Anyone who has been cursed with using anything related to CarWings might not be surprised by this. I swear their backend is running on some intern's personal laptop. That feature where you can preheat your car from your phone? Be sure to allow a few minutes to do that. Start the app, wait 30 seconds for it to log in. Go to "Climate". Oh, shoot, it thinks the heat's still on (the app does a pathetic job of managing state). Click "Turn Off". Wait another 30 seconds (or more) while it round-trips to the car. Click "Turn On". Wait another 30 seconds. Go to car, expecting it to be warm. Open car door to discover that it's stone cold.
That's just one example. Nissan said they'd charge for CarWings after three years. Going on almost five years later, we've yet to receive a bill. Nissan knows if they tried to charge for CarWings, they'd have three paying customers because no one else would pay for that crap.
With all its warts, I would have said nothing much would surprise me were a security hole were found. But this is just astounding. The prior API at least required creds. So they took an API that had some modicum of security, discarded that and just use a string that's visible from the outside of every vehicle? Picture me with my lower jaw hanging between my knee caps.
> Nissan knows if they tried to charge for CarWings, they'd have three paying customers because no one else would pay for that crap.
That and the service is going to break this year anyway.
AT&T is sunsetting its 2G network on December 31, 2016. It's already dismantled it (to reallocate the spectrum to 3G/4G/LTE) in some regions.
Most Leafs on the road only have 2G AT&T modems. I'm pretty sure Nissan was still selling them new in 2015 with 2G modems, despite knowing AT&T's plans. There won't be any CarWings service, or charging location updates, or anything else that needs internet on those cars once the 2G network goes away.
That's just one example. Nissan said they'd charge for CarWings after three years. Going on almost five years later, we've yet to receive a bill. Nissan knows if they tried to charge for CarWings, they'd have three paying customers because no one else would pay for that crap.
With all its warts, I would have said nothing much would surprise me were a security hole were found. But this is just astounding. The prior API at least required creds. So they took an API that had some modicum of security, discarded that and just use a string that's visible from the outside of every vehicle? Picture me with my lower jaw hanging between my knee caps.