5 comments

  • darknavi 1 hour ago
    > November 3, 2025: Reported.

    > November 10, 2025: No response, followed up.

    > November 17, 2025: No response, followed up and copied some additional people on the thread.

    > November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed.

    > July 27, 2026: Published

    Quite the generous timeline on this person's behalf.

  • Xeoncross 43 minutes ago
    There is security that protects users and then there is security theater that provides litigation protection for the company.

    Sometimes overlapping, but they are not the same thing.

  • spockz 53 minutes ago
    This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car.

    Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy.

    On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?

    • motbus3 9 minutes ago
      How they will be able to block you from using your car when they deem that you should by a new one? Or how would they be able to make something a paid feature after you bought it? You need to support these poor fellas
    • samdhar7 7 minutes ago
      [flagged]
  • nhance 1 hour ago
    I love this sort of content on HN. I am very curious what the impact of powerful AI has on these type of things
    • EatonZ 54 minutes ago
      In this case, AI wasn't used for anything.
  • superloika 38 minutes ago
    I feel obligated to post this very cool FSF Car right-to-repair video https://www.fsf.org/videos/fight-to-repair/