this post was submitted on 13 Oct 2025
217 points (98.7% liked)

Technology

76041 readers
3219 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 20 comments
sorted by: hot top controversial new old
[–] deathrattledregs@lemmy.ml 2 points 8 hours ago (1 children)

Again, WHY in the actual FUCK does a car need software updates?

Apart from maybe a stereo software? Infotainment? Make a good powertrain and leave it alone. Absolute insanity.

[–] floofloof@lemmy.ca 1 points 8 hours ago

This was an update to the entertainment system that somehow had the side effect of disabling the power train while driving. You'd think these would be two entirely separate computer systems, but they must be sharing something.

[–] BombOmOm@lemmy.world 72 points 1 day ago* (last edited 1 day ago) (6 children)

The power train (and other vital components) of a car should be air-gapped from the internet. It's crazy car manufacturers are even able to brick a car like this.

Is your car going to get security updates 5-10-20 years from now? No. The power train should be air-gapped from the internet.

[–] rainwall@piefed.social 28 points 1 day ago* (last edited 1 day ago) (1 children)

Apparently it was supposed to be. They have the core functions in a "can't OTA" container, with less important functions like AV/etc in a "can OTA" model.

This update was pushed to the "can update" side and fucked the "can't update" side, which is its own can of worms. Another can? Jeep pushed a silent, emergency update "to all Jeeps even those who have automatic updates disabled."

So the issue is not that they have no security model, it's that it clearly doesn't work and they can and will push secret updates even when you decline all updates.

[–] tal@lemmy.today 9 points 1 day ago* (last edited 1 day ago)

https://www.reddit.com/r/Jeep/comments/194cbbj/turn_offdisconnect_remote_access_to_my_2021_gcth/

I just got a text from my dealership saying my oil light was on. Super pissed off about it... When I got the Jeep 2 years ago I asked Jeep to turn off ALL remote access/phone home capabilities to the vehicle. I was on the phone for a couple hours with them until I finally got someone who said they did it.

Weather alerts, contextual ads on my console, distant recording of my travels, whatever, I wanted everything off.

It has a 4G cellular module in the head unit, which connects to a separate 4G antenna via a port on the back of the head unit. Unplug the antenna from the head unit and it cannot communicate to anything. Obviously you have to remove a bunch of trim and the unit.

Now, it's possible that during maintenance, the process might involve uploading or downloading data to/from the manufacturer. That's hard to avoid.

[–] FordBeeblebrox@lemmy.world 7 points 1 day ago

https://en.wikipedia.org/wiki/Gig_Car_Share

I worked for AAA during this program and literally every single weekend someone would take a car up into the mountains or down the coast and lose cell service…which would then brick the car and leave them stranded in the woods with a Prius they couldn’t even open to get inside. Add fires (thanks PG&E) and mudslides and it was a massive clusterfuck just getting a tow truck to them, which could take hours or days

[–] Nindelofocho@lemmy.world 25 points 1 day ago (1 children)

Companies dont even give a shit about cybersecurity with their internal systems why would they dare put a cent into thinking about security for systems their customers use

[–] andyburke@fedia.io 11 points 1 day ago (1 children)

This just keeps happening until we decide our governments work for us and not for corporations.

[–] Venator@lemmy.nz 5 points 1 day ago

unfortunately corporations decide what most people decide via control of media and social media ...

[–] dgriffith@aussie.zone 11 points 1 day ago

The problem is that the "release a minimum viable product, then update-update-update" software development model has reached cars.

But all other ways cost more and take longer to get to market which makes shareholders unhappy, so we can't have that.

[–] ToastedRavioli@midwest.social 9 points 1 day ago (1 children)

In most push to start modern cars, it isnt really one central computer like how cars used to be. You still have an ECU, like the computer that is relevant to the drivetrain. But then you also have one or two others separate units that have to have authority over the ECU by nature because of other things they do. Like if the unit that communicates with your key to say “its okay to allow you to use the car” doesnt have authority over operating your powertrain, then it would be much easier to steal your car (i.e. kia and hyundai from a certain period of time). In many cars it also monitors engine performance and can make live adjustments to the operation of the engine, prevent some catastrophic failures, etc.

So having some smarter computer aspect of your car rule your powertrain is a pretty good security and operational thing, even if it leads to the potential for inconveniences. Like if your electric key dies you could lose the ability to start your car, which would never happen with a physical key

That said, I think all updates for cars should be done at dealerships, and not be an over the internet type of thing

[–] FordBeeblebrox@lemmy.world 2 points 1 day ago

My push to start has an RFID slot for the key so even if the fob battery dies it still will recognize and start, push to start may be convenient but I’m more worried about adding additional wires between ignition switch and battery/starter. I absolutely do not want my vehicle connected to the internet, I want gas brake and steering, OTA updates are just a terrible idea

[–] kokesh@lemmy.world 1 points 1 day ago

Yeah, but how else would you be able to pay for power upgrades? I'm keeping my old cars for as long as possible.

[–] helpImTrappedOnline@lemmy.world 20 points 1 day ago* (last edited 1 day ago) (1 children)

Charge whoever pushed this "telematic update" for reckless endangerment or something.

They're lucky there were no accidents related to this (as far as we know).

[–] tabular@lemmy.world 14 points 1 day ago (1 children)

Calling it, next update includes forced arbitration clause for accidental bricking.

[–] ReginaPhalange@lemmy.world 4 points 1 day ago

Click here to agree, contact car disposal services otherwise.

[–] NatakuNox@lemmy.world 27 points 1 day ago (2 children)

Don't buy American. Don't buy Stellantis vehicles no matter what!

[–] Blackfeathr@lemmy.world 6 points 1 day ago

Can confirm; used to indirectly work for them. Stellantis holds nothing but contempt for their employees, suppliers, and customers. Their products are inferior and overpriced.

[–] jaschen306@sh.itjust.works -5 points 1 day ago (1 children)

Um...Ford isn't as bad. Def not in the same shittyiness as Stellantis.