Totaled Teslas contain unencrypted and personally revealing data about owners
cnbc.com
cnbc.com
Comically, on the car itself, the previous navigation searches were not cleared and included a nearby strip club that my wife found before I did.
On my wife's X (also bought from tesla.com second-hand), she was sent a whole bunch of financial information about the previous owner, both through text messages and on the online portal.
They really don't do an especially good job of securing customer information.
We rented a car last week that had 11 paired Bluetooth devices and like 1400 entries in the phone book. I was kind of jealous because my Leaf only allows 3 devices. I wiped it all out before returning the car.
Sure, but considering that most users don't even know how to pair a device without step-by-step instructions, I find it highly unlikely that they'll understand the implications of the car reading and storing personal information provided by their phone much less how to delete it.
And given that this is Tesla we're talking about, whose products directly encourage you to have your phone paired (more than any other car of its type), even more people would be affected than they would be from, say, a Leaf (where you don't have to do that, and where it's unlikely to be as easy as it is on a Tesla).
They do? The cars all come with wireless data, streaming, maps, and internet. In the Model 3, using your phone as a Key is done via BLE and doesn't involve pairing which is a sperate function.
I would say they're indifferent to your phone but let you use it if you choose.
If the secondhand purchase was a general person-to-person sale, sure.
If buying secondhand from a dealer, or the manufacturer, I'd be expecting some sort of refurbishment. At the minimum a proper detailed cleaned, full service, and software factory reset plus latest software upgrades at the relevant price-point.
If it is a true certified, the checklist (standarized by the manufacturer) will have to be signed off by a factory-certified technician, so there is a paper-trail.
If there is a law covering it, I'd be interested to know it.
I believe a court would find it was the owner's responsibility to wipe it, not Tesla's. Tesla didn't put it there.
Sounds like you theory crafting rather than an actual law.
If so, does it clear out data on car only or does it clear me out of Tesla's cloud as well?
In that case it really isn't obvious that the dealer is the one who should be responsible for wiping the car's memory.
Names and addresses are generally not even considered 'private' information here; its only that the situation for apartment dwellers are inconsistent so no one bothers with record keeping there.
Here is the relevant passage from Tesla’s owner’s manual;
“Our collection of Tesla vehicle data. If you no longer wish us to collect Telematics Log Data or any other data from your Tesla vehicle, please contact us as indicated in the "How to Contact Us" section below. Please note that, if you opt out from the collection of Telematics Log Data or any other data from your Tesla vehicle, we will not be able to notify you of issues applicable to your vehicle in real time, and this may result in your vehicle suffering from reduced functionality, serious damage, or inoperability, and it may also disable many features of your vehicle including periodic software and firmware updates, remote services, and interactivity with mobile applications and in-car features such as location search, Internet radio, voice commands, and web browser functionality.”
Also worth nothing that agreeing to the telematics / monitoring is part of the purchase agreement.
1. The language is not far from "this car might kill you if you don't let us collect data."
2. I can't see a technical reason that opting out of telemetry means opting out of software updates --- it just seems like a cynical disincentive.
(I was already very critical of Tesla for Stallman-esque reasons, but this particularly stands out.)
I actually really like that they offer the option to run the car totally dark. Of course you don’t get your GPS maps, or streaming radio, or software updates in that case.
I would assume software updates could still be installed by a service tech using a direct connection if the remote uplink is severed. Obviously automatic updates are a non-starter for a system which you are not connected to.
Keep in mind this opt-out is separate from the auto-pilot opt-in which lets your share short video clips and associated sensor data with Tesla to help them improve their lane tracking and feature detection algorithms.
As a sidenote, I guess it's just a sad reality that 'automatic updates' are phrased as necessary for safety on a car... this implies Tesla originally shipped a broken / dangerous system (or at least a high enough chance of that to include this language).
For example Model 3 got an update which reduced its stopping distance under heavy braking. If you don’t get this update in real-time and instead don’t see it until your next service interval, that’s a time period where your car was actually less safe than other Model 3s in the road.
Other than tire rotation, the maintenance schedule for the Model 3 is check brake fluid every 2 years and replace as needed, and once every 4 years or 50K miles to change the battery coolant.
You could easily go 4 years without bringing the car in to Tesla for service.
There's been ample discussion about their "autopilot" whose behaviour changed significantly enough between updates, and in a bad way, that owners noticed.
"Nice car you have here Would be a shame if something happens to it"
But that won‘t apply to anyone buying used.
When you sell a device, any kind of device (car but also computer, hard drive, TV, ... event flat!), you reset it or remove all your stuff. That's your responsibility.
But when the car (or device) is not going out of your hands while you manage it, it's a totally different question and not a simple one.
Of course on computers/phones/hard drives we have encryption now, maybe it's time for cars to have that too? linked to the finger of the driver? maybe time for something like Touch/FaceID?
Otherwise it'll be fun to wander in a scrapyard in the next few years with a computer and see what you can gather... won't be for spare-parts anymore :-/
Not that wipe always wipes. In my second hand BMW i3, I wiped it to delete the last owners contacts. The wipe missed one thing : the map locations it was charged at. Likely that included their home.
Ideally there's a standardized wipe feature that really does it.
"video, location and navigational data showing exactly what happened leading up to a crash"
My Honda has a continuously operating camera, I would be shocked if it didn’t record a few seconds of video.
So also not unique to Tesla.
Ultimately it doesn't strike me as unreasonable for the user to need to wipe their info from their car when they sell/scrap it, just as they need to remove their physical belongings from the interior. (Although I'm sure things could be designed better to make the wipe process easier to accomplish and harder to forget.)
It’s an interesting thought to get a junk car a rich person owned for cheap and then trace the location data back to their house and other places they frequently visit. It could be useful for espionage, extortion, theft, etc.
It would be nice to have a way to physically remove the data from the car if remote connectivity is down. Some kind of FRU part in the trunk where all the user specific data for the car lives.
Get in a crash and just make sure to take the "hard drive" out of the car and then you dont have to worry.
But they can also store the content on the phone, and then we have gone full circle with the idea. :)
But no, gotta charge hundreds for in-car map updates (that only get updated as often as you purchase them) and radio/traffic subscription that mobile apps charge a fraction of and always up-to-date for as long as you keep the apps updated.
Bluetooth is just so encumbered with legacy concepts and limitations. It hosts a myriad of protocols that don't benefit users but are easy to implement to check the Bluetooth feature checkbox. There's a full generation of Bluetooth equipped cars that only support headset or handsfree protocols but not A2DP or other useful protocols people want.
This happens with any rental car or and car transaction.
Also, end of the day, this data isn’t particularly sensitive. Your state DMV provides your registration and license data in real-time to third party data brokers. Cellular carriers sell geo data. Its pretty common for folks to have contact lists slurped up by third parties.
When I take my car in for service, they get the address of a gas station down the street.
TTT the article is pretty convincing to me and its conclusion doesn't surprise me. But I thought rather than be immediately downvoted for criticizing T I could pose a more open-ended statement and see if anyone had a counterexample. Doesn't look like there is one.
For that matter, what is the situation with other newer cars, electrical or of the exploding chemicals persuasion?
You can disable the mobile data and disconnect it from wifi.
If you want the updates you MUST be connected somehow.
You can get a copy of the videos via USB.
[And may I say: This is the strangest thingI have ever had downvoted. A simple question. At times I simply do not grasp the HN dynamics].
This is deeply personal to me. I would die if the next owner finds out I like Roxette, drive to places and take two attempts to parallel park.
What 2019 car should I buy to avoid this?