3 ms·
Quite a few other manufacturers have done the same thing. I use a reverse engineered Polestar library to get charging status but I'm in the middle of building a
by venzaspa 4mo ago
Quite a few other manufacturers have done the same thing. I use a reverse engineered Polestar library to get charging status but I'm in the middle of building a CANBUS sniffer to do the same job because I don't trust they won't do the same thing as this.
I don't really understand it, it doesn't seem to offer a huge potential revenue stream and it pisses off the people who are most invested in your product.
- ethagnawl 4mo agoRight? I imagine there would be a non-trivial sales/marketing boost for the one/first company (in any segment) to fully embrace HA. IKEA is arguably a good example of this.
- summm 4mo agoThey already add cryptographic authentication to some CAN messages, so you can't change them. It is only a matter of time until they add encryption. This is mostly a corporate problem of risk aversion in my opinion. Some department writes down a risk assessment with a list of miniscule risks, for example of some 3rd party app backend being hacked. Or just a headline "Tinkerer hacked his car to use with his home assistant" in the local press. This list circulates, and since nobody in the middle management wants to be responsible for anything, and there is no officially approved positive use case, draconian countermeasures are drafted and constructed one by one.
- ornornor 4mo ago> draconian countermeasures are drafted and constructed one by one. Except when it’s about privacy or anything else we actually care about: then absolutely nothing is done because it would cost more than 0 to do anything.
- reactordev 4mo agoOn the contrary, lots are being done about it, they have to update their terms of service…
- summm 4mo agoDepends. In some sense EU companies are quite afraid of the GDPR. Privacy is used in a twisted way in that argument: if any privacy relevant data is exposed to another party, and there is any incident down the line, they fear they could be made responsible. So they to block you as a user to access your own data. Of course, if that privacy risk came from them storing and selling your data, they happily accept that, you are right in that regard.
- formerly_proven 4mo agoIt’s a fair assumption that most of these things are trickle-down effects of CMS/R155 and CRA combined with very high risk aversion on the company side. The less you expose, the lower the risk.
- cisophrene 4mo ago> It is only a matter of time until they add encryption. I hope I won't be in one of those cars when the in-memory encryption key gets bit-flipped by the unfortunate cosmic ray.
- b3lvedere 4mo agoProving that autopilot killed that poor old granny because of cosmic rays would be an interesting case study.
- cisophrene 4mo agoIt actually happened with Toyota around 2010: they went into a settlement regarding an unintended acceleration issue because it was proven the code was terrible and a single bit-flip could cause the behaviour. https://en.wikipedia.org/wiki/2009%E2%80%932011_Toyota_vehicle_recalls https://en.wikipedia.org/wiki/2009%E2%80%932011_Toyota_vehic...
- b3lvedere 4mo agoVery interesting read. Thank you for the link.
- cisophrene 4mo agoAnother interesting case: a proven case of bit-flip that affected a voting machine in Belgium: https://www.independent.co.uk/news/science/subatomic-particles-cosmic-rays-computers-change-elections-planes-autopilot-a7584616.html https://www.independent.co.uk/news/science/subatomic-particl...
- b3lvedere 4mo ago“ A mobile phone with 500 kilobytes of memory might only have one error every 28 years, but a router farm, such as those used by Internet providers, with 25 gigabytes of memory could have one every 17 hours.” I wonder if current AI devices have protection against this…
- therealpygon 4mo agoI suspect the manufacturer probably cares less about what you do to your own car and hacking it, than they do about the potential for security compromise of their products on a broader scale, where they will then get blamed and sued for not having closed said loopholes. It is a no-win situation when it comes to fault assignment.
- ryandrake 4mo ago> Or just a headline "Tinkerer hacked his car to use with his home assistant" in the local press. It's pretty sad that "User used their product in a novel way we didn't expect" is seen as a risk that must be mitigated.
- SoftTalker 4mo agoThey had to add this stuff because it was possible to unlock and start a car by accessing the headlight socket. https://www.thedrive.com/news/shadetree-hackers-are-stealing-cars-by-injecting-code-into-headlight-wiring https://www.thedrive.com/news/shadetree-hackers-are-stealing...
- andylynch 4mo agoThis is kind of an interesting contrast with BSH (Bosch and Siemens home appliances ), who are also German. They appear to have seen making their Home Connect platform open as at least in part a matter of compliance with EU data transparency and portability laws.
- tclancy 4mo agoIs there a repo for the new project?
- qludes 4mo agoThe ability to interface with your car is fundamentally at odds with the regulatory momentum that's going towards encrypted everything. Take a look what the automotive risc-v people are working on or the requirements of the EU cyber resilience act.
- Tangurena2 4mo agoJohn Deere started the trend with locking down the farm equipment they sell.
- MostlyStable 4mo agoI just found out about an open source product that might fit your needs, the WiCAN: https://www.meatpi.com/products/wican-pro https://www.meatpi.com/products/wican-pro
- c10o 4mo agoI open my VW app and I think I know why: https://imgur.com/a/nj0dLku https://imgur.com/a/nj0dLku