Feed aggregator

BMW ConnectedDrive lets me control my returned rental car (Sixt)

Hacker News - 10 hours 37 min ago

Last week I rented a BMW from Sixt (Italy).

The default rental driver profile had Bluetooth disabled, so I created my own BMW ID, paired it with the car, removed the existing profile, and even triggered software updates.

When returning the car, I told the Sixt representative that I had linked my BMW ID — they assured me that the vehicle would be reset.

Today — just before deleting the “My BMW” app — I checked out of curiosity.

Surprise: I still had full remote access:

- live location tracking

- remote lock/unlock

- honking (hehe)

- turn lights on/off

At this point, the car was presumably already rented to someone else. I could track the new renter’s location and remotely interact with the car.

IMO, this exposes a serious security/privacy issue:

- BMW ConnectedDrive still had my account associated to the vehicle VIN

- Sixt’s reset procedure didn’t revoke my BMW ID access

I suspect this may not be limited to Sixt, but could affect other rental fleets using ConnectedDrive if proper backend disassociation isn’t done.

BMW allows fleet integrations via ConnectedDrive Fleet Services, but I wonder how many rental cars globally still have previous renters’ IDs attached.

Comments URL: https://news.ycombinator.com/item?id=44296237

Points: 1

# Comments: 0

Categories: Hacker News

Show HN: Jan-nano, 4B agentic model that outperforms DeepSeek-v3-671B using MCP

Hacker News - 11 hours 5 min ago

We’ve been experimenting with how far a tiny model can go when it’s good at calling external tools - and have just released Jan-nano, a 4 B model trained for MCP.

Jan-nano: - tops DeepSeek-V3-671B on MCP tool-use (SimpleQA 80.7%) - handles live web search and multi-step deep research - runs fully on-device (≈4GB VRAM)

Tech notes

- Base: Qwen3-4B - Fine-tuning: DAPO - We're going to release the full technical report soon

Links

- Demo tweet: https://x.com/menloresearch/status/1934809407604576559 - Model + GGUF: https://huggingface.co/collections/Menlo/jan-nano-684f6ebfe9... - Jan Beta desktop (viewer/runner): https://jan.ai/docs/desktop/beta

How to try it:

- Install Jan Beta (macOS/Win/Linux): https://jan.ai/docs/desktop/beta - Go Jan Hub and download Jan-nano (onboarding steps help you to download it) - Get your free Serper API key to test deep research & real-time web search: https://serper.dev/ - Settings -> MCP -> paste your SERPER_API_KEY (gives the model web search access).

We’re testing Jan-nano inside Jan's beta (an open-source ChatGPT alternative). Feedback on both the model and the app is very welcome.

If setup feels clunky, follow us on X for a short walkthrough video (coming soon) or join our community chat.

- X: https://x.com/menloresearch - Discord: https://discord.gg/Exe46xPMbK

Huge credit to the Qwen team for the base model.

Comments URL: https://news.ycombinator.com/item?id=44296141

Points: 2

# Comments: 0

Categories: Hacker News

Pages