Who is collecting data from your car?
themarkup.org
themarkup.org
under your passenger dash is a black metal box, usually documented. unplugging the harness and removing it, you can open it to expose a baseboard and a riser. the baseboard is for things like infotainment usually but the riser is your cellular modem. pull it and you'll get a warning light on the dash, but no more data collection. older cars will have a Sim in the riser you can pull if thats less invasive to you.
note: OnStar is also disabled and will not dial 911/999 on collision.
Once disconnected, the car isn't going to be able to send anything even if it tried. Only question is if your car is gonna bitch at you because it's disconnected (mine doesn't).
So we’ve never had a right to not have our whereabouts known or tracked, but companies and the govt have also never been able to track everyone extremely easily until recently. So there’s legitimate concern that the ease and scale of location tracking mean that we should perhaps establish a right to some privacy, but I’m not sure how that stands up to other people’s rights to see you and identify you when you’re in public.
I was just thinking about the famous “Photographer’s rights” pamphlet that has gone around the internet for a while, and people who post YouTube videos of being harassed by police or security guards who claim photos can’t be taken of a building or site when the photographer is standing on public ground. The pamphlet patiently explains that you’re allowed to photograph anything visible from public land. Googling, I see a page at ACLU dedicated to the same idea https://www.aclu.org/issues/free-speech/photographers-rights
I’m thinking about the future: imagine people made a stink about cars transmitting this data, and companies deciding instead to install cheap cameras everywhere on all roads. How do the photographer’s rights interact with people’s expectations for privacy? What should we expect, and what expectations are unrealistic and need adjusting? Are there any developments were lawmakers are addressing where the right boundaries are between public rights, private data, and the scale of cheap ubiquitous digital tracking?
One thing to consider is what would happen if license plates actually did go away. This idea is completely unrealistic- license IDs & license plates (or some way for police to identify you) are never going away. But assuming they did, what would happen? This would mean an astronomical increase in hit and run accidents, in uninsured driving, and in criminal activity from unsafe driving to theft. Do you think that wouldn’t happen, and if so why? Why would having no plates be a better thing than having them?
Your actual license number or other identifier, plus a time-based nonce, is encrypted with the DOL's public key. The displayed value changes as the nonce changes according to its schedule, so third-party observers can't correlate the displayed value across time.
If you get in a hit-and-run and note the displayed plate, the DOL has the other half of the keypair, the time, and the derivation function for the nonce, so can translate the displayed value to the actual owner.
Not being able to publish a single stable value in amber alert cases would be a bit of a regression, but you could still publish what a value would be at a particular time interval.
Doesn't do anything about governmental abuses of ALPR data but could be effective at cutting out corporate abuses. I'm probably missing something but it doesn't seem to increase info leakage w.r.t the status quo either - you'd theoretically be able to figure out when a particular image of a plate was taken, but that source would almost definitely be timestamped anyway.
e: I don't think "just ban private ALPR" is a solution; it's simply way too easy to do with COTS+FOSS and way too hard to enforce against.
Which leads to another issue, that local governments have contracted these corporations to do just this. From red light cameras to suvellience cams, police don't actually store this data themselves, private companies do the bulk of the work here.
Yeah, I actually started out writing that comment about how license plates are probably unnecessary given the volume of other forms of location data accessible to LE but the peak HN strat was more fun to think about.
> We haven’t yet established that being able to identify someone in public is bad, or conversely that being able to travel anonymously is a goal we want, right?
I don't have full answers here, but I think it's worth considering the modes of enforcement enabled by this change. Despite there being no de jure change in privacy protections while in public, there's been a de facto change from that kind of data only being accessible in cases of specific, targeted investigations to that kind of data being accessible to automated dragnet enforcement. Targeted investigations are inherently limited in scale and there's (at least theoretically) a nexus between the investigation and some kind of probable cause, but dragnet enforcement generally disregards fourth-amendment protections. The Carpenter decision theoretically offers some protection against this, but parallel construction is trivial enough that I'm not exactly resting easy.
So, I think it is possible to be against ALPRs without necessarily being for wholly anonymous travel in public - it's an issue of probable cause and avoiding the fruit of the poisoned tree, not one of absolute lawlessness. My (admittedly silly) suggestion is also problematic because it doesn't address this concern at all. My real feelings are a lot closer to 'calvinmorrison, but I acknowledge that "just get rid of license plates" isn't exactly a winning proposition to the average voter.
You’re suggesting that a solid plate of metal that can sit, neglected, out in the weather for multiple years without much visual wear, and when damaged by the car wash can just be bent back to shape, and replace that with your delicate little piece of electronics and software? And pile on some PKI to boot?
I’m seriously on the fence in deciding if this comment is trolling me, or if this is what late-stage HN looks like. :-)
I bet you could figure out the physical aspects. E-ink tech itself has come a long way in the last few years following some patent expirations, and the electronics stuff is basically just a yubikey JB welded to a license plate frame. The cost per unit would be pretty low at scale, so just replacing borked units seems pretty doable.
Imo, a bigger problem is competent implementation. Yeah sure, the DOL is gonna run a bunch of PKI infrastructure and not mess that up. At least in my region, just keeping a largely static website up seems to be a struggle.
There's no reason license plates expire, there's no reason we should have to pay for inspection, there's little proof it even is effective in improving safety.
Drivers licenses again prove very little. People are pulled over constantly for suspended and expired licenses, were the unable to drive? clearly they were.
The issue with license plates is that it creates a automatic background check on every person who drives past a police officers with an ALPR. It's about as bad as the slave catching squads from the ante-bellum era. There's no reason I should have a bench warrant from missing a traffic ticket in New Jersey cause a police officer to detain me, arrest me, jail me, and send me back to New Jersey.
The problem is, you cannot separate the benefits from the bad. The problem is the government routinely abuses their power of licensure (see may-issue licenses in new york) to the point they cannot be trusted to license at all.
Given the rampant abuses on our civil rights from the government, especially state and local governments who tend to do the day to day brunt of enforcement, I hesitate to offer them any option to be more efficient.
I can separate the benefits from the bad. The road without rules is a net loss for everyone. Companies and individuals would gladly save on getting inspections if it saved them a few dollars at risk to everyone on the road when their bald tires and bad brakes finally failed them.
Depends on what you mean, it sounds like you’re saying the government cannot be trusted to be perfect. I’d agree with that. But the counter problem is that the public cannot be trusted either. A huge number of people can and will avoid maintaining their car if they don’t have to, will wait to purchase tires until after they’re bald, will drive with smoky exhaust, will avoid paying sales taxes if they aren’t caught, will crash their cars and run if they can’t be tracked down, etc. etc.
This isn’t really a government problem, it’s a people problem. People just happen to make up the government.
> There’s no reason license plates expire, there’s no reason we should have to pay for inspection, there’s little proof it even is effective in improving safety.
Kind of a lot to unpack there. Contrary to your claim, there are reasons plates & registration & IDs expire. Whether you accept and agree with those reasons is a separate question. Cars do change hands and degrade over time. It makes sense to check in, especially from the POV of the govt who maybe primarily wants to tax any sales, and keep track of who’s associated with each license plate.
Safety and emissions inspections are improving our safety & air, and there’s data over time to show it.
> Drivers licenses again prove very little.
There’s some proof; we have lower accident rates than some other countries where drivers have a lower barrier to entry. Aside from that, licenses are partly for identification. You might not like that, but that is part of their purpose.
> It’s about as bad as the slave catching squads from the ante-bellum era.
Hard disagree. Treading dangerous water with this one.
> There’s no reason I should have a bench warrant from missing a traffic ticket in New Jersey cause a police officer to detain me, arrest me, jail me, and send me back to New Jersey.
Sure there is, you appear to be fleeing when you miss a court date and drive across state lines. I’m skeptical this happens with any regularity over minor traffic tickets with no other context and a clean record. But again you’re saying “no reason” when what you mean is you don’t like it.
> Given the rampant abuses
You’ve established that you have a fear of abuse, but not that it’s affecting you routinely. I haven’t seen any dragnets ever, personally.
I'm curious about this. Most US states do not require regular safety inspections, and some of those that do, only require them for a subset of vehicles (only commercial vehicles, only vehicles over a certain age, etc.). Around half of states require emissions testing, though often it's not yearly, and there are often exceptions for newer cars.
Certainly there are political and cost-related drivers to not requiring this sort of testing. But I do wonder what studies have been done, specifically for safety inspections: do they significantly reduce incidence of vehicle crashes, or at least of fatalities or serious injuries when crashes do happen?
Now I will agree that they can be an instrument for evil, but sometimes they are the only way to avoid a lot of deaths.
> license plates ensure drivers have had basic training
No, that’s what a drivers license does.
> and that the vehicle has been inspected for basic safety and emissions standards.
Most states (even ones that do require those inspections) issue license plates without these.
> To police, the license plates offer a way to find out who the driver is.
They really don’t, because vehicles are frequently driven by people who did not register them.
I've lived in enough states that various parts of my experience from various jurisdictions both confirm and refute each of the points made.
It's important for everyone to remember that their experience is not the only experience.
There is no other indication on the license plate. just the numbers and letters.
I assume that expiry dates on US plates is related to either road tax or vehicle inspection
Usually yearly registration, though some US states do gate the registration completion on some forms of inspection.
California, for example, requires emissions testing every other year for cars older than a certain age, and won't send the new registration until that's been completed. But most states don't require any kind of regular safety or general road-worthiness inspections. I think that's kinda bonkers, but I haven't really looked at stats around how many car crashes are caused by a failure to maintain a car or its safety features. It's possible that the cost of doing such testing is often deemed too high, when considering the benefit.
In all 50 states, plates represent the registered owner and not the driver, because non-owners can drive cars in all 50 states.
As for safety and emissions, only a minority of states do each of these, and the majority of those denote compliance with a sticker, or have exemptions:
https://en.m.wikipedia.org/wiki/Vehicle_inspection_in_the_Un...
Someone else driving your car doesn’t prevent the police from compelling you to tell them who drove your car. The point is the police can come to you. Different story if the car’s stolen, of course, but license plates in fact are used often as the first point of contact to identify drivers, regardless of whether it is their car. Without the plate, there might be nothing to go on, right?
Your other corrections are valid, I was imprecise with my point. Do you agree with parent that plates are pointless? I was only trying to point out the utility and reasons for the existing system of licensing and registration, plates, IDs, and stickers. I can see parent is making more of a political statement than one of actual utility, but maybe also important to keep in mind that purpose and utility of the various parts of this scheme look different depending on who you are.
And this can be used, in turn, to look up a lot of the other data you pointed out, even if it does not do so directly.
> Without the plate, there might be nothing to go on, right?
There’s the VIN, but they’re difficult to see at a distance, and don’t indicate the jurisdiction of registration for out of state vehicles, and so, they’d be a PITA for most things states care about using plates for.
Without a license plate, all you have to go on is make / model / colour and any obvious modifications, essentially the same as seeing a random human but with less cardinality since vehicles are mass produced
Whenever I get one of the geotracking cars, hopefully the antenna wire will develop a fault.
Most people don’t have businesses registered.
There is a Youtube channel where someone got a Hummer, ripped off the engine, and transformed it into an electric vehicle. When he went for registration (as a custom car) nobody even asked to see it.
From public land I can see people sunbathing in their gardens.
For a photographer, there may exist an excuse such as "yes but the landscape in the background"...
For data such as the routes of a car¹, there is no excuse.
(¹Which does not overlap with "what enters or leaves a territory" - monitored in many administrations.)
I guess that discussion is veering away from the practical question of whether anyone should be able to know who you are if you’re driving on public roads. It doesn’t require any special technical or mechanical means to see people’s license plates and faces from the side of the road or from poles or overpasses, right? What I’m really curious about is whether there should be laws established against such surveillance because it has become too cheap and easy to monitor everyone at once all the time, or whether as a society we deem activity in public space to be public knowledge and not a matter of privacy, whether no privacy should be expected.
there are somethings that are illegal that the public, and enforcement simply ignore most of the time. there are other things that are legal but apalling to the public when they encounter them.
i think this distills to a threshold for surveillance. there needs to be some discriminator between casual observation, and active surviellance.
there seems to be a need to revisit just what a warrant is, and why it is required. i really would like to see a warrant apply to any means of collection, as in the warrant is allowing posession of the data itself, regardless of the origin as a court appointed priviledge for the term of the investigation, -regardless of origin
Along the same lines, if an office follows someone (they believe might be related to a crime, etc) around town to track their whereabouts, that seems within reason. If the police force (using advances in technology) tracks the whereabouts of all people at all times, it's unreasonable. It's the same thing, just at a different scale.
We need to find an effective way to allow the "components" of something that isn't allowed, without allowing the thing itself.
I think it’s pretty clear from precedent you have none.
Every vehicle displays a unique number in large, readable type, and has for longer than any person has been alive. I haven’t seen any objections.
The same applies to driving licenses that are covered in very personal information which is handed over willy-nilly to anyone who asks for it.
In California they make it clear that driving is a “privilege”, not something in which you have any rights.
Edit: another example: notice that the automatic toll collection systems are always implemented as registration+billing based systems rather than as any kind of privacy-protecting cash-like schemes.
Because the bar to getting that data used to be quite high and limited in scope. Now with license plate reader software in conjunction with street light cameras, the dynamic has completely shifted to easily record and store a detailed tracking log for all observed license plate numbers in a city.
Big power dynamic changes like that result in fundamental shifts like “right to be forgotten”, the GDPR, etc.
The only thing that has prevented an uproar so far is that you can’t go type in your neighbor’s license plate into a website and get that detailed tracking log at the drop of a hat. Similar thing for cell phone location records from cell companies.
Or public air space, for that matter.
As for photographer's rights, I work in a public space. I don't care whether people photograph me unless it crosses the line of harassment. Likewise, if I notice someone taking photographs of other people's children, I will do my best to make them feel uncomfortable with their actions. Context is always important.
The idea of what is public and private data is also constantly changing. I recall governments making public data available online in the mid to late 1990's. Records that you could visit government offices for in prior decades (e.g. certain types of property records) were viewed in a very different light once they became easily accessible. These changes will continue to handle, in part to balance rights but also because we need to address an imbalance of power due to an imbalance in access to information.
this might be true in the USA but it is definitely not true in Japan. People's right to privacy trumps your right to take pictures in public. In crowds it's usually not a problem but make a particular person the subject of your photo and you could easily get in trouble. Same for buildings if you publish the photo
It used to be it was rare for me to see a major violation. Now it's is literally every single time I go for a drive or ride my bike, at least in the city of San Francisco, that see (a) someone running a red light, (b) someone turning right from the 3rd lane (meaning they should be in the first lane), (c) someone turning left illegally before the on-coming traffic when the light turns green, (d) driving for blocks in the bus only lanes, I even saw someone drive down the wrong way down a one way street to take a short cut. Often I see 2 to 3 of these during a single outing.
If more surveillance would stop this then I'm for it.
I'm curious what changed (a) my noticing ... I really don't think that's it but it's possible (b) people for some reason no longer giving a fuck (c) too many video games (half joking, half not, personally love video games but of course in a video game you drive however you want. Of course you also kill people in video games (d) cycling culture bleeding into driving culture. (e) ....
Legal protections would be nice, but I'd like to stop being stalked _immediately_.
An alternative would be to use something Ms Fried built in 2006[0], but more specific. Come to think of it... this might be a small business idea...
> Vehicle Data... After your Vehicle’s ignition is turned off, the Vehicle transmits the location of the Vehicle and the time it was turned off.
If every car with Sirius installed transmits the time and location when it was switched off to marketers, that would close the loop on all those "I just moved to this place and I'm getting local robocalls to my cell number".
This is more than likely just a combination of National Change of Address database (which is updated daily, I think, and there seems to be a lot of companies selling it) and some marketing information from one of many services that sell it, almost all of which contain your cell phone.
Is there a list of cars which don't have remote data collection?
I'll take just the aux then, at least as long as I can. Aux (as in: 3.5mm jack on both ends or else on one end and the other one cinch or DIN to support even older devices) is something which has been working fairly universally to get music from any portable and even some not-so-portable players to amps in the past 30 years or so, extend to like 60 years to include anything compatible but with DIN (just a rough guess here, I still have some old Telefunken radio with an aux input via DIN and I'd estimate that is it's age; still works, moreover they really figured out nice warm bass from small speakers back then already). It's simple, it's a de facto standard, it really just works, it's a good idea (doubling as headphone out) and well-executed.
Bluetooth audio on the other hand tries to be all of that, but I never quite got the feeling it's there yet, after all those years, and I wonder it will ever be the same level of 'just works'.
If they manage to install ABS/ESP, they might actually be an interesting choice, if it weren't for the likely lack of EU market authorisation and spare parts.
A car + phone combination is always more capable, because its almost always up-to-date and the user is already used to it.
Imagine if the whole world refused to use any car older than 2 years... how many cars would have to be made every year? even if that made any economic sense, it certainly doesn't make any environmental sense. You might not think of it this way but those people you know are privileged, they would not be able to get a new car less than every 2 years unless there was a 2nd hand market. Cars need to last.
I have family that work at a car dealership. Most of their business comes from people leasing or trading in vehicles every couple years (or less).
I just got z-wave locks from a company ultraloq, figured I don't want the integration with the app etc. I will just use z-wave and connect to my local offline hub. But once I get down to set it up, I can only connect to the hub via z-wave from the ultraloq app. I install the app and I need to register an account by providing first name, last name, email and phone number, then the only way to pair my lock with the app is by enabling bluetooth and providing location access to the app with gps enabled. I do that and then I find out that once I install the app and register the lock, I am not allowed to use it in standalone/offline mode (setup/change lock codes directly from the lock) unless I do a factory reset. Funny enough, if I factory reset, I lock is no longer connected to my hub on z-wave.
Basically to use z-wave with my offline hub, I need to provide the company my gps location, first name, last name, email and phone number and stream data of lock usage every time the door is unlocked/locked to the company. How is this not a security risk for the company? If they ever get hacked, all their customer PII data including the gps location of where the locks are installed are compromised.
They do care - it is just what they care about is diametrically opposed to your interests. The post-sales revenue stream from collected data is not only profitable, but in some cases more profitable than the sale itself.
I don't really believe in this theory. Certainly the average HN commenter trends more privacy-aware than the average person in our societies but I know many "normal" people who don't like the intrusion but accept it because they don't see any viable alternative apart from giving up a normal life.
The correct solution when competition in commercial markets doesn't solve a problem like this because it's just too profitable for everyone to carry on the abuse is for governments to regulate in the public interest. Of course that relies on elected representatives to do their jobs and not just pander to whichever industry gives its lobbyists the most funding so the success of the strategy is likely to vary wildly depending on which country you live in.
I think the current incentive has warped the market beyond repair for certain products.
Take TV for example, non-smart TVs cost the same or more than smart TVs because manufacturers can subsidise smart TVs’ cost by selling or utilising data. Not to mention other “benefits” like locking consumers into their ecosystem: a lot of Korean newly weds buy all Samsung or all LG for electronics for this reason. With all these incentives, it makes sense for the companies to only make smart TVs.
We need regulations to offset these incentives. There most be a real tangible cost to collecting data and appliances should be required to use open protocols. Then it will make more sense for manufacturers to make just normal TVs that can compete with smart TV.
Will any of this happen? Probably not.
Nobody ever reads the manual. Nobody wants to know whats inside their gadgets. Nobody has bandwidth to consider the tradeoffs of data collection.
Life is short.
So the company collects data that in some cases is more (much more) valuable than their main product.
I only buy stuff that I can reflash (tasmota, esphome, or whatever), because everything else will either be deprecated, the cloud will be discontinued, the app wont work on the newest android, or there will be a huge security breach, that the company won't fix for "legacy" devices.
This makes stuff pretty limited, but you can still find atleast some things that are (eg.) esp8266 based.
Everything made before this technology existed?
Here it is:
.
Unfortunately to the best of my knowledge I am not joking. This is one of the big reasons why I haven't bought a new car with modern automation and connectivity for a long time.
I think they will be unreliable.
I think they will be insecure.
I think they will be privacy-invasive.
I think the technology at the original time of sale will age quickly and manufacturers will abuse that to extract more money from current owners or any potential new owners who might buy the vehicle from them.
I think the technology will allow for artificial limitations on vehicles' physical capabilities and encourage manufacturers to make pay-to-play style upgrades and rental models the industry standard.
And I think there is a non-trivial risk that eventually someone will successfully exploit a remote vulnerability on a popular model and gain enough physical control over a large number of vehicles simultaneously to cause injury or even loss of life on a massive scale.
Absolutely nothing I have seen about the auto industry, the people who lead it, or the people who regulate it would undermine any of those claims and apart from the last one there seems to be plenty of evidence that they are already starting to happen.
Of course this does nothing on the security side - the fact that the vehicle is still somewhat accessible from the outside makes it less secure. But not having to worry about privacy at least is nice.
There is a hack[0] that you can do that will give you android auto. I do find maps on my dash is pretty helpful. There's no great place to put my phone to see maps and picking up my phone frequently to navigate isn't that great. Though sometimes I have problems with it disconnecting from my phone (cabled). But then again, I have a Scion iA (rebaged M3). I'm not sure if anyone knows of a newer (and maintained) version of this.
Though there are a lot of things about android auto that piss me off and it makes me feel confident that the engineers aren't dogfooding. I get that they want voice commands, but when those fail the solution shouldn't be "pick up your phone, detach, do the thing, reattach." What a crazy failure mode. Who thought this was okay?
Modern automotive hardware is almost completely undifferentiated, and this commoditization means the hardware is essentially being sold at cost. The only opportunities for differentiation, and therefore profit, in the automotive market involve leveraging the vast quantities of sensor data thrown off by vehicles. In many cases the data of interest is not even about the driver per se but the external environment. There are many use cases for this data, both by the automotive OEM and third parties. In most developed countries, both the automotive OEM and the government have a right to this data. The regulatory frameworks for this were put in place decades ago.
Organizations that work with this data have great difficulty because off-the-shelf data infrastructure can't handle it in a meaningful way. Currently, exploitation has been more theoretical than practical.
Forgetting about the smartphone data, many cars have a Navigation system, which means the car itself knows where you are. Is it being communicated in real time, or does the car at least remember?
I actually asked someone who works in car automation this very question, and he said it's really manufacturer-dependent.
The car manufacturers are hoping no one digs into this. So let's dig.
The dealer charges about $200 to do it. It's probably possible for someone to do it on their own, but I don't drive enough to bother looking it up.
No. its' a second hand buy. maybe if purchased directly
> Could the police subpoena it?
it's also an import. probably any info is saved in a server somewhere in germany. Possibly yes, but which police ? in which country ?
If you were sitting on PII location data and no one knew you had it, you'd probably want to keep it that way. Going public would certainly get the authorities after you.
GPS itself is entirely passive. The last position is definitely stored in the receiver to make it faster to acquire a position fix the next time it's turned on, but the question is whether that is sent outside the car. A standalone GPS unit of the type that people add as an aftermarket accessory, instead of being integrated, will almost certainly not be transmitting its location elsewhere.
On the other hand, there's money to be made by selling that data. So I wouldn't blindly assume every manufacturer just leaves it sitting on the table.
What mostly happens is that data sharing goes both ways: for instance if your embedded navigation system shows live traffic data, your car is probably sharing its location upstream, which gets aggregated and anonymized according the legal framework and the terms between both parties.
You can do stuff with a car that you wouldn't be able to do with a smartphone, for instance using sensors to scan curbside parking, whereas Google needs to extrapolate street parking availability based on driving patterns. But I'm not aware of anyone doing that yet... I've only seen proofs of concept.
Do you know that for a fact?
If you sell or otherwise transfer your vehicle, it is your responsibility to delete all information (such as contacts, address look-ups, saved map addresses, or preferences) from the vehicle and contact us to transfer or cancel your account. If you do not delete this information, it may remain in the vehicle and may be accessible to future users of the vehicle. For instructions on how to delete information from your vehicle, please refer to your vehicle owner’s manual.
So apparently, if you look a place up (say, the motel where you and your extramarital partner meet), it stays with the car and/or your OnStar account.
I understand, it’s privacy and stuff, but how does _this_ make a compelling argument? Is covering up that someone cheats on their spouse, beats their kids, and launders money, now some service provider’s responsibility?
Right. If you have nothing to hide, then the police are welcome to watch and listen to everything you do. Correct?
Much of the discussion seems to be around the government (usually, but not limited to, police) monitoring the location and operation of a vehicle on public roads.
While I'm not a huge fan of government surveillance, registering a vehicle (and obtaining a driver's license) and monitoring the performance of that vehicle (and its driver(s)) are governmental functions purporting to ensure the safe operation of a vehicle.
Corporate entities, like auto manufacturers, dealers and "tech" companies have no such responsibility, nor do they have any role in (except in abiding by the law/regulation -- e.g., emissions standards).
So, unless there is some sort of government mandate to collect such information, corporate entities have no reason (other than their own profit) to collect location, velocity and/or in-vehicle activities.
IMNSHO, that they do so should be much more concerning than red light or speed cameras, being followed for a few miles by the police, or as is popular where street parking is a thing, checking registration/inspection expiry.
Just as one (or should be) is horrified by the levels of tracking by corporate entities on IOT devices, "smart" TVs, dishwashers(?!?), etc., etc., etc., why are folks focusing on the government here?
They aren't gathering the boatloads of information being collected by the corporate entities (and if the government starts buying such data, they should be smacked down hard!) that are invading/destroying what little privacy we might have.
As such, I don't get why the focus is on the government rather than on the folks actually gathering all this data.
Where might the government get such data? They certainly aren't gathering it themselves.
Rather, it will come from the corporate entities that are already gathering such data.
What's more, I can organize my neighbors to vote out folks who want to spy on me.
I can't do that (well, I guess if I had a few trillion dollars to buy majority stakes in various corporations, although that wouldn't work with Facebook[0] though) with the corporations that are already spying on me.
Just so I understand your position, you appear to believe that bad things a government might do with the help of corporations that are already doing those bad things is what we should be concerned about rather than what those same corporations are already doing.
Is that your argument? I just want to make sure I understand, as I'd like to have a discussion and not create straw men. Thanks!
[0] https://www.businessinsider.com/mark-zuckerberg-control-face...
PC/laptops were first, smartphones were done next and now car are too be 'degoogled'.
Edit:- 'Smart' TV's were between smartphones and cars.
You do not open to security risks when advantages are negligible or even negative (privacy issues make them negative).
Notorious among them are electric cars like Tesla. Even petrol/diesel car manufactures have started doing same stuff.
It is a disaster that cars are now part of it, but - the most extensive research to identify a decent product will be necessary.
Edit: what I fear most (second to a market that allows perversions - i.e. buyers of unacceptable products), is cretinous legislation what may remove options.
I have a hard time buying this (no pun intended). Your greatest fear is other people being able to buy things? I fear very much my not being able to buy what I want, and I can see knock-on effects from other people being OK with (or not understanding) the violation of their privacy and so indirectly violating my privacy, but it's hard for me to see that raising to the level of my greatest fear. So I wonder if I'm misunderstanding you, or we're frightened by different things.
Which 'this' do you mean? There is the 'this' where other people buy stupid things (meaning 'smart' things, in the marketing terminology we've had foisted upon us), and there is the 'this' where I can't buy what I want. Phones and TVs are examples of both, to be sure; but, as I mentioned in the comment to which you are responding, these two phenomena seem different, though linked, and it's not clear to me that the former is inherently bad.
Yes, you misunderstood. I stated that the fearsome weakness in the system is a market which is mostly made by careless buyers who will disregard low quality, absurd specifications and dystopian features in the products.
A product would not circulate in the market if people did not buy it, and people in general most unfortunately tend to buy what is available, without assessing it, without considering the effect of their purchases on the market.
You would not struggle to find e.g. telephones with replaceable batteries in the market if people generally refused to purchase otherwise. The same is valid for bluetooth-operated only washing machines (and other appliances), etc.
Bad products are around because people buy them.
> I fear very much my not being able to buy what I want
Exactly: that is already largely the situation, and it comes from a polluted market, spoiled by purchasers accepting bad products.
What exactly are you saying here? Is this a "telemetry is necessary for effective product design" argument?
Apologies if I'm misunderstanding, but if so: I personally don't buy that it is except in very specific circumstances. Gathering data through telemetry to make product decisions, when it's not just about data sales for extra revenue, doesn't always make a lot of sense, particularly when that data gathering capability directly compromises the product quality. I would argue that often it's done because of people trying to cargo cult competence at product design by doing what seems cutting edge, analogous to "architecture astronauts" designing overcomplicated & inelegant software systems with too many bells and whistles.
No, I wrote that nowadays, before buying, as you will need to «identify a decent product», you will have to research a lot, and discard the largest number of - useless - options. If nowadays you are in need of buying an item you will have to do extensive research of what is available in the market, because most of the products around are unacceptable.
These are already attack objectives - thermostat ransoms.
but here is a generic article on The Atlantic from 2016 - year relevant, because there had been cases of actual ransomware for some thermostat models then:
https://www.theatlantic.com/technology/archive/2016/01/the-e...
Which also contains the line:
> When it comes to connected vehicles, the possibilities are even more frightening. And thanks to an experiment where white-hat hackers remotely hijacked a Jeep as it hurtled down a St. Louis highway, they’re not that far-fetched
http://www.wired.com/2015/07/hackers-remotely-kill-jeep-high...
Which raises another point: security faults in cars have been used to stop them, to take control of them etc. Among the malicious purposes, one can emerge of ransom: "We now control your car. If you want to drive it again...". Nothing new in the crime scene ("We just stole your car. If you want to drive it again...") - only, now through fully avoidable technical holes which should not be there in the first place.
--
About the thermostats:
Hackers demonstrated first ransomware for IoT thermostats at DEF CON // Ransomware-infected smart thermostats, it's no longer hypothetical. An attacker could crank up the heat and lock the IoT device until sweltering occupants paid a ransom to unlock it (Aug 2016)
https://www.computerworld.com/article/3105001/hackers-demons...
I wonder if you turned off the “online” search results and routing if it would shut off data collection, or if you’d have to physically cut off the cell connection.
This is a fantastic catchphrase.
> Otonomo is one example of the dozens of companies that market their attempts at keeping information anonymous. Otonomo describes its platform as having “privacy and security by design” and notes the use of patented “data blurring” technology to protect user privacy.
> It also has an “Otonomo Driver Pledge” page promising drivers the ability to easily grant or revoke access to personal data,
This doesn't add up. If they collect only anonymized data, then they won't be able to find that customer's data and do anything with it.
This can be looked up. I suspect it is not their own patent though, so not under their own name.
With cars and their drivers killing more than a million people every year, a little constructive feedback would be a major help to avoid so many tragedies.
edit: and the last four entries on the list from tfa.
Another way your wish already exists partially is that people who cause accidents have higher insurance rates. This isn’t 100% effective, but some of the people who prove themselves more dangerous really do pay higher insurance already.
That’s not what happens in practice: drivers concerned about their privacy don’t use those apps, not those who drive the most carefully. Subscribers remain a minority. This is a shame because careless driving requires very little information, nothing that is genuinely affecting privacy.
But if we’re to have dangerous drivers pay more, without it being a voluntary opt-in system, then someone needs to be able to monitor all drivers, right? What information are you thinking of that isn’t considered private? You could have the cars reporting only speed & steering & accel/decel telemetry, but that might be easily hackable. Having GPS to compare against is much more trustworthy. What if primary components of safe driving are where and when you drive? Choice of roads and time of day may matter for some drivers as much as speed. Maybe the behavior in the proximity of other cars is a primary factor, I wonder how that could be reported - how often you pass, how much room and time you leave when changing lanes, how closely you follow, etc.
I wonder what it would really take to identify dangerous driving. The largest factors identified by the NHTSA are: drinking, speeding, being “distracted” (using a cell phone), and driving tired. Speeding might be the easiest, while monitoring for drinking and tired and cell phone use seem more invasive.
I’ve done consulting work for that industry.
> What information are you thinking of that isn’t considered private?
Statistical distribution of the absolute jerk. People who race, and distracted drivers have to correct at the last minute both have sudden changes in acceleration.
My kids use the insurance company apps and they are pretty awful in terms of accuracy. The apps nit pick the turning and braking based on acceleration data, and I’ve ridden with them and watched it call out safe driving as bad. One downside of this is that neither my kids or my wife and I trust the insurance company app to understand safe acceleration. I’m a little bit worried about what happens to this data and to the insurance company’s conclusions about what stops and turns were safe or not. It would be bad IMO if this record follows people around informing law enforcement using poorly decided thresholds for safety. The crappy app, of course, does not mean that the insurance company can’t reliably identify dangerous drivers, but there’s no indication to me that they’re using the data in a way I’d want or agree with... even if I’m completely on board with your suggestion to identify dangerous driving and charge for it.
Back in the 80's there were already such solutions that would monitor speed and location based on cell tower. the data would be chirped back periodically. The price of the insurance would depend on driving speed and postal code for the cumulative information of the entire truck fleet.
Today, this is not even a question. It is the de facto way of charging fleet insurance.
The data really doesn't bear this point out, or the category of drivers your considering are such a small part of the total that changing their behavior will have almost no noticeable impact on the total.
Further.. at least in the US, the majority of fatal accidents are single vehicle accidents where the driver was impaired either by alcohol or other drugs. You don't really need to mine data from the car to figure out who and who isn't the problem here.
> With cars and their drivers killing more than a million people every year,
That's uncharitable. Bad road design and failure to make protected pedestrian paths (16% of all fatalities in the US are pedestrians) definitely deserve some credit here too.
> a little constructive feedback would be a major help to avoid so many tragedies.
Based on US data: If you drink and drive you should be revoked for 10 years. It should be illegal to give people under 24 vehicles with more than 250hp, or any power level with a turbo.
Also, this shows that no matter if you pay for the product or not, you become the product for squeezing the data anyway.
Also, this could be a national security issue everywhere except US if US government would be able to track the cars all around the world. For example, what if they will track the cars used by defence industry employees or military personnel?
Such tracking equipment should be banned for import, but it is more likely that local government will just ask to provide the data to them too.
Because it's not due to money, but power. They have the power to put spy devices in so many cars it becomes (near) impossible to buy one without, and so they do it.
A product only respects your rights if you can control it, if you have the power and leverage to change how it works. If you don't, you get user-hostile features whether you like it or not (the Intel Management Engine, and its AMD equivalent, being just two examples).
If auto financing taught us something, it's that manufacturers are compelled to control every monetization opportunity.
I expect car companies will soon give their partners a choice - either sell yourselves to us or get locked out.
It is hard to summarize the situations briefly, but, essentially, the government can do whatever they want and the courts hardly ever slap them on the hands.
(IJ also _fights_ these issues in court pro bono - they are a law firm! - so supporting them looks like a good idea. disclosure: I am not affiliated with them in any form, just a podcast listener and a very minor donor)
Someone really needs to qualify the boundaries of what is considered a breach of privacy.
Sending location, heading and speed anonymously is perfectly ok by me because in return we all get real time congestion aware routing.
This is unlikely to be in the service manual, though. Are people identifying where the radios in new cars are?
It's also not impossible that you'll start to experience odd behaviors and warnings after a month or two, as the software stack expects connectivity eventually.
Tesla issued a press release years ago in which they reassured the public that their cars were used in connection-less or heavily-firewalled territories, and they still run.
While on the one hand those reassurances are sinister ("our new feature will not impair function"; "our electronic systems will not fail when driving in the desert" - which was false for some manufacturers), also note that - as one poster nearby notes - that the item seems to work properly at some point in time is not a warranty for the future.
The new car sometimes feels more complicated than my smartphone, and data collection was one of my first worries. Of course there's an app that comes along with it, and while the information and remote functionality it provides is interesting, having done without this stuff for the first 25 years of my driving life, I feel like I can easily do without it.
Another poster talks about removing the cellular modem to ensure the car can't phone home, and I'm seriously considering doing it. Though I imagine when I bring it in for service, the techs will want to reconnect it. I'm even afraid that they'll claim they can't service my car without doing. In addition to that, I do want to receive OTA updates to the car's software.
I'm curious to know if it's possible to opt out of all data collection (perhaps aided by the CCPA, as I live in California), without modifying the car's hardware. Sure, in that case I am then relying on trust (trust that is so far unearned), but I'm curious nonetheless. The thing that worries me most is location tracking, followed by the possibility that my driving "style" could be sold to my insurance company. I've filled out the CCPA opt-out form from my car's manufacturer (though that's about sale of information, not collection), but I'm sure that's woefully insufficient to actually protect my privacy.
IS there a way to know where the chip is ? Is there a way to jam it so it can't send information back ?
You do. The bill is included in the purchase price of the vehicle. The manufacturer sources data SIMs, pays for data ahead of time, and that’s to the cehicle price.
There's your data aggregator. At least one of em.
Also can't imagine that Mitsubishi would be wasting money putting a SIM in a Mirage.
Am I wrong? If so, how do I find out short of physically inspecting dozens of vehicles myself to see if they contain a SIM?
They do also do live tests with a sensor, but the "ECU says car is emissions ready" is an additional requirement. At least in many US states...maybe not yours?
Not exactly. Boring monitors like those for sensors or actuators are excluded / always reported as ready. Even misfire is always ready, and fuel was, too, until recently.
But of course since the more intersting monitors take long to complete, when they do reach ready, simple sensor checks would long have set at least a pending code if there was a problem.
Next update in california will likely require all monitors to be included in the readiness status latest for model year 2027.
To be clear here, not all of them are like this; possibly not even most of them. But enough of them are that I generally try to always go to a local shop to get my oil changed. It's not worth the risk to me. If you have one that you know enough about to be comfortable with, none of this applies to you.
[1] I had this happen to me. Got home, popped the hood, and there was a screwdriver sitting on top of my engine. If it had fallen in on the highway, it could have caused some serious damage/injuries. Luckily, it didn't.
https://www.toyota.com/content/dam/toyota/brochures/pdf/2022...
Hey-- where's that free market HN poster on this one? I want to know how to use the law of supply and demand to find a new car without a SIM chip.
Availability of such cars is declining of course, but I don't think they are extinct yet. If in doubt check Lada or similar.
You aren't going to find "sim card" on a car's spec sheet for the same reason you wouldn't find "lug nut". It's a component.
If a vehicle has any sort of telematics, and/or an emergency assistance feature, it's got cellular data connectivty.
That includes the Prius you mentioned, and a a boatload of other Toyota vehicles.