Car Chat General discussion about Lexus, other auto manufacturers and automotive news.

Select Lexus Models Reportedly Vulnerable to Theft via Big Flaw

Thread Tools
 
Search this Thread
 
Old 04-01-24, 06:14 PM
  #1  
Curated Content Editor
CL Editor
Thread Starter
 
Curated Content Editor's Avatar
 
Join Date: Aug 2016
Posts: 1,575
Received 172 Likes on 119 Posts
Default Select Lexus Models Reportedly Vulnerable to Theft via Big Flaw

Select Lexus Models Reportedly Vulnerable to Theft via Big Flaw
By Brett Foote

As is the case with a lot of newer automobiles.


Curated Content Editor is offline  
Old 04-03-24, 04:45 AM
  #2  
bitkahuna
Lexus Fanatic
iTrader: (20)
 
bitkahuna's Avatar
 
Join Date: Feb 2001
Location: Present
Posts: 75,302
Received 2,514 Likes on 1,653 Posts
Default

wow, just read this article... that's BAD. (CL: can you please fix slideshows like this, they're still broken - using the next/prev doesn't always work, but the arrows on the pics do).

wonder if they'll do a recall for this.
bitkahuna is online now  
Old 04-03-24, 09:54 AM
  #3  
FrankReynoldsCPA
Lexus Test Driver
 
FrankReynoldsCPA's Avatar
 
Join Date: Apr 2011
Location: Las Vegas
Posts: 7,094
Received 103 Likes on 73 Posts
Default

Originally Posted by bitkahuna
wow, just read this article... that's BAD. (CL: can you please fix slideshows like this, they're still broken - using the next/prev doesn't always work, but the arrows on the pics do).

wonder if they'll do a recall for this.
Actually, please just ditch slideshows altogether. They are the dumbest way to present news by far.

​​​​
FrankReynoldsCPA is offline  
Old 04-03-24, 10:15 AM
  #4  
arentz07
drives cars
Forum Moderator
 
arentz07's Avatar
 
Join Date: Nov 2016
Location: GA
Posts: 8,614
Received 3,923 Likes on 1,980 Posts
Default

This is pretty scary. I hope something can be done to better secure the vehicles.
arentz07 is offline  
Old 04-03-24, 10:22 AM
  #5  
Margate330
Lexus Test Driver
 
Margate330's Avatar
 
Join Date: Apr 2019
Location: FL
Posts: 7,353
Received 1,030 Likes on 814 Posts
Default

I checked out the slide show and there are a couple of things to point out, IMO.

1: CAN bus exploits are not the car mfgs fault any more than if someone hacks your computer and then blames Windows.

2: it only takes one person to make an exploit of the system and then sell it or make a download available to everyone. This is the danger of driving a computer on wheels.

That's the simple version. Lol

Last edited by Margate330; 04-03-24 at 12:30 PM.
Margate330 is offline  
Old 04-03-24, 12:15 PM
  #6  
LeX2K
Lexus Fanatic
 
LeX2K's Avatar
 
Join Date: Sep 2010
Location: Alberta
Posts: 20,673
Received 3,060 Likes on 2,572 Posts
Default

I'm sure some other auto makers are the same or similar, in the case of Tesla the stolen car can easily be tracked. Car is flagged you won't be able to supercharge. You'll never get OTA updates. Only way you could drive the car at all without being flagged is completely disable connectivity. Leaves you with chopping the car up and selling for parts.

This opens up a privacy and ethical dilemma auto maker knows exactly where you are at all times. Great for theft prevention, not so great for privacy. Imagine law enforcement wanting travel logs. Then what? But I suppose it is no different than your smartphone.
LeX2K is offline  
Old 04-03-24, 12:24 PM
  #7  
AMIRZA786
Lexus Champion
 
AMIRZA786's Avatar
 
Join Date: Oct 2019
Location: California
Posts: 14,426
Received 2,266 Likes on 1,765 Posts
Default

Check the date of the Article...April 1st. Not sure if that has anything to do with it, but lots of April fools day articles. I saw one where someone was able to open and drive his Tesla using a Pokemon card. The article looked 100 percent legit until I saw the tags. Just a thought before everyone panics.......
AMIRZA786 is online now  
Old 04-03-24, 12:34 PM
  #8  
Margate330
Lexus Test Driver
 
Margate330's Avatar
 
Join Date: Apr 2019
Location: FL
Posts: 7,353
Received 1,030 Likes on 814 Posts
Default

Originally Posted by LeX2K
This opens up a privacy and ethical dilemma auto maker knows exactly where you are at all times. Great for theft prevention, not so great for privacy. Imagine law enforcement wanting travel logs. Then what? But I suppose it is no different than your smartphone.
It also gives people an excuse to argue against open protocols or forced encryption on the car's network bus.

Which will of course make everything proprietary and must go to the dealer for everything.

Even code scanners will no longer work.

There are other ways to help get around this but I see a big opening for them to try and "lock it down".
Margate330 is offline  
Old 04-04-24, 11:22 AM
  #9  
geko29
Super Moderator
Senior Moderator
 
geko29's Avatar
 
Join Date: Feb 2007
Location: IL
Posts: 8,053
Received 311 Likes on 239 Posts
Default

Originally Posted by AMIRZA786
Check the date of the Article...April 1st. Not sure if that has anything to do with it, but lots of April fools day articles. I saw one where someone was able to open and drive his Tesla using a Pokemon card. The article looked 100 percent legit until I saw the tags. Just a thought before everyone panics.......
Unfortunately it's not a hoax. This has been reported previously, as "headlight hacking". Here's an article from one year ago (but not April 1st):

https://www.autoblog.com/2023/04/18/.../?guccounter=1
geko29 is offline  
Old 04-05-24, 10:07 AM
  #10  
gsquared
1st Gear
 
gsquared's Avatar
 
Join Date: Apr 2024
Posts: 1
Likes: 0
Received 0 Likes on 0 Posts
Angry Lexus Thefts - We Are Ignored in North America

This CAN bus vulnerability has been widely known for a LONG time. Once the thief has their easily obtained $5000 device, they have the keys to any vulnerable vehicle that they want. It’s like Toyota/Lexus sells us a vehicle with a toggle switch on the dashboard so that anyone who would rather steal than buy, simply plugs in to the CAN bus connector and starts your vehicle and just takes it away. NICE…

Toyota/Lexus are ignoring us here in North America, I’ve inquired; they simply say they meet all applicable standards… they simply don’t care that our vehicles can disappear at any time or they would do something. Toyota/Lexus are already addressing this vulnerability in Europe by retrofitting a fix, but not here. Check out these news releases from Toyota South Africa and Toyota Great Britain.

https://www.toyota.co.za/discover/ne...vehicle-safety

https://mag.lexus.co.uk/lexus-uk-sta...vehicle-theft/

I have tried to get answers from Lexus Canada as well as my Local Lexus Dealer, but a similar fix is not offered, despite the fact that the technology and fix does in fact exist… FRUSTRATING!!!

gsquared is offline  
Old 04-05-24, 10:33 AM
  #11  
703
Lead Lap
 
703's Avatar
 
Join Date: Aug 2001
Posts: 3,836
Received 794 Likes on 539 Posts
Default

It’s good business for Lexus. More stolen cars = more sales of new cars or parts.

most of the stolen RX goes to Africa anyway. You can buy your car back there 😀

View this post on Instagram



Last edited by 703; 04-05-24 at 11:08 AM.
703 is offline  
Old 04-06-24, 09:18 AM
  #12  
SW17LS
Lexus Fanatic
 
SW17LS's Avatar
 
Join Date: May 2012
Location: Maryland
Posts: 57,820
Received 2,774 Likes on 1,981 Posts
Default

I'll be waiting for the outrage and shock that Hyundai and Kia received for the same thing.

Waiting....and waiting....and waiting lol
SW17LS is online now  
Old 04-06-24, 09:21 AM
  #13  
Striker223
Lexus Champion
 
Striker223's Avatar
 
Join Date: Oct 2019
Location: Ohio
Posts: 11,684
Received 1,251 Likes on 932 Posts
Default

Originally Posted by SW17LS
I'll be waiting for the outrage and shock that Hyundai and Kia received for the same thing.

Waiting....and waiting....and waiting lol
A CANbus spike attack is very different from just force the cylinder....one costs about $4k the other 4 cents
Striker223 is online now  
Old 04-06-24, 10:37 AM
  #14  
SW17LS
Lexus Fanatic
 
SW17LS's Avatar
 
Join Date: May 2012
Location: Maryland
Posts: 57,820
Received 2,774 Likes on 1,981 Posts
Default

Originally Posted by Striker223
A CANbus spike attack is very different from just force the cylinder....one costs about $4k the other 4 cents
If this weren’t a Toyota issue people would be freaking out.
SW17LS is online now  
Old 04-06-24, 10:56 AM
  #15  
LexBob2
Lexus Champion
 
LexBob2's Avatar
 
Join Date: Aug 2006
Location: Illinois
Posts: 11,274
Received 139 Likes on 113 Posts
Default

Originally Posted by SW17LS
I'll be waiting for the outrage and shock that Hyundai and Kia received for the same thing.

Waiting....and waiting....and waiting lol
Any time now...It won't be long lol...
LexBob2 is online now  


Quick Reply: Select Lexus Models Reportedly Vulnerable to Theft via Big Flaw



All times are GMT -7. The time now is 08:49 PM.