Mystery GPS Tracker on a Supporter’s Car
eff.org
eff.org
The GPS tracking device had absolutely no connection to the individual being an EFF supporter, and was in fact entirely benign (if unknown to the vehicle owner).
What we need from the EFF: a serious discussion about anti-theft vehicle tracking and privacy (e.g. a list of brands/dealerships installing these devices, how/where to find them, how to disable them, which anti-theft GPS brands don't sell your location data)
What we got: someone at the EFF learns about UART, called a car dealership, and wrote a clickbait title
I believe awareness of technology is crucial for civil society. Sure it's got a clickbaity title, but it worked in getting HN on it.
EDIT: I've had my faith restored. Added reply to a comment below.
This article has a good story arc, and I enjoyed the read, and learnt something to boot.
There's also the fact that the article did not cheat in any way, but reflected one's mindset while discovering such an issue. A bit of trickery, sure, but what's life without plot twists?
BUT: I didn't read the whole article. I read kogepathic's comment first, which gave away the twist and framed the headline as clickbait, and I went along with that. But I now see it's as you say. Lesson learned.
I definitely don't think that writing an intriguing headline and delivering on it with a satisfying story counts as clickbait. Clickbait is something that fails to deliver at all, not something that delivers in a way you didn’t expect.
https://money.cnn.com/2016/05/17/technology/tor-developer-fb...
The EFF is roughly in the same bucket - i.e. some interest from federal agencies due to empowering individuals relative to the state.
The article as-written provides almost no useful information apart from an anecdote about one person finding a GPS tracking device in their car and contacting the EFF.
> Given how many people have been surprised to find this specific GPS tracker in their cars (as mentioned above) it’s possible that many car dealerships are installing these devices without proper customer notification.
One person is mentioned in the article. If the EFF knows how widespread the installation of this tracking device is, why isn't this discussed? How many car dealerships did the EFF contact to find out if they install such devices?
All the useful questions at the bottom of the article are unanswered:
> Is the sky-link GPS device still sending location data back to a Sky Link server? If so, could it be accessed by an employee, or someone who activates the device in the future?
Writing an article about a single individual who was not targeted: FUD
Writing an article about how many cars these devices are installed in, what data they transmit, who the provider(s) sell your location data to: useful for privacy and policy discussions
They did investigate "a single individual who was not targeted"
You can't write an article about something you haven't done.
They explain why they did it in the article.
FUD is fear uncertainty and doubt, they did the exact opposite. Dispelled the FUD with an investigation. And then published it.
Please point out the original FUD the EFF is refuting in this article.
Their title is sensationalist, a more accurate title would be, IMO, "a car dealership installed a third-party GPS tracking device in a vehicle" but anything more is a stretch because they have n=1 here. But you can see my proposed title is certainly less interesting than their portrayal.
> You can't write an article about something you haven't done.
Yes, and my point is that they are the EFF, not hackaday. The article does not inform the reader of how common GPS trackers are in vehicles, or what privacy implications they have, because the EFF just took the lack of a response from the sole vendor they contacted and went ¯\_(ツ)_/¯
I would expect an organization that's supposed to advocate for privacy issues and carries clout to have covered at least some of the privacy concerns in more depth. FFS, they couldn't even establish if the device is still (or ever was) transmitting the car's location.
Geolocating cars is not new or novel, OnStar (GM) has had this capability for ~20 years now. [1] If the EFF wants to raise awareness about the privacy issues of vehicle location technology, they could have easily picked a more common case.
The case they investigated was one that came to them, from one of their own, they explain that.
Research costs time and money. I don't think you should _expect_ that donors money is spent, when after investigating this isolated case, nothing too nefarious was found. As you say, geolocating vehicles is not new or novel.
It's a good write up of the work that was done, and the thought process, engaging and short, and as I mentioned above, you don't always want a spoiler in the title.
Something between two private individuals, which was resolved through the subsequent investigation. No need to write an article about this.
> As we probably all did when clicking the title.
FUD is generally a strategy to influence perception by disseminating negative and dubious or false information and a manifestation of the appeal to fear. [1]
> you don't always want a spoiler in the title.
The GPS tracker is not mysterious (they identified the source and likely purpose), and the individual's support for the EFF did not contribute to the presence of the GPS tracker in their car.
Could you clarify how the title accurately reflects the situation in light of this?
> Research costs time and money.
Indeed, and FUD is free.
[1] https://en.wikipedia.org/wiki/Fear,_uncertainty,_and_doubt
To clarify your underlying principles here:
Are you broadly suggesting there should be rules for what type of articles can be written on the internet (presumably that align with your values)?
Are you suggesting that EFF should not have written this article (because of the $/time cost?)? And that it's okay if someone else wrote the article?
Are you suggesting that EFF should not have done the investigation in the first place, because of the $/time cost?
As an EFF supporter myself, I enjoyed the article. I liked the walkthrough of the investigation, and all the steps they used to deduce the source of the tracker. It was interesting on its face, and also educates on a methodology for making deductions for other things.
Yes, the EFF should not be promoting FUD.
As I have stated several times in my comments, if the EFF had chosen a less sensationalist title, there would be no grounds to label this as FUD.
> And that it's okay if someone else wrote the article?
Yes, if someone had written such an article for their personal blog, or as a private individual on a site like hackaday, then it wouldn't have the endorsement of the EFF.
> Are you suggesting that EFF should not have done the investigation in the first place
No, however their choice to pulicize an otherwise unnoteworthy event was in my opinion, an extremely poor choice.
> As an EFF supporter myself, I enjoyed the article. I liked the walkthrough of the investigation, and all the steps they used to deduce the source of the tracker. It was interesting on its face, and also educates on a methodology for making deductions for other things.
That's fine, and I'm not here saying "the EFF should not be doing this" I feel I've been very consistent in saying:
* the title is sensationalist and this is bad for the EFF's credibility
* the methods in the article are very amateur, a more detailed investigation and/or a discussion about the privacy and legality of vehicle tracking would have been much more in keeping with the EFF's stated mission
I think it is within their remit to discuss such issues.
I enjoyed reading it, I feel it received quite a harsh critique for a short article that was well written and engaging.
If the goal was to get people thinking about the privacy implications, it worked. Here we are talking about it on HN.
With the suggested title "a car dealership installed a third-party GPS tracking device in a vehicle" I doubt I would have read it. If it hadn't been by the EFF I doubt I would have considered the privacy implications.
I dont even think GDPR data protection laws cover that data grab!
Title should make a reasonable effort to summarise the content and allegation of the article. It's not the case here.
I call that extremely worrying! I’d want to remove any such device from my car immediately.
Full text: https://www.congress.gov/bill/117th-congress/house-bill/3684... Relevant section: https://archive.ph/eMF8Y#toc-idb8cfafb0-6273-428e-a005-03391... HN discussion: https://news.ycombinator.com/item?id=29427068
So, there’s plenty of technician’s manual out there under those former and current M&A names.
Also, FCC ID is a great starting place, just don’t forget merger and acquisition as well in the business world during your RE effort.
Also identifying RF frequency in FCC filings will help narrow the cellular coverage. If it’s CDMA, then it’s obsoleted.
- https://loginping.com/inilex-gps
- https://www.automotive-fleet.com/130525/spireon-acquires-gps...
The dealer even added a $250 fee to "remove" this device, but I found it was still installed, so I think I ended up footing the bill for the device itself.
The device is ostensibly to protect inventory from loss, but it seems like they are incentivizing dealers to leave these in cars to capture location data, for whatever reason.
But Honda already has telematics in these cars in the infotainment system, and it would be trivial to add anti-theft to the existing system. It all just feels a bit.. fishy.
I had one on a car I bought, and it kept draining the car battery whenever I left it more than a few days. I wasted many hours buying new batteries, testing alternators, and tracking down leakage currents before finding it consuming nearly a watt continuously.
This happens even if you drive the car every day. Since a full charge of a lead acid battery is 12+ hours, if you only drive the car half an hour per day, then each day you are discharging more than you charge.
As someone who used to work in that industry, no, it's not sending location data. You don't activate the SIM until you have someone who is going to pay for the service, otherwise you're losing money for no reason.
We'd get that question often though, someone activating a device hoping they'd be able to see everywhere it was for the last month.
If it is then we have a concealed tracking device that can be used against the interests of the car owner at any time. It just happened that EFF didn't have the know-how to extract the logs.
GPS doesn't need a SIM, and indeed the devices will have a fix all the time whether activated or not. They do require cell service to send their updates anywhere. They're all simple GPS receivers, not transmitters, thus require an active SIM.
Edit: To clarify, before then you would have something like a 300 baud modem that didn't have an out-of-band command set, so you would dial the number on your phone and flick a switch on the modem to make it connect and everything would be sent to the other side verbatim. The "+++" is the escape sequence you send to a Hayes modem to break it into command mode, the "AT" is the prefix for the command (attention?), and "H" means "hang up". IIRC, puritans would say "ATH0" because the "0" represents some particular state to hang up to, but it's the same as "ATH".
IN#3 (Apple ][ command to hook input from slot #3)
^A ^F (modem command to set full duplex)
^A ^Q (modem command to pulse dial the following number)
^A ^Z (modem command to hang up)
https://mirrors.apple2.org.za/ftp.apple.asimov.net/documenta...https://en.wikipedia.org/wiki/Hayes_Microcomputer_Products#E...
https://www.computerhistory.org/collections/catalog/10264598...
https://www.ebay.com/itm/393165436881
Later on once the Hayes AT command set took over and BBSs became popular in the 80's, there was a flat $25/month subscription service called "PC Pursuit" that had banks of modems in different cities connected by a network, which you could dial up locally, then connect over the network to another modem, and dial out to a local BBS system. It was a subsidiary of Telenet, which spun off from BBN, and later was a subsidiary of U.S. Sprint.
http://www.bbsdocumentary.com/library/CONCEPTS/SERVICES/PCPU...
https://bbs.fandom.com/wiki/PC_Pursuit
https://blog.tmcnet.com/blog/tom-keating/voip/pc-pursuit---t...
https://en.wikipedia.org/wiki/Telenet#PC_Pursuit
There was a fun game you could play called "PC Roulette", in which you first connected to a remote modem with the PCP command, then issued the command "A/" directly to the modem, to redial the last number somebody else dialed on that modem!
It usually worked. I don’t remember if the baud rate was 300 or 110.
most sensors are connected via I2C to the CPU. some weird ones via SPI. most GPS sensors are different, they connect mostly via UART. so you can connect to them directly, bypassing the CPU.
ftfy
But I2C would do too if they would offer a proper register interface as opposed to always expecting you to parse those verbose NMEA messages.
Oh and only generating an interrupt if the fix is valid would be nice! But they just shoehorned the SPI interface onto it, exposing exactly the same data as they would over UART. So if you have to wake up, parse the message and only then will you find out if you have a valid fix or can go back to sleep and try again.
Afaik they dropped the SPI mode in the newer chips though.
Being able to communicate with arbitrary electronics using the $30 Bus Pirate device seems like a very fair price.
The Pirate is awesome, and was rather magical when it first appeared (I bought mine in 2010), but nowadays I would just use a USB/UART adapter [1]. They're cheap as ... something cheap on Amazon, and simpler since they're special-purpose.
[1]: https://www.amazon.com/s?k=usb+uart&crid=1JQRTOTBVDDCW&spref...
And it makes sense from an engineering standpoint. Equipment for interfacing to a serial port, even in 2022, is widely available (you can get a basic TTL-level dongle for the price of a coffee) and pretty much every microcontroller/SoC has at least one hardware UART. If you want to see what your code prints to stdout while it's running on real hardware you could either implement a fancy redirection layer that sends logs over whatever interface your device has (and hope there are no bugs in it) or just use the built-in UART, wire it up to an off-the-shelf dongle and call it a day.
> Sarah [not real name] also mentioned that the car had been transferred from another Audi dealership in Orange County, California, when she bought it. Could they be the culprits? We called the original dealership and asked if they were familiar with this hardware or if they install GPS devices in their customers' cars. The dealership told us that they used to work with a company called Sky Link to install anti-theft devices, but didn’t activate them unless the buyer paid for the service. Could this be an explanation for this rogue GPS device?
[...] Turns out, it had. The GPS device was bought by the dealership, but it was never activated. At last, we had proof that this was a device installed by the dealership.
It feels like there are several "layers" to this story, putting all of them in one probably just confuses a lot of readers. In other contexts the UART pin-outs and bit-banging would be interesting to me but I just wanted to find out whodunnit.
OTOH: how is that even legal? I can't fully grasp how privacy is perceived as a sacred basic right in the US, but then they have dealers tracking people's cars for repossession purposes...
I think the EFF needs to hire some hardware people in the future to handle future teardowns. :-)
Funny they explain what Flash is. It's just two years since it's officially dead, however Flash used to be around everywhere until at least ~2015. For me it feels strange there are younger people not knowing what Flash is... I am getting old ;)
Most of GPS's perceived suck (in cold boot (TTFF) time, general receptivity) is actually just bad antennas/chips. I bet this thing has a large, possibly active, antenna and a modern, possibly multi-service, gnss module.
As an example, I have some very cheap ~10mm passive antennas that never pull a signal indoors, and some very cheap modules that take >20 minutes to TTFF even with a clear view of the sky. I also have some big chonker 30mms that, with a modern module, have a <2min TTFF inside/in a car/whatever.
It's possible to make good guesses, but it's a pain, and they're still guesses. (Well, they were at my level anyway)
https://blog.mass.gov/transportation/massdot-highway/highway...
Also, it would be nice to fool the GPS through a jammer that emits false signals in order to make it report a fake location, after placing cameras at that place to record whoever shows up.
At least in my experience many years ago managing an enterprise mobile account, I could have SIM cards and handsets sent out with no name or similar allocated - the name was a nicety for getting the package to the right person, but there was absolutely no verification of anything. The name helped you reconcile the bills, so we had users on the account called "office spare 1" and "field engineer spare". Any customer support had to go through the B2B account.
At scale, an M2M device customer won't be telling the operator anything else about the device or user - the customer will manage allocating subscriptions to vehicles or devices, and won't want to have to deal with their operator for this.
So if it was a CDMA device, then it probably doesn't use a SIM.
This isn't true for all of the EU. For example, in the Netherlands, you can buy and activate a prepaid SIM without any identification requirements. This prepaid SIM, once activated in the Netherlands, can then be used in other parts of the EU without subsequent registration.
First : don't confuse jamming with spoofing. Jamming is extremely easy to perform by any idiot, while spoofing GPS is significantly harder https://archive.fosdem.org/2019/schedule/event/sdr_gps/
Second : keep in mind that both of them are actually illegal in most countries, and besides unless you exactly know what you are doing it's fairly easy to jam/spoof on much larger areas than you would intend to ! (and GNSS is not restricted to consumer products and maps but are used in a lot of industrial/serious applications so it can actually have consequences)
You are very wrong. Spoofing GPS is downloading a file, and then running a commandline program with a hackrf attached. The *only* hard part is getting a HackRF or other TX capable SDR.
Download and compile https://github.com/osqzss/gps-sdr-sim
Download today's ephermis https://cddis.nasa.gov/archive/gnss/data/daily/
run:
gps-sdr-sim -e $EPHERMISFILE -l $LAT,$LON,$ALT
And, if you're nearby an airport, you're violating felonies with FCC AND FAA.
Having a broken VCR is significantly easier than downloading a file and then running a commandline program with a hackrf attached.
I recall seeing someone's project that did exactly that: transmitting at a very short distance a radio signal that spoofed a number of satellites so that the GPS receiver would report completely bogus positions. Anyway, that would be unnecessary as I completely missed that the GPS receiver is connected through a serial port, therefore spoofing NMEA strings would be much easier.
jamming GNSS satellite connection? only heard of Russians doing that. could be more expensive than exploring this little modem.
What would be enough? Decapping all chips, dumping and decompiling the firmware, figuring out what the people who made the device had for breakfast?
Wow. I imagine a dealership doing this here in Germany. Even repossession isn't that easy in Germany. In Germany, you have to go the official route and get the vehicle seized by the bailiff.
Installing a tracking device without clear informed consent would go against the GDPR and be illegal.
This German article [0] from 2022-02-03 for example mentions cars storing some usage data:
> In summary, it can be said that data is constantly being recorded for all cars, which allows conclusions to be drawn about the usage profile, the intensity of use, the number of drivers or even the driving style. A few examples of data evaluation and transmission:
-
Usage profile:
Separate storage of the kilometers driven on the freeway, country roads and in the city
Number of individual journeys, broken down by kilometers
Charging and discharging cycles with time, date, mileage
Utilization data of the combustion engine in plug-in hybrids
Regular GPS data with status report of important vehicle data
Hours of operation of the vehicle lights, separated according to individual light sources
-
Driving style:
Number of electric belt tightenings (how often do you brake hard?)
Entries for excessive engine speed or temperature (speeders)
Charge and cell voltage of the drive battery
Duration, how as long as the driver uses the various modes of the automatic transmission (continuous/manual/sport)
-
Intensity of use/number of drivers:
Number of adjustments of the electric driver's seat (allows conclusions to be drawn about the number of drivers)
Number of media inserted in the CD/DVD drive
Duration and time d he phone calls
--
[0] https://www.adac.de/rund-ums-fahrzeug/ausstattung-technik-zu...
Interesting that they don't.
[1] ISA, Intelligent Speed Assist: https://etsc.eu/intelligent-speed-assistance-isa/
The investigative effort they put in was quite good.
- the cost of these units is very cheap in bulk maybe ~$100
- their shoddy mechanics cut into power and CAN bus cables to sloppily and cheaply install them. They're usually zip tied up under the steering column. They tie into CAN so they can also immobilize the car.
- they install them right when the cars come in for their own theft protection and inventory control
- then they try to add anywhere from $500-$3000 onto the car with "theft protection" and 100% recovery warranty add-ons. It sounds like you are getting something built into on-star, but it's not. It's great - they get you to pay them for their own anti-theft and inventory purposes, and can often make several hundred dollars on top of it!
- if you avoid the bait and don't pay, then they just deactivate the unit, but they don't take the time to remove it or fix the damage they did to your wiring.
- nearly every dealer in CA does this. it's not at all just for repos, so especially upscale dealers too.
- which is terrible because 10 years later when you're contorted upside-down under the dash troubleshooting a intermittent CAN-bus problem on your expensive car, and you find one of these things is the problem, you get pretty angry about it.
Many of them pay the owner to allow them to recover the device when the loan is paid off.
What you're referring to are devices installed by smaller shady "buy here pay here" dealerships that do in house financing for people with bad credit. Even then, gos trackers are extremely rare. Much more common are remote disabling devices. If you make a car unable to function, it's not that hard to find. Heck, they don't even really want to find it. They want to motivate the owner to make their payment, which disabling it usually does.
Finally, what some normal dealerships do to increase profit and ease of making aftermarket sales, is preinstall theft deterents or safety devices to ALL cars on the lot, and then hope they can upsell each buyer during the paperwork process. The reason this is done is because having to bring the car back to the dealership to have your after market products installed is a huge pain, which becomes a major sales objection. Thus, dealerships decided to start installing the devices in every car ahead of time, since they are cheap parts anyway, and using that as a sales tactic to sell you on paying for the actual service contract or insurance (the word used loosely here) as part of the product they installed.
Tldr; dealerships install $39 GPS trackers in every car on the lot. 25% of the time, they manage to extract $500-1000 of profit by selling the service for $1200 to a buyer. This pencils out on the end, thus they keep doing it. Definitely a more sleazy tactic that almost no dealership I worked for used, but not uncommon. Heck, the OP story was done at a franchise Audi dealership.
Poor people are a great source of extra income through fees for exploitative companies. I bet re-enabling the car costs a significant fee...
Well kinda. I've helped investigate high end auto theft rings, and I can tell you almost all luxury cars have tracking built directly into the infotainment system. Only manufacturers and a handful of people at the largest auto groups can activate it remotely.
There's no way anyone at AutoNation or Penske Automotive knows how to do this.
I guess calling the company and giving them the serial was what solved the mystery in the end, but the hardware investigation left a lot to be desired (and was fruitless in the end).
Other comments: those jumpers can be unreliable, and I'm surprised they managed to solder with those leads. In any case, it was clearly a learning experience for them, so that's good.
As for VOD, maybe it underreported miles driven because the gps stopped working in areas with poor signal.
If I saw this device under my seat I'd assume it was part of some electronic system and never touch it. The only thing that I'd see that would make me go "huh" would be CDMA – and even then I would probably assume it was part of my car's infotainment system like my old Saab's OnStar that used a Verizon 2G CDMA network that died before I purchased the car.
I have a pretty good mechanic as well, and unless I was complaining about a jammed seat adjustment, he wouldn't be down there to see. I wonder if he'd even be able to eyeball it as suspicious as he's an independent; who knows what kinds of things get hooked up below seats.
Assuming this part isn't narrative, kudos to those who found it. Now where should I go look?