What kind of data is my new car collecting?
theglobeandmail.com
theglobeandmail.com
I'm curious what this will do to the used car market in 10-15 years. Say the original owner consented to all this data tracking. They go to sell the car to buy a new one, and the 2nd owner does not agree to the tracking. Is there a vendor-provided way to shut this off? Or is the vehicle always stuck in a "data collecting mode" regardless of who it is sold to?
Furthermore, if a customer changes the car to stop data upload, that could be seen as tampering with a vehicle. This could lead to legal consequences, but I'm not a lawyer so I can't dwell on the specifics.
That said, I believe that there is very limited legal recourse for a vehicle OEM who wants to prevent an end user from changing the data collection and upload features of their vehicles. The worst thing would be potentially voiding the warranty, but for 10-15 year old used vehicles, that's not an issue.
I work as an in-house counsel at a vehicle OEM (likely not one you've heard of). Our end customers are generally large companies, so it may be different for personal passenger vehicles, but we actively plan for the contingencies where our end users switch out their telematics module, or request to have the telematics data stream be directed to another service provider. Further, in our market, the idea that the customer wouldn't want telematics at all is not really likely, but we also plan for that possibility.
So, I don't believe the used market isn't as big of a deal as you may think. The real concern for personal vehicles is losing essential warranty or service options for new vehicles by turning off the data collection.
Which is super scary. A couple years ago one of their firmware engineers had his NDA expire, and he posted some stories about his time there in some forum.
One of the stories that stuck with me is they were really sloppy with their updates. One time the pushed one that wasn't fully cooked (it might have bricked some, I can't remember), so one of the engineers literally wrote a script to SSH into each of the cars to roll back part of the update.
Update: here's the original source: https://twitter.com/atomicthumbs/status/1032939617404645376
https://www.wired.com/2016/08/jeep-hackers-return-high-speed...
Since the author remains anon, I always thought it was just a troll.
Full quote:
> model s and x use openvpn to talk to their backend. inside that backend there are metadata services that feed info to the system, one of those things being a ~20MB+ (generated by the worst erp system) json payload that describes supercharger shit for the map in the touchscreen. somebody was smart enough to do automated linting but forgot to validate against the custom parser the car runs which caused a segfault in the qt app that runs the ui, which in turn for a variety of reasons forces a reboot of that component. I think we clocked about 15 seconds before it read the file and faulted after boot. it was doing that for an hour before everyone panicked and got me and qa on the phone to fix it. i wrote a quick python/fabric script that ssh’d to as many cars as possible at a time to rm the file
- "On that note, China has a law in place that mandates all electric cars send real time telemetry to their government servers - Model S/X/3, NIO cars and any other electric car if they're driving already complies with that law to be road certified"
- "Don't be surprised if that becomes a mandate in other countries"
They regularly lambast HN via this thread. It would be great if more people read their criticisms of the community here.
https://forums.somethingawful.com/showthread.php?threadid=39...
However, I believe consumers also have a way to laugh Tesla out of the room, eventually: public policy ideas like the first sale doctrine, or just straight up passing new laws saying that when you buy a car, the manufacturer must provide basic certain basic services (such as allowing the vehicle to run, and warranty for basic components) even if the purchaser elects to deactivate some of the data collection.
In the past few decades, we have really allowed power to accrue to large corporations, but I think that things like the right-to-repair movement show that the pendulum may swing the other direction, at least in some contexts. Regardless of overall political or economic ideology, as soon as a large portion of the population realizes that these OEMs are basically saying "yes, pay me a good chunk of your annual salary, and I'll let you use this vehicle as long as you don't piss me off," I think things will swing very quickly in favor of consumers. The reason it hasn't yet is because most people don't have to deal with vehicles with these restrictions.
I'm sure its not going to be long before you don't _own_ your car, you just purchased a license to use it for a period of time.
Have they updated the software such that this isn't possible?
>I work as an in-house counsel at a vehicle OEM
If you're really a lawyer, I'm surprised you'd write any of this, because it's blatantly false. The Magnusson-Moss Warranty Act of 1975 makes it blatantly illegal to "void" a warranty for any modification, unless it can be proven that the modification caused the issue that the customer is making a warranty claim for.
But in any case, your post does strengthens my main point, which is that fear over surveillance of vehicles by OEMs, with no consumer recourse, is somewhat overblown.
EDIT:
Just read Magnusson-Moss, and I have a question since you seem to know about it - you said the act "makes it blatantly illegal to 'void' a warranty for any modification, unless it can be proven that the modification caused the issue that the customer is making a warranty claim for."
But the act itself says "the warrantor shall not impose any duty other than notification upon any consumer as a condition of securing remedy [...] unless the warrantor has demonstrated [...] that such a duty is reasonable." 15 U.S.C. § 2304(b)(1).
Based on what's actually in the text of the law, I could imagine Tesla or some other OE making the argument that it is "reasonable" to condition the warranty on the consumer continuing to feed the stream of telematics data to the OE, because it allows them to identify warranty issues before they require substantial repairs, thus potentially saving significant money for the OE, and significant time for the consumer - certainly a reasonable thing. I personally don't agree with that argument, but I'm curious how you would respond to it, and how you can be sure that a court would shoot it down.
As for your example, that sounds pretty contrived and ridiculous to me. Doesn't mean someone might not try it though; companies have tried lots of ridiculous legal tactics before, such as Oracle's current API lawsuit. But I imagine any decent court would shoot it down pretty quickly. Warranty claims are made because parts fail before the warranty expires; the absence of telematics isn't going to magically make some mechanical part fail faster. It might help identify it sooner, sure, but it's still a defective part for failing that quickly, so I don't see how the consumer disabling telematics absolves the manufacturer from covering this. In short, it's never been "reasonable" before this for car companies to have telematics to keep their machines working properly through the warranty period, so why is it suddenly required now? It's not reasonable for anything else either; does a new house need telematics for the house warranty to be valid? How about a blender or toaster in the kitchen? I don't see this argument going far at all.
I have never run into a situation where my current company tried to limit its warranty in legally interesting ways (and it wouldn't necessarily get to my desk anyway), so I never really had call to dig and find Magnusson-Moss. I suspect that knowledge of that law is probably more top-of-mind for DIYers than for OEM lawyers.
I still think that whether requiring telematics is a "reasonable" condition for a warranty is more complicated than you think, but what you're saying is exactly the counterargument I would make.
And, I hope I've provided some assurance that I am, in fact, a lawyer. Whether I'm a good one is perhaps up for debate. :)
E.g., Tesla already seems to try and decide the questions in the way manufacturers would likely have them, i.e. suppressing data transmission is tampering and the problem of car reselling doesn't apply as cars cannot be resold anymore without manufacturer involvement.
I think it's up to consumers to offer a different perspective here.
I suspect this will become a huge societal problem if it continues like this in a car-dependent country like the US. Yes, the middle-class people will probably still be able to purchase $30,000-40,000 cars for the foreseeable future (even adjusted for inflation), but what will happen to the people who won't be able to purchase a second-hand car that costs more than $5000-6000 (or even $1000-2000)? How will they continue to get to work in a country that values public transport so lowly?
a) Certified pre-owned and similar programs making some used cars more appealing (and thus more valuable), removing them from the supply of unvetted, cheap used cars.
b) More folks being able to afford used cars around the world. It seems like at the lower end of the market, many American used cars are shipped to Latin America or the Caribbean (in Europe many older cars are sent to Africa), again reducing the supply of used cars.
This is my sketchy recollection of things I've heard and read, I don't have any direct sources to link you to, but I've certainly heard multiple people bemoan that say, $5-10k doesn't buy you nearly as good a car as it used to (even adjusting for inflation).
EDIT: As an aside, the issue of shipping cars to different regions could also prove interesting for owners down the road. There are already some issues there - I believe my car's navigation system is for North America, or maybe US+Canada. So if my car gets shipped to Argentina in 10 years, the Nav will be useless or will need an update. Not a huge deal. But if Tesla's Autopilot is tuned for conditions and laws in a certain region, it would presumably require reprogramming for another region. Would that be an automatic over-the-air update? Or would Tesla not want to bother with free updates to a 20-year-old car?
The OP talking about a $5,000 car is talking about a 10-20 year old car with 100,000+ miles.
Both cars appeal to a different set of buyers. The CPO car effectively competes against new cars.
It's not uncommon at all today to see a car tick over 200,000+ miles, so buying a car for $5,000 with 100,000 miles on it can be seen as a pretty good deal. Usually people would recommend a good Japanese / Korean car (Toyota, Honda, etc.).
At the same time, emissions controls changed the market in that cars are more governed by use not age. I mostly buy Hondas and know the market a bit, and they are all good for about 200,000 miles without significant maintenance.
I sold a 2003 Honda Pilot with 250k miles for $2,500 last year -- really high considering all of the stuff that will break on a car of that vintage. In the 90's, that pricepoint would be for a much younger car. A place like CarMax will sell a 2010 Pilot with low mileage for $15k, which works because the TCO works out -- you won't have lots of maintenance.
That seemed to be true for a while, but I've seen prices relax quite a bit lately. It's possible this was just local, and I'm not seeing a broader trend.
It's also the case that perfectly good brand new cars can be had for $13-$14k, (Nissan Versa, Ford Fiesta) which I appreciate are not attainable for many people.
That's why you don't see less-wealthy people commuting to their jobs in an early 2000s Mercedes S-Klass or in a VW Phaeton (even though they'd be able to purchase such vehicles at today's prices), but instead they use an older Honda or a Toyota or a slightly newer Nissan.
Sourcing a CANBUS module for a 10+yo car is already a roll of the dice. Take all the modules that are required for the vehicle to operate, are matched to the VIN, can't be re-flashed, aren't available aftermarket and aren't made by the OEM anymore and anything that breaks where those sets intersect turns the vehicle into a brick. The list gets a little longer every day and won't get shorter until we get right to repair legislation with teeth.
You can drive a car without all the fancy electronic doodads. Everyone who drives a 20+yo car does it every day. You can't drive a vehicle that won't start because it doesn't see some quasi-essential (e.g. ABS) module talking on the bus.
I'm starting to doubt this more and more. Dumping the ROM from a read-only chip and flashing a new one isn't rocket science. After watching stuff like http://www.youtube.com/watch?v=yqWhId-tQXs&t=9m31s and guys like Dave Jones and Louis Rossman, it looks like the entire repair industry is long due for disruption. Sure, finding old or obsolete parts will still be a problem, but not impossible.
This seems like a violation of long-standing consumer protection laws and precedents.
Not that I doubt that they believe this, or even that they've said or implied it, but is there any official statement from Tesla to the effect of prohibiting, or even trying to limit, resale without Tesla's involvement?
I wonder if anyone will jump at the market for cars that don't track you. I wonder who would fund that.
In the Tesla Model 3 and Nissan Leaf there are menu settings to disable it. Additionally in the Leaf it prompts you at interval (every 2000 miles?) to notify you about it.
Or every g-ddamned time you start the car, depending if you have a first-gen or not. The GPRS radio in ours is unhooked, so now the button press is just ceremony so you can see the screen.
But do note the part where the cell radio is unhooked. Whatever the car, there’s a module in there somewhere that probably just needs to be unplugged.
My in-laws have a Ford Escape that does that.
Where are you getting this crazy idea? If it's your car, you can tamper with it all you want, as long as you don't violate emissions laws and stuff like that. There's no law preventing you from tampering with your car's data collection or transmission, or most other things for that matter. How do you think the entire aftermarket parts industry exists?
However it will likely require legislation to ensure there's no DRM bullshit in the battery packs.
https://www.evwest.com/catalog/product_info.php?cPath=4&prod...
Used Tesla battery, 5kWh for $1500. you're looking at ~10 of these for decent range.
(What happens when an EU national drives one of the American surveillancemobiles? Sounds like a straightforward GDPR violation to me, although good luck getting that resolved)
A potential privacy issue yes, but much less so than the data collection.
I imagine it'll be like any useful service, once you turn off the data collection, it suddenly loses a bunch of useful features
In Europe there needs to be due to GDPR. It will be interesting to see how this works out as this has not been challenged as far as I know.
Depends on LEO. If it is easier to deal with trackable cars, then untrackable cars will be hotter than black tinted windows and radar detectors.
It already is, to some extent; why can I not gut my catalytic converter & change some programming so my car says the outputs are fine? Because the state wants me to get rid of my old functional car to support the economy of newer more expensive vehicles.
...also probably to protect the environment?
Yes, retrofitting would be better, but if that's not possible, what else would you do to get converters into cars?
Also, I think GP was talking about removing a converter from a car that already had one. Literally not doing anything would be better for the environment than that.
modifies car to literally emit noxious emissions everywhere
I miss that bike sometimes.
Edit: https://en.wikipedia.org/wiki/Jaguar_Mark_2#Portrayal_in_med...
I have converted modern cars to points and carbs, its not that difficult. No reason you couldnt drive any car with some motorcycle carburetturs clamped to the intake runners. Hardest part is spinning the rotor and remembering how to set your points. Never drive-by-wire cars will need a throttle cable, and a manual transmission is the only electronics-free option. I have heard a simple mechanical relay logic system can control many autos, but have never tried.
The ignition coil will probably not survive an EMP event, so the bike will not run.
However, it should be pretty straight forward to wind a new ignition coil if you ever find yourself in a post-nuclear situation.
A distributor is only there to distribute the spark to the cylinders. On modern engines the distributor has been replaced by individual coils (on per cylinder).
And while the ignition cam may or may not be near the alternator or generator, it has nothing to do with it functionally.
Also, I forgot that some old Harleys have the points in a housing sticking up above the crankcase. It's debatable if this should be called a distributor though, since the spark plug wires don't go anywhere near it.
This setup is even used on modern-ish vehicles, where two transistors drive two coils to run four cylinders.
Unless your car is very old, chances are that you have a more reliable reluctor-based ignition, where instead of points you have a magnetic pickup that's triggered by a toothed wheel on the distributor shaft. That pickup drives an ignitor (which may also be inside the distributor, or it might be a separate module) which generates the high current input to the ignition coil primary.
You can twist the distributor to change your base timing, plus you have the vacuum mechanism that moves the points or magnetic pickup to adjust timing according to manifold vacuum, and it probably also has sprung weights that swing out as rpm increases, which moves the cam or reluctor wheel to advance timing.
The actual distribution part of the distributor consists of the rotor and terminals on the cap. That's what routes high voltage from the coil out to each spark plug.
On an old motorcycle, you just have the points (one set for each coil for each pair of cylinders as described above) without the distributor cap and rotor part. You can move the points around the cam to adjust base timing, and you might have springs and weights to advance timing as rpm increases. I don't think vacuum advance was nearly as common on bikes as it was on cars.
The purpose of a distributor on a car was to distribute the output of one coil to several spark plugs. When you have a separate coil output for each plug, there's no need to distribute anything.
It's one of the last types of Mercedes which were meant to go through WWIII and back.
The trucks were equipped with some type of an emergency throw should that situation ever arise. We never had to use it in my time there.
Since at least the ~2000 era, a VW diesel will run with no alternator (for a while) but not without a battery.
[1] https://en.wikipedia.org/wiki/Mercedes-Benz_OM616_engine
Different kind of bike, but I used to feel that way about my bicycles. However, sometime last year I was parking at the office and realised even that world is on its way out.
The No-True-Scotsman actual cyclists have largely moved to electronic shifting and such, and the utility bikes are quickly moving to e-bikes.
Not true at all.
Electronic shifting is a thing, yes: google for "Shimano Di2". However, road bikes with this are usually at least $4k: it's really something reserved for very high-end road bikes. I got a $3k road bike last year and it doesn't have it, nor does anything else in the low-to-mid range. It'll likely be a while before it comes to low-end road bikes (which are generally still "high end" compared to cheap Walmart bikes)
>and the utility bikes are quickly moving to e-bikes.
Again, not really. There's at least an order of magnitude difference in pricing between a regular utility bike and an e-bike. I've been to cities recently where many, many people commute by bike, and only a very small percentage are e-bikes, though they are getting more popular, but still they're a LOT more money than a regular cheap bike.
The car salesmen have no idea about whether the cars they're selling have modems or not, so I found you have to ask about them indirectly in terms of features. I has success with this line of questioning: 1) Does this car have connected car features? 2) If it does, and I decide to get them later, can you enable them from your computer without me having to bring my car in? If the answer is yes to both questions, the car has a modem.
Unfortunately, my wife wanted a car that failed that test. However, my research had indicated that those features seem to be implemented by a module that's separate from the entertainment system. Hopefully I can physically disconnect it without the car nagging about it being missing, but that's a project for another day.
Don't count on it. Physically locating it and disconnecting it might be very difficult. Worse, since the module in networked via CAN, you literally have no idea how the rest of your car will react. It could switch to limp mode, for example.
I already know where it is: it's in a box underneath the entertainment system ("head unit"), and there are a lot of instructions about accessing it.
I also have two options for disconnecting it:
1) total disconnection
2) leave it connected, but cripple its function by removing the antenna connections
I'm thinking that if #1 results in an error #2 would be less likely to.
The EU's eCall would like to have a word:
Also depending on what's in the car, they may know who was driving it.
How long before a speed safety campaign starts arguing that car manufacturers should be handing over information about people breaking the law in their cars to law enforcement...
An obvious example would be in Germany. The autobahn for example has sections that are unrestricted, but those same sections are 130kmh (or sometimes lower) if it's between certain times or raining or whatever.
Half of the time my car interprets that as just being 130.
Outside of that; there are countless instances of my car thinking I'm in an 80kmh zone when it's actually 100, 120, whatever. I can override that because I know what the actual speed limit is. Would the car be constantly reporting back that I'm doing a bad?
Ultimately I reckon perfect enforcement of this would just stop me bothering. I'll get someone else to drive me around like an Uber and they can take the endless tickets instead.
Where there are dynamic speed limits in place, it would be plausible to report back possibles (car location and speed) which could then be checked against a central database which was more accurate.
I'm not suggesting that such a system is a good idea, but that I can see car safety campaigners looking on it as the next step in their campaigns...
If the law were strictly applied the cumulative offences would result in virtually all drivers of “smart” cars being instantly banned from driving
You would like to think saner speed limits could be agreed as car brakes and safety have rather improved since the 70mph limit was imposed...
Which I suppose could theoretically be done far more easily.
If the GPS coordinates are within the ring road of the city and no limit higher than your current speed exists there then you're a baddie and we should bust through your ceiling.
Personally, if we're going to use car telemetry I'd be far more in favour of having the system decide whether someone is actually driving dangerously rather than deciding that 55mph on the North Circular at 2am is worth hitting someone's license up over.
The really stupid thing about this is that driving 80+ and the occasional hard braking is just normal traffic condition on some roads at some hours. Penalizing people for needing to use those roads at those times and acting like every other normal human around them when doing so defeats the point of insurance.
You won't be allowed to break the law. The petrol heads will complain but they will lose because "think of the children".
Little did I realise that was a direct admission I'd been speeding on my way back to the studio!
- ed
(It wasn't even bad speeding (mostly) - I'm in London after all - it kicked in every time I went a mile an hour over whatever limit I was subject to. Very [very] annoying)
The problem is, if more and more people switching to those insurances it becomes very expansive for people who mind their privacy.
I would be completely unsurprised if they've run the numbers and determined that penalizing entire zip codes is far more lucrative.
Cars are required to have certain telemetry capabilities starting in 2020 or 2021 as well. We’ll have automatic inspections and taxation by the end of the decade.
Law enforcement already has fairly pervasive networks of fixed and mobile LPR. You cannot leave most cities without a record of it, and if you attract federal attention, passage through many interstate corridors is captured with LPR and photos of occupants.
Whatever happens, insurers will make it more and more expensive for a human to drive a car once it becomes clear that it's safer for a computer to do the driving.
This is true for all current map providers.
Probably sometime after we have speed limits reasonable enough that the overwhelming majority people do not routinely exceed them and/or the politicians who write the laws stop driving.
There are currently no serious financial downsides to scraping, hoarding, selling, or leaking customer data. There is huge financial upside to doing or risking all of those things.
Companies' data policies may be user-hostile, but they're economically rational.
Data becomes "worthless" when the average joe's phone number is worth $0.003 to marketers, but there's a $500 fine for leaking it, allowing access from an internal team for purposes not specified in a granular opt-in form, or for being found to possess it after its deletion was requested. Routine third party audits are mandatory if you want to interact with other serious players in your industry.
For all the ways that banking and healthcare are hellish, they've at least got the semblance of teeth on stuff like this.
We'll know it's working right when companies spend the same effort to avoid hosting your data that they spend on collecting it today.
No. Just no. Why would anyone allow collecting this kind of information? There is no way it can't (so, won't) be used against you. Everyone gets angry from time to time.
It's also 32 years old, gets 14-15mpg, and drives like a truck. It's a 1988 Chevy Suburban. I bought it a few years ago, for $1450 and really haven't put much into it overall. It runs reasonable well (still some things to figure out) and is comfortable. If I had some money I'd fix some of the things wrong with it and update the interior with seats out of a newer model, but overall, it just works.
And that's what I see going UP in value over time. To think I could own a car that could tell some corporate partner where I went for lunch is just unfathomable. I can't afford to own a car that "cool" and I'm glad for it.
1. Why is this one or the other? Can't we have efficient cars that also don't track us?
2. How, in 2020, do people still not understand how serious location data is? In the USA, and likely anywhere that has cars + little public transportation (like rural areas), your car basically displays your life. Where you live, work, eat, meet people, attend events, etc. How long until law enforcement asks for all people who drove near a protest/rally? Or advertisers get that data and start targeting you based on where you drove? Why should a freaking car company (who is 100% guaranteed going to sell your data) have access to your entire location profile? The thought of this alone is frustrating and maddening because of how easily we hand out our data. People have no idea how powerful bulk collection of user data is.
For all the complexity of a modern Suburban (at over $50K USD!) it gets 14 MPG around town and up to 23 MPG on the highway. Mine gets about 14/17. Since most of my driving is local, it doesn't really matter.
Do you work in the industry or have you simply been conditioned to parrot the notion that anyone concerned with being spied upon is crazy?
* Pothole tracking --> sell to local goverments
* Tyre wear --> sell customer data to target adverts for them / promotions
* Hybrid battery charge levels --> sell data to EV charge point companies.
What was even more concerning was that this data is being collected by another company (who supplied the hardware), who had first dibs on the data.
Will the data collected about you and your behavior be used in ways that never go against your best interests?
Can individual software developers and teams working for these corporations do much about this if they disagree with it?
The answer to these and many other related questions is probably not.
Little by little, we human beings are gradually building a panopticon monitored by machines under the control of corporate organisms whose behavior is beyond the control of most human beings. As an example, think about about all the people at Google who have tried, mostly without success, to prevent it from acting like every other impersonal corporation. There's nothing preventing it.
Assuming good faith here, this is one of the best privacy statements I've read.
Same idea though: drive it until it dies and then pray that uber/lyft/whatever is mature enough that I never have to think about it again.
The idea that they'd have some kind of generic login for this would be hilariously insane and definitely make headlines.
But the idea of eg samsung brokering a deal with comcast to get conditional access to comcast modems to upload telemetry data in exchange for a modest access fee?
You could even market this feature directly to consumers: If you're in a house that rents a modem from comcast, your samsung smart TV "just works", and nobody has to fiddle with the wifi password.
There's no evidence that this happens today, but I'd be surprised if it hadn't been pitched repeatedly, and was currently under construction in some form.
You can also find other brands on Amazon.
https://www.walmart.com/browse/electronics/sceptre-tvs/3944_...
Yes that means in ten years or so I will be riding a used shabby old car.
You can get a new car for $15k in the US. "completely rebuilding" a used car of any quality, by any definition, is likely to surpass 15k in labor alone, unless you're doing the work entirely by yourself, at which point it's likely to cost 15k in tools.
https://www.toyota.com/privacyvts/images/doc/privacy-portal....