Live data from Hacker News

VW breach exposes location of 800k electric vehicles

cyberinsider.com

61–70 of 317 posts

Re: VW breach exposes location of 800k electric vehicles

#61

Earlier quoted context omitted.

I refuse to believe that it’s not possible to drive the car without the app.

The data is collected even if you don't use the app or hit agree. The manufacturer has your personal info attached to the car from the warranty info. They're required to collect it so they can send you recall notices. It's trivial to put a car in limp mode if the vehicle computers don't detect all the modules the manufacturer put there. It's slightly less trivial to detect missing antennas, but that tends to disable…

> The data is collected even if you don't use the app or hit agree

It’s irrelevant. The matter of the discussion is “cannot drive a car without hitting I agree button”.

Re: VW breach exposes location of 800k electric vehicles

#62

Earlier quoted context omitted.

I refuse to believe that it’s not possible to drive the car without the app.

Back in the day, during the original Browser Wars, when the US Department Of Justice was trying to force Microsoft to detach Internet Explorer from Windows, Microsoft argued that it was impossible for Windows to operate without IE baked in. Well, it took a couple of "hackers" about a day to prove them wrong. I ran Windows XP without IE for years just fine. So yeah, cars can run without the app.

Of course they can. It doesn’t even make sense to consider that microsoft/ie matter.

Re: VW breach exposes location of 800k electric vehicles

#63

Earlier quoted context omitted.

The problem was caused by Cariad, not VW directly. Cariad will be held responsible for, not VW.

CARIAD is a 100%-owned subsidiary of the Volkswagen group.

Sure. Good accounting and disaster prevention from VW. The matter of the discussion proves that the decision was correct.

Re: VW breach exposes location of 800k electric vehicles

#64
post #45

Earlier quoted context omitted.

That would risk unintended consequences. For example, suddenly slowing cars on the highway down to 30 kph because a small road with that speed limit runs right next to the highway.

This becomes a thing and I'll have a 25mph sign hanging off the back of my truck. I eagerly await starting a youtube channel of new cars losing their shit on jammed tailgating attempts.

Or in Germany, if you live in the village, put up a 60 sign by your driveway and when confronted just say someone is having their 60th birthday… Germans for whatever reason like putting up a speed limit signs by their driveway when celebrating birthdays.

Re: VW breach exposes location of 800k electric vehicles

#65

Earlier quoted context omitted.

The data is collected even if you don't use the app or hit agree. The manufacturer has your personal info attached to the car from the warranty info. They're required to collect it so they can send you recall notices. It's trivial to put a car in limp mode if the vehicle computers don't detect all the modules the manufacturer put there. It's slightly less trivial to detect missing antennas, but that tends to disable…

> The data is collected even if you don't use the app or hit agree It’s irrelevant. The matter of the discussion is “cannot drive a car without hitting I agree button”.

The post you were responding to is specifically about the lack of consent, not whether the button is necessary.

Re: VW breach exposes location of 800k electric vehicles

#66
post #43

Earlier quoted context omitted.

Opt in you mean, like the cookie banners? Oh no that'll never happen because VW are a European company and the money is in fining US tech companies!

VW paid "$14.7 billion to settle civil charges in the United States" and was ordered "to pay a $2.8 billion criminal fine for 'rigging diesel-powered vehicles to cheat on government emissions tests'." https://en.wikipedia.org/wiki/Volkswagen_emissions_scandal

"Seems low" and "cost of doing business" - paraphrasing any thread about US company. Could also says "VW should be sued out of existence".

Also I genuinely think those fines were low.

Re: VW breach exposes location of 800k electric vehicles

#67
post #5

Why is nobody talking about the fact that this should not be possible? There is precisely zero reason for them to have this location data. Give the CEO one year of jail per person whose location was illegally tracked.

Can we some how hack the car and disable this "feature"?

Most likely that's illegal in DE, FR and PL. See a related thread about trains at CCC.

Re: VW breach exposes location of 800k electric vehicles

#68
post #28

EVs are topping the list of (imho) useless extras in cars. I'm still cherishing my Honda Fit pre-touchscreen edition. I'm going to drive it until it will fall apart. My next car will be an EV but I have yet to find one that still comes with mechanical features (door handles, knobs/buttons), without a whole battery of surveillance/telemetry tech and (crossing fingers) exchangable batteries. Simple electric propulsion…

Just to be clear, this breach mostly affects non-EV cars. Even my stick shift, manual window crank car came with a hidden cellular data modem, collecting my GPS location by default.

Re: VW breach exposes location of 800k electric vehicles

#69
post #66
post #43

Earlier quoted context omitted.

VW paid "$14.7 billion to settle civil charges in the United States" and was ordered "to pay a $2.8 billion criminal fine for 'rigging diesel-powered vehicles to cheat on government emissions tests'." https://en.wikipedia.org/wiki/Volkswagen_emissions_scandal

"Seems low" and "cost of doing business" - paraphrasing any thread about US company. Could also says "VW should be sued out of existence". Also I genuinely think those fines were low.

The fact that it did not seem to stunt their growth speaks for itself:

https://www.macrotrends.net/stocks/charts/VWAGY/volkswagen-a...

Re: VW breach exposes location of 800k electric vehicles

#70
post #52

Earlier quoted context omitted.

Ackhually, it is that hard, unless your method relies on millions of your devices out in the wild acting as sensors in a mesh network, as Apple does.

That’s a much harder problem than VW would need to solve. Also, Find My substantially predates the Find My network and AirTags. There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, w…

[deleted]
Post reply on HN