What is your phone telling your rental car?
consumer.ftc.gov
consumer.ftc.gov
I made fully resetting all electronic systems in the car as much as possible (which sometimes ends up being not at all) a ritual before returning cars.
Some cars offer a master reset (such as Ford with their SYNC system), some don't (such as BMW's iDrive). Some cars can have their multimedia systems reset but retain some information about the paired phones and some history as fragments on their SD card (such as the Nissan Maxima, where the multimedia system also malfunctions by forgetting all settings between power cycles if no SD card is present, make sure you check before you pick one up).
But in 95% of cases people don't give a damn and I would get a car that has all the previous customers' data in it. Phone logs, Navigation history, sometimes even contacts and text messages. I think it's scary.
I've seen TVs with a "kiosk mode" option that do things like disable channel switching.
My most recent rental car (a Dodge Caravan) had a USB port on the center console that mounted the phone as a USB drive for media playback.
However, the problem still remains for their loan fleet. I often get vehicles with a few different phones synced and several months worth of navigation history. I clear it all out when I get the car, but they should institute a policy to wipe out any saved data when getting a loaner back.
Maybe there's a way to disable that?
Hopefully these vehicles will auto-limit speeds based on the area's speed limit. These chucklefucks that think they deserve to blast by me at 95 on a 65 area wouldn't cause so many accidents. (tons of blind curves == speed limit for a reason!)
Edit: Which of course is not hardware level per se, but something similar should be possible to implement on iOS for anything it connects to. Trust this? Enable data.
I detest that MTP is the 'best' protocol offered for sharing the filesystem. I find it incredibly buggy and limited. (I would like to be able to use some of that filesystem for carrying around large files!)
It says Powercore 20100 but the form factor that comes up on amazon matches the one linked. Looks like they refreshed and increased capacity.
I need to find one that works with 12VDC for my Thinkpad.
I bring a couple on any trip where I think I might have to use USB to charge a device, since I don't trust strange USB ports.
This also begs the question of how secure these "infotainment" systems are in the first place. Physical access to individual cars' data histories is relatively limited, but if these connected machines are remotely accessible then the resulting attack surface might be scary.
[1] https://www.ftc.gov/tips-advice/business-center/guidance/cop...
Cars are already beginning to be connected to the internet. Just wait a few years; they'll fall victim to the IoT epidemic soon enough.
They've made the network side of the attack a lot harder than it used to be, the vehicles are no longer visible to anyone with a Sprint cell phone.
I went through that list and un-paired every phone, and cleared out the contacts list in the entertainment center. I also informed my dealer of the issue, and I hope they are a bit more mindful of it going forward. Cars are basically designed to only ever be used by one or two people at a time, so this isn't a huge risk for most owners, but for rentals it's kind of a privacy risk.
Fortunately, Android asks if you want to sync contacts, to which I always reply "No". It seems like that should be the default with an option to enable specific cars.
But on the other hand, for corporate espionage...if I know a certain company's employees rent cars from a certain location...I'd be poking around.
Every company's business is collecting data on their customers. It's very widespread.
> Any word that gets out that they even use that data without your permission is going to be very bad press
I disagree. Word on such behavior gets out all the time and few people care.
We need more dumb inductive charging. And no, the charger does not need a data connection.
$6/each (when you buy a pair) and they do rapid charging with absolutely no data connection. There are many other branded ones that are over-priced so avoid those and try these. If you don't want the Micro USB tips you can buy the standard USB adaptor to place inline between the outlet and your existing data cable.
That is, "power only" cables are not recognizable to the user, and malicious chargers came into being for that reason.
It's a minor annoyance not being able to sync up your own music or handle calls through the system but it's much safer. Charge off your computer or a cigarette adapter. They're always safe... as far as I know.
Safe cables represents a much smaller attack surface than "plug into random ports" which sounds like an improvement to me.
http://www.monoprice.com/product?p_id=13166
(This makes a data USB port appear to the phone as if it's connected to a wall charger.)
Or with the user who unthinkingly allows their phone to share contacts without considering the possible ramifications.
Most users are accustomed to just saying "yes", like when an app asks them for permissions, etc.
My guess is that it's not done because receivers were never supposed to handle missing data for something that shows up in device capabilities.
Businesses need to get more savvy in this area.
[0]: http://www.ebay.com/itm/Wireless-Bluetooth-V4-1-3-5mm-AUX-Au...
There's no longer any reason to tether the phone back to your Mac for backups or updates, so why is the phone so eager to share data? All of that can be accomplished with iCloud authentication.
I'm honestly surprised that leasing agencies have not implemented some sort of a wipe procedure even if it's not a forensically secure wipe when a car is returned.
That said I once picked up a car at the airport that had someone's passport tucked into the overhead sun protector shade thingie.
For instance, if a drivers' license didn't have a unique number, then stores couldn't be tempted to demand said number when processing a return.
It's akin to the difference between naive full disk encryption, and a true steganographic filesystem.
Currently, SSN reveal detailed personal history when used by someone who knows how to read the encoding, which is public information.
Beyond that, use of SSN for non-official use is illegal, but the government doesn't do enforcement.
Is it really the government doing this? It seems to me that it's businesses, not the government, that insist on using SSNs as consumer identifiers. While this drives me crazy, I'm not sure that it's reasonable to pin it on the government (which, essentially by definition, is the party that is intended to use them as identifiers).
EDIT: What delinka (https://news.ycombinator.com/item?id=12425976) said.
And the private businesses security help, such as Google's, only talks about government and not business attackers.
Maybe I'm just weird. Never had any reason to connect my phone to the car, not rental nor my own. I make phonecalls from my... well, phone, not the car. I use my phone's Google Maps if I need to refresh my memory to get driving instructions. I don't have music on my phone either. It seems that being a bit ignorant to new technology does pay off at times.