BMW ConnectedDrive lets me control my returned rental car (Sixt)

42 derturm666 15 6/17/2025, 6:33:38 AM
Last week I rented a BMW from Sixt (Italy).

The default rental driver profile had Bluetooth disabled, so I created my own BMW ID, paired it with the car, removed the existing profile, and even triggered software updates.

When returning the car, I told the Sixt representative that I had linked my BMW ID — they assured me that the vehicle would be reset.

Today — just before deleting the “My BMW” app — I checked out of curiosity.

Surprise: I still had full remote access:

- live location tracking

- remote lock/unlock

- honking (hehe)

- turn lights on/off

At this point, the car was presumably already rented to someone else. I could track the new renter’s location and remotely interact with the car.

IMO, this exposes a serious security/privacy issue:

- BMW ConnectedDrive still had my account associated to the vehicle VIN

- Sixt’s reset procedure didn’t revoke my BMW ID access

I suspect this may not be limited to Sixt, but could affect other rental fleets using ConnectedDrive if proper backend disassociation isn’t done.

BMW allows fleet integrations via ConnectedDrive Fleet Services, but I wonder how many rental cars globally still have previous renters’ IDs attached.

Comments (15)

dylan604 · 19m ago
I've read in multiple places that this "resetting" is something that is on a list of things to do, but is rarely done. I seriously doubt any person working at the rental place prepping the car for the next use does anything but the most basic/obvious of refreshing. I'm guessing after checking the fuel status and the mileage, they just don't care. I doubt that cars get vacuumed after each rental and only if it's obviously needed.

As the person that is entering their own personal information into a car that you do not own, you absolutely should be the one to remove that data. Do not depend on someone else doing their job. You took the time to add it, so take the time to remove it. It is the only way to be sure.

bayindirh · 32m ago
I once rented a Peugeot 3008, and wanted to pair with Apple CarPlay. The car warned me that it's in "rental" mode and pairing will disable that and will share tons of data (which was listed as bullet points) about me and the car between my (apple) profile and the car.

I rejected and didn't go further. I appreciate the honesty, though.

jsumrall · 5m ago
I rented a BMW from Sixt in the USA earlier this year. I wanted to use the ConnectedDrive features, but it was blocked by BMW because the vehicle VIN was (correctly) registered as a Fleet Vehicle (i.e. a rental car) and thus none of those features were allowed with that car.

I have rented BMWs in the Netherlands and don't recall being able to use these features either.

Thus you seem to have encountered a situation which BMW and Sixt know about and have procedures in place to prevent, but their Italian subsidiary seems to have missed it with a certain batch of fleet vehicles, or just this specific one. I'd report it Sixt and move on.

nunez · 10m ago
Yes, this has been known for many years.

Most rental car companies don't bother setting up fleet services for their connected vehicle services. They require infrastructure that car rental companies don't seem to consider important.

I've used this mostly to remote start my rental car in cold climates. I delete my account after my rental is done, though I've learned recently that some providers, like Hyundai, make this SURPRISINGLY difficult.

The only exceptions I've seen to this are FordPass with Avis (this was locked down a few years ago) and Tesla with Hertz (before they unloaded them all).

thatjoeoverthr · 53m ago
What timing. I rented a BMW from Sixt in Italy last week. Worst thing I have ever experienced as a driver. I wrote about it here: https://x.com/thejoephase/status/1933156741031633159

Constant interruptions and problems from the computer. I've dealt with a few "modern cars" but this was over the top. I'll never rent or buy a BMW going forward.

powvans · 37m ago
This is amazing! I am vacationing in Spain and rented, I think, the same model as you. A BMW X2 M something or other.

Absolutely rock bottom by far the worst driving experience ever. Ultimate driving experience indeed. Insane and subtle annoyance, major wtfbbq moments, endless alarm dinging when you exceed whatever speed limit it incorrectly read from a sign, and on and on. The slamming on of the parking brake as you approach a large blade of grass in reverse is nerve wracking and startling even when you know it’s going to happen.

On narrow streets and in parking lots it feels less maneuverable than my full size American SUV. It may have the same turning radius despite being half the size.

Your tweet is making me laugh because honestly you cannot exaggerate how bad this car is. Every time we get in and start going my wife and I share a moment of incredulity. How can they have made this car this bad?

wil421 · 16m ago
None of these things happen in my X5. It will even detect my bike rack and not automatically stop like my wife’s X7 does with iDrive 7. You can turn off all the speed warnings but no one is going to do it in a rental.

Not surprised the X2 sucks it’s the cheapest model and usually the Germans do not do well in this category. The cheap small Mercedes are similar.

The biggest annoyance is the horn beeps when I leave the car running and grab something from the trunk.

thatjoeoverthr · 11m ago
I believe some of it should be configurable, but I'm mystified that the default configuration should be so aggressively unempathatic to the driver. I did manage to turn off the thing where it covers the map with my forward camera view. But if Car Play worked, I wouldn't have bothered, and would have kept using Google Maps.
skylurk · 14m ago
Same experience here, with a brand new Audi I got "upgraded" to. I'd take an old Yaris over that zoo any day.
FirmwareBurner · 10m ago
>How can they have made this car this bad?

Typical German beancounter MBA run company treating SW like a cost center. "We need to add interactive computers on cars because that's the latest hip trend, but we need to outsource it to the cheapest bidder because SW development is not a "real" engineering discipline and we don't like paying for good SW developers."

Neywiny · 43m ago
Not sure how it varies across the pond, but I've rented a few cars in the States and they've never been reset. You'd think they'd have a rental mode or something. But instead, it's full of their preferences, phones, etc. Very annoying when they turn off modern safety features and stuff
abcd_f · 9m ago
I have a year old BMW and the software is a complete and utter f*cking trash. The whole UX is just garbage.

Basically BMW goes out of its way to force drivers onto ConnectedDrive. Half of the functionality is hidden - for no clear reason - behind online ID.

You'd assume that if my wife or I open the car with our respective keys, we'd have the matching profile loaded, the seat adjusted, etc. Mwahahaha. NO! Unless the key is linked to an online ID - no soup for you! Infuriatingly stupid.

The dealer essentially forced me to create an online ID and activate ConnectedDrive saying they can't deliver the car otherwise. Immediately after, the car enrolled itself in some sort of Premium trial and never bothered to mark what functions are included and which are premium. It took 2 phone calls to get the trial cancelled and - what do you know - the traffic info was a part of it! What a bunch of wankers.

Even then, you'd assume that if they are so set of online bullshit, it would be polished. Ha, dream on. If you unlock the car and it has no cell connectivity, you get a guest profile. Car starts speaking German, all settings are at defaults, including the seat position.

I mean ... it's not my first BMW, but the pace of its enshittification is beyond belief. Stay the heck away.

bryant · 1h ago
Enterprise Holdings manages theirs via fleet, so while a BMW ID can be added, the car is generally fleet restricted. Includes restrictions on capabilities like using (the cursed) subscription "features" you've paid for.

So yeah at least one of the big renters has handled it appropriately on the cars I've rented from them.

monster_truck · 18m ago
They seem to be better with some brands of cars than others, the sports car I rented from them was not reset or restricted in any way.
7bit · 7h ago
If you want to invest the time you can report this DPA violation. They are obliged to reset the car to ensure the next renters privacy, especially if you told them. Violations can be expensive and it is generally a good idea to report so the big corps keep getting reminded that privacy is an important right of their customers.