Live data from Hacker News

Toyota runs a car-hacking event to boost security (2024)

toyotatimes.jp

51–60 of 115 posts

Re: Toyota runs a car-hacking event to boost security (2024)

#51

My brother had his car (a sleek AUDI) stolen in front of his house. He left the key in the entry hall, and someone extended the range. Are current electronics (the consumer ones) good enough at scale to limit the time the round-trip car-key-car takes?

I think a fundamental problem is that keys aren’t security forward compatible - break the keys and you’ve broken an entire generation (or more) of cars. The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees. But the car manufacturers don’t give a fuck if your 3 years and one day old car gets stolen. You move to the next competitor, only for the same to happen…

>The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees.

Wouldn't this require the phone to be trusted and not run unsigned software?

Re: Toyota runs a car-hacking event to boost security (2024)

#52
post #33

Earlier quoted context omitted.

> That's great, but the writing is still on the wall if Toyota doesn't get serious about electric cars. It seems they know what they are doing. Toyota is a very profitable car manufacturer, with profit in 2024 more than Tesla and Volkswagen combined. Unlike Nissan, the maker of the best selling EV of all time, who is struggling very hard.

Tesla sells nearly as many cars in a quarter (497,099 in Q3 2025) as the Leaf managed in its entire lifetime (577,000 between 2010 and 2022).

I stand corrected, the Leaf figure was wrong. Nevertheless, Toyota is very profitable despite (or because?) it does not sell a significant number of EVs. Margins on EVs are currently extremely low or even negative, and that is hurting EV manufaturers more than ICE manufacturers.

Re: Toyota runs a car-hacking event to boost security (2024)

#53

That's great, but the writing is still on the wall if Toyota doesn't get serious about electric cars. With their current trajectory Toyota is headed at 1000mph directly towards being the next Blackberry, Kodak, Nokia or Blockbuster. I say this as someone who owned a Prius for 10 years and loved it, and have also driven their hydrogen car. The BZ4X is badly named overpriced garbage, not enough and not good enough. The…

Tesla is not the manufacturer to beat.

Re: Toyota runs a car-hacking event to boost security (2024)

#54

Earlier quoted context omitted.

Very little maintenance is one big feature. After 3 years I have only had to change the tires, air filter and windscreen wipers. For long road trips I’ve never had an issue stopping to rest/stretch while fast charging for between 15-30 mins.

Sure, but we are talking about a Toyota so there is (at least in my experience) not that much maintenance to begin with.

Toyotas may need less repairs than other vehicles, but of course they have the same maintenance schedules and costs as other vehicles.

Compare periodic oil changes, spark plug changes, ignition coils, stolen catalytic converters, exhaust system, PCV system, air and fuel filters, brake pads, transmission fluid, and other ICE maintenance items with the electric drivetrain. At 120,000 km I've replaced the tires once and the brake pads look brand new. That's it. Even the windshield wipers are still in good shape for some reason.

Re: Toyota runs a car-hacking event to boost security (2024)

#55

Earlier quoted context omitted.

Very little maintenance is one big feature. After 3 years I have only had to change the tires, air filter and windscreen wipers. For long road trips I’ve never had an issue stopping to rest/stretch while fast charging for between 15-30 mins.

Sure, but we are talking about a Toyota so there is (at least in my experience) not that much maintenance to begin with.

Oil filters and brakes are on the easier spectrum of maintainenance, but I’d still rather not do them if I don’t have to (which with my EV, I won’t)

Re: Toyota runs a car-hacking event to boost security (2024)

#56
There's 2 things when it comes to security:

Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony.

Also, companies are not responsible (liable) for their own poor security. If they do something like leak the private data of half the nation--shrug--what can you do?

How convenient for companies. It's literally a matter of national security; our national security is made worse by this status-quo, but at least companies aren't bothered by unwanted security researchers.

We need to pick a lane.

If companies want to be solely responsible for their own security, then they should also be solely reliable for any damages done by their own poor security.

Or, we can recognize that security is really hard and make it a team effort and setup laws to protect security researchers, and then special "events" wouldn't be needed for security research; anyone could test the security systems at any time, and especially people would be able to test the security of devices they own.

Re: Toyota runs a car-hacking event to boost security (2024)

#57
post #51

Earlier quoted context omitted.

I think a fundamental problem is that keys aren’t security forward compatible - break the keys and you’ve broken an entire generation (or more) of cars. The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees. But the car manufacturers don’t give a fuck if your 3 years and one day old car gets stolen. You move to the next competitor, only for the same to happen…

>The only solutions I can see are software based keying and a mobile app or legally enforced security guarantees. Wouldn't this require the phone to be trusted and not run unsigned software?

The software part is a solved problem - this is how the web is secured. There would be an exchange of keys with the car, and done.

This does not solve the problem of the timing (but the sibling comment explained that this one has a solution)

Re: Toyota runs a car-hacking event to boost security (2024)

#58

The legacy automakers have been cramming ever more ECUs into their cars, at a considerable cost expense. Tesla did something different with the big screen and one 'big computer' rather than a bevvy of ECUs. This appears to be the design pattern going forward, as evidenced by VW's investment in Rivian, where they also go for the 'big computer' approach. It seems to me that the security of Tesla cars is pretty good, co…

You can't hotwire a Tesla, but the manufacturer can, and can stop you from driving it too. I am not sure on the whole I prefer that option.

Re: Toyota runs a car-hacking event to boost security (2024)

#59

My brother had his car (a sleek AUDI) stolen in front of his house. He left the key in the entry hall, and someone extended the range. Are current electronics (the consumer ones) good enough at scale to limit the time the round-trip car-key-car takes?

Electric cars are theft proof. No car thief would steal an electric car.

Re: Toyota runs a car-hacking event to boost security (2024)

#60
post #2

The CAN bus, the network interface vehicle components use to communicate was, at least as of a few years ago, the source of basically infinite vulnerabilities. Add in over the air updates or worse, updated bluetooth or radio firmware and you find things like stopping a vehicle remotely at highway speeds[1] [1] https://fractionalciso.com/the-groundbreaking-2015-jeep-hack...

IIRC, many TPMS systems run as CAN over IP, basically giving unsecured network access to a car if it thinks it's talking to a TPMS. Granted that some/most these sensors typically have to be "paired" with a car using a scantool (sometimes), but IIRC, some are self-pairing creating a vulnerability where the legit sensor could be replaced with a hostile one. Also the possibilities of spoofing, sniffing, and/or packet in…

I know the receivers are often in a vulnerable position. But, on my 2008 era car- the code I've seen for SDR decoding is a broadcast MAC, pressure and a temp value.
Post reply on HN