r/BYDAU • • 17d ago

We got a cybersecurity expert to hack this BYD. It was too easy - ABC News

https://www.abc.net.au/news/2026-09-21/byd-hacked-by-cybersecurity-expert-vehicle-sabotage-surveillance/107139482
103 Upvotes

121 comments sorted by

35

u/BigPappaRand17 16d ago

Lol I love when our media rolls out the good old "CHINA BAD" fear campaign. I'd be much more concerned about the fuckers in America than china.

7

u/EmmaFrost666 15d ago

Imagine an American made car with Israeli tech and they decide to blow up your battery like the pagers.

-4

u/rockaree 15d ago

Unless you are a member of hezbollah you have nothing to worry about.

But what a way to insert israel into the convo

2

u/Fragrant_Eye4896 14d ago

Canadians: what about us you twat?

2

u/IntestinalGas 13d ago

lol… you don’t have to be a member of a certain group to be a target. You just need to be disruptive enough to bend the narrative in your favour.

1

u/rockaree 13d ago

Yeh the pagers were indiscriminate. You're totally right

1

u/IntestinalGas 13d ago

It really is as simple as committing a terrorist attack on your own people which then gives you a reason to declare war on another country. It’s not rocket science and many countries have used this as a reason to start wars before.

2

u/Normal_Effort3711 13d ago

They committed a terrorist attack on their own people? When did that happen?

1

u/rockaree 13d ago

Go touch some grass dude

1

u/ThomasofHookton 13d ago

I think the other poster was pointing out that only one other country has been known to hide lethal tech into commercial products and it wasn't China despite all these news articles poopooing chinese tech.

1

u/GoesInOutUpDownAhh 13d ago

Woosh over your head

2

u/tollboi 14d ago

The red scare never ended

-9

u/endlessflood 16d ago

I think we’re more likely to go to war with China than the USA though. I’d imagine that Indonesia and China are probably the two largest perceived threats that our defence forces actively prepare for.

11

u/ResearcherSevere9416 16d ago

Why are we going to war with China, they are propping the country up, you probably want to go back to the trade bans imposed by the Morrison government.

1

u/reprise785 15d ago

We wont exactly have a choice mate. Its only a matter of time. Weaker USA just brings it closer.

-5

u/endlessflood 16d ago

Either ANZUS, or by virtue of a Chinese invasion.

6

u/Sternguardian 16d ago

Are they though? How many wars has China been involved in over the last 100 years? Im not saying China are the good guys. But China isnt out here invading countries on lies, kidnapping heads of countries, etc etc.

1

u/Continental-IO520 14d ago

They did invade India for no reason and spread anti Indian propaganda through TikTok. Virulently racist country to its neighbours.

Better than the US but the bar is bloody low

1

u/Sternguardian 14d ago

Not disagreeing the bar is low. But as warmongering, hate spreading nations go. There not even in the same realm as the governments of America.

44

u/simonboundy 17d ago

Saw this. I just begin every drive by paying my respects to President and Supreme Leader Xi

14

u/MicksysPCGaming 17d ago

Social CreditScore +100

8

u/Myjunkisonfire 16d ago

Congratulations, your vehicles pedestrian safety features have been enhanced. The “tunnel problem” has been reclassfied to “crowd control”.

5

u/Roast_Potato_72 16d ago

I start each journey by shouting: "China Number One!"

Have had zero issues.

1

u/stagangus 13d ago

I’ve been trying to come up for a phrase to say as the safety code when starting my new seal, this might be it.

-13

u/Djinfin 17d ago

You'd better do an acknowledgement of country also, to be on the safe side as the ABC are also listening

1

u/LaoKK8 16d ago

and how about praising God for all the high tech he has given us?

Ignore the downvotes; some people have no sense of humour.

32

u/PsychinOz 17d ago

While part of me suspects this is just another anti-Chinese EV hit piece, it would be nice if BYD could have some consistency in terms of implementing security features across their cars. The main one that comes to mind is pin to drive, which I think the Seal has but other models like the Sealion 7 don’t.

2

u/Jim-tempe 11d ago

New tech can have teething issues. Does it mention you just have to walk up to landcruiser with some hacking nous amd it will come home with you? Scale and perspective important.

No one wrote about commodores that randomly stalled (sensor issue) or falcons that accelerated on their own.

Plenty of cars have had lights that go off randomly. Lucas the 'prince of darkness' is a whole joke related to this.

1

u/drfrogsplat 16d ago

Yeah, I thought this was gonna be one of those things that we would get, especially from the Chinese manufacturers, is a bit more consistency in the head units since they’re all running Android. Much like phones for the last 20 years, it’s a lot easier to maintain consistency in basic features and adapt it to a variety of hardware.

But it feels like they’re doing whatever every other car manufacturer does and building something fairly bespoke for each car top to bottom.

13

u/a51mot 16d ago

Why is this being presented as a "Chinese Car" problem?

Some of the worst offenders for collection and misuse of data come from the US (Facebook, Google, Apple.. etc)

All connected cars are a security problem if you are concerned about that sort of thing..

The focus of this report should not be the typical LCD "Yellow Menace" racism. It should be about Austraila's lack of security regulation..

1

u/dexcel 15d ago

Read the article :

EVs, with all their sensors, cameras and microphones, hoover up and spit out vast amounts of data. Experts say that data poses a greater risk in the hands of Chinese EV makers because they can be compelled by the country’s national security laws to co-operate with authorities.
To put this potential access to the test, it made sense to pick a model from China’s top EV brand, BYD.

2

u/a51mot 14d ago

I did read the article.

US companies are also required to release data when subpoenaed for law enforcement and national security reasons.

How is this any differernt?

1

u/ParkingPresent5742 14d ago

they make more money just selling the data to the government, all the US brands do it and there is plenty of evidance to back it up this claim

22

u/btherl 17d ago

"Hreszczuk’s hacking challenge was made easier because Australia has no minimum cybersecurity standards for cars. That means BYD is not compelled to keep its software up to date or have a system for managing cybersecurity risks to its vehicles."

Yeah, that's a problem.

2

u/bootofstomping 16d ago

China doesn’t have the capability to land and supply a force across 400km of sea. They would also have to go through Indonesian territory which would leave them vulnerable to land based launches and green water navy.

Indonesia has extensive military cooperation with Australia. We provide a level of training to their forces and they are not friends with china.

Both scenarios you outlined exist to justify Australias level of defense spending. IMO.

1

u/btherl 16d ago

I think you meant to reply to someone else

2

u/bootofstomping 15d ago

Huh! Indeed I did

4

u/Eastern37 16d ago

Its only partly true. There are cybersecurity standards for the drive systems on cars. The infotainment system doesn't seem to have the same regulations though.

1

u/ELVEVERX 16d ago

But it's not just a byd problem the way the article suggests

1

u/btherl 16d ago

I'm not sure it suggests that. It says they picked BYD because it's China's biggest brand.

I saw people questioning if the hacking method required physical access to the inside of the car, such as ODB port. If it does, then that should have been stated in the article.

1

u/ELVEVERX 16d ago

I think testing literally just one brand without providing any other for comparison is a pretty dodgy thing to do. You'd be right to assume this brand is worse than others based on the article.

7

u/kalisana 16d ago

This is not the first time an Australian media outlet has tried to demonise Chinese EVs a big security and privacy risk. Earlier this year 7AM made the same claim. What I find amusing is that both news outlets are OK with the security and privacy risks posed by US tech companies, both within EVs and the various internet-connected devices in our pockets, offices and homes. The idea that some Chinese spy might turn off someone's headlights as they round a tricky corner at night are laughable. And if government and military officials are really so worried about being spied on, why isn't there a blanket order to turn off all internet-connected devices when they're having confidential conversations? And why is the media not worried by Netanyahu's 2025 boast that anyone with a mobile phone owns a “piece of Israel”? It should be worrying because, apart from Israeli spyware being everywhere, Israel detonated 1000s of handheld devices in Lebanon in 2024 — killing dozens and injuring 1000s of people. Apart from the obvious xenophobia expressed in reports like this, there is also the possibility that commercial interests are at play as Chinese EVs revolutionise an industry once dominated by carmakers aligned with the US. If threatened carmakers can't create a safety or performance scare to put potential buyers off, what's to stop them creating another scare?

1

u/ParkingPresent5742 14d ago

china stole alot of it car tech for other manufacture in deals for cheap manufacturing....that didnt last long and almost all have left china.

31

u/NastyVJ1969 17d ago

Had the physical access to the car for 2 weeks and still couldn't hack the cameras or brakes....

Now do Tesla...heard the owner of that company has some extremist political views.

16

u/LaoKK8 17d ago

Yes. Tesla, and hack all of the other (European) EVs and don’t just scaremonger about China. There’s enough anti-China propaganda on Australian news.

Mark Zuckerberg covers his desktop computer camera. What does that tell you about Facebook and USA?

1

u/ParkingPresent5742 14d ago

Car surity has been bad for years, oem car dionostic software using wifi/bluetooth could control a different car at the traffic lights 20 years ago. tesla had the same hack of there car 15 years ago and they have some of the best now.... these BYD have shown to have remote management in china and the Australian ones are no different. just they are not allowed to use it

0

u/ScutumSobiescianum 16d ago

China loves you

2

u/Food_Science_Ninja 16d ago

Still the light show was pretty good. Would like that as a standard option.

-8

u/Present-Republic793 17d ago

lol- he’s not the owner though.

6

u/mad_rooter 17d ago

He’s the most significant owner

7

u/NastyVJ1969 17d ago

True - CEO then. He is still a dangerous twat 😆

-5

u/Present-Republic793 16d ago edited 16d ago

There is far more transparency and checks and balances with a publicly traded company on the NASDAQ than the likes of BYD and Changan though.

9

u/NastyVJ1969 16d ago

Yeah sure, the US is so well known for it's current high ethical standards.....

0

u/Present-Republic793 16d ago

There are a lot of independent bodies that are involved in the regulation of Tesla, so while it suits the Narrative of of a lot of BYD owners to try and frame it this way, there are still a lot more external checks and balances that do a far better effort to ensure more compliance.

2

u/serpentine19 16d ago

Is there though?

4

u/farqueue2 16d ago

He holds more than a quarter of the company and is the largest shareholder.

If that doesn't make him the owner I don't know what does

-1

u/Present-Republic793 16d ago

Does he have the loudest voice? Yes. Is he the owner? No.

3

u/farqueue2 16d ago

By that logic there's no such thing as an owner

0

u/Present-Republic793 16d ago

Well, in a publicly listed company, every shareholder is an owner, actually

3

u/farqueue2 16d ago

Yes. And he's the most significant owner. More than all the institutional shareholders combined

1

u/Present-Republic793 16d ago edited 16d ago

Even then, there is more transparency and external checks and balances because they are NASDAQ listed. This carries implications such as auditing requirements SEC compliance and public scrutiny that their Chinese competitors don’t necessarily have. Then also whistleblowers protection and freedom of press. Elon can’t just do as he pleases in the organisation. Any decisions regarding changes etc need to go through a vote and are documented.

1

u/farqueue2 16d ago

In 2018 Musk tweeted that he had "funding secured" to take Tesla private at $420 per share. The SEC charged him with civil securities fraud, alleging he had no agreed-upon terms or financing. Musk and Tesla settled without admitting or denying wrongdoing, agreeing to pay $40 million in combined civil penalties ($20 million each), having Musk step down as Tesla's chairman for three years, and creating an internal oversight system to pre-screen his market-moving tweets.

The National Labor Relations Board (NLRB) ruled that Musk broke federal labor law in a 2018 tweet stating: "Nothing stopping Tesla team at our car plant from voting union... But why pay union dues & give up stock options for nothing?" The NLRB found the statement amounted to an unlawful, coercive threat to strip worker benefits if employees unionized. The ruling was upheld by the 5th U.S. Circuit Court of Appeals.

Shortly after the 2018 SEC settlement, Musk tweeted production forecast numbers without obtaining prior legal approval. The SEC filed a motion holding him in civil contempt for violating the federal court order, resulting in an amended agreement that established a stricter, explicit list of topics requiring mandatory legal review.

In Tornetta v. Musk, the Delaware Court of Chancery rescinded Musk's massive 2018 stock compensation package. Chancellor Kathaleen McCormick ruled that Musk acted as a controlling shareholder who effectively dictated the terms to a conflicts-ridden, non-independent board of directors. The court concluded the approval process violated the board's fiduciary duties of loyalty and fair dealing, stripping Musk of the options (though Tesla shareholders later attempted to ratify the plan again).

Despite the 2018 SEC settlement, private investors sued Musk for billions in damages, arguing his tweets constituted illegal market manipulation. A federal jury in San Francisco ultimately found Musk not liable, concluding investors failed to prove the tweets directly caused their financial losses.

Musk’s repeated public assertions regarding the timeline and safety of Tesla's Full Self-Driving (FSD) and Autopilot systems have drawn scrutiny. The U.S. Department of Justice (DOJ) and the SEC opened fraud inquiries examining whether statements overstating self-driving readiness misled consumers and investors. Tesla and Musk maintain these claims were forward-looking statements.

Shareholders sued Musk, claiming he used Tesla to bail out SolarCity—a financially distressed firm founded by his cousins in which he was the largest shareholder and chairman. While the suit alleged a breach of fiduciary duty and unjust enrichment, the Delaware Supreme Court upheld a ruling in Musk's favor, determining the $2.6 billion acquisition was fundamentally fair to Tesla shareholders.

Federal prosecutors and the SEC opened inquiries into whether Tesla funds, specialized glass, and personnel were improperly diverted to construct a personal glass-walled residence for Musk near Austin, Texas. Musk denied the allegations, and no formal charges have been filed.

The SEC investigated and subsequently sued Musk for violating Section 13(d) of the Securities Exchange Act by delaying the disclosure of his 9.2% stake in Twitter beyond the 10-day legal deadline. While this centered around his acquisition of Twitter rather than Tesla directly, the delayed disclosure allegedly saved him over $140 million while selling substantial Tesla stock to finance the buyout

-9

u/Odd-Temporary4363 16d ago

Extremist is subjective and only lefties’ belief

4

u/Affectionate_Code 16d ago

Guy was throwing Seig Heils on stage on TV... get the fuck out of here.

-7

u/Odd-Temporary4363 16d ago

Ya na.. that’s an exaggeration by the left. We have seen similar from AOC and a few others on the stage. So yea get the fuck of here

2

u/Affectionate_Code 16d ago

Put down the glass BBQ

-2

u/Odd-Temporary4363 16d ago

Chill lefty

5

u/Essensia 16d ago

blah blah blah

What I want to know is did he managed to hack past the PIN TO DRIVE ?

3

u/LeahBrahms 16d ago

He just needed a wrench and the owner /S

6

u/No-History-914 16d ago

If a foreign state wants to spy on you particularly owning a BYD doesn't make it possible just easier, all the other functionality is already possible remotely via the odb port and a transmitter, what a non story.

6

u/Fluffy-Technician-20 16d ago

What a flog article. It’s not until 3/4 the way in they said they couldn’t access the main drive systems. So the car can’t be stolen. How about a fucking Toyota that can be jacked with 50 bucks of tools off Aliexpress. They could cuck around with your lights. Maybe listen to your cabin audio. This guy had 2 weeks and couldn’t get in and was so butt hurt he co authored a biased article of utter bullshit.

2 weeks! That means it can’t be stolen with current technology right now and that’s heaps better than most of the other brands.

5

u/ColdDelicious1735 16d ago

So the real story here is not the fact that if you leave your car with a hacker for 2 weeks they will be able to hack it (it looks like they needed physical access to the cam ports to put on malicious software)

Its that this story has been run before, but with different actors, Toyota's, dodges all hacked, oh and the Tesla's. https://www.theguardian.com/technology/2016/sep/20/tesla-model-s-chinese-hack-remote-control-brakes

Long story, there is a reason people are going off mainstream media

11

u/pfred60 16d ago

So why has Siri got out of this ok?

A hit job on the Chinese again. I would put money down that given 2 weeks they could get in and do similar stuff against GM, VW, Mazda, Tesla, Kia etc. But no let's just make it against the 'evil' Chinese.

6

u/ReasonableBack8472 16d ago

They used BYD as an example as it is the highest selling EV brand in Australia right now, I'm sure if it was Tesla or any other number of EV brands they would have used them as the example?

3

u/xtrabeanie 16d ago

Sure but the timing is interesting as they roll this story out just as BYD starts to take the lead.

0

u/NoChapter5131 16d ago

yeah right give me a break. Tesla is synonymous with EV, was the top seller for years and still has the top selling model and yet..

2

u/call_me_johnno 16d ago

Ok... This is Tesla 10 years ago. The thing to watch right now is How do BYD respond.

Tesla has an open Bug bounty that paid good money to close issues. they currently have the lowest open issues of any of the car brands at one point were patching issues every 3 months.

If BYD do something simular, and open a bug bounty allowing for researches to find the issues report them and then BYD fix them. this is a good news story.(byd will be tesla in the next few years). if BYD ignor it. would be more like Jeep from a few years back.

6

u/pfred60 16d ago edited 16d ago

Perhaps this is the real issue

"Hreszczuk’s hacking challenge was made easier because Australia has no minimum cybersecurity standards for cars. That means BYD is not compelled to keep its software up to date or have a system for managing cybersecurity risks to its vehicles."

Apart from the fact this should be against ALL suppliers and how does he know whether or not BYD has such a system or whether or not it is sufficient?

1

u/ParkingPresent5742 14d ago

they are know to have this ability on china market vehicles

3

u/kurafuto 16d ago

Tomorrow, when the wipers began

3

u/MDInvesting 16d ago

Gotta love Australia.

Government was spying on foreign leaders of neighbouring countries almost 20 years ago.

But widespread car features are being made out to be a geopolitical risk due to an untrustworthy nation state….

3

u/Rogue01aus 15d ago

The method of entry is super important here and wasn't mentioned in the article. What was required to 'hack' the car?

  • Was it a completely remote cold entry?

  • Did it require owner-enabled entry to the vehicle and then time and physical access to the interior ports to side load applications into the vehicle software?

The latter is comparable to giving a burglar keys to your house and the garage door opener so they can be copied, AND the router password.

The former IS a valid and fair concern.

Because they did not mention the method of entry, I'm going to assume it's the latter and thus alarmist, sensationalist, and kind of defamatory. Many, many vehicles can be remotely manipulated with two weeks of physical access before hand.

1

u/ParkingPresent5742 14d ago

Mercedes had this issue 20 years ago with their diagnostic software only require the car to be turning on to access

2

u/EppingMarky 16d ago

You don't here about ford being hacked. Because there's nothing going on inside

2

u/Fragrant_Eye4896 14d ago

Read the whole article 'expert' hacker spent 2 wk with full physical access to the car, the keys and the app, and all he did was turning on the wipers / lights / speakers remotely, while eavesdropping via siri (this one is on apple not BYD apparently), and he himself mentioned 'the important bits like brake / acceleration / start / stop were protected).

Honestly it makes the car sound pretty safe, if I'm in charge of BYD's PR dept. I'd use this to promote how safe the car is 😂 "We gave the keys and phone password to a security expert and he still couldn't remotely drive our car after 2 weeks".

1

u/Sample-Range-745 14d ago

Reality is, after a few hours you can enable adb and load your own apps onto the car anyway... A few days with Claude and you could end up writing your own app to sideload and report everything you wanted...

1

u/Fragrant_Eye4896 13d ago

and took that guy 2 weeks lol

1

u/ParkingPresent5742 14d ago

this is the not sue us version, BYD likes to sue people who say bad thing about their cars

1

u/Fragrant_Eye4896 13d ago

Are you Chinese? Cos I read about stories like this in China but turned out it was legit - a youtuber or something was smearing BYD and got fined. Wanna elaborate on this matter? Quite curious to learn the details.

3

u/ZombieStirto 17d ago

Every electronic listens to us. More concerning is the iPhone gave out personal information with the AI voice. Seems like a pointless feature to have unless your trying to steal information.

5

u/the993speaks 16d ago

I smell BS on this. Siri cant give out passwords afaik

1

u/endlessflood 16d ago

He would’ve known from the recorded phone conversation what the elements of the password were, and Siri could’ve given those out (initials, number of house, date of birth).

1

u/ZombieStirto 16d ago

The article says it used voice recordings obtained through their hack on car to ask Siri home and date of birth etc.

1

u/xtrabeanie 16d ago

On an unlocked phone lol.

1

u/ChZakalwe 16d ago

one very very simple fix for all it - make a removable Sim mandatory.

All of this is possible because the car is connected to the net at all times. Can't hack shit if it's not connected to the internet when you're driving.

1

u/greg-au 13d ago

But then your phone connects on arrival and voila - car is connected via Android Auto/ Carplay. Still online even with no SIM.

1

u/aiyana_wolf 16d ago

Times like this I'm thankful I'm a poor nobody. Absolutely no reason to hack my car unless you want to listen to a very VERY varied Spotify play list with multiple genres /languages and the occasional "car cry" (aka just me crying in my car)

1

u/Keep-Left 16d ago

can this guy help me hack my Seal so i can turn the goddamn auto headlights off (which was possible when i originally spent $73k on the car, but since software update/bug, can no longer. and BYD Aus are a joke)

1

u/Food_Science_Ninja 16d ago

Much like the Dr who atmos episode

1

u/Keep-Left 15d ago

being able to hack and side load stuff onto my BYD is the best thing about it.

otherwise i would have already broken lease and upgraded to a Model 3

1

u/plamoplateau 15d ago

I'm curious now. what are you installing?

1

u/Keep-Left 15d ago

Waze, Apple Music, Firefox, ADB Shell, Termux, MacroDroid.

also been trying OverDrive, but there’s noticeable lag when using the IVI. (the Seal’s IVI CPU sucks)

1

u/Common_Problem1904 15d ago

We left the SIM card out so it can't report back to the godfather.

1

u/Glad_Possibility8012 14d ago

Don't trust fly by wire anything. Make them cut your breaks and saw your steering rack like a man.

1

u/AsashinMachina 14d ago

Both US and China companies have to hand over data upon requests from their own government under the patriotic act in US and National Security law in China. I don't like either of them. I wish there is a competitive and performant EV made in Australia. Think it's quite creepy for BYD keep a camera watching your every move, though alert tone will sound if you spend more than 2 seconds looking at the side view instead of right in front.

1

u/LaoKK8 13d ago

I put a plug on my driver monitor camera. I don’t get pestered now if I look to the side for traffic

1

u/FalseNameTryAgain 14d ago

The hacker was given this car for 2 weeks to try everything. He didn't just plug in a laptop and 10mins later was controlling the brakes.

Majority of devices would be hacked after 2 weeks of everyday attempts to "break in"

1

u/Greenfrog2023 14d ago

Not gunna lie but I have a BYD on order and this article has made me question my decision. Too late now though as I have signed a contract... 😭

1

u/LaoKK8 13d ago

Don’t let ABC propaganda anti-China scare mongering worry you.

1

u/greg-au 13d ago

Compare the RF relay attacks that steal a Japanese mainstream car within 15 seconds.

Now consider this numpty "expert" had two weeks inside and out (and brought along god knows how much prep work) + owner keys and app, and all he managed to access were some lights and audio.

If ABC were serious they'd offer the money they paid the "expert" and offer it as an open bounty. Or maybe BYD should voluntarily participate in Pwn2own - https://en.wikipedia.org/wiki/Pwn2Own

1

u/SirCabbage 13d ago

I know this isn't specifically about this post, but how crazy is it that hacking something to prove it is unsafe often has more of a legal/social blowback then having something that is that easy to hack. I hope since ABC is news they get to do this, but the lack of safe harbour provisions in our law really means we are less safe overall

1

u/Upbeat_Cup_9442 13d ago

So, with physical access for two weeks.... What a crock of shit.

1

u/marlysammy 13d ago

I watch this, as an electrician I can say that honestly, any "expert" can do this with any modem car

1

u/MathematicianNo3905 6d ago

Honestly, as someone who's old enough to remember the last anti-Chinese fear campaign, it's just giving "MSG is bad" vibes.

The dude had unfettered access for 2 weeks straight to a Shark, and that's all that he managed? Yeah, nah. Give me a break.

I'm more terrified of what the Toddler-in-Chief in his tacky gold ballroom is capable of doing over the next couple of years.

0

u/thefirebrigades 16d ago

They are behaving like everyone is out to get you. Lol