NHacker Next
  • new
  • past
  • show
  • ask
  • show
  • jobs
  • submit
Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles (eaton-works.com)
darknavi 1 days ago [-]
> November 3, 2025: Reported.

> November 10, 2025: No response, followed up.

> November 17, 2025: No response, followed up and copied some additional people on the thread.

> November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed.

> July 27, 2026: Published

Quite the generous timeline on this person's behalf.

greyface- 1 days ago [-]
And terrible (non-)response from VECV, if they have any interest in receiving timely disclosure from future researchers.
r_lee 23 hours ago [-]
reminder, these vendors like Volvo etc., don't really want you to report vulns, you should just sell them to a broker instead and get some actual money as well, it's a win win.
mpdpsycho 22 hours ago [-]
I don’t know why particularly here over elsewhere, but this thought really makes me feel disappointment in the whole chain of humans responsible for the cost optimization away of product integrity.

Though in this case, with all the tracking being thrown into newer cars, maybe a bit of a gap is a good thing for the future. Jailbreaking vehicles would be a cool thing to see become widespread.

r_lee 4 hours ago [-]
there's no point in being moral when these companies with their immense resources will just ignore you or refuse to give a measly bounty

things won't change until they have to make an effort

cromka 22 hours ago [-]
reminder, Volvo is Chinese.
johanmrtnsn 12 hours ago [-]
Are you thinking about Volvo cars? There are two Volvo companies, Volvo cars and Volvo group. This seems to be about Volvo group which makes commercial vehicles like trucks and busses.
ashu1461 8 hours ago [-]
Also the exploit is not directly via volvo but with a third party
loloquwowndueo 21 hours ago [-]
How so? Sources?
solarkraft 21 hours ago [-]
dhathorn 21 hours ago [-]
That would be Volvo cars. tfa is about Volvo group, which is Swedish and makes among other things Volvo trucks. (Or HGVs as they might be called in Europe)
cromka 21 hours ago [-]
Oh, fair. I assumed this was consumer cars.
1 days ago [-]
tesnorindian 12 hours ago [-]
No wonder a few weeks before few BMS apps based on BT was banned in India as they were misused for remote disabling of e-Rickshaws.

https://timesofindia.indiatimes.com/business/india-business/...

Securing BMS should be the top priority for EVs. Keeping unsecured BT connection in BMS would be the worst thing.

MisterTea 7 hours ago [-]
I was recently researching building large LiFePo4 battery banks and realized just about every BMS I looked at featured a BT connection. That was disappointing as I assume there is little to no security for pairing ans communication. Anyone could sabotage or shut down a battery bank.
spockz 1 days ago [-]
This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car.

Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy.

On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?

jjice 1 days ago [-]
Agreed that it's absurd. Consumers continue to purchase cars that do this though. BMW doing this, having proprietary bolt heads, and the subscription heated seats fiasco from nearly a decade ago have made it clear that BMW is a make that will try to screw you at every turn, yet people continue to purchase them.

It's a shame. I will continue to purchase vehicles with as internet connected and touch screen features as possible. My 2025 Toyota has knobs and a physical key still. Terrified what will be left on the market when I have to get a new vehicle in (hopefully over) 15 years.

gruez 1 days ago [-]
>On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?

Surely there's more to this story? AFAIK last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time.

xp84 1 days ago [-]
> last time I heard about something like this, it was because the guy's car was parked 5 stories underground, and didn't carry his car keys, because he was using his phone to unlock all the time

I hope you aren't suggesting that set of details makes this okay. I should be able to park in a faraday cage 2 miles underground and still start it the same as I can on the surface. Including with my phone, if it's equipped with phone-as-key.

The phone-as-key shouldn't only work when online and shouldn't require the car to be online, either. And this is a problem trivially solved with proper use of cryptography.

The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup. Just like I don't carry two car keys.

bri3d 1 days ago [-]
It doesn't; BMW use the CCC Digital Key standard for "Digital Key Plus" and there's no Internet required post provisioning. This story really reeks of misunderstanding or "needs more information" as for BMW especially, I don't see any scenario where this could have happened, regardless of physical or phone key use.
cloudfudge 1 days ago [-]
It's possible they were trying to do something like remote start, which (at least in my bmw) does use the godawful bmw online service. In the retelling, this might have expanded to "couldn't start the car."
gruez 1 days ago [-]
>The reason for this is that if the car gives people the ability to start a trip with a phone, it's dangerous to assume they'll always carry a keyfob as a backup.

How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works, and then getting mad at the shop/credit card company/apple when the payment terminal randomly decides to not accept apple pay? Not to mention there are plenty of other ways a phone can fail. It can fall into a toilet, you can drop it and the screen cracks, etc. By not carrying the keys, you're rolling the dice every time.

>Just like I don't carry two car keys.

That all depends on your risk appetite. I normally wouldn't carry money in my socks, but if I'm in a foreign country I very well might. Likewise if I'm going on a road trip where I might be days away from home, I very well might bring a second key, in case i accidentally lock one in the car or whatever.

throwway120385 23 hours ago [-]
ApplePay doesn't communicate with Apple through your phone, it presents the card details as a contactless EMV transaction through the card reader, so it's pretty much spot on as an example of how this should work.

Just so you know, EMV can work entirely offline if you need it to, because the reader has the public keys that the card requires to authenticate and vice-versa. ApplePay uses the same NFC standard as regular EMV contactless cards to communicate, it just happens to be a powered microprocessor instead of a radio-powered microprocessor but that's about the only difference. The smart card standard is really old and covers the exact use case of "what happens if I need to use this thing without the Internet because the Internet wasn't ubiquitous when it was developed.

kalleboo 17 hours ago [-]
Back when I had an Apple Watch, I failed to use Apple Pay on it enough times due to it being stuck in an "Updating cards" mode, so GPs "95% of times it works but sometimes you need a fallback" rings true to me.
xp84 4 hours ago [-]
That's surprising. Of all the Apple Watch's many failings (such as its hilariously bad transcription) I've never had Apple Pay not work flawlessly on it. One of the main reasons (the other being the "make my phone loudly beep" button) I even bother having one, the rest of the features being so underwhelming for its price.
jtbayly 1 days ago [-]
It's very different, because you aren't moving from car to car. You're using your car with your digital key. There is no expectation of things changing. Rightly so.
esterna 1 days ago [-]
> How's this any different than say, not bringing your wallet with you, because 95% of the time apple pay works

Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable.

Unlocking my car needs me, and my car.

> when the payment terminal randomly decides to not accept apple pay?

I would be justified in being mad if, randomly, my BMW car would decide to not accept a BMW key (virtualized or otherwise).

> Not to mention there are plenty of other ways a phone can fail. It can [...]

"I will not accept this Euro bank note. You could have dropped it into the gutter on your way here, so it's strange for you to be mad at me if you don't have a backup."

gruez 1 days ago [-]
The point isn't that it's fine for smartphone car keys to randomly fail, it's that there's plenty of other reasons they can fail that you're already living on the edge if all you're carrying is your phone. Therefore the "it's dangerous to assume ..." claim doesn't hold.
xp84 4 hours ago [-]
> there's plenty of other reasons they can fail that you're already living on the edge if all you're carrying is your phone

I see what you're arguing, but I just want to point out 2 things:

1. If I leave the house for a trip (especially a distant trip) with just my phone, I and anyone would understand intuitively my own responsibilities: namely, to keep my phone intact and its battery from draining completely. Since I already have a strong interest in both of these for other reasons, this is basically automatic anyway, and a backup plan for the latter is completely doable - I'd have to drop $20 on a gas station phone charger and hang out somewhere for 10 minutes while it goes from 0->6% or whatever. Anyway, if I understand my responsibilities like this, I'm able to make an informed decision on whether to trust it.

2. If we're victim-blaming here, saying "Serves him right, should have carried the keyfob as a backup" that renders it pointless to even have phone-as-key. The fob not having to be in your pocket or handbag is the only benefit. Unless, I suppose, you consider phone-as-key as the actual backup, for use only in the case you drop your keyfob into a storm drain. But that isn't how it's marketed at all. In my entire life, I've literally never lost my car keys, because they just stay in my pocket the whole time I'm away from home. So I'd value a 'phone-as-backup' at $0.

noja 1 days ago [-]
> Apple Pay involves at least a third party (your bank) as a part of its function. This entity has to be reachable.

No it doesn't. It has to have a recent token, and if it does not it will contact your bank.

formerly_proven 24 hours ago [-]
Apple Pay even works if the phone/watch battery is "dead"
kalleboo 17 hours ago [-]
Only for Express Transit though, right? Not normal payment cards.
graemep 13 hours ago [-]
A lot of people do not carry wallets anymore. A lot of people are not accustomed to thinking about those sorts of lists.
dotancohen 1 days ago [-]
My Tesla works like this. No internet connection needed, just Bluetooth.

I do keep a card key in my wallet just in case.

spockz 1 days ago [-]
In this case it was with car keys and the valley where they are parked has no cell reception at all. Apparently they could still enter the car but not “start the engine”. They then managed to get a code from the dealer to unlock the car. I’m unsure whether it was a software bug relying on communication unnecessarily, a intended feature, or something like an alarm being triggered which triggered some fail safes.
motbus3 1 days ago [-]
How they will be able to block you from using your car when they deem that you should by a new one? Or how would they be able to make something a paid feature after you bought it? You need to support these poor fellas
knowaveragejoe 1 days ago [-]
I just want the most basic, no-frills EV truck. I'd even pay a premium over what such a thing _should_ cost. I want no cloud connectivity _at all_ unless I add it myself in some way.
xoxxala 1 days ago [-]
You might want to check out Slate:

https://www.slate.auto/en

No embeded modem.

Cider9986 1 days ago [-]
Rivian let's you disable all connectivity.

https://news.ycombinator.com/item?id=47967786

Grombobulous 24 hours ago [-]
That is admirable, though of course it should be a legal standard, and there should also be legal standards for building features in a way that allows you to use them when your data collection is disabled.

Disabling data collection shouldn’t disable entire major features like lane centering and navigation. Even tech giant spyware companies like Google offer offline maps.

dotancohen 1 days ago [-]
I believe that Tesla does, or did. I never disabled mine as I want the vehicle to improve on the roads that I frequent. And it has, noticeably so, in the four years I've owned the vehicle.
jeffbee 1 days ago [-]
You can disable connectivity in any car by pulling fuses.
olyjohn 23 hours ago [-]
Yeah but sometimes that disables other things too. Like when I pulled the fuse on my car for the radio, it disabled the power door locks and the door/headlight chime. Not every item gets it's own circuit.
HDBaseT 18 hours ago [-]
Not without consequences.

You could be sacrificing other features, increasing your increase premiums (or get claims denied) or potentially breaking the law.

jeffbee 18 hours ago [-]
Telematics systems for insurance are not even lawful in my state.
morkalork 18 hours ago [-]
Should honestly be a matter of national security. A bad actor could brick and entire county's vehicles
samdhar7 1 days ago [-]
[flagged]
heaney-555 24 hours ago [-]
>modern cars

Tesla doesn't have this problem. It just works. No cloud needed, other than at the time of purchase.

vitally3643 24 hours ago [-]
That's only because they were all designed before the always-on spyware madness began.
MattGrommes 22 hours ago [-]
They send over-the-air updates all the time. If they project that it'll be profitable, they'll switch everybody over as soon as you can say the words.
wkjagt 23 hours ago [-]
I should look into how this affects my 1981 Volvo 244
Xeoncross 1 days ago [-]
There is security that protects users and then there is security theater that provides litigation protection for the company.

Sometimes overlapping, but they are not the same thing.

pixel_popping 1 days ago [-]
Both are important actually, the security theater often deter from trying because it could be too annoying, it's generally "free to do", along with additional obfuscation, it's useful too but does not replace proper security, but from experience, theater+obfuscation+security is greater security than just security.
superloika 1 days ago [-]
I feel obligated to post this very cool FSF Car right-to-repair video https://www.fsf.org/videos/fight-to-repair/
nhance 1 days ago [-]
I love this sort of content on HN. I am very curious what the impact of powerful AI has on these type of things
EatonZ 1 days ago [-]
In this case, AI wasn't used for anything.
dotancohen 1 days ago [-]
I believe that it was used to generate the post that you replied to.
kjs3 24 hours ago [-]
AI driven/automated farming for kharma will only get worse...
formerly_proven 24 hours ago [-]
The person you are replying to wrote that post.
Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
Rendered at 21:23:02 GMT+0000 (Coordinated Universal Time) with Vercel.