Earlier quoted context omitted.
> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable. Unlocking my car needs me, and my car. > when the payment terminal randomly decides to not accept apple pay? I would be justified in being mad if, randomly, my BMW car would decide to not accept…
Apple Pay even works if the phone/watch battery is "dead"
Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
51–60 of 64 posts
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#52Earlier quoted context omitted.
>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…
ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work. Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regula…
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#53Earlier quoted context omitted.
> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped w…
>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention ther…
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#54Earlier quoted context omitted.
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
reminder, Volvo is Chinese.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#55https://timesofindia.indiatimes.com/business/india-business/...
Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#56Earlier quoted context omitted.
reminder, Volvo is Chinese.
Are you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#57No wonder a few weeks before few BMS apps based on BT was banned in India as they were misused for remote disabling of e-Rickshaws. https://timesofindia.indiatimes.com/business/india-business/... Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#58Earlier quoted context omitted.
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
I don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity. Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.
things won't change until they have to make an effort
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#59Earlier quoted context omitted.
ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work. Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regula…
Back when I had an Apple Watch, I failed to use Apple Pay on it enough times due to it being stuck in an "Updating cards" mode, so GPs "95% of times it works but sometimes you need a fallback" rings true to me.
Re: Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles
#60Earlier quoted context omitted.
> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable. Unlocking my car needs me, and my car. > when the payment terminal randomly decides to not accept apple pay? I would be justified in being mad if, randomly, my BMW car would decide to not accept…
The point isn't that it's fine for smartphone car keys to randomly fail, it's that there's plenty of other reasons they can fail that you're already living on the edge if all you're carrying is your phone. Therefore the "it's dangerous to assume ..." claim doesn't hold.
I see what you're arguing, but I just want to point out 2 things:
1. If I leave the house for a trip (especially a distant trip) with just my phone, I and anyone would understand intuitively my own responsibilities: namely, to keep my phone intact and its battery from draining completely. Since I already have a strong interest in both of these for other reasons, this is basically automatic anyway, and a backup plan for the latter is completely doable - I'd have to drop $20 on a gas station phone charger and hang out somewhere for 10 minutes while it goes from 0->6% or whatever. Anyway, if I understand my responsibilities like this, I'm able to make an informed decision on whether to trust it.
2. If we're victim-blaming here, saying "Serves him right, should have carried the keyfob as a backup" that renders it pointless to even have phone-as-key. The fob not having to be in your pocket or handbag is the only benefit. Unless, I suppose, you consider phone-as-key as the actual backup, for use only in the case you drop your keyfob into a storm drain. But that isn't how it's marketed at all. In my entire life, I've literally never lost my car keys, because they just stay in my pocket the whole time I'm away from home. So I'd value a 'phone-as-backup' at $0.