logoalt Hacker News

brabeltoday at 8:52 AM3 repliesview on HN

If they’ve done it using Secure Enclave it’s essentially physically impossible to spoof.


Replies

Retr0idtoday at 9:58 AM

The github OP reports that browser-based login still works, so it'll likely be circumventable.

dullcrisptoday at 9:31 AM

Wouldn’t any Volkswagen keys need to cross the network to get into the Secure Enclave? Or couldn’t you exploit the Volkswagen app itself?

show 1 reply
msandfordtoday at 11:27 AM

If the data is going through the air or a wire it can be sniffed, right? Is every message signed or encrypted like ssl/tls, or is this just some kind of extra header(s)?

show 1 reply