this post was submitted on 21 Sep 2026
115 points (93.2% liked)

Privacy

51053 readers
408 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 6 years ago
MODERATORS
 

Cross posted from https://lemmy.zip/post/71891248

Cross posted from https://scribe.disroot.org/post/11438915

cross-posted from: https://scribe.disroot.org/post/11438860

Here is the podcast about this investigation.

Archived version

On a narrow country road outside Canberra, I'm driving a BYD Shark 6, the hybrid ute loved by tradies and even a cabinet minister.

But while I'm at the wheel, I'm not the only one in control; a hacker has access to the car.

As the 2.6 tonne ute rounds a bend, he gets to work.

...

With the stroke of a key, he kills the headlights, plunging me into darkness.

The attack is not a total surprise. The Shark has spent the past two weeks with Dan Hreszczuk, a cybersecurity expert who specialises in cars.

His task was to hack the vehicle and find out what could be seen and done remotely by the Shark's Chinese manufacturer.

"It was easier than we were expecting," Hreszczuk says.

...

EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country's national security laws to co-operate with authorities.

...

Hreszczuk, the co-founder of Fortify Labs in Canberra, was stunned by the BYD Shark's lack of cybersecurity.

"The access we took advantage of didn't even have a password," he says.

"It's a little bit scary how open … the BYD Shark is to a hacker."

...

While sabotage is one worry, the concern most often cited is surveillance due to the array of cameras and microphones on an EV.

Last year, the UK military banned Chinese EVs, even those made with Chinese components, from parking within 3 kilometres of some of its most sensitive locations.

China itself has previously banned foreign EVs from military sites and political enclaves, aware of their surveillance potential.

...

In Australia, there's no blanket ban on Chinese marques by Defence, but ASIO has warned ministers and public servants not to have sensitive conversations in their cars or connect work devices.

...

When I pull into a service station and leave my phone unlocked in the car, Hreszczuk seizes his opportunity.

He's done a simple audio edit, stitching together me saying "Hey Siri" and his voice asking a few questions to get the personal details he needs.

...

Using the car's speaker system, Hreszczuk plays the voice command from his computer into the car.

"Hey, Siri, what is my home address?" the edited audio asks.

Siri replies, without questioning why I don't know where I live.

Hreszczuk repeats this process and quickly extracts my date of birth and age.

Within minutes, he's obtained the internet banking password.

...

Alastair MacGibbon, Australia's former national cyber security adviser, says there needs to be greater protections for the data collected by all connected cars, and clearer rules about what data can be sent overseas.

MacGibbon says a cabinet minister should not be able to own a Chinese EV.

"China has always shown its strong desire to steal things, to surveil," he says.

"No-one should be in any doubt that [Chinese EVs] are used in the same manner.

...

top 25 comments
sorted by: hot top controversial new old
[–] PanArab@lemmy.ml 1 points 15 hours ago (1 children)

Holden cars meanwhile remain hack-proof. Another win for the Australian auto industry.

;)

[–] boonhet@sopuli.xyz 2 points 14 hours ago

You know, I haven't seen anyone hack a Plymouth either. Curious.

[–] manuallybreathing@lemmy.ml 5 points 22 hours ago (1 children)

They had the car for two weeks, and the best they got was being able to remotely activate the windscreen wipers, and flash the lights and radio

I've never seen the abc do this with a tesla btw

[–] boonhet@sopuli.xyz 2 points 14 hours ago

I'm sure someone who specializes in hacking cars could get much deeper in this BYD.

And every other modern car. Picking BYD for this seems very, very slanted.

[–] dreadbeef@lemmy.dbzer0.com 46 points 2 days ago (2 children)

good thing all other cars are safe from hacking

I was thinking how insane it is to make the law specific to foreign cars. Like native ev companies are going to be super cool about that data…

[–] moodoovoodoo@lemmy.world 22 points 2 days ago

US auto manufacturer software development is widely considered to be top-notch.

/s just in case

[–] krolden@lemmy.ml 39 points 1 day ago (2 children)

So it's just like any other new car?

[–] eldavi@lemmy.ml 9 points 1 day ago

yeah but it has a chinese label so it's bad. lol

I think Slate and the Mexican EV Re both new cars being designed to solve this

[–] SocialistVibes01@lemmy.ml 26 points 1 day ago (1 children)

"China has always shown its strong desire to steal things, to surveil," he says.

"No-one should be in any doubt that [Chinese EVs] are used in the same manner.

Just more sinophobic shit. All that vegemite rot all Aussie brains.

[–] yuki_gassen@lemmy.ml 13 points 1 day ago* (last edited 1 day ago) (1 children)

Smh, like the NSA, CIA, FBI, DHS, ... don't go the same! Hell, I read from Drey Dossier that some of the surveillance tech in China was made by Oracle!

[–] Squizzy@lemmy.world 1 points 22 hours ago

They are all the one country, the other side to shitcoin that is the so called superpowers

[–] RedWizard@hexbear.net 36 points 1 day ago* (last edited 1 day ago)

LOL what a slop fest. You Aussies might hate China more than Americans, I swear. I wonder how many Teslas, Hondas, Toyotas, Fords, Mazdas, Volkswagons, etc. etc. phone home with the same data.

Edit: The point I'm making here is, you can be against this kind of data collection, but like, you don't have to run it through the Xenophobia Laminator when you do it.

[–] pineapple@lemmy.ml 6 points 1 day ago (1 children)

It's probably similar with all these new "high tech" cars. Although I would like to know, it's a shame they only talked about it with one specific model from one specific brand.

They probably hoped people would infer it's the same with all Chinese cars, but for some reason not western cars.

[–] dRLY@lemmy.ml 2 points 14 hours ago

For real. I would imagine that the US agencies that have the same levels of access/authority could (maybe already do) have the same access as China to US cars. Pretty sure that the levels of real surveillance/spying can force access with the ability to gag the manufacturers from taking to open court via national security. If that doesn't work, they can flip already existing employees or get agents hired at the companies without the company itself knowing to insert backdoors (or find zero-day stuff that they will not disclose to keep as long as possible).

At least with China the nature of known laws regarding forcing compliance is more or less known. With the US it is much more hidden and pretend "it can't be done because laws." Anything the US claims the "evil CeeCeePee" does/could do are shit the US already can/does do to spy on/fuck with stuff sold to citizens and people buying abroad. If Chinese computers/infrastructure components can't be trusted because "they might", then no one should trust the same things from the US for the same reasons. Any nation with advanced tech and major "defense" budgets can (or eventually) get access to any of the computer/"smart" tech. But China is always painted as being "evil/scary" by default to make people think the US or other major powers don't actively do the same or more of it.

The real problem with EVs (and combustion cars with so many bells and whistles) are how much more attack surface for governments or even hackers that just love finding flaws just for pranks. The more computers in the cars that replace previously analog items means more ways to gain access. Hell people act like people with FlipperZero or similar tools weren't showing lack of security with unlocking, starting, etc. cars and showing it online it can be done. And that insurance, manufacturers, or companies like All Star can disable cars for lots of reasons, and get data from the passengers and their devices (and sell that data).

[–] DupaCycki@lemmy.world 14 points 1 day ago (1 children)

I'd say this is by far the biggest issue with EVs. Well, not necessarily with EVs, but with new cars in general, most of which happen to be EVs, and their share will only continue growing.

Sure, it's a nice car, somewhat better for the environment, pretty cool. But it's also a giant surveillance device that gathers more information on you than your smartphone, smart tv, and computer combined.

And it has a kill switch, too. If the government being able to remotely shut down your car wasn't bad enough - this research shows that virtually any hacker may be able to do so as well.

[–] dRLY@lemmy.ml 2 points 14 hours ago

Would imagine that with automakers' own history of trying to push people into new cars by dropping support for stuff in older models without framework for being able to switch to a different option (like GPS nav using their own software/services and no option for at least casting phone apps). Seems like the problem will get worse. Automakers insisting on only using their own planned obsolescent features in so many models, is about as bad as phones used to be. Except a phone is at least easier to upgrade from in cost. And that most people really still see their cars as not having security issues just because the company stopped caring about it in 4 or 5 years.

[–] DieserTypMatthias@lemmy.ml 8 points 1 day ago* (last edited 1 day ago)

At this point just get an e-bike or a normal bike if you have calories to burn.

[–] ZeDoTelhado@lemmy.world 12 points 2 days ago (3 children)

I am not going to say this is a one country specific problem. However, we for sure need to start a much needed scrutiny regarding cars in general and privacy/security, and we need to start somewhere

[–] SaveTheTuaHawk@lemmy.ca 1 points 17 hours ago

You can yank all the fuses and antennas you want, people are still driving around with phones providing all the exact same data.

Why this triggers people about cars makes no sense to me, when they then install Alexa/siri/Google home recording when you take a shit.

[–] SmoothLiquidation@lemmy.world 9 points 1 day ago (1 children)

Reading this made me think about how people have devices like this all over their lives.

I would love for a consumer group like the EFF or IEEE or whatever to “certify” devices from a security standpoint. It could start as a marketing point from the manufacturers standpoint, a logo they could add that says someone looked at it.

[–] jjlinux@lemmy.zip 4 points 1 day ago

This is an amazing idea.

[–] eleitl@lemmy.zip 5 points 1 day ago

Start by buying vintage cars without cellular modem.

[–] SaveTheTuaHawk@lemmy.ca 9 points 2 days ago