VW breach exposes location of 800k electric vehicles
cyberinsider.com
cyberinsider.com
No, a software switch is not enough. We need to be able to physically unplug the cellular modem entirely and have the vehicle work with 100% functionality (barring features which inherently require cellular connectivity like turning the heating on remotely)
Car manufacturers' features are mostly useless anyway thanks to Android Auto/Apple CarPlay
The simplicity makes me think that law-makers can understand it.
They can and do though, and they are.
https://www.peters.senate.gov/newsroom/press-releases/senato...
Opt In should NOT be required to enable features.
Features should not be rented, and should be delivered as purchased with the car. Shipped but disabled features that take up additional vehicle weight (relative to lacking the feature) should not be allowed. (This phrasing is precise, to allow for silicon and software enhancements which are not a material change to vehicle manufacturing / design.)
Setup processes should always empower the user. If there are multiple choices or paths a default may be indicated, but alternatives MUST NOT be in other locations, and MUST be displayed with equal prominence in a logically adjacent section of the dialog.
Example from a website: 'Paperless' should not be force enabled by default; the ability to have paper or paperless billing should be radio boxes next to each other. Additional benefits (E.G. higher account interest rates) should not be tied to either selection.
If this made it more expensive, because having cars that are physically different is harder, would you prefer that?
Why can't I simply not care that I don't get something I've not paid for and there's a doodad in the car that's capable of it?
If the alternative is having to buy that feature or pay more for a car that doesn't have it, that sounds like a bad outcome.
If I'm not free to do so - then do I actually still own my own product? Or is it now a lease?
Why should the era of rebuilding your car simply end? There are already safety regs you need to comply with. The average hotrod modifies a considerable proportion of the car. Reusing the majority of the structure in ways the manufacturer did not intend.
Somehow hammer manufacturers can live with this. Why can't automakers, tech device manufacturers, and software developers live with this?
"Your hammer has reached its monthly nail limit. Please upgrade to the pro plan to unlock an additional 60 nails"
Anyone that has built a moat/lock-in will, sooner or later, screw you over.
Hammer manufacturers would too, if they could. But hammers are simple devices.
But the larger point is definitely true.
Although, it seems to have been only available/produced in Brazil, Columbia, Russia, Uzbekistan, which I'd argue is in line with my original sentiment.
I always bought medium sized cars at 10 years when they're already only a grand or two. The smallest ones are made so cheaply that they're already too tired at this age and strangely enough they're more expensive due to the lower road tax. So more people want them.
And then I used to drive them till the maintenance becomes too expensive, for 5 or 6 years or so. And just scrap them then.
I guess if I still owned a car I could still do this for a good while without having to get spyware. But not too long.
More like every couple months on the road, from my experience in having driven one. Just this year here are couple of things that have occurred:
>glowplugs burnt out
>air-mass sensor failure
>faulty abs-sensor
>fuel nozzle malfunction
>brake failure
>engine back support failure
>short circuit after worn-out manufacturer divider causing massive sparking, heating and a drained battery
Some additional fixes identified recently not yet fixed:
>faulty brake booster
>moisture buildup(?)in door mechanisms leading to it sometimes not opening from inside
>rust buildup in some parts, needs replacing before reaching important bits
>transient misfire/spray/clog on acceleration leading to computer shutting off engine power
My last car was a Volvo S40, had really nice leather interior, nearly full option and cost me €2000.
I only had a few brake pads an a broken trunk cable to deal with (super common issue on this model), the latter I did myself for €40 in parts. Ran great for years. But yeah there's an element of luck also.
My previous car was an Octavia, that had more issues. Electric window broke and I replaced it all myself. But it was a pretty nasty job. Eventually the gearbox started whining and when I brought it to the shop it basically blew up. But it had served me 5 years at that point. Cost me €1200 to buy.
20+ years old Volkswagen as a long range vehicle and daily driver. Yearly (preventative) maintenance: $300-400.
As another example, side impact airbags have been mandatory in the US since 2013, but the Volvo 850 had them in 1995 and they were present on something like half of new cars a decade before they were mandatory and >97% of new cars three years before the mandate.
I'd hope in 10 years 4G and maybe be 5G would also be defunct with their networks turned off.
https://foundation.mozilla.org/en/privacynotincluded/toyota/The only possible use of cell service is for infotainment and even that’s questionable in a world of ubiquitous cell phones.
(/s)
Yeah, that can save 15 minutes of scraping the windows for snow and ice in the morning and afternoon.
If they had a garage next to their house to park their car they wouldn't need either. However there are lots of situations where the car isn't close yet it need pre heating. For me this is driving the car to and from work in the winter, and certain one off situations (going home from the hospital, picking up the car after avriving at the train station).
Also handy to find your car if you manage forget where you parked for some reason. Or to set a destination for GPS navigation.
Marginal knicknacks vs. serious risks kind of thing here.
It wasn't even the point of analogy dear. Help: the benefit/risk ratio is the point.
What you think about using information is different to what criminals think about using the information of anyone using the product. Not you is the point here, wrong orientation again. Everyone have the superfluous knicknacks, and everyone had their data leaked.
Maybe if you think you will not loose your credit card, you are much more organized for that or whatever superpower makes it so, or there will be no-one to take significant ammount from it, then please, write your PIN on the back. For you precious convenience. Better yet, have everyone's PIN written on it!! : /
Sorry for the bitter sarcasm, but I hate so much the self centered reasoning in something that is for everyone, you kind of people ruin things for all of us by allowing, even asking for fiddle-faddle tacky things, that expose all the rest to risks and dangers!
I thought I saw instructions somewhere for my 2020 prius but can't find it now. a few reddit threads asking about it, I like the suggestion that even if its eSim or somehow embedded in the cellular modem, "Disconnect the antenna! / shunt the telecommunication modems antenna with a resistor shunt. It will trick the radio into thinking the antennas still connected but won't allow any data to be going out they just won't get signal"
https://www.reddit.com/r/Toyota/comments/1be9zuc/wheres_the_...
But I guess you mean on the car side like two modems? Yeah that would be nice, or at least to mandate the option to turn all manufacturer telemetry completely off. The EU never bothered to do this for computers and phones either though.
https://www.thalesgroup.com/en/markets/digital-identity-and-...
But the sim card doesn't have access to the car telemetry. Probably even the whole baseband module doesn't. It just gets that data to transmit when an accident happens.
The worst you could do by hacking the SIM is to make the modem send nearby cell data somewhere. Which is serious enough because the rough location can be derived from it. But it's a far cry from what these manufacturers collect.
Of course when the modem is on you can't be sure that it's not doing that but that's what we have laws for.
No need of having always on connection to the network, enable on emergencies only. Thus no remote hacking of SIM/base band possible at random times, or broadcasting presence until used. Mechanic or user can check battery periodically, replace if low, just like refilling wiper fluid. Car could even cut all other electric systems after deploying the integrated autonomous V16-like system.
Car manufacturers deciding to make their ECall implementations complex and privacy invading was their choice.
I'd rather focus on standardizing a transparent and privacy safe way to gather these metrics. Consumers would know what metrics are collected and there would be guarantees that privacy is kept. There are ways to accomplish this today.
Providing a way to disable metrics is never going to be sufficient for anyone other than a power user.
Honest question, what is a good reason to do this?
My Logitech software sends telemetry to Logitech.
My VW apparantly sends my GPS coordinates.
How is this useful for improving their hardware?
The most obvious metric that everyone wants to know is failure or crash rates. After a software update it's always good to know if those rates went up. Those errors may be recoverable, but it's good to try and understand them to improve reliability. Maybe pairing android auto with specific phone models is more problematic, or maybe trying to pair Bluetooth is particularly bad under specific conditions like high thermals in warmer climates. It's pretty difficult to interop testing with all possible parties in all conditions.
You know what will help in those situations ? Testing.
It is expensive, i know. Why not skip it and just analyse the KPIs from the telemetry. /s
I'd rather see laws to have it disabled by default. People who don't mind can then opt-in again.
Tell that to Microsoft. Although their products have telemetry, they become shittier every day.
It should have a standard UI for doing so, but if you are technically inclined it is usually trivial to do- pulling a fuse, or changing a setting over the OBD port.
However, you will lose useful features like advanced charging controls, and starting the HVAC remotely on EVs.
Also, effects mostly EVs, but not only. (If the EV motor was the group usually logged to the opened AWS bucket, I don't understand how there were ICE or possibly hybrid cars involved in the leak.)
https://streaming.media.ccc.de/38c3/ had a german language video on it, live, but will surely add english translation and permanent video link soon.
I can't parse this. Is there a missing word? Mostly implies other possible inputs but the last part of that sentence specifically says this is confusing. Why is it hard to understand how ICE or Hybrid groups also had access to a bucket EVs mostly had access to?
Many Volkswagen cars somehow report telemetry. Looks like there is data not only from the EVs based on the MEB plattform? But for a Name/email to be associated with the VIN of the car, the owner has to register and use the app (once). Many EV owners did, but fewer of the non EVs did.
The data-collection has nothing to do with the used engine, but the software-platform. Basically, the "OS" on which the car is running. EVs and premium Cars where the first to modernize this platform, and for obvious reasons they all use the same platform. After that, other cars are moving on to this platform too, so they now have a mix of different car-models who are mainly defined by their price-category.
I will not buy a car that does this. I am starting to turn my phone off when I am not using it as well. Being tracked every second of my life is not acceptable.
In the case of full location data, it would need to be a lot more though. Yes, that might bankrupt the company. They should have thought about that before they illegally stalked nearly a million people then put their highly sensitive data on the Internet.
If I did this to one person, I'd probably (and rightfully) go to jail. I'd like the same standard applied here.
Adbusters magazine (credited with spurring occupy wallstreet with a solid meme campaign) tried to get inertia going around revoking corporate charters, stop acting like we don't have power, corporations are borne into existence by acts of government, we are not powerless to punish them for crimes against humanity (to be dramatic about it, I don't know what language would be appropriate for collecting location information for a million individuals without disclosure), but didn't see much traction about it.
https://www.adbusters.org/full-articles/rise-of-the-corporat...
A dynamic economy is great on paper where you don't have to worry about disrupting the lives of tens of thousands of people. Call that a political moat.
Unfortunately it looks like that might be pretty hard:
https://foundation.mozilla.org/en/privacynotincluded/article...
In the name of data protection, you are not even allowed to have two main users of the car. As a result, it’s either me or my SO being able to see the car‘s state of charge in the mobile app. It’s impossible for both to see it except you do account sharing
We all just let surveillance haplen to us, in fact we paid for most of it
Kindergarten transactions one day, escort payments on another.
It was — and still is — creepy. An average Joe like me shouldn't be able to pry into someone's private life like that.
Instead they should think from the perspective of an evil person. E.g. "how can I proactively use whatever data that I can get to hurt someone."
For example, at a previous job I went to my managers and pointed out that every developer working on our system had access to our user's names and their involvement with racial justice programs our client was running. By guessing someone's ethnicity from their name, a bad actor could target minorities involved in racial justice. The response I got was not to fix the security issue; instead it was horror that I would ever conceive of such a scheme.
Do you have a written record of the conversation?
From experience, they usually come up with some variation of "If you have nothing to hide, you have nothing to fear" [1]. And even those who buy the idea that private information could be used against them, most of them don't believe that someone would do this to them. What seems to be missing is understanding of how scalable and automated these attacks can be in the digital world.
[1] Amusingly enough, one of those "I have nothing to hide" people was pretty shaken when they asked me to take a look at a scam email that said "Hello <firstname from leaked database>, we have photos of you watching porn. Pay us or we'll post them on Facebook."
Has anyone had success with informing people about these types of abstract dangers? I find that people either get it almost immediately, or they never really get it until it happens to them.
Ignoring of course that the amount of aggregated surveillance makes it impossible to escape monitoring. Credit cards, license plate scanners, phone GPS, airtags, doorbell cameras, "Eye in the Sky" spy planes, etc
Trip to McD's with a price of exactly happy meal + tax one day, and a recurring payment for XXX website OnlyFans access the next. Adjust the values to taste/theory. Sometimes a credit card is just a credit card.
"A rich one!"
The average joe is merely a side effect of the government collecting all that data. The government is also why your car reports its location.
I can even keep driving while the whole system is rebooting. Around here (where we have many immigrants and some odd practices) I’ve seen people with a towel hanging over their screen while driving, to protect it like a dust cover I guess.
The one thing you might argue I do need from my screen is the speed, which is very easy to see and usually not needed in the flow of traffic.
The outcry against screens is just misinformed imho. My car has plenty of mechanical buttons.
At least you're still acknowledging the abysmal state of modern cars by including this statement. Why on earth would anyone expect otherwise from a car?
EVs are computers on wheels, expecting them to work during reboot is not unlike expecting vim to work during a reboot :)
EVs are not computers, they have computers. The controllers that make it go should stay on during a "sudden reboot". Expecting them to keep working is like expecting my coolant pump to work during a reboot, not vim.
I’ve owned and driven EVs from several brands. Prior to this, I could pretty much always expect the following from my car:
1. The drivetrain always operates normally and safely (aside from some actual mechanical failure) with no computer glitches.
2. I can always see my speed and gear selector state on a dashboard somewhere, even when (not if) the infotainment screen crashes and reboots. I’ve had (2010-2020ish era) Lexus, Audi, and others have infotainment glitches, crashes, and reboots, but the speedometer, drive train, and AC all had physical controls running on isolated systems and so they always continued to work through a reboot or glitch of the infotainment.
3. The AC is always operating (aside from some actual mechanical failure) with no computer glitches or lag to my ability to control it. I consider this a critical safety system given that many drive in climates with weather that can be dangerously hot or cold.
In pretty much every EV I’ve owned, none of these have been true except maybe #1, and that is pretty sad to say that the only thing that hasn’t happened is my entire cars wheels locking up on the highway (and yet still this is reported happening for many EV brands, Tesla, Audi, and Porsche at least come to mind where I’ve read stories).
It’s insane to me that it’s even possible for the cars computers rebooting to entail AC shutting down, not being able to see your speed, etc. If this EVER happens, the entire vehicle line should legally require a recall until it’s guaranteed this won’t happen. We have ways of guaranteeing computer systems don’t fail like this to extremely high probability — car companies only don’t do it because it’s expensive and more complex than just throwing all the same crappy software into one single system rather than designing multiple isolated fault tolerant systems.
Less horrible but still shockingly bad regression is how almost all modern cars AC is controlled through an often laggy computer system (not to mention the almost universally despised move of AC controls to touch screens, instead of physical controls). Maybe not so laggy on Tesla, but in my experience both BMW and Audi have AC control touch screens which sometimes respond but occasionally can have 1-10 second random lags before anything responds. Presumably due to garbage collector lag or something. But this is also a mild safety issue since the lack of predictable behavior from common controls makes it very distracting when trying to so something so common and simple as adjusting the temperature that should just be as simple as a simple physical button or knob.
I don't want to have anything to do with a company like that.
But hey, maybe if I wait around another 5-10 years, there'll be more than 3 mainstream electric sedan options available for the US market and I'll be able to find the perfect car.
Fully EV, real buttons and knobs, and of course the model is cancelled.
The original tracking was 2G cellular, later updated to 3G cellular. 2G is long depricated, and 3G is already shutdown in many places.
This is a great car! Which explains why it's no longer available. It doesn't meet modern american needs, like being at least as large as a small building, or having 0 visibility over the hood, or costing at least $75K. (p.s. I paid $15K for mine, with 18K miles on the odometer and 150 miles of battery range)
But if you're into retro, like buttons and knobs, I highly recommend it...
p.s. I have to wonder if the data breach doesn't affect ICE cars as well? Would they use a separate surveilance system?
Expensive yes but might be worth it if you value your privacy.
I'd be surprised if there was a dedicated fuse for only a modem really, especially in an EV or hybrid.
In the process some forum threads would pick up hundreds of posts over a decade or more so that removal of every nut, bolt, screw, plastic plug, etc is documented with photos, allowing anyone with the vehicle to see exactly how to take ownership of the vehicle from the manufacturer.
True old-school old manning involves not only removal of all the bullshit, but also covers all cosmetic changes to the vehicle that would be needed to eliminate all signs that any of the offending components were ever installed and would include things like how to accomplish all the trim and body work necessary to permanently fill all the holes in the vehicle like antenna penetrations through the vehicle body and plastic trim mods to fill holes that formerly held buttons or switches that no longer exist.
In the process, old-school old manning would attack the software used in the vehicle, removing all the offending functionality with a custom flash tool so that the only software running on the vehicle after all the mods are completed would be that which controls and monitors engine and transmission functionality since that is actually the only software on a vehicle that adds value by allowing the vehicle owner to track operating efficiency in real time.
The region sharing might be needed to efficiently update things like the map and the speed limits.
https://www.mediarealm.com.au/articles/fm-rds-radio-data-sys...
https://cariad.technology/content/dam/digitalmindofmobility/...
EDIT: Just noticed this is an ISO9001 certificate. Though on their job offer site they do ask for "Foundational understanding of security related regulations and standards preferred (e.g. ISO21434, ISO27001, NIST-800)". Unclear if they are actually ISO 27001. Found the 9001 one by fluke, they don't seem to list that one on their site either.
Please explain that to my IT department.
edit: I've never prepared for our audits and we always get our certification, no matter what they find as long as you say "yes, we are aware"
I drive a 1997 ES300 that needs a new left rear taillight lens. The new part doesn't exist anymore, and I can't find a used part in Canada.
Most modern cars, especially ones that fit into more "luxury" brands have an app. That app gives you telemetry and location data for a price. It's rather convenient to be able to pre-condition your car, or figure out where you parked in a massive unlabeled parking lot, etc. This is all consented to, but regardless the data is tracked anyway via some GPS/cell system modern cars have. When you pay for it you get more stuff - anti-theft, better tracking, service tracking, etc.
It's a convenience. I'm not entirely comfortable with it but if you want a better-than-decent car made after 2016 you probably have it on-board and unless you rip the ECM out you're stuck with it. Personally, I'd rather pay BMW, for example, for anti-theft and tracking than pay OnStar or another service that is gonna stick me with a ridiculous contract and stuff my car with even more buttons.
Unless you somehow aren't kidding, in which I'll clarify: I'm skeptical that a modern electric vehicle that goes to the trouble of being a computer on wheels can work without an app. And I'll even clarify "can" - the car manufacturer allows you to operate the car without using its app.
It's trivial to put a car in limp mode if the vehicle computers don't detect all the modules the manufacturer put there. It's slightly less trivial to detect missing antennas, but that tends to disable other features people enjoy like directions and data. Manufacturers simply don't care to cat-and-mouse this right now.
It’s irrelevant. The matter of the discussion is “cannot drive a car without hitting I agree button”.
Especially in the EU, the hypocrisy is jarring: on one hand, GDPR, protecting users from surveillance by businesses, etc, and on the other hand, car companies get a free pass, because they are car companies, and the EU likes car companies.
Based on what sort of data was exposed, it seems plausible that it is one of the services from WirelessCar.
Stop people driving to protests? areas of strategic interest? congestion? Yep that's all coming quick.
The US does not have a GDPR so the collection of this information is legal. How much data is lying around at GM and others for someone to abuse?
Then maybe the rest of the world will follow suit.
I know, I know, I am kidding myself.
Oh no that'll never happen because VW are a European company and the money is in fining US tech companies!
(I am in Europe for reference, this is not an external perspective)
Also I genuinely think those fines were low.
https://www.macrotrends.net/stocks/charts/VWAGY/volkswagen-a...
I've had cars with both automated speed limit sign readers, GPS+map databases, and more show me two different speed limits and neither one was actually correct for the lane I was in. This is a somewhat common occurrence on the highways around me.
A few examples:
1) drive past the end of town sign in a particular German town, the car thinks it is 30kph, but only during the day because at night it doesn’t see the sign so it thinks it’s 50 where in reality it’s a 100 until the next speed limit,
2) driving between a couple of roundabouts inside of a town in the Netherlands, the car thinks it’s 30kph even though we stay within city limits and there’s no sign so the speed limit remains 50kph,
3) this is the funniest one so far… driving in Antwerpen along the Turhoutsebaan, there’s a massive 30 sign painted on a red painted road surface, the car insists that the speed limit is 50kph.
Those are just three out of a dozen examples happening consistently within 30 square kilometres I normally remain within. And I drive this car for 2.5 weeks. I have seen the future and I don’t like it. Number 2) happens routinely inside of the city limits after right or left turn. Car drops the speed limit to 30 just to realise a 100m down the road that it is 50.
Apologies for the ad hominem, I normally stay away from such tone. I genuinely hope that such pseudo cops like you get a grip. Because it’s my life you’re talking about and I already use speed limiter routinely. Every idiot around me on the road has exactly the same choice as me: curb the ego down and slow down or behave like a douche.
> but it would be even better if all cars' speed were automatically limited to the speed limit of each road
Yeah, you just described the ISA of 2027. This is going to be a tough year for car manufacturers. I forecast a ton of unsold new cars remaining on parking lots because one has to be really technically illiterate to buy something so dangerous willingly. Either full self driving or give full control. Everything in between is a disaster waiting to happen.
By the way, here’s a funny thought. So what is going to happen when that mythical zero casualties is reached and more people will be dying on bicycles than in car accidents? An implant in the brain? Where does it stop?
I don't think anything will need to happen at that point. We wouldn't need to tackle down the top causes of death if the numbers were low, as seems to be the case of bicycle deaths not caused by cars. And when it comes to speeding, it's already against the law, so the technology is only trying to help prevent it. But of course, my enthusiasm is tied to a future where this technology works reliably, so I don't really expect anything like it with all the problems you're describing with current models.
It’s also illegal to participate in the traffic drunk yet I routinely see drunk people riding bicycles and scooters in regular traffic, often ignoring traffic lights, often with their face glued to a phone. That’s half a problem, the other problem is those same people with those same things on the sidewalk. I bet you, a ton of those people do not even have a driving license and/or understanding of traffic rules. Humans will be humans. First they cry for cycling paths, when they get them, they don’t use them. Cannot win stupid.
As a pedestrian in the city I want scooters and bicycles regulated AND enforced. But nobody cares. I stopped counting how many times I have to do acrobatics to walk around scooters and bicycles left in the middle of the sidewalk.
It would also give local governments a power they never had before: To directly control your behavior in the moment, with no judicial control or oversight.
No, thank you.
The only question that matters is would it result in fewer road deaths? I bet the answer is yes.
In the US every single day 100 families are torn apart by a death on the road. I’m sure you don’t want it to be yours.
Neither you nor me live in the US. They have other options to reduce those deaths. There’s no reason to drive a 4 ton EV truck made out of stainless steel doing 0 to 60 mph in 3 seconds.
Speed doesn’t kill, it’s the sudden stopping that does.
I live in Europe. Regulations here make Teslas slam on the brakes when the road is curved by more than x degrees, and break off a lane change apruptly if they take longer than x seconds. The intentions behind these rules written by some buerocrat in Brussels surely were as good as those behind the cookie banner.
I’m glad I still get to override those rules with my pedals and steering wheel.
The system can tell you if there was a runaway truck (at your time and location), so an appeal should be easy for that uncommon situation.
- Speed of every car on the road is recorded continuously.
- If you stay within the limit, you pay nothing. For each second that you are faster than the limit, you incur some financial penalty, where the amount is calculated based on both the speed difference and the purpose of the limit (pedestrian safety vs. noise pollution, for example). In extreme cases, you can lose your drivers license.
- Speed data is also made available to your insurance. So drivers know they won’t get away with somebody else paying for any damage they may cause.
As a driver, I very much prefer this not to exist. But I think it would be the right thing from a “veil of ignorance” perspective of justice.
Earlier it said I was on a 30mph road despite being on a 20mph road
What is the speed limit in that field?
Would a car suffer from similar problems? Should it continue at the original rate of speed or slam the brakes?
Did the same with two other phones. Car play takes the location from the car rather than the phone.
Huge privacy violation. I would just close down this business. Unfortunately it's a state cartel, and even part owner. They'll change the constitution to save those criminals
Your license plate already has your name and address associated with it.
It was a very clear prompt during initial setup, and it shows me a very unambiguous notification that it's enabled every time I start the car. If I click on that it takes me to the setting.
edit: might even have been opt-in during initial setup, now that I think about it. I do recall it being a very deliberate thing during setup.
Of course I'll have to trust that turning it off actually turns it off, no way for me to verify that.
The reason I keep it on is because my SO is a bit absent minded to where she parks the car, and I value not having to run around in the streets trying to find it when I'm in a hurry over the potential privacy loss.
edit: Renault was found[1][2] to be the "least problematic" with respect to privacy by Mozilla last year.
[1]: https://foundation.mozilla.org/en/blog/privacy-nightmare-on-...
There are very straightforward solutions, depending on the threat model. For example, the app could send VW a private key every day, and VW would send that key to the car. Then the car sends periodic location reports, encrypted to that key. VW can, upon request, send the report to the app, which decrypts it. But VW can’t decrypt the report itself, so they don’t know the location of the car. Also, it’s forward secure in the sense that a leak of VW’s database is entirely useless after a day.
It would also introduce a lot of additional failure modes.
Doable but not exactly trivial.
I realize that modern development has layers and layers of documents and teams and overcomplicated interfaces, but this is the kind of thing that could be done by one developer, using two servers and a load balancer (or a more creative HA scheme with client assistance that can easily survive complete loss of a datacenter or two), that can handle the entire fleet.
My car for example doesn't have reliable connection when it's parked in the garage, which is where I charge it.
Your solution would add a lot of extra edge cases that needs to be considered.
You have to ensure the updated key is reliably transferred to the mothership in a timely fashion, and subsequently that the key is reliably transferred to the car in a timely fashion.
That's the back-end stuff. There's also the front-end stuff, like will my SO understand why her app isn't showing the car's location but mine is?
Not saying it's impossible, but it adds a lot of complexity beyond simply encrypting the location with multiple keys.
Losing connection for extended periods of time can get in the way of "timely" key updates but they won't cause the encryption to fail.
> That's the back-end stuff. There's also the front-end stuff, like will my SO understand why her app isn't showing the car's location but mine is?
Well the reasons I can think of are either things like the server being broken, which can happen without any encryption, or she didn't finish setting up her app and waiting for it to sync which can also happen without encryption. Or she was removed from the list because she didn't open the app for a year... which can also happen without encryption.
To be fair, if the car is offline while a newly installed app logs in, then the app won’t be able to locate the car until the car checks in. Which is not actually the end of the world, and there are ways to mitigate this. (See iMessage and Keybase for a couple of different approaches to this. See Signal for a shockingly poor group of bizarrely mutually incompatible solutions that barely work. I think that Matrix tries, too. MLS should be able to handle it, and piggybacking off an existing standard like MLS might be entirely reasonable albeit dramatically more complex than the simple solution I outlined.)
Where do you work and are you hiring?
Otherwise, if there is no pre-existing private channel, the key (which by the way would have to be the public key, not the private key) could be switched out by VW acting as a man-in-the-middle, allowing it to access all encrypted content going through it.
The same is true for Apple. There are parts of the protocol or the pairing where you have to trust Apple, either their servers, or if the establishment happens locally via bluetooth or similar, their software that runs on the local devices.
I’m a owner of a id.4 (or rather a user of it, since my company owns it)
(I know the EU doesn't mandate annoying cookie banners but unintended consequences etc)
I can't seem to find a link to the leaked data. I want to see if I'm in it.
As per this guy, maybe I should sell my vehicle before VW is sued out of existence. https://www.reddit.com/r/electricvehicles/comments/1hnh3sg/c...
The government will investigate itself and find no wrongdoings, let's go after the journalists who committed the ultimate crime: Embarassing Officials.
Never mind that it's a for-profit company that does the surveiling, and wrote the faulty IT structure.
Neoliberal religion runs deep...
no one is denying it's a for profit company, but its governance model doesn't really scream "neoliberalism". assuming you're from the US, (German) enterprises like VW are vastly different from what exists in the US, not just in the terms of their structure but also their influence on Germany and EU.
Maybe legal needs to have a talk with marketing.