Live data from Hacker News

Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

neowin.net

91–100 of 225 posts

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#92

I want a dumb EV. No infotainment system. Just speakers and a way to plug my device into them. Anything critical to the car should be completely air gapped and require an absolute minimum amount of software, preferably zero.

Nobody will sell you one for cheaper than a whole package.

See also ‘smart’ tvs vs digital signage displays aka dumb tvs.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#93
post #22

They're swapping out hardware, which is why they're asking money for this to compensate the labor costs. Not saying this justifies it, but the title is misleading.

Swapping software, pentesting, testing, QA, CI/CD pipelines, image caches aren't free either. Can we then start making more money as software developers to patch CVEs? We clearly should consider holding ourselves to a lower standard. Your requests are getting 5xx errors? Pay me more to fix it, not my problem that your requests is failing.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#94

[flagged]

This isn't about normal wear-and-tear but a fundamental security design flaw that allows thieves to steal these cars with a $25 device exploiting the CAN bus - more akin to GM shipping cars with a master key hidden under the floor mat than a pickable lock.

The article claims it's a $20k device.

Claiming it is a "security design flaw" is absurd paranoia, the same paranoia that causes manufacturers to destroy the aftermarket and fight right-to-repair in their quest for "security".

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#95

I want a dumb EV. No infotainment system. Just speakers and a way to plug my device into them. Anything critical to the car should be completely air gapped and require an absolute minimum amount of software, preferably zero.

https://configurator.microlino-car.com/en/edition-microlino?...

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#96

Earlier quoted context omitted.

Check out Slate trucks. I want that too and this seems to be perfect. Has windows you roll down even. Fingers crossed it actually launches. https://www.slate.auto/en

Yeah I’ve seen these posted here previously! Probably the most appealing new car to me at the moment. Hopefully they take off and we can get them outside the US

Have you seen Telo?

https://www.telotrucks.com/

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#97

Earlier quoted context omitted.

As far as I'm concerned, security issues (outside of very niche situations) in a product mean that the product was defective. If you sell a defective product, you should be on the hook to correct the defect.

There’s no bright line that defines “defect” and makes this determination. What Hyundai should be considering here is whether consumers will decide that buying a car from a company that doesn’t fully own their security mistakes isn’t worth it.

I agree it's hard to draw a bright line, but I'm personally comfortable erring heavily on the side of defect for security issues.

I'd be willing to agree that certain security issues might not constitute a manufacturing or design defect. If a thought-to-be-secure encryption was cracked tomorrow, that doesn't make products using it defective at the time of manufacture.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#98
If the ignition and door locks in your vehicle were mistakenly designed in such a way that they are trivially shimmed or could be operated by any key it seems absurd to suggest the customer should pay you to replace these mechanisms with ones that are properly secured. This seems roughly analogous to that situation at least to my understanding.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#99
post #93
post #22

They're swapping out hardware, which is why they're asking money for this to compensate the labor costs. Not saying this justifies it, but the title is misleading.

Swapping software, pentesting, testing, QA, CI/CD pipelines, image caches aren't free either. Can we then start making more money as software developers to patch CVEs? We clearly should consider holding ourselves to a lower standard. Your requests are getting 5xx errors? Pay me more to fix it, not my problem that your requests is failing.

> Pay me more to fix it, not my problem that your requests is failing.

If you are employed in a position where there is a defect in the product then you are already being paid. Imagine going to a restaurant and you get an uncooked frozen steak, and when you tell the waiter they tell you that since the cook will need to spend more time on it you now have to pay extra.

Re: Hyundai wants loniq 5 customers to pay for cybersecurity patch in baffling move

#100

If the ignition and door locks in your vehicle were mistakenly designed in such a way that they are trivially shimmed or could be operated by any key it seems absurd to suggest the customer should pay you to replace these mechanisms with ones that are properly secured. This seems roughly analogous to that situation at least to my understanding.

The story has a bad spin yes. But it’s just as much of a controversy if they had require people themselves pay the cost if they found out the cars where shipped with defective breaks. It’s a product error not wear and tear or user error, they should eat the costs, but the cybersecurity framing of it is being used to attempt to push the cost to the consumer.
Post reply on HN