, and then asking why it doesn't fly.

Re: Volkswagen started blocking GrapheneOS users

#427
post #354

Earlier quoted context omitted.

>Their developer ToS that absolves them of any sort of liability for anything. This is... obviously not true? If you could (somehow) meaningfully damage a car via the app, do you think VW wouldn't be liable because of the Google Play developer ToS?

My point was that Google would not be liable. VW cannot evade liability from app misbehavior by using Google Play Protect, so why do they do it?

It will look better for the project lead if there's an issue though. You can say that you enabled everything recommended by Google or w/e, following best practices, and still got pwned instead of arguing that your own security model had a tiny little flaw that no one recognized. And it frees up project hours which can either be the difference between doing the project or not doing it and/or allow you to have other project work billed to this project.

Re: Volkswagen started blocking GrapheneOS users

#428

Earlier quoted context omitted.

Are you taking from the experience that this is not blockeable in Russia? EDIT: I might be confusing vless/xray/reality but seems like there are no problems to block it based on ip reputation + tls fingerprint + amount of connections https://habr.com/ru/articles/1044396/ Of course this would block some valid websites but when has government cared about that

The IPs are Cloudflare, the TLS fingerprint is uTLS Chrome, and the number of connections with xhttp is the same as your normal browsing. If you are willing to block browsing all ordinary web sites fronted with a CDN, then yes you can block reality/xhttp. You cannot, however, differentially block it via any of the three things you mentioned.

They are willing to break some cloudflare-fronted websites. That's already a reality in Russia.

The government (any government) hates its citizens and the freedoms it had to allow them

Re: Volkswagen started blocking GrapheneOS users

#429

Earlier quoted context omitted.

One is people one is companies.

It sends very weird signals when the EU will fine an American company over some data moving in a direction they don't like while at the same time EU governments will allow home grown companies to de facto force people into using products from those same American companies all while lecturing us about duopolies and privacy only to re-enforce those same problematic patterns. It is absurd.

All countries are more lenient with their own companies. Remember who started grounding the 737 Max? It wasn't the FAA, an otherwise highly respected organization. Who is paranoid about Chinese routers while spying on everyone? Etc.

Re: Volkswagen started blocking GrapheneOS users

#430

I have no plans to buy a car but I'm curious: what is the sensible choice for technical people with a reasonable amount of money? I rent cars whenever I travel to the US and I've never not been pissed off by a car's software. If you live in a country that makes it practica/affordable and you don't need too much range, I wonder if buying an old car with a broken engine and paying someone to do an electric conversion i…

> I'm curious: what is the sensible choice for technical people with a reasonable amount of money? I am probably the extreme minority, but I prefer cars with as little "tech" as possible. I don't need "drive assist" and sorts. All my cars are 10+ old benzes, Nissans, Toyotas. All under good maintenance routine so giving me very little headache. I had all sorts of stupid issues with modern cars while renting. One toyo…

The "driving" tech I want in my car is:

- Cruise control.

- Camera for parking. I guess sensors too. These are just unbelievaly useful IMO, it makes parking trivial in cases that used to require quite intense focus. I see the appeal of fully automated parking, but with cameras and a car that you have lots of experience parking I think I am fine Austin-Powers-ing into any space that the car physically fits into.

- I guess, maybe, I kinda like the thing where it automatically watches your blindspot and has a little orange light to remind you that there's a car there.

I dunno, when did cars get all that stuff? (Cruise control was basically universal in the US before I was even born I think, but not sure when the others showed up).

But then there's some non-driving tech that I do want:

- Completely frictionless navigation and media control. Android Auto just seems to be fucking nonfunctional so I think maybe what I want here is actually just a Qi mount and a reliable bluetooth controller?

- I've never had it but I bet remote climate control is really nice (warm up the wheel 5 mins before you set off on a frozen morning / turn on the AC 2 mins before you get into a car that you couldn't park in the shade).

Post reply on HN