So, I still receive telemetry information from my old lease car, a Kia e-Niro, to my app. A huge, HUGE privacy issue.

I made sure to remove my profile from the car before turning it in, and doing a factory reset of the car’s software.

I can see everything, AC, whether there are doors open, odometer, and above all, location.

Also tried to see if I can turn off the AC, but any commands throw an error, so disabling my account on the car at least did something 😅

I had it in the Netherlands, it’s in Poland, and it looks like it’s on its way to Ukraine.

Kia, you need to check your security.

Edit:

Holy shit it gets real bad. I can lock and unlock the car.

  • fmstrat@lemmy.nowsci.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    30 minutes ago

    This 100% needs to be reported. First to KIA, then to the media after whatever time is required to pass for responsible disclosure in your country/region.

  • Nonagon ∞ Orc@lemmy.world
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    57 minutes ago

    Cybersecurity professional here, I’d read up on Kia’s responsible disclosure policy, to avoid any potential trouble, and for guidelines on how to disclose it to them and handle this ethically.

    https://www.kia.com/eu/vulnerability-disclosure/

    Unfortunately they don’t do bug bounties, which is too bad.

    Edit: I wouldn’t listen to people telling you to lock the car, exploit it in other ways or disclosing it to the media first. That is unethical at best and illegal at worst.

  • kcweller@feddit.nlOP
    link
    fedilink
    arrow-up
    53
    ·
    19 hours ago

    I can lock and unlock the car that’s I don’t own. This is slightly worrisome, and me and my partner have just decided not to get a eNiro of our own 😅

  • ThePantser@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    36
    ·
    19 hours ago

    My brother who was working on buying a Kia EV6 could see and track its location before even signing the paperwork. All you need is the VIN.

    • mxcory@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      39 minutes ago

      I bought a used ev6 and the previous owner profile was still on there.

      Had to send info including proof of purchase and ID to have that old account removed.

      This was from an actual Kia dealer that made it a certified pre-owned as well. I don’t understand why they didn’t have the old account removed.

    • toast@retrolemmy.com
      link
      fedilink
      arrow-up
      19
      ·
      edit-2
      18 hours ago

      On some websites, you can get the VIN with just the plate number.

      Of course, the VIN is also displayed on the exterior of most cars anyway

  • scytale@lemmy.zip
    link
    fedilink
    arrow-up
    28
    ·
    19 hours ago

    Yeah iirc Hyundai/Kia are one of the worst in the car industry when it comes to handling user data.