Researchers drove a NIO ES8 electric SUV deep into a Norwegian underground mine specifically to sever its external connections. The car kept attempting to reach servers, most of them located in China. These findings echo broader concerns about hidden data collection, similar to how a surveillance app was built to covertly target users without their knowledge.

That finding sits at the center of Project Lion Cage, a multi-year study initiated in 2022 by Tor Indstøy, a risk management and threat intelligence executive at Telenor Group. Indstøy purchased the NIO ES8 as a dedicated research platform.

The project arrives as Chinese EV brands expand across European markets with assurances about local data processing. Observed network behavior appears to contradict those assurances.

  • njm1314@lemmy.world
    link
    fedilink
    English
    arrow-up
    61
    arrow-down
    1
    ·
    6 days ago

    Why on Earth wouldn’t it keep trying? That’s how signals work. If my router goes down my computer is going to keep trying to connect to it even though it’s off. That’s not fucking news.

      • toddestan@lemmy.world
        link
        fedilink
        English
        arrow-up
        22
        ·
        6 days ago

        My assumption would be that they drove the car into the mine to see what would (or wouldn’t) work if the vehicle was cut off from the mothership. My hunch is they didn’t really find anything of interest so this is what gets reported.

        • freely1333@reddthat.com
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          4
          ·
          6 days ago

          Also all us cars do the same thing and I would much rather have my data in China than the US.

    • FordBeeblebrox@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      9
      ·
      6 days ago

      If I’m reading correctly, they specifically tried to stop it from doing so and even in what is essentially a faraday cage it keeps trying to link with Beijing to spill the tea, not exactly what you want if you “own” a product

        • FordBeeblebrox@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          3
          ·
          6 days ago

          It doesn’t specify in the article if they toggled the WiFi switch off in the OS, one would assume they did before driving it into a mountain.

          If so, not cool to keep calling home. If not, PEBKAC error

  • Null User Object@lemmy.world
    link
    fedilink
    English
    arrow-up
    55
    arrow-down
    1
    ·
    7 days ago

    The car kept attempting to reach servers

    To the surprise of whom?

    ANY device that relies on radio signal communication for any of its functionality, taken anywhere (underground mine, parking garage, Antarctica, Santa’s workshop, etc), and it’ll try to maintain it’s connections. That’s just what they do.

  • cub Gucci@lemmy.today
    link
    fedilink
    English
    arrow-up
    38
    arrow-down
    2
    ·
    6 days ago

    My BMW checking if my bmw subscription is active when I’m trying to enable seat heater

    • foo@feddit.uk
      link
      fedilink
      English
      arrow-up
      7
      ·
      6 days ago

      I wonder what the security is like. I’d love to know how difficult it would be to set up a mock-service to just tell it you have everything.

      You’d expect there to be encryption and some kind of certificate validation to check the response is trustworthy, but given what we now know about the CAN bus that many cars use, and how vulnerable it is to attack, it suggests the motor industry is way behind the times in terms of security.

        • brucethemoose@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 days ago

          Yeah, that’s the thing. It’s not like a transistor in a microchip or something; it’s a wire you can work with.

          I bet BMW makes the disassembly needed an absolute pain, though.

  • Bubbaonthebeach@lemmy.ca
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    3
    ·
    6 days ago

    A more honest researcher would say “bought any vehicle from x country and it kept trying to contact servers in x country even after driving it into a mine”. They lose credibility when they try to insinuate that this only happens with EVs and only with China made vehicles.

    • Hawk@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 days ago

      I have no idea what the point is of driving it into a mine? Of course the client will keep trying to reconnect to the server, that’s how software usually works…

  • Fedegenerate@fedinsfw.app
    link
    fedilink
    English
    arrow-up
    22
    ·
    edit-2
    6 days ago

    Step 1: make a PiHole

    Step 2: examine every thing the PiHole blocks from calling home

    Step 3: research small holdings

    Step 4: throw it all out and go farm Llamas

    Seriously, I own a Firestick as a jellyfin client. It’s network access is limited to local only. Anyway, here’s one entry from that Firestick on one PiHole:

    global.telemetry.insights.video.a2z.com 42590

    Number is the number of times my PiHole has smacked it down. One entry, from one stick, to one PiHole (I have a redundant one too).

  • sapetoku@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    5
    ·
    7 days ago

    Ah, because neither Google nor Apple track their users and would never, ever share said data with US (or other) agencies… right? RIGHT?

    • CriticalThought@lemmy.world
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      6
      ·
      7 days ago

      Sure. Don’t worry about this bad behavior, because others engage in it, and it’s not like anyone calls out US tech privacy issues. I struggle to imagine someone naturally reacting this way. Are you for real?

      • LifeInMultipleChoice@lemmy.world
        link
        fedilink
        English
        arrow-up
        8
        ·
        6 days ago

        I agree it is something we should worry about and pay attention too, but just because something occurs doesn’t mean it was nefarious on purpose. Apple is better than many, but let’s say you have an iPhone. The iPhone is constantly reaching out and reporting it’s location to the findmy app that is only accessible by the users. If that phone is in a cave performing this test, it will be reaching out continuously similar to this car. Apple doesn’t sell that data, but where it becomes a breach of privacy is that if a judge gives a warrant, Apple has to turn it over. (So suddenly it isn’t only accessible to the user meaning verification is NORMALLY required to allow Apple to access the data, but they could bypass said verification.

        So does that mean no one should ever enable find my on their devices… Maybe, but people weigh it against whatever they find useful about it.

      • sapetoku@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 days ago

        What I’m saying is just because it’s China doesn’t make it any worse than devices and cars phoning home to US agencies/corporate entities. Might be fuckery from both sides but I don’t get the disproportionate uproar.

  • kent_eh@lemmy.ca
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    6 days ago

    The car kept attempting to reach servers, most of them located in China

    Now try the same experiment with cars from other countries.

    And then let’s hear from someone who can tell the world how to disable this anti-feature without breaking the car that we bought and paid for.

  • GreenKnight23@lemmy.world
    link
    fedilink
    English
    arrow-up
    20
    arrow-down
    4
    ·
    7 days ago

    I have Chinese manufactured IP cameras. they do not connect to the internet. yet, they still attempt to connect to Chinese servers at least once a minute.

    this has been going on for at least 15 years.

    • YeahToast@aussie.zone
      cake
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      2
      ·
      6 days ago

      I have an Chinese manufactured American developed phone. It connects to an American server frequently.

      • GreenKnight23@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 days ago

        difference is, China has been caught multiple times creating backdoors into their hardware through software.

        I guess that means America is just better at foreign espionage than China 🤣

  • Shayeta@feddit.org
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    3
    ·
    7 days ago

    I’d like to not be spied on. But if forced to choose, I would rather be spied on by a foreign goverment than a domestic one.

    • pycorax@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 days ago

      We shouldn’t be capitualting to any form of spying either way. In the first place, why is a vehicle phoning home? While I disagree, it’s still somewhat thinly understandable if the CarPlay or Android Auto system is doing it but if not, why?

      Maybe it’s because I have an old Mitsubishi from almost a decade ago with a fully offline third party car entertainment system that came with it but it runs perfectly fine without any of this nonsense.

    • frongt@lemmy.zip
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      2
      ·
      6 days ago

      Why? At least with a domestic government you can vote and lobby for data controls. GDPR, etc.

  • stinkytofuisgood@lemmy.ca
    link
    fedilink
    English
    arrow-up
    11
    ·
    6 days ago

    Somebody smarter than I will definitely delve into the guts of incoming Chinese EVs and figure out what part(s) to strip to stop this…

    And if you’re in America and you have an EV, it’s statistically likely to be a Tesla. Tesla has starlink compatibility baked into their cars too and you’d better believe that sweet juicy data is being shared around.

    If I was stuck with a Tesla against my will, I’d at least try the same thing for it, too.

  • Someonelol@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    9
    ·
    7 days ago

    Can’t this be solved with legislation? I mean, all they have to do is say “no vehicles may be sold within our borders if they attempt to communicate with any servers.” Vehicles never did this 15 years ago and it’s insane they operate like massive phones with wheels now.

  • ogrrr@lemmy.zip
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    1
    ·
    7 days ago

    And this is exactly why runor has it military installations in my country don’t allow EVs to enter at all.

  • pycorax@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 days ago

    Am I the only one in this thread that feels like a vehicle here shouldn’t even have any form of internet connection regardless what nation it is from? The fact that this is from China doesn’t matter. Why does a vehicle even need network equipment (other than a FM radio at most)?

  • kreskin@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    7 days ago

    With all our formidable intelligence and NSA capability and massive massive funding, no one can tell whats in those communications after all this time huh. We even have physcial access to the devices and we still cant figure it out. Next time we are told the government needs to remove citizens constitional rights to privacy or needs us to use insecure encryption keys, we should all question what the hell for. And next time I hear “Israel helps us with our intelligence” I want to hear what they came up with in understyanding what chinese devices are sending home, or they can shut the hell up. So far all we seem capable of is spying on our own citizens, IF we all use insecure communications and allow our every movement in public to be videoed. I am not impressed.