this post was submitted on 23 Jan 2025
261 points (99.2% liked)

Technology

60956 readers
3876 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 32 comments
sorted by: hot top controversial new old
[–] [email protected] 5 points 4 hours ago

You know, if they didn't track and connect to your car, there would be nothing to hack! Cheaper all around!

[–] [email protected] 5 points 7 hours ago

Jokes on you, my car is 20 years old

[–] lunatic_lobster 42 points 23 hours ago (1 children)

For anyone who has a Subaru and wants to get rid of this there is an aftermarket part you can install to bypass the telematics radio without losing access to any other features (if you just unplug it I think speakers stop working)

https://www.autoharnesshouse.com/69018.html

It's $80 for the one that retains the OEM head unit, but I'm thinking that might be worth it.

[–] Blaster_M 9 points 23 hours ago

Now that's something I'm looking for

[–] DarkFuture 30 points 1 day ago* (last edited 1 day ago) (2 children)

The Starlink system is TRRAAAAAAAAAASH.

Shit is designed like shit and crashes/freezes all the time. A pop up you have to hit AGREE on pops up every time you turn on the car and you have to wait a solid 5 seconds before you can hit it. You have NO control over the touch screen until you do so. None of the physical buttons work either. So whatever volume you had your speakers at when you turned the car off is what you get for a solid 5 seconds when you turn the car on before you can turn the speakers down. What kind of shit for brains developers/engineers were responsible for that gem?

It is categorically awful. It's really unfortunate that a bad touch screen system can basically eliminate a car for perspective buyers.

[–] EncryptKeeper 5 points 9 hours ago

Mazda has the same pop up issue. Luckily online you can flash a program to a USB stick that lets you pick and choose infotainment hacks to apply to your car, that pop up, and the restrictions on using the touch screen when moving along them, and then you just plug it into the car and it auto applies.

[–] [email protected] 3 points 10 hours ago (2 children)

Are there any car infotainment systems that aren't complete shit?

I bought a Subaru over 10 years ago and I didn't give the infotainment part enough scrutiny when checking it out. I love the way the car drives, but anything dealing with the radio just pisses me off. I don't even have Starlink.

[–] [email protected] 3 points 4 hours ago

I have a 9-year old Subaru I bought used, first thing I did was trash the "radio" and replace it with an iDoing chinese Android head unit.
It's not super polished, but much better than the trash Subaru put on it. The good thing they did was NOT integrate it into the car too much, so replacing it meant losing no functionality at all.

[–] [email protected] 3 points 8 hours ago* (last edited 8 hours ago)

Are there any car infotainment systems that aren't complete shit?

Absolutely.

The infotainment system in my car consists of a glass-mount phone holder that turns the in-panel display from a worthless piece of glass into a convenient spot to rest my phone while I drive. A+, 10/10, would highly recommend.

(I did mount it on the corner of the display, but I don't actually use the built-in system. Haven't even bothered to get the backup camera replaced since it stopped working.)

[–] [email protected] 35 points 1 day ago (1 children)

The scary part to me (noted in the article as well) is less the technical hack but more so the amount of data they are collecting.

Subaru had/has an ongoing issue where the telematics drains the battery while the car is parked, especially if it’s parked out of reach of cell towers. With the amount of data they are sending, it’s not surprising.

There is no need for the car to report its position whatsoever unless I request assistance.

[–] [email protected] 19 points 1 day ago

At 38C3, there was a talk about Volkswagen - a German car manufacturer - that didn’t correctly secure the data it collected from its vehicles and what you can „learn“ from this data. The talk can be found here, it’s in German but there’s also an English translation in another audio layer

https://media.ccc.de/v/38c3-wir-wissen-wo-dein-auto-steht-volksdaten-von-volkswagen

[–] [email protected] 77 points 1 day ago (4 children)

Simply removing the two-factor auth element which does nothing to access the main page underneath. I do that shit with newspaper paywalls. That is wild.

Also having a script in there that just resets a password no questions asked. WTF is going on with modern software development? It isn't just Subaru. It's almost everything in the last 15 years. Behind all the pretty lipstick, IT systems are jankier than ever.

For any aspiring programmers, remember, never ever assume the user is rational, expecting them to follow the rules. At least half of your user data-handling code should be validation and sanity checks. Code defensively.

[–] [email protected] 1 points 7 hours ago

That password reset looked to be like step four of something. So it's a business logic bypass. Still awful of course but slightly more understandable given other ways this vulnerability could have been introduced. The cool part was detecting all the steps completely blackbox because everything was in the Javascript.

There is no excuse for issuing a valid token before mfa succeeds though. That is negligent.

[–] [email protected] 67 points 1 day ago (2 children)

WTF is going on with modern software development?

Lowest bidder.

[–] [email protected] 6 points 11 hours ago

Now add AI in the mix :)

[–] orrk 16 points 1 day ago

even worse, it's a joke, but it's true, the proof of concept is often also the final product

[–] [email protected] 14 points 1 day ago

Trust no-one, not even yourself.

[–] [email protected] 22 points 1 day ago (1 children)

Subaru data opt out page from the eff:

https://www.subaru.com/support/consumer-privacy.html

No idea if they respect it, but its a good idea regardless.

[–] [email protected] 4 points 10 hours ago

Best case: It actually opts you out.
Worst case: They ignore it, and you've only supplied them with info they already have.

[–] PalmTreeIsBestTree 19 points 1 day ago* (last edited 1 day ago) (2 children)

I’m glad Starlink doesn’t work anymore on my older Subaru since it used 3G cell towers. To be specific, if any of you got a pre 2020 Outback, then you should not have to worry about this. I had a battery issue and the reason why is because my car was constantly searching for the towers and draining it. I ended up getting a free battery out of that ordeal though.

[–] Dr_Nik 7 points 12 hours ago (1 children)

They will now replace the Starlink module free of charge under a recall. Your battery will keep dying unless you either replace the module or remove the fuse that activated the thing.

[–] PalmTreeIsBestTree 4 points 12 hours ago (1 children)

They told me specifically that they didn’t replace it. I told them not to.

[–] Dr_Nik 6 points 12 hours ago (1 children)

Well sure...they won't replace it unless you want them to...it's your car. But what I mean to say is that they can replace it under warranty now and if you don't replace it you will keep losing batteries. That's what happened with my 2018 Outback (I went through a battery every 3-6 months for 3 years).

[–] PalmTreeIsBestTree 2 points 12 hours ago

I only had this battery replacement last year. My previous battery actually still worked okish when they replaced it, but they said they would replace it for me for free. It was almost 7 years old when I had it replaced.

[–] [email protected] 8 points 1 day ago* (last edited 1 day ago) (1 children)

Here's the list. Looks likes its mainly models up to 2018. Your 2020 is likely still affected.

[–] PalmTreeIsBestTree 5 points 1 day ago

Mine is an 18.

[–] just_another_person 28 points 1 day ago

Something similar was found on another system by a certain Korean carmaker and silently patched. I'm positive these types of systems will all be exploited more in the future, and need to be completely overhauled. Cars should not be reachable entities on any sort of network, especially one without proper IAC restrictions. They should be consumers of said information at best, but even that will eventually be impersonated somehow. We have the potential for turnkey system with all the damn devices running around that can be used as a 3-key-minimum system to ensure proper identity, but that would be giving consumers TOO MUCH CONTROL 🤣