• encelado748@feddit.org
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    So you have hackers mass compromising rooted android os around the world hoping for an overlap with Volkswagen users with the app, so that they can hack the app to unlock a car hopefully located near them instead of just opening the first car you find with a suction cup on the glass.

    Ok, got it

    • artyom@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      2 days ago

      you have hackers mass compromising rooted android os around the world

      Not necessary. You only need to compromise one. Any one without some sort of integrity service. And it ain’t that hard. Pick one of many with poor security practices.

      instead of just opening the first car you find with a suction cup on the glass

      You cannot start a car with a suction cup.

      • jj4211@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        You cannot start a car with a suction cup.

        I can’t start my car with my car’s app either.

        If you really want to be picky about it, block out the unlock feature and any potential ‘phone as key’ functionality. Leave starting the air conditioning and information.

        • artyom@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 days ago

          I can’t start my car with my car’s app either.

          …okay? I can. What is that supposed to mean here?

          block out the unlock feature and any potential ‘phone as key’ functionality

          So you want them to break the app, rather than just securing it?

          • jj4211@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            It means that if you are so obsessed with protecting a user from making an informed decision about their own security, then you could gracefully degrade in your ‘horribly insecure context’ instead of just bombing out completely.

      • encelado748@feddit.org
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        2 days ago

        Ok, I am the hacker from France that compromise the golf in Florida. Now what? Do I start the engine to pre-condition the car from across the ocean? You know you cannot even drive with the app, just start the engine… There is no reason at all for going all the way and doing this. None.