Researchers drove a NIO ES8 electric SUV deep into a Norwegian underground mine specifically to sever its external connections. The car kept attempting to reach servers, most of them located in China. These findings echo broader concerns about hidden data collection, similar to how a surveillance app was built to covertly target users without their knowledge.

That finding sits at the center of Project Lion Cage, a multi-year study initiated in 2022 by Tor Indstøy, a risk management and threat intelligence executive at Telenor Group. Indstøy purchased the NIO ES8 as a dedicated research platform.

The project arrives as Chinese EV brands expand across European markets with assurances about local data processing. Observed network behavior appears to contradict those assurances.

  • cub Gucci@lemmy.today
    link
    fedilink
    English
    arrow-up
    36
    arrow-down
    1
    ·
    21 hours ago

    My BMW checking if my bmw subscription is active when I’m trying to enable seat heater

    • foo@feddit.uk
      link
      fedilink
      English
      arrow-up
      7
      ·
      19 hours ago

      I wonder what the security is like. I’d love to know how difficult it would be to set up a mock-service to just tell it you have everything.

      You’d expect there to be encryption and some kind of certificate validation to check the response is trustworthy, but given what we now know about the CAN bus that many cars use, and how vulnerable it is to attack, it suggests the motor industry is way behind the times in terms of security.

        • brucethemoose@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          14 hours ago

          Yeah, that’s the thing. It’s not like a transistor in a microchip or something; it’s a wire you can work with.

          I bet BMW makes the disassembly needed an absolute pain, though.