Both are important actually, the security theater often deter from trying because it could be too annoying, it's generally "free to do", along with additional obfuscation, it's useful too but does not replace proper security, but from experience, theater+obfuscation+security is greater security than just security.
This is my primary concern with modern cars. You are at the complete merci of the security and correctness of the cloud management software for the correctly functioning of the car.
Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy.
On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?
How they will be able to block you from using your car when they deem that you should by a new one? Or how would they be able to make something a paid feature after you bought it?
You need to support these poor fellas
> November 10, 2025: No response, followed up.
> November 17, 2025: No response, followed up and copied some additional people on the thread.
> November 20, 2025: It was no longer possible to access any of the internal APIs. The primary vulnerability was now fixed.
> July 27, 2026: Published
Quite the generous timeline on this person's behalf.
Sometimes overlapping, but they are not the same thing.
Wouldn’t it be better if your phone/devices would pair directly with the car, exchange keys, and have the company cloud only function as a proxy.
On holiday a guests BMW didn’t want to “start” anymore because it couldn’t phone home because of lack of phone reception. They had to contact the dealer at home and move heaven and earth to get some dealer code to allow the car to start again for a while. Why is this even allowed?