Live data from Hacker News

Toyota runs a car-hacking event to boost security (2024)

toyotatimes.jp

71–80 of 115 posts

Re: Toyota runs a car-hacking event to boost security (2024)

#71

That's great, but the writing is still on the wall if Toyota doesn't get serious about electric cars. With their current trajectory Toyota is headed at 1000mph directly towards being the next Blackberry, Kodak, Nokia or Blockbuster. I say this as someone who owned a Prius for 10 years and loved it, and have also driven their hydrogen car. The BZ4X is badly named overpriced garbage, not enough and not good enough. The…

EVs are trash compared to equal price gas car. For example if you compare camry with a similarly priced EV, BYD or Tesla doesn’t have quality/reliability at the same level

Re: Toyota runs a car-hacking event to boost security (2024)

#72
post #64

Tangent but I have a 2016 Toyota 4Runner. Great car and fits my family and needs perfectly. The key fob broke so I needed to get a replacement, I got a blank and had a locksmith cut and program the blank. He must have not done it right because it worked and then I got stranded cause it must have lost its pair to the car or something. Nothing wrong with the vehicle, the engine wouldn’t start because of the key. I do r…

Did you get a genuine key? I never had one fail on me. The immobilizer is the single best piece of technology for preventing car theft. If you create a backdoor for bypassing it, you'll end up like Hyundai/Kia which decided to sell cars without the immobilizer in recent years and which have turned into a joke in the minds of potential customers. It does not require a battery in most cases and is separate from the kee…

The Stellantis systems I’ve worked on have a nice feature that there is a battery for the proximity use, that you can keep the key in your pocket and press the button to run the car, as long as the key is within the four or five proximity sensors you are fine.

When that battery dies, you can press the directly to the start button and it uses a “receiver powered transmitter” RFID close proximity to start and run the vehicle.

Most people don’t know this, so when that battery dies they panic and suffer.

Re: Toyota runs a car-hacking event to boost security (2024)

#73
post #64

Tangent but I have a 2016 Toyota 4Runner. Great car and fits my family and needs perfectly. The key fob broke so I needed to get a replacement, I got a blank and had a locksmith cut and program the blank. He must have not done it right because it worked and then I got stranded cause it must have lost its pair to the car or something. Nothing wrong with the vehicle, the engine wouldn’t start because of the key. I do r…

for my 2016 Mazda, the keys do not need a battery to operate. you instead need to hold the fob up to the start button and it will work passively, rather than just being in the car normally. Glad they still give manuals with cars as I had to learn that without service.

There are three systems to the key, the doors and remote start, the “passive entry” which requires the battery, and the backup RFID you’re talking about.

Re: Toyota runs a car-hacking event to boost security (2024)

#74
post #14

Earlier quoted context omitted.

The iPhone did everything the Nokia 3310 did, better. Electric cars do not (yet) do better some things hybrids do, such as being able to be fuelled with 400+ miles of range in 5 minutes. I’m nowhere near the point of wanting an electric car to replace my hybrid. The convenience of petrol and the cost of electricity is too high. High electricity costs aren’t going to be fixed in my country any time soon so Toyota will…

The iPhone actually had way worse battery life than basically any Nokia. It’s a great comparison. People happily traded more features for having to plug their phone in every night.

iPhone also had same modem as everyone. It wasn't a Wi-Fi device, it was a phone-computer hybrid.

Compared to that, EVs feel more like Wi-Fi or WiMAX device that owners would say theirs are daily drivable but only make Discord calls. Overall situation more closely resemble PDAs before iPhone.

Re: Toyota runs a car-hacking event to boost security (2024)

#75
post #2

The CAN bus, the network interface vehicle components use to communicate was, at least as of a few years ago, the source of basically infinite vulnerabilities. Add in over the air updates or worse, updated bluetooth or radio firmware and you find things like stopping a vehicle remotely at highway speeds[1] [1] https://fractionalciso.com/the-groundbreaking-2015-jeep-hack...

IIRC, many TPMS systems run as CAN over IP, basically giving unsecured network access to a car if it thinks it's talking to a TPMS. Granted that some/most these sensors typically have to be "paired" with a car using a scantool (sometimes), but IIRC, some are self-pairing creating a vulnerability where the legit sensor could be replaced with a hostile one. Also the possibilities of spoofing, sniffing, and/or packet in…

>IIRC, many TPMS systems run as CAN over IP,

I’ve been in this industry for 20-some years not a single system I’ve ever seen operates like that.

CAN over IP does not exist invehicles. IP over CAN doesn’t exist at all. UDS over IP does, but this is automotive Ethernet and an entirely different discussion.

Re: Toyota runs a car-hacking event to boost security (2024)

#77

The legacy automakers have been cramming ever more ECUs into their cars, at a considerable cost expense. Tesla did something different with the big screen and one 'big computer' rather than a bevvy of ECUs. This appears to be the design pattern going forward, as evidenced by VW's investment in Rivian, where they also go for the 'big computer' approach. It seems to me that the security of Tesla cars is pretty good, co…

Wasn't Tesla basically a Toyota until recently? The big dash computer was just a car equivalent of Nest thermostat, at least when I looked at it, it could have been an Arduino with a key cylinder and the car would work fine.

Re: Toyota runs a car-hacking event to boost security (2024)

#78

Earlier quoted context omitted.

Did you get a genuine key? I never had one fail on me. The immobilizer is the single best piece of technology for preventing car theft. If you create a backdoor for bypassing it, you'll end up like Hyundai/Kia which decided to sell cars without the immobilizer in recent years and which have turned into a joke in the minds of potential customers. It does not require a battery in most cases and is separate from the kee…

The Stellantis systems I’ve worked on have a nice feature that there is a battery for the proximity use, that you can keep the key in your pocket and press the button to run the car, as long as the key is within the four or five proximity sensors you are fine. When that battery dies, you can press the directly to the start button and it uses a “receiver powered transmitter” RFID close proximity to start and run the v…

This technique of pressing the dead key to the starter button works for quite a lot of brands, not just Stellantis vehicles. Always worth trying if you are in a "keyless" car with a dead key fob battery.

In my experience virtually everything made in last 15 years will either support this RFID backup or have a spare physical key hidden inside the keyless fob.

Lots of them will even let you press the dead key against some part of the exterior to unlock the doors too.

Re: Toyota runs a car-hacking event to boost security (2024)

#79

Earlier quoted context omitted.

Tesla sells nearly as many cars in a quarter (497,099 in Q3 2025) as the Leaf managed in its entire lifetime (577,000 between 2010 and 2022).

Is the hating Tesla tantrum over? That being said, you can’t really compare the sales of all of Teslas to the sales of one specific form factor/model with any kind of seriousness. Nor do I think it’s a fair comparison to compare Tesla that has parted on various hype patterns over the years to tap the zealots into even becoming their free advertisement and marketing departments not unlike how Apple fanboy cult people…

The Toyota number is very misleading because dealership employees don’t have Toyota badges; they have Dave’s Hometown Stealership badges. Tesla store employees have Tesla badges.

You’re counting customer-facing employees for Tesla and leaving them out for Toyota.

Re: Toyota runs a car-hacking event to boost security (2024)

#80

There's 2 things when it comes to security: Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Also, companies are not responsible (liable) for their own poor security. If they do something like leak the p…

> Companies are responsible for their own security. You cannot try to hack them without their permission. Security researchers who do something like test the security of a car without the permission of the car manufacturer (like in this post) are committing a felony. Not a single sentence here is correct.

I think you need to expand here. My understanding is that there is a lot of law you can fall foul of pen testing and sharing vulns on products of companies you don't work for.
Post reply on HN