this post was submitted on 01 Jul 2025
265 points (99.6% liked)

Privacy

40404 readers
581 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

So, I still receive telemetry information from my old lease car, a Kia e-Niro, to my app. A huge, HUGE privacy issue.

I made sure to remove my profile from the car before turning it in, and doing a factory reset of the car's software.

I can see everything, AC, whether there are doors open, odometer, and above all, location.

Also tried to see if I can turn off the AC, but any commands throw an error, so disabling my account on the car at least did something πŸ˜…

I had it in the Netherlands, it's in Poland, and it looks like it's on its way to Ukraine.

Kia, you need to check your security.

Edit:

Holy shit it gets real bad. I can lock and unlock the car.

top 26 comments
sorted by: hot top controversial new old
[–] kcweller@feddit.nl 73 points 1 month ago (2 children)

I can lock and unlock the car that's I don't own. This is slightly worrisome, and me and my partner have just decided not to get a eNiro of our own πŸ˜…

[–] SkyezOpen@lemmy.world 8 points 1 month ago

Just don't get a Kia period. They're notorious for being stolen because their security is shit.

[–] reallykindasorta@slrpnk.net 8 points 1 month ago

That’s wild!!

[–] ThePantser@sh.itjust.works 56 points 1 month ago (3 children)

My brother who was working on buying a Kia EV6 could see and track its location before even signing the paperwork. All you need is the VIN.

[–] toast@retrolemmy.com 31 points 1 month ago* (last edited 1 month ago)

On some websites, you can get the VIN with just the plate number.

Of course, the VIN is also displayed on the exterior of most cars anyway

[–] mxcory@lemmy.blahaj.zone 13 points 1 month ago (1 children)

I bought a used ev6 and the previous owner profile was still on there.

Had to send info including proof of purchase and ID to have that old account removed.

This was from an actual Kia dealer that made it a certified pre-owned as well. I don't understand why they didn't have the old account removed.

[–] porous_grey_matter@lemmy.ml 7 points 1 month ago (1 children)

I don't understand why they didn't have the old account removed.

why bother when you'll go through the hassle for them, I guess

[–] FordBeeblebrox@lemmy.world 5 points 1 month ago

Or they could charge you. When I bought a used Ford the dealer wanted me to pay a $100 fee to change the door keypad code, something I did myself in about 2 minutes.

[–] UndulyUnruly@lemmy.world 12 points 1 month ago

HO LY FUCK!

[–] bjoern_tantau@swg-empire.de 51 points 1 month ago* (last edited 1 month ago)

Report it to a local tech site. That's a scandal.

[–] nonagonOrc@lemmy.world 35 points 1 month ago* (last edited 1 month ago) (1 children)

Cybersecurity professional here, I'd read up on Kia's responsible disclosure policy, to avoid any potential trouble, and for guidelines on how to disclose it to them and handle this ethically.

https://www.kia.com/eu/vulnerability-disclosure/

Unfortunately they don't do bug bounties, which is too bad.

Edit: I wouldn't listen to people telling you to lock the car, exploit it in other ways or disclosing it to the media first. That is unethical at best and illegal at worst.

[–] otter@lemmy.ca 8 points 1 month ago* (last edited 1 month ago) (1 children)

This comment is being reported. Did you mean to post a different link?

[–] nonagonOrc@lemmy.world 12 points 1 month ago* (last edited 1 month ago) (1 children)

Oh wow this is very embarassing very sorry about that. Edited to include the proper link.

[–] otter@lemmy.ca 5 points 1 month ago* (last edited 1 month ago)
[–] scytale@lemmy.zip 34 points 1 month ago

Yeah iirc Hyundai/Kia are one of the worst in the car industry when it comes to handling user data.

[–] ashenone@lemmy.ml 26 points 1 month ago (2 children)

I'll kill myself before I get a car connected to the internet

[–] FordBeeblebrox@lemmy.world 6 points 1 month ago

I used to work for AAA which has a program called GIG (Get It Going) where you can rent a Prius in the Bay Area much like a Lime scooter. They had to stay connected and EVERY SINGLE WEEKEND someone would take one up to hike in the mountains or drive down the coast, lose connection and it would instantly go into lockdown mode. They would have to call for us to tow a dead car they couldn’t even open to get their things out of.

So hey, a bear or crackhead might do the killing for you if you get a WiFi car

[–] anomnom@sh.itjust.works 5 points 1 month ago

I was so happy when the shut down 3G networks killed off a ton of car data planes.

[–] fmstrat@lemmy.nowsci.com 21 points 1 month ago

This 100% needs to be reported. First to KIA, then to the media after whatever time is required to pass for responsible disclosure in your country/region.

[–] hddsx@lemmy.ca 17 points 1 month ago (1 children)

But think of the shareholder value lost if we invest in that!

[–] Logh@lemmy.ml 2 points 1 month ago

Just short it mate.

[–] Buske@lemmy.world 10 points 1 month ago

If you think that's bad, ANYONE CAN DO IT.

You should report this to somewhere like 404 media

[–] MonkderVierte@lemmy.zip 5 points 1 month ago* (last edited 1 month ago)

I can lock and unlock the car.

Keep it locked once the passenger is out. Maybe then they care.

[–] KingGimpicus@sh.itjust.works 3 points 1 month ago* (last edited 1 month ago)

Nissan does this too. I leased a new Kicks when they came out and HATED it. Seats were terrible, car was underpowered, and some jackass decided to program the cvt to "shift" because Nissan got complaints that the car was stuck in gear. Just learn how a CVT works.

Anyways, 4 years later, I still get emails about monthly maintenance work, tow alarms, and tracking updates. I never asked for them to begin with and I guess I'm stuck with it as a VW guy now.

[–] Willem@lemmy.dbzer0.com 3 points 1 month ago

Meldt het bij tweakers, die willen er vast een artikeltje overschrijven