Live data from Hacker News

Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

eaton-works.com

51–60 of 64 posts

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#51
post #17

Earlier quoted context omitted.

> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable. Unlocking my car needs me, and my car. > when the payment terminal randomly decides to not accept apple pay? I would be justified in being mad if, randomly, my BMW car would decide to not accept…

Apple Pay even works if the phone/watch battery is "dead"

Only for Express Transit though, right? Not normal payment cards.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#52
post #15

Earlier quoted context omitted.

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work. Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regula…

Back when I had an Apple Watch, I failed to use Apple Pay on it enough times due to it being stuck in an "Updating cards" mode, so GPs "95% of times it works but sometimes you need a fallback" rings true to me.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#53
post #15
post #13

Earlier quoted context omitted.

> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…

>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…

A lot of people do not carry wallets anymore. A lot of people are not accustomed to thinking about those sorts of lists.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#54
post #41
post #39

Earlier quoted context omitted.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.

reminder, Volvo is Chinese.

Are you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#55
No wonder a few weeks before few BMS apps based on BT was banned in India as they were misused for remote disabling of e-Rickshaws.

https://timesofindia.indiatimes.com/business/india-business/...

Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#56
post #41

Earlier quoted context omitted.

reminder, Volvo is Chinese.

Are you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.

Also the exploit is not directly via volvo but with a third party

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#57

No wonder a few weeks before few BMS apps based on BT was banned in India as they were misused for remote disabling of e-Rickshaws. https://timesofindia.indiatimes.com/business/india-business/... Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.

I was recently researching building large LiFePo4 battery banks and realized just about every BMS I looked at featured a BT connection. That was disappointing as I assume there is little to no security for pairing ans communication. Anyone could sabotage or shut down a battery bank.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#58
post #39

Earlier quoted context omitted.

reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.

I don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity. Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.

there's no point in being moral when these companies with their immense resources will just ignore you or refuse to give a measly bounty

things won't change until they have to make an effort

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#59

Earlier quoted context omitted.

ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work. Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regula…

Back when I had an Apple Watch, I failed to use Apple Pay on it enough times due to it being stuck in an "Updating cards" mode, so GPs "95% of times it works but sometimes you need a fallback" rings true to me.

That's surprising. Of all the Apple Watch's many failings (such as its hilariously bad transcription) I've never had Apple Pay not work flawlessly on it. One of the main reasons (the other being the "make my phone loudly beep" button) I even bother having one, the rest of the features being so underwhelming for its price.

Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles

#60
post #29
post #17

Earlier quoted context omitted.

> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable. Unlocking my car needs me, and my car. > when the payment terminal randomly decides to not accept apple pay? I would be justified in being mad if, randomly, my BMW car would decide to not accept…

The point isn't that it's fine for smartphone car keys to randomly fail, it's that there's plenty of other reasons they can fail that you're already living on the edge if all you're carrying is your phone. Therefore the "it's dangerous to assume ..." claim doesn't hold.

> there's plenty of other reasons they can fail that you're already living on the edge if all you're carrying is your phone

I see what you're arguing, but I just want to point out 2 things:

1. If I leave the house for a trip (especially a distant trip) with just my phone, I and anyone would understand intuitively my own responsibilities: namely, to keep my phone intact and its battery from draining completely. Since I already have a strong interest in both of these for other reasons, this is basically automatic anyway, and a backup plan for the latter is completely doable - I'd have to drop $20 on a gas station phone charger and hang out somewhere for 10 minutes while it goes from 0->6% or whatever. Anyway, if I understand my responsibilities like this, I'm able to make an informed decision on whether to trust it.

2. If we're victim-blaming here, saying "Serves him right, should have carried the keyfob as a backup" that renders it pointless to even have phone-as-key. The fob not having to be in your pocket or handbag is the only benefit. Unless, I suppose, you consider phone-as-key as the actual backup, for use only in the case you drop your keyfob into a storm drain. But that isn't how it's marketed at all. In my entire life, I've literally never lost my car keys, because they just stay in my pocket the whole time I'm away from home. So I'd value a 'phone-as-backup' at $0.

Post reply on HN