BMW ConnectedDrive lets me control my returned rental car (Sixt)
By
derturm666
Last week I rented a BMW from Sixt (Italy).
The default rental driver profile had Bluetooth disabled, so I created my own BMW ID, paired it with the car, removed the existing profile, and even triggered software updates.
When returning the car, I told the Sixt representative that I had linked my BMW ID — they assured me that the vehicle would be reset.
Today — just before deleting the “My BMW” app — I checked out of curiosity.
Surprise: I still had full remote access:
- live location tracking
- remote lock/unlock
- honking (hehe)
- turn lights on/off
At this point, the car was presumably already rented to someone else. I could track the new renter’s location and remotely interact with the car.
IMO, this exposes a serious security/privacy issue:
- BMW ConnectedDrive still had my account associated to the vehicle VIN
- Sixt’s reset procedure didn’t revoke my BMW ID access
I suspect this may not be limited to Sixt, but could affect other rental fleets using ConnectedDrive if proper backend disassociation isn’t done.
BMW allows fleet integrations via ConnectedDrive Fleet Services, but I wonder how many rental cars globally still have previous renters’ IDs attached.
Comments URL: https://news.ycombinator.com/item?id=44296237
Points: 21
# Comments: 3
You might also wanna read
AI-Driven Layoffs Create Unrecognized Grief Crisis Among Tech Workers
The article examines the psychological and emotional toll of AI-driven job displacement on tech workers, arguing that the experience closely
Sergey Brin tells Google AI staff 60-hour workweek is the 'sweet spot' for productivity
Sergey Brin, Google cofounder, wrote an internal memo to employees working on the Gemini AI products recommending a 60-hour workweek as the
Project Glasswing: AI-assisted vulnerability detection finds over 10,000 critical software flaws
Project Glasswing is a collaborative effort launched to secure critical software against potential threats from increasingly capable AI mode

NYU Researcher Explains Why AI Models Still Struggle to Play Video Games
Julian Togelius, director of NYU's Game Innovation Lab and co-founder of Modl.ai, discusses a recent paper exploring why LLMs and AI models
spectrum.ieee.org·1h agoKefir C compiler development moves to private mode indefinitely
The developer of the Kefir C compiler announces the cessation of public development, transitioning the project to private mode indefinitely.
How wind and solar made Spain one of Europe's cheapest electricity markets
Spain's wholesale electricity prices have dropped dramatically to become among Europe's cheapest, averaging €44/MWh in early 2026 compared t
