Hacker News new | ask | show | jobs
by fardo 818 days ago
I feel like some of the fault rests in car authentication tech being downright antiquated by having a “whoever has keys is driver” policy.

We wouldn’t accept, in any corporate environment, a computer system where the only form of authentication was a yubikey with no password, the fact that our cars essentially still work like this in 2024 is appalling.

6 comments

You want to have to enter a password to use your car?

I guess it could help with climate goals, so I can see your point.

The main problem is not that a key is enough to use a car, but that owning the car is not enough to keep others out of it.

You can actually activate PIN-to-drive authentication on a Tesla. It's a useful added security feature for when you need someone you don't know to use your car, like valet parking or leaving it at a body shop, but you can activate it as default as well.
I’d love it to have face detection as well. The cameras and the “GPU“ are there.
Would be actually useful for when you share a car with family members and want it to remember seat position when you are both in car. Strange they haven't done it, but headlines "Tesla facial recognition" would make few people wet their bottoms. Even on this forum.
I’m more of a mind to criticize it based on how often Technology fails.

Tesla has had multiple recall issues with the interface pad malfunctioning or not even turning on.

Meanwhile I can just put a key in my car and go. Sure, someone could steal the key - but statistically that is far less likely that a software or hardware failure.

Sure. Let the auto manufacturers also leak your biometrics along with all the shit they collect on you.
Always funny in movies and tv series when a stolen key card is enough to get in almost anywhere when a simple pin code would have made it impossible.
Hmm, how far we are from instant DNA checks? So we could register drop of blood in car and then each time car starts you would need to provide some...

Ofc, then you run risk of blood being taken by force, but it would be bit more secure.

You haven't seen the demolition man, have you?
This!

Whenever people get a hard on for biometrics I tell them exactly that.

No I don't want to loose a finger. I'd rather just give them my password.

> DNA checks

It's same as having keys tho. Authorization vs authentication.

p.s. pin to drive exists already.

What are you suggesting? Have you heard of rubber hose cryptanalysis?
I can't wait for the day that anyone with the right credentials can remotely disable/track/summon your car.

Despite the tradeoffs, I think our current approach is better than the alternatives.

Credentials don't have to leave the car and they can still enhance security quite significantly.

For example Face ID in iPhones works pretty well, and your face data is stored on the phone only.

My corporate environment accepts it.

I'm the only employee in the company. :)