How connected car tech is eroding personal privacy
bbc.com
bbc.com
One day a fault developed with the seatbelt sensors on the rear seats. He kept getting the warning beeps to fasten the belts when no one was on those seats.
It was still in warranty so he took it get fixed. The dealer pulled his driving logs from the on board computer/data recorder and said his driving was too aggressive and that violated the warranty.
Truth be told his driving was terrible. I accepted a lift home from him once, and only once because his driving scared the bejeesus out of me. But that being said how could that affect the pressure sensors in the rear seats?
It took some solicitors letters to get the dealer to agree to a warranty repair.
I think its inevitable that manufacturers are going to use all this data to stop you claiming under your warranty. "Oh dear you slammed your door too hard one day, I'm afraid that invalidates your warranty". Insurers will demand this data in before giving you a quote. Its also likely that there will come a time when this data will be used to help price your car if you sell it or trade it in. And of course the government will want to use positioning data to automatically issue parking fines.
And this ignores all the obvious security risks that come along with this sort of stuff, for example all those BMW keyless car thefts.
That, at least, is potentially defensible. How the car is treated & how/where it was driven do have a big impact on long term reliability.
In fact, if you are a gentle driver who lives in a good location and operates the vehicle under optimal conditions, you could expect to get more for your vehicle- today, because the buyer cannot easily tell, they pay you somewhere in the middle.
Insurers will demand this data in before giving you a quote.
Same goes here, once it becomes commonplace, insurers will be able to reliability identify "golden goose" customers who, based on driving patterns, are exceptionally unlikely to get in an accident. They will fight eachother tooth and nail for these drivers.
I think its inevitable that manufacturers are going to use all this data to stop you claiming under your warranty. "Oh dear you slammed your door too hard one day, I'm afraid that invalidates your warranty".
Thankfully we have Magnuson-Moss, so while bad apples might give you the occasional runaround, the law is on your side.
I understand that this is what insurers are striving for, and same with good drivers, the problem with it is that personalizing prices to everyone essentially makes insurance useless, since you'll essentially end up paying how much damages would really cost if you had no insurance + extra premium, because insurance wants to make money
The whole idea of insurance is that you have a pool of people and there is probability that percentage of it will have an accident, the remaining group subsidizes essentially creating a safety net.
All of that is negated when insurance prices individually, since you'll always lose on it.
The point of insurance is not to have some people cross-subsidize others on average, the point of insurance is that you might prefer to have 100% chance of paying ten bucks instead of 0.1% chance of having to pay ten thousand at a point when that would ruin you - and if you can afford the loss if it happens, then yes, there's no point in insurance for you, it's not a charity where you expect to get a net benefit from the insurance company.
Bad drivers hitting me and don't paying isn't useful, be it paying me directly or reimbursing my insurance company.
If your lifetime probability of a $10M accident is 0.01%, it is probably preferable to pool your risk with other drivers of equal risk, and pay $1,000 + small extra premium.
And that would be excellent. Peppercorn insurance for drivers who won't have an accident.
Killers will effectively be banned from driving. Zero traffic deaths.
In that case, why not just cut out the middle man and pay out of pocket when accident happen, it would be cheaper.
Essentially this tendency defeats the purpose of having insurance in the first place.
Insurers make their money on investments of premium dollars, not on loss ratios. Sure, they might have a good year or two with low loss ratios, but that means they're collecting too much premium compared to competitors and so may lose market share if the others lower premiums due to more accurate forecasts of losses (closer to 100%). This is one reason insurance marketing and advertising work so hard to drive customer loyalty and retention.
So your rates went up even though you didn't have an accident? Better look to see what the stock market has been doing lately.
I think that tailoring the premiums based on the driving style is fair, and would give bad drivers the option to improve to reduce their insurance, with the nice side affect of making the roads safer. It isn't going too far down the slope to do this.
In the extreme, it would mean everyone would need to become a safer driver or not drive at all, which is probably a good thing.
They will become safer drivers then pay a small premium to cover them for chance accidents like a collapsing bridge or a blown out tire.
I'd love to know how the dealer could justify saying a high-end Audi, a car (and company) with an established racing pedigree, was driven "too aggressively".
Look at their commercials for crying out loud.
There are no illusions that this is something the warranty would or should cover.
This isn't obvious. Sure, some irresponsible driving behavior is evident in braking, acceleration, speed, etc. data.
I suspect the much larger pool of bad drivers is people who are braking and accelerating very gently because they are spaced out, drowsy, or on their phones.
I don't know the actual specifics, just that my boss came in to work one day raging about it. I suspect the dealer was just looking for excuses to not do the fix.
But just a cursory read around the web seems to imply that this is happening more and more and to be honest I think it would be unwise to assume that manufacturers wont make it an official policy at some point.
We have an infestation of middle aged men who drive mid to high end Audis (always painted black) with a set of gold clubs permanently stored in the boot.
Sometimes, "book time" to fix a particular defect is lower than the actual time, and manufacturers pay out on book time.
However you spin it, the dealer-manufacturer relationship ends up working in favor of the manufacturer, as they control the inventory and the bottom line of the dealer's balance sheet.
the whole system is a mess. yeesh.
I live a highly automated life and my database has when I woke up, where I drive, when I get home, what TV shows I watch, how long I spend on Hacker News and when, when I enter the house it is recorded... and then more benign stuff like how long my air conditioner has been on. And and I do this voluntarily.
Overall it's a gig of data a day.
The weird thing is my wife has access to this data too and I have access to her's (which is less extensive but still there... for example, if her code is used to disarm the alarm, it is stored that way).
I also might be crazy, most people would be disturbed with this level of data.
As a side note, I store the database on my own server and I am very comfortable with the security on said server. Firewalls, tripwires, multi-factor auth, encryption, the works. Even I wouldn't trust that database with a third party.
Have you done any analysis on the data? I'm wondering if you can find out if you're coming down with an illness before your body even exhibits the symptoms.
Here's the implication of why I say this: IoT companies who sell this data to third parties will then have this bit of leverage over you. The next time you browse Amazon/FB/News your browser, sans-adblock, will be just as infested with ads as your body is with the cold.
The only exceptions I make are weight lifted and repetitions when working out and only because I haven't found a good way to do it and it... I've been playing with Arduinos and accelerometers and measurements (waist, chest, thighs, etc) which I only do once a month.
So in theory it is possible.
But in any case, per your motivation behind the question. I avoid devices that report data to a central server so advertisers using it would be hard pressed, but not all consumers are as careful. I can't avoid it entirely without making my own hardware. For example my Fitbit data goes to Fitbit, my treadmill data goes to iFit, and 23 and Me has my DNA sequence. But I think you'd need all the pieces to it all together and there is no third party that has them all.
At the time I couldn't convince my wife to let me spend $200 on it so I've been trying to make my own :) Maybe she'll get one for my birthday.
That said, I absolutely, positively don't want this data to be owned by third parties. It should be my data, for my perusal.
Could you explain what you mean by this? That level of data collection disturbs me for privacy reasons. I don't see how I lack touch with reality. It's interesting and I would like to have all that data on myself too but the privacy risks make it not worth it for me.
My point is - existence of such data should not be disturbing. How much of it is being collected by third parties - that's another story.
[1] One nice thing about owning the database is if I want to, say, stick it in an R program and graph some stuff / make some models I can. Which as a software engineer is fun for days and has allowed me to see and correct and/or automate patterns. For example, my bank accounts and credit cards are also in this database and it has allowed me to see spending patterns that I needed to fix.
http://hanselminutes.com/399/chris-dancy-the-worlds-most-qua...
Now I see "myself" as just a thing in the Internet of Things that I can track metrics on (and tell to do things) just like any other thing.
Don't take me philosophically or spiritually with that statement. As a human I am trained to think of myself as more than "just a thing" and to think otherwise would be a bit morbid :) but from an architectural standpoint I don't treat my own metrics different than the rest of the 200+ devices in my IoT network.
[1] A little more detail on that because I'm sure they might find it interesting:
- If there is a phone, Linux, or Mac app I use Charles to try to intercept the traffic
- If that fails I use Wireshark
- If that fails I decompile their app
- If none of those work, I have to ditch the hardware and try new hardware.
What other data is sitting around? How about raster images of whatever your "copier" printer fax has handled? Even if you're using USB, if there's WiFi capability in there, assume it can be awakened. A link that's not compatible with your sniffer is a possibility too. Drag out a spectrum analyzer and directional antenna. While you're at it, check those new LED streetlights for bursts of r.f. too.
Authy supports the algorithm as well, they just don't advertise it because they want you to use their's.
It's actually an RFC https://tools.ietf.org/html/rfc6238 and there are implementations for almost any language.
To make myself more efficient. Automate things I have to do but that don't make me happy. Improve my physical health (I'm motivated by numbers... they get me to the gym). Make more informed decisions.
Basically I run my life like a business. I track KPIs[1] and use them to plan and act.
For example, right now my app is telling me I'm spending more than my average amount of time on Hacker News. And based on that, I can make the decision I should probably get some work done :)
Also, if I ever get murdered, unlikely for sure, the cops will have an easy job ;) (joking, this isn't a primary motivation but, certainly a side effect).
Edit: plus I think it is fun, it's a hobby. Everyone needs a hobby :)
[1] Key performance indicators
For my software:
- Node.js
- MongoDB
- Ubuntu Server
- Docker
- Java for my mobile app
- Electron for the desktop app
For hardware:
- Galaxy Note 5 using the accelerometer and GPS
- Macbook Pro running custom monitoring software
- Fitbit smart scale
- A lot of Aurdinos
- A few Raspberry Pis
- A few Spark Photons
- A Vera for home automation and integration with household sensors
- A whole slew of Zwave and Wifi house sensors and switches
- The cameras and alarm are through ADT Pulse but to be honest I wish I had used a more open solution. Everything runs through their servers, I can't talk directly to the cameras.
- Some more home automation stuff that is not really quantified self (more IoT) so I'm not including (Nest thermostats, myQ garage door opener, etc)
For protocols (you'd be surprised at how many devices you can get data from knowing these three protocols):
- UPnP
- Bonjour
- HTTP
- IMAP
For APIs:
- Fitbit
- IMAP for email (not an API in the sense people think of APIs but still...)
- Nest
- A bunch of stuff that I had to reverse engineer because they don't offer public APIs
For analysis:
- R mostly
For reverse engineering hardware devices that don't open their APIs:
- Charles for a proxy to sniff traffic (if they have an app)
- Wireshark for devices that don't obey proxies
I'm sure I forgot something.
As you can see, it is a LOT of work. But it's a hobby so I enjoy it. I want to open source it one day but as you can imagine... none of this is unit tested or meets any of the criteria I would use for an open source project. It is, in effect, a "hack"... but it works.
Also, have you considered doing any machine learning on the data to detect hard to spot patterns?
However, Zwave is pretty nice because it doesn't tie up my Wifi bandwidth, is quick to set up, and it forms a mesh network. Plus the devices are a fraction of the cost of the Wifi connected one.
All the improvements have been minor but they add up to large lifestyle improvements. Some examples:
- I never have to worry if I left the garage door open or the lights on.
- I can set my alarm (the intrusion detection kind not wake up kind) without leaving bed if I forget to set it.
- Controlling all my entertainment devices is now one click instead of messing with 5 different remotes. It's also easier for guests to understand.
- My sprinkler system adjusts watering based on the moisture level and the last time it rained. Which conserves water.
- My thermostat knows when I'm not home which also conserves energy and saves money.
- My exercise equipment turns on when I need it on schedule, which helps me to stay motivated. The TV with the workout DVD in it also turns on on schedule.
- Holliday lights turn on at dusk and turn off at 1 AM. Or when I tell them to with my phone.
- I can get woken up at the right time so I'm less tired throughout the day.
- If I have someone coming over to say, fix the plumbing, I can give them a temporary code that is only good during the time they are supposed to be there. Or they can call me and I can unlock the house from my office. And I can see them on video while they are there. Plus the alarm can set when they leave.
As I said, little things that add up.
The health and quantified self type stuff has helped me spend less time on stuff I shouldn't be doing and more time being healthy.
One of my favorite devices in terms of effect on my life, as weird as this sounds, is my Sonos system. I have speakers in every room in the house and I can use them to play music that sets the right mood whether I'm working out or eating. It's also nice to be able to pipe the TV audio to other rooms during, say, the presidential debates.
Have I considered machine learning? Yes. I actually use some to automate email. It deletes email I don't want to read and nags me about email I really should reply to (hence my previous post that mentions IMAP). But I'd love to find more uses of it.
One use I've been toying with is learning when I need to go places (like the grocery store) and alerting me when I'm driving near it so I can save an extra trip. Example: the milk will be gone in two days and you're right next to the store, you should get more now so you don't have to make a trip later.
None of this is important on its own and some of it is downright silly, but in aggregate it adds up.
I guess I'd have to change my database to be built on blockchain technology so that it is cryptographically impossible to modify past state without detection. Then I'd just need to make sure the computer has append only access to the backups.
It’s absolutely true that connected cars and the wider IoT space has miles to go in terms of security and privacy. Far too many companies treat security as an afterthought, and then we see everything from Jeeps to Barbie dolls being compromised. Those same firms then treat privacy as a winner-take-all game, where they expect the customers to give them maximum access with minimal accountability. And frankly, it pisses us off.
At Automatic, we’ve laid out our security procedures and privacy policies incredibly clearly. No firm is perfect, but I think we’ve done an outstanding job at creating systems that are difficult to penetrate, and in setting precise expectations with our customers about how we’ll use their data. You can read about those here: https://blog.automatic.com/security-at-automatic-how-we-keep... and https://blog.automatic.com/our-privacy-principles-4d2fd93654...
To get back to the article - car manufacturers that hide what they’re doing from consumers should knock it off. I don’t think they’re necessarily being nefarious, I just think they’re being foolish. In this age where consumers are waking up to the risks and rewards of connectivity, obscuring the data you’re collecting and how you’re using it is only going to become more untenable.
Edit: sorry, I extrapolated too much from my own experience. It's still not legally mandatory until 2018, however some manufacturers do indeed make it mandatory today.
Due to privacy protections I don't think marketers and insurers have access to driving data, but the security concerns remain. Their back-ends can be hacked, rogue employees could listen in, etc.
For freedom, ride a bike.
They've been talking about that technology for years, but that's a long way from not being able to buy a car without it.
In fact, the official site[1] says:
"On 28 April 2015 the European Parliament voted in favour of eCall regulation which requires all new cars be equipped with eCall technology from April 2018. eCall will be seamlessly functioning throughout Europe by that time."
And that's before the inevitable privacy lawsuits and so on.
[1] https://ec.europa.eu/digital-single-market/ecall-time-saved-...
He was so impressed by the automatic assistance call that he actually bought the car.
:D
I hadn't heard of this. Just looking at the article you linked it seems it is only available in Slovenia and only since 2015. Is the tech still in all cars but just not being utilised?
eCall is weird. There are supposedly privacy protections, but I can't see how it can work without being always on the mobile network. Which tells you what cell the car is in.
Hardly anyone has heard of it and details seem vague.
My current car has it. It used to be optional before 2015, but then they made it mandatory with the expectation that the law comes in effect.
Not true. Chris Urmson, former head of Google's self-driving car project, before he left Google, made that point at a "connected car" conference. Google's self-driving cars don't rely on car-to-car communications. They rely on sensors. Lots of things a self-driving car needs to know about aren't "connected", and you can't trust the ones that are.
Google's own cars download their logs when they get back to the barn, but that's for debugging purposes. A production vehicle would not need that feature.
On the other hand, the Event Data Recorder in most cars isn't a big deal. It's a crash recorder. After a crash that caused airbag deployment, someone can dig into the wreckage, plug into the box, and look at the last 15 seconds before the crash. Useful for accident analysis, but not Big Brother. OnStar type systems are much more of a concern; they run all the time and have GPS inputs.
Who pays for this? Can you pull out the radio and use it for general purpose internet access?
I have a taste for the secret,
it clearly has to do with not-belonging;
I have an impulse or fear or terror in the
face of a political space, for example,
a public space that makes no room for the secret.
For me, the demand that everything be paraded in
the public square and that there be no internal
forum is a glaring sign of the totalitarianization
of democracy. [. . .] if a right to the secret is
not maintained, we are in a totalitarian space.
(Jacques Derrida, in Roudinesco, Jacques Lacan & Co., II, p. 599.)Things such as improved emergency response (so long as equipment is upgraded), tips on how to improve your own driving (upon request) to make your car last longer, aggrevate data on different things to teach new drivers, and how common behavior x, y, and z are. I have little problem with the auto-ticketing, provided the state tests the system once a year or two to make sure it is functional (and when it is contested). This stuff makes the roads safer.
Though folks could hack into his brakes or disable his vehicle, right now that doesn't happen often to actually fear, and safeguards could be put on the vehicle to keep him safe.
The bigger threats he mentions are private firms and law enforcement.
The biggest factor with law enforcement is to have safeguards to check the honesty and things like that. Make sure the laws are fair and that law enforcement isn't tempted to bend them.
Private companies, such as insurance companies, are slightly different. While I believe this could be changed with legal protections, I believe there is very little hope of such legal protections being made with the current political climate. I don't think the information is bad per se, as we could learn quite a bit about normal driving habits, but the companies could decide to lobby for things like better enforcement of traffic violations, lower legal BAC levels, and other such things to gain the same sort of safety.
Now your car is broadcasting its location at all times via cell signal, and that data may be (almost certainly is) being recorded.
That, and you can always drive without a cellphone if you so desire.
Not to mention the same holds true for rural areas of other countries as well, as the bus system might not come often enough to work, let alone buy groceries. Or you might have to deal with weather which makes bike riding (let alone walking) inconceivable.
Since humans are terrible at assessing risks that have probabilistic or delayed effects, most people - including some engineers that should know better - don't understand or underestimate how powerful patter-of-life analysis can be when it can utilize entire lifetimes of timestamped location data.
The point is you shouldn't assume everyone has a cellphone in their pocket. Therefor a car that broadcasts its location would compromise an existing expectation of privacy.
The rapidly growing use of ALPR devices is causing a similar compromise of privacy, but that's a separate problem.
Just because something is the new normal, doesn't mean it is "right".
If it spread to security cameras ... consequences could be a grave new world where a young Dennis Leary is caught in his very first act of subversion.
I like to consider myself a good driver, I'm mostly concerned about black-and-white application, where we had officer discretion in the past. (Discretion is hard to teach computers)
The traffic light I "ran" yesterday springs to mind. Second in line at stoplight (behind a cop no less). Light turns green, we roll into intersection. Light changes to yellow, then red, before either of us exit the intersection. An officer would not ticket me, but a computer that was not meticulously programmed probably would.
But I'm much more interested in the egregious stuff in the rest of the world that goes largely unpoliced and kills millions a year - the Costa Rica version of your story is intersections routinely blocked by busses that are eager to cross when there's no space and an orange light!
VW is shady.