Toyota: Car location data and videos of 2M customers exposed for ten years
bleepingcomputer.com
bleepingcomputer.com
Am I dumb or are they? If you know someones home address, then all you need is a geo lookup, and a filter which selects for cars parked near that address at 3AM over some time period. Which then gives you the VIN and the entire location history, right? Sure you might get more than one car if the someone lives in a city and uses street parking but its still going to reduce down to just a handful of cars which can then be cross referenced against place of work, relatives, etc.
And of course home address lookup can be made with any number of public databases with little more than a name and maybe some additional filtering (age, city, phone number, etc).
You are correct, but I can't imagine why anybody would go to that much trouble for a speculative answer. Your idea requires quite a bit of intelligence collection as well (relatives' addresses, addresses of known hangouts, etc. that you have to vet for accuracy).
If you have a confirmed home or work address, just go to their home or work and take a picture of the target VIN through the windshield.
But they do have the internet, and further no meatspace means scams can be automated/scaled.
Honestly, this seems very bad.
For example, if you ever use public wifi, and you hit a web page with real-time bid ads on it, your ip address and tracking cookie will be reported. The IP can be geolocated, and presto, you have one time/location datapoint. Credit card transaction data can also be bought, and a cc transaction often gives you a location and a time.
The criminal networks are pretty sophisticated.
I’ve had to relay this on to people I train: It’s their job. It’s a business and it’s unreasonable for you to be better at aspects of it than they are.
I think the slide is titled “Someone is going to be the goose, hopefully not you”.
In nature, the predator has the fangs and claws.
You can read the VIN of neighbors and significant others pretty easy.
https://www.justice.gov/archives/jm/criminal-resource-manual...
"Members of the state police, any local police department or any peace officer acting pursuant to his special duties shall seize and confiscate a motor vehicle or trailer if any original identification number or special identification number is destroyed, removed, altered, defaced or so covered as to be effectually concealed."
I don't think you're wrong. I wonder what incentive bleepingcomputer has to make it seem not so bad.
Given any dataset like this it is trivial to pick any entry and trace where is home and where is work thus de-anonymizing it. Conversely given any home or work addreas it's trivial to find all other related entries for the individual.
Of course it would all be incredibly boring to analyze. We can conclude that people live at a certain location, (dumbly for no good reason) drive to another one 5 times per week and go a few other places.
Sure you might be able to find the odd person that is doing something weird or illegal but if you already know location x1, y1 contains bad guys might as well just go there and arrest them instead of creepily analyzing data that you know you shouldn’t have.
Interior images, exterior images, facial geometry, voice recordings, location/driving data, "multimedia screen data",
https://www.toyota.com/privacyvts/
https://web.archive.org/web/20230512182022/https://www.toyot...
The EULA for my Honda says that Honda can and will share all available data with itself and third parties, named and unnamed, for any or no reason.
It's 100% allowed within the EU, even for OEM licences. There have been multiple court cases about this and microsoft lost every single one. But I guess that's not what you were implying?
Because of some adversarial legal precedent in a major market that would impair them more then the expected benefit.
Microsoft probably is moving away from selling permanent licenses partly due to this, for everything except those to large customers they can individually keep tabs on.
excuse is "games are art, not computer software Oracle vs Usedsoft doesn apply".
> "games are art, not computer software"
That's not the legal interpretation of the topic, no.
0 tracking by the manufacturer. No subscription services needed. No annoying beeping when you forget to put on your seatbelt for 10 seconds. No touchscreen, all physical buttons. No Android/Apple spyware. No cameras. No ads on any display. No car-key that can run out of battery.
It's nice.
Literally anything is better than sitting and solemnly spelling out what "will" and "must" be.
~~~ Their's is a lot better, does still include Geolocation, audio recordings, navigation usage, however the usage looks limited to just Honda and the obviously required services: ~~~
> We will not use Geolocation Information for our own marketing purposes or disclose identifiable Geolocation Information with third parties (except our service providers) without your consent.
https://web.archive.org/web/20230512194748/https://www.honda...
EDIT: I just noticed the following:
> These companies may use Covered Information for their everyday business purposes, including marketing, customer service, fulfillment and related purposes. These disclosures may qualify as a sale under certain state privacy laws.
Also their definition of "Service Provider" is way too broad (see below comment). So I might need to retract my statement on their policy being good.
There's also that little qualifier "identifiable" in there. Companies usually take a very different stance on what constitutes "identifiable" than people think.
What that's really saying is that they will share the geolocation information with third parties without your consent, but they'll probably do a little handwavy "anonymization" thing on it first.
But… it’s just metadata. It can’t possibly be cross referenced, in bulk, with high accuracy, in 5 minutes, right? And even if it could, I bet there’s no money to be made selling people’s data, so there will never be any shadow industry that “brokers data” of regular uninteresting people, that’d be ridiculous!
Satellite, traffic, and telecommunications companies; Roadside assistance vendors; Contact centers; Research and development vendors; Providers of software integrated into our vehicles and systems; Marketing and non-marketing communications, analytics, and consulting firms; Professional service firms such as attorneys and accountants; Day-to-day business operations vendors such as courier services, facilities management suppliers, and information technology and network support.
Although it's worth mentioning:
> These companies may use Covered Information for their everyday business purposes, including marketing, customer service, fulfillment and related purposes. These disclosures may qualify as a sale under certain state privacy laws.
So I might need to retract my statement on their policy being good.
As for law enforcement:
> We may use and disclose Covered Information and any other information about you to government or law enforcement officials or private parties if, in our discretion, we believe it is necessary or appropriate to respond to legal requests (including court orders, investigative demands and subpoenas), to protect the safety, property, or rights of ourselves, consumers, or any other third party, to prevent or stop any illegal, unethical, or legally actionable activity, or to comply with law.
Being a prepper isn't extremist. (Yes, it's expensive, done right, but not necessarily extremist.)
[disclaimer: I live in Los Angeles]
That's a different crowd from someone who is just prepared for emergencies and disasters.
It seems like you have a cognitive distortion to work out. Amplifying an anecdotal sample to classify all people with a shared interest as having other characteristics of your sample is understandable but also misguided.
You, 3 weeks ago.
This is an absolutely unbelievable level of privacy intrusion IMO. I 100% support very heavily fining this sort of behavior, otherwise it will continue to proliferate.
Probably when a legislators private graphic videos with an escort or drug dealer or something more interesting gets leaked. Perhaps some government officials data is present in the leak as we speak. It might be harder to spot if not a personally owned vehicle or still cloud registered to a previous owner.
CHIPS Act of 2022 allocated money to support US semiconductor manufacturing. Right-to-repair laws have been gaining traction even though it can't benefit any large economic interest directly. Those are two recent examples off the top of my head that aren't a reflection of a government that "only want more control and restriction."
I get that politics is frustrating but this kind of blanket caricature just relieves people of the responsibility for engaging with specifics, and when people commit to it that actually covers and enables real corruption.
So what solution do you have that doesn’t involve regulation?
I wonder how that factors into this.
> Your Facial Geometric Features will only be stored on your vehicle.
> Vehicles equipped with Teammate use sensor and/or image data from the vehicle’s interior and exterior to evaluate the vehicle’s surroundings
Not only is this all by design, but in many countries, the "free mandate" - i.e. the notion that the politician can say A before the election and then do ~A after - is even legally codified. In theory, this is supposed to allow the elected representatives to apply their own judgment based on nuances of the moment instead of pandering to the mob. In practice, it means that your representative is free to pander to people other than those they "represent" while still claiming a public mandate based on the votes received.
They're just praying that one will be moderately less terrible than the alternative.
There's never an option to say, "No, none of these power-hungry psychos should get to make this set of decisions on my behalf."
We elect representatives at every level of government. In a country of 335,000,000 people a slow moving central government is a feature. If you really want to make a difference pay attention to your city council.
Note, by the way, that I'm not claiming that changes don't happen in this system. What I'm saying is that changes happen when the ruling class is convinced it's time for them, not when the populace as a whole is - and no amount of voting changes that.
The fewer people each representative represents, the closer it is to an actual democracy, which is why city councils etc generally work better (although they are still far from ideal and have the same fundamental problems I described). But the nature of modern politics weaves local issues into broader ones on higher levels, and what ought to be local politics increasingly becomes national.
If it's a particularly cheap car I wouldn't even mind if it doesn't have a screen or interface, and just supplies an API to the phone and a holder for it.
Either way would be a million times better than any car made between 2005 and 2015 has to offer.
This is how Apple Carplay works. It just streams the phone to the display, and accepts input from the car's buttons. I think Android Auto does the same.
US lawmakers : you suck.
https://en.wikipedia.org/wiki/Vault_7
you have to wonder how many vehicle 0-days nation state actors have saved up for when they need them, even just displaying the ability would grind the country to a halt because people would be afraid to even drive
Ah, so only Americans are getting shafted.
If companies want to collect such personal data it should not be by default, and each clause should have to be independently validated by the customer including what data, how it's used, where stored, for how long, who it's shared with.
Nobody will accept basically so that says something about the asymmetry here.
> Certain vehicles equipped with an interior, driver-facing camera [...] If you opt-in and link your user profile using the in-vehicle “Setup Face” process, the Face Identification feature may use your Facial Geometric Features and Profile Data... Your Facial Geometric Features will only be stored on your vehicle.
> External Vehicle Video Capture. Owners of certain vehicles equipped with [...] may also opt-in to participate in External Vehicle Video Capture...
> To use the App Suite, you must download the application and accept the End User License Agreement... We will use Voice Recordings to improve our responses and voice recognition. To facilitate functionality of your App Suite and linked third party services, your vehicle may share your Location Data and Voice Recordings transcriptions with your third party services...
(Emphasis mine)
It would be great if there was some website that collected all the detailed instructions for removing the spy devices from different car models.
edit: hah, should have just googled it first. looks like people are trying it out more now
https://www.ascentforums.com/threads/disabling-the-starlink-...
ecall is a functional safety feature of your vehicle, which, like tire pressure sensors or abs or ESR or whathaveyou has been prescribed to save human life's. it only phones home, so the logic, in case of a severe accident. automatic registry of any sim card with mobile network towers is just a technicality, according to that logic.
ecall is a prescribed feature for homologation (German: Typzulassung). if you manipulate a homologation relevant feature of the vehicle, your general operating license becomes void ("allgemeine Betriebserlaubnis erlischt")
in other words: you can sure disable it on your own car --- but that car in that moment loses insurance and you're no longer allowed to operate it on the road, except to bring it to the workshop.
that's the mechanics of "homologation" and "general operating license", i.e. the mechanics of road safe vehicles.
now, are you looking for a source of these mechanics? or a source for where ecall is listed as generic mandatory feature?
This was the first result when I searched "telematics module front speakers"
The data included timestamped GPS data, which has been demonstrated to be easy to de-anonymize.
As far as I'm concerned, this is PII. That statement is a bald-faced lie and a state AG should bring charges over this - it's extraordinarily irresponsible for Toyota to collect this data and then leak it for TEN YEARS.
Relatedly, PII sucks as a basis for privacy law. The laws enshrining PII were made in response to identity theft[2], and that's the "threat model" those laws are protecting against. They do a reasonable job protecting against that threat model, but are very narrowly-focused on that threat model.
Fine-grained location data is absolutely sensitive data, and any non-braindead privacy legislation would consider it as such. The US lacks such legislation. It would be considered Personal Data under GDPR, and Personal Information under CCPA.
[1] Actually like 400 definitions in 400 different laws, but there's a lot of similarity.
[2] Specifically, the first data breach notification law was made in response to lawmakers being the victims of identity theft. This is a common thread in US privacy laws. See also Robert Bork.
(1) ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
GDPR accepts that person can potentially be identified with reference to location data.
Anyway, "Personally identifiable information" is a weird term. Person can be identifiable in various ways. Information is just information. GDPR doesn't use this term.
In the U.S., the definition of PII varies depending in which federal department regulates your company.
My company's legal department recently sent down new PII rules, with links to the relevant federal agencies policies. Much purging of log files ensued.
I think most tech people would be shocked to see what very basic information some federal agencies consider PII.
I mean does anyone think there HASN'T been a leak of VIN numbers and owners that would be trivial to join with this?
It's also kind of staggering how long this was a problem
Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023.
Not that 10 years of data was exposed for a short period
While I don't do that, I do always use a nearby neighbor's address for my Google Maps directions. I'm sure Google isn't fooled but it amuses me.
In-vehicle control systems are typically garbage.
Several hacks have been shown where vehicle data is exposed over cellular links, in some cases with remote attackers being able to actually control elements of the vehicle (eg: Jeep).
Software updates are rare, with manufacturers often trying to charge exorbitant amounts for basic updates.
Data breaches of various customer data, credentials, PII, etc. are repeated.
IMO we are at the point where in-vehice technology is a thing that is never going away. Auto manufacturers need to become bona-fide software developers and take development, QA, cyber security, etc. far more serious than they have so far.
The dirty truth is often times these domains were designed and chiefly operated by non-software people. Not to say a mechanical engineer or electrical engineer can't program, it's just that their focus is on their work, and the software is but a tool to accomplish those means. So the world of software has leapfrogged over PLC and automotive design and gone to run laps around it several times since the 90s. It's only in say the last 5 years or so that I've seen a cultural shift in controls towards embracing the modern realities of software, networking, security, version control, databases, etc.etc.etc.
I'm not going to go too much further into this, but this is why Software Engineering as a regulated profession is going to be a necessity as much as civil engineering or electrical engineering has been. The digital world is just too vast and complex now with so many pitfalls for those who only ride the edges can handle. And people's lives are starting to matter. It is no longer safe to treat security as secondary with an "oopsy" anymore. We don't tolerate bridge collapse or electrical design that can destroy livelihoods, why do we still tolerate hacks governing data and safety of public?
Wouldn’t it be easier to regulate the quality of software used in critical products?
AFAIK similar regulatory standards and certifications exist for aerospace software.
ISO26262 - "Road vehicles – Functional safety"
But it's not nearly as prescriptive as what you have in DO-178C for example.
Nevertheless most of these telematics systems are not "considered" safety-critical in a hazard analysis unless you have OTA updates or something similar so large chunks of of 26262 would also not be applicable.
Sure, but who is responsible/accountable?
Often times I bring this topic up to have a bunch of people looking for gotchas in my overly broad wishful thinking. I don't want Engineers to be a requirement to work in software as a whole. I don't even think being an "Engineer" makes you better in any functional way than your peers. But I do believe in ideas of accountability, responsibility, ownership, and all the legalese involved with taking that seriously.
If the software is holding people's personal info, say to the point where a leak would constitute real risk, I want a Software Engineer stamping the security design to show they follow best practices and the company isn't taking shortcuts. If the software is controlling a robot that could maim someone, I want to know that some intern wasn't the one signing off to say its safe.
We aren't there yet. And there's lots of work that needs to be done to get us there. I recognize that. But I want to keep putting the bug in people's ears to have that thought for the years that come as we watch more software glitches cause harm to people, to the environment.
Unfortunately the challenge with this is still the same as always: do we even know how to engineer software, in the sense that established engineering disciplines use the term, yet?
If we started permitting only “qualified” software engineers to make the big technical decisions, who would decide on the required qualifications? Would it be the few experts who really have spent whole careers successfully developing genuinely high-reliability software in industry or researching innovative techniques for improving quality in academia? Or would it be people like career consultants who write popular books on “best practices” and give keynote speeches at conferences with big name sponsors?
The dominant trend in the software industry for years has been towards short-termism and ad-hoc everything. That often makes sense as a business strategy, at least given the current financial incentives, but it’s not necessarily the best way to promote robustness, predictability and longevity. Prematurely trying to codify accepted practices for engineering software might end up entrenching the status quo, when what is really needed as software eats the world is disruption by people who have demonstrably figured out better ways to do it.
So while I strongly agree that we need to raise standards in parts of the industry where Very Bad Things can happen when software fails, I don’t think regulating software engineering in the same way as more established engineering disciplines is a viable way to do that. Not yet, at least.
Follow the money.
Their core business depends on the sale of a manufactured good, software is not the product. Software in Automotive is a cost centre.
They will absolutely contract out to the lowest bidder (coincidently probably the least capable). Cost downs in BOMs/features are trimmed to the cent because they are manufacturing in volume so manufacturing cost per unit is King.
What we define as sane Software best practices™ is a result of an industry were Software or services via software are in fact the product.
Also people won't vote with their wallet because we absolutely post-rationalize features and UX in a car. Most people don't realize or won't admit how reptilian their decision process goes in buying a car it's 80% "do I like the looks of it" and 20% the price tag.
I searched online for how to disable it, and found this question:
https://carkiller.com/scottykilmer/qa/how-to-permanently-dis...
These responses are typical:
"But you're still going to be traceable by your phone."
"...everyone, EVERYONE, on the planet has their information out there. There is no such thing as "off the grid." "
"your phone has sent more than enough info about you to every advertiser on Earth mord than the DCM will ever do."
Many people just don't care....
Revenue = (value of data per person) x (number of customers) - (probably of data loss) x (probability of fine) x (cost of fine).
If that number is greater than zero, they'll do it, if it's less than zero, they won't.
The CEO of Toyota plays golf with the uncle of the head of the “we track you forever” group. They both feel like the nephew has a big future and there is a ton of money to be made over the next 5 years before the CEO plans to retire.
Plus, according to their marketing team, Volkswagen is worse. Much worse.
There is way less science and way more emotion at play.
So the OP's perspective is accurate. It's not all just golf and nepotism.
"The evidence suggests that Ford relied, at least in part, on cost-benefit reasoning, which is an analysis in monetary terms of the expected costs and benefits of doing something."
https://philosophia.uncg.edu/phi361-matteson/module-1-why-do...
Most variables are impossible to accurately predict. e.g. "Cost/probability of fine" -> how do you model the cost of brand tarnishment?
You don't, therefore its cost is mostly absent from budget calculations.
And if that doesn't work, you can always rename the company.
Although I still don't want them doing it if they think they can keep it safe, so may be make fines for just collecting it without opt-in consent.
If you pull the DCM fuse, you'll loose the microphone and potentially one of the right-hand speakers - these can be fixed by jumping the wires in/out of the DCM.
What's concerning to me are reports of the car still uploading all the collected data if you attach a cell phone to the radio's bluetooth. Apparently the car just relays all the info.
I kinda want to snoop that data and see what it is, at least collect the encrypted packets... but my car is from 2007 and has no connected features, so...
This must be if you have the car manufacturer's app installed. I can't think of any other way for it to phone home from DCM via buetooth if the cellular module is disabled.
Unfortunately as far as I can tell it only actually stops after the "remote connect" trial period ends one year after you buy a new vehicle that opts you in automatically. There are probably ways to physically disable the data collection modules for this, if you're comfortable tearing apart your car's dash. https://www.tacomaworld.com/threads/2020-data-transmittal.63...
If a lot of people start regularly sending CCPA delete requests to these companies maybe they will stop gathering this data.
I think it's a shame that the EV regulations and incentives (at least in America) are not as friendly for traditional hybrids and plug-in hybrids. They have basically zero downsides compared to full ICE or full EV, and would still make a massive dent in emissions.
PHEVs in particular - most people are going under 100 miles a day, so there would be 0 emissions.
For example, the electric-only range for the 2012 Prius PHEV is 15 miles, not enough for many people's daily commute unless you can plug in at both destinations. The 2023 Prius Prime is around 40, which is much better, so maybe you can just plug in at night at home.
It is only the 5th generation Prius that is truly designed around having a higher capacity battery pack, ditto for the recent RAV4 PHEV model. The 4th gen Prius fits in the larger battery pack as compromise, with reduced cargo area and wasted volume.
I would have bought a Prius Prime in 2017, and tried to get the tax credit, but there were several issues. There weren't many available in my area, the standard 2017s had driving and parking assist, while the Prime did not, reduced cargo area with no spare tire, and the price, because even with the tax credit was a bit too high for my liking. Just went with a standard Prius instead, and definitely have not regretted the choice. Today I'd buy a PHEV RAV4 or 5th gen Prius though.
Once we collectively get over range anxiety a whole new world is going to open up in EVs.
I agree that huge batteries are a waste, but I think there's basically no future in fossil fuel ground transportation. Hybrids are a transitional technology we might use for awhile because we don't have the EV production capacity.
In the long run I think we're better off electrifying our major highways so cars and trucks can charge without stopping. There are several ways to do it, of which induction is the least practical and most expensive.
They need oil changes. Some don't mind, but I do. It's a downside.
IMO getting under your vehicle twice a year is a good thing and more people should be encouraged to do it. Getting eyes on the stuff hidden underneath before it gets bad enough to start breaking is always useful.
This is honestly not true - there is an order of magnitude less parts in an EV drivetrain vs a modern ICE car. You can go a decade between seeing a service center in an EV, largely thanks to regen braking/one pedal driving allowing you to avoid new pads or discs. There is no transmission in virtually all EVs, with drive direct from the motor through a fixed gear etc. The motor's moving parts are effectively friction free - the rotor and stator in an EV never touch, so there is no wear.
I think anyone currently running both an EV and a gas car will have similar experiences; The EV needs tires, cabin air filters and wiper blades from new to the 10 year mark, there are no other regular trips. The only scheduled fluid change on a tesla is a relatively inexspensive 10 year battery coolant swap.
My suspension and brakes get inspected for safety issues every time I get new tires on the EV - I'm fine with not getting under it too.
I’m almost there with the old-school way: a manual transmission and downshifting to decelerate.
While not as effective, drum brakes really lasted a while.
For people like myself, looking at the underside of a car is worthless. I wouldn't even begin to be able to recognize something needs attention until it's very obviously broken. And even then, I might not know.
If you're paying someone else to do it, presumably they're a set of eyes that's a bit more experienced with cars and can more confidently identify the sorts of things one could see from the perspective of an oil change.
EVs do have downsides, but so do ICE and hybrid.
And that doesn't count how much better things get if you fully charge the electric 25-mile range battery and measure the mpge.
Additionally, I offer into evidence what happens if you rent a Prius Prime and drive up to the valet at the hotel of your choice. Answer: they won't come and help you. Reason: they'll think you're an Uber driver. Upshot: the idea that Uber drivers could or would eat the cost of worse gas mileage due to dead weight is fatuous.
Toyota does a 10 year manufacturer warranty; the availability and price of used ones older than 10 years (I think they're called Prius Plug-in) should tell you that Toyota has a handle on the complexity of the system they built.
Toyota. Oh what a feeling.
Also, anyone who has one: hit me up if you're thinking about getting rid of one of these pieces of dead weight.
Yes you need big teams to deliver huge projects. Operating systems, compilers, languages, etc all take huge investment to build out. The thing is though the initial conditions have a massive downstream effect. The core contributions by genius 10x computer scientists and software engineers set the pace for everyone else. Unix, C, Linux, Git, LLVM, Perl, Python, who knows what else. It's the individuals or small dedicated teams doing it the 'wrong' way, or going for a weird untested approach that starts a small speck that snowballs into huge multi-billion industries.
The culture and economic conditions in the US are perfect for this to work. Japan, and for different reasons and certainly not the the same scale Europe, not so much.
It's still not clear when (and if) the ev transition will happen. There are many unknowns.
The robot had odometry from the wheels, though it was a bit noisy due to the construction of the omnidirectional mechanism. They decided to ignore wheel odometry and use only an odometry module based on the planar lidar, essentially visual odometry. This worked fine in most circumstances, but basically completely failed in hallways as they lacked distinctive features. This interfered with my work which involved the robot navigating around the office.
I had worked on this problem before, and ROS has an excellent sensor fusion library for dealing with multiple noisy sensor readings. You just need to combine wheel odometry and laser odometry with a kalmann filter, and the sensor fusion library makes this relatively easy.
However even though I worked at a Toyota office with full time Toyota employees, and the code was pretty much off the shelf ROS code, and the robots were produced in very low volumes and only in use at Toyota, they wouldn't give me the source code. I think maybe they wouldn't even give me root access.
Still, I was able to control the names of ROS topics using the ROS launch files (it has been a while since I worked with ROS and I forget some of the terms). I remapped the lidar odometry topic to an intermediary topic name instead of /odom, then directed the intermediary topic in to the sensor fusion module along with the wheel odometry, then mapped the sensor fusion output to /odom. The system got odometry information but now it did not come from the lidar odometry but from the sensor fusion module, so it was happy.
The fix worked great. It had normal behavior when lidar was good, and had reliable odometry in long hallways. I was finally able to implement my office navigation code.
I did my best to communicate these changes back to Toyota. They had not been very helpful when I was asking for help solving the issue, but I had hoped that since I had it working they would appreciate this. I asked where I could file a git issue or otherwise push the code to some private git repo.
They were not using git. Ultimately I was instructed to email the raw code files I had used along with instructions for how to integrate it. I found this quite surprising. I have no idea if they ever implemented the changes I suggested, but I kind of doubt it. From what I have heard of japanese software practices, they basically do not accept code suggestions from the bottom up.
I know of some people who worked for Toyota Research Institute who said they were trying to get the Toyota folks to integrate silicon valley coding rigor in to their systems. Maybe they had success, I don't know. But certainly 6 years ago things were a total mess.
That's not "silicon valley", that's "anywhere remotely modern" coding rigor. Sounds like they need to get with the times, especially with regards to developing systems with software stacks that are a couple orders of magnitude larger than in the recent past (like 15 years ago).
This was refreshing to read. Within my bubble in tech, it's often easy to get jaded about how _unrigorous_ our "engineering" often is.
What exactly makes u come to this conclusion?
https://www.economist.com/asia/2023/04/16/how-japan-is-losin...
But any of their engineers could tell them the same thing, so what'd be the point?
I used to have a Ford. Their app was generally good but I think all you need is the VIN to add a new car. Now you have the ability to track that car, lock the doors, remote start it, and so on.
All second-hand car buyers should get their car's app and activate their car on it to lock out all other sessions - hopefully.
There can also be other devices similar to a black box in the vehicle which record data and store it in case of a crash for forensic purposes. I would leave these alone as long as they don't have network connectivity.
The result is that that we are no more than five years away (at most) from the surveilance economy getting a terminal stranglehold on society.
You will not be able to buy a car that is not always dialing home, the same way you already cannot buy a mobile that is not always dialing home.
In any case you will not be buying a car. You'll be buying a subscription to a car, renewable annualy under certain (small-print) terms of service.
Cars will not work without some insurance conglomerate receiving all information it wants and trading your behavioral data in opaque insurance markets.
Cars could stop working at any point. A digital roadblock is much cheaper and more comprehensive that a physical roadblock.
Taking public transport was never private (its in the name after all) but this mobility mode too is getting deeply integrated in the surveillance economy: you will only be able to pay for a trip using identifying mobile devices.
The argument is that people "don't care" about the direction things are taking. This is the most evil argument ever advanced.
This is one of the biggest reasons I left, as I couldn't agree on an ethical level with the decisions around customer privacy.
https://www.toyota.com/support/privacy-notice/
https://web.archive.org/web/20230512181415/https://www.toyot...
For example, under the category: Sensitive personal information or data, such as precise geolocation data, biometric information for the purpose of uniquely identifying an individual, account login information, driver's license, and financial information.
... > Purpose of Processing: For location tracking, to identify you, and to provide services to you.
> Other: We may have used and disclosed your Personal Information for other reasons described in the How We Use the Information We Collect and How We Disclose Information sections.
...and the section 'Sensitive Personal Information' for their explanation of limits on what they do with it.
...and:
Your Privacy Rights: 4. Right to Know and Access... You may have the right to request that we provide you with the Personal Information we have collected about you, including the categories of Personal Information; the categories of sources from which the Personal Information is collected; the business or commercial purpose for collecting, selling, or sharing Personal Information; the categories of third parties to whom we disclose Personal Information; and the specific pieces of Personal Information we have collected about you.
>This incident exposed the information of customers who used the company's T-Connect G-Link, G-Link Lite, or G-BOOK services between January 2, 2012, and April 17, 2023.
>T-Connect is Toyota's in-car smart service for voice assistance, customer service support, car status and management, and on-road emergency help.
Well, at least one does. Me. The risk of that is the primary thing that is in my mind, over literally every other aspect of the car.
I also wouldn't trust that any controls to not send data would actually stop all data from being sent.
Chevrolet has had OnStar since 1996, and has sold data related to it for probably just as long -- this isn't some new phenomenon.
I remember these same arguments echoed back then -- but at least it was a unique happening at the time.
A bunch of Toyotas have a telemetry module (basically an LTE modem tied into the can bus and the head unit), but the introduction date varies.
Tacomas for example didn’t have it until 2020.
I’m not sure though if this data is/was getting pushed through that or something else.
> The Toyota Production System (TPS) [..] is based on the philosophy of the complete elimination of all waste in pursuit of the most efficient methods [it] has evolved through many years of trial and error to improve efficiency based on the Just-in-Time concept developed by Kiichiro Toyoda, the founder (and second president) of Toyota Motor Corporation.
Or their home address? Location data is absolutely PII and easily deanonymized. Am I missing something?
But I've asked people who work with automotive computers whether any cars just automatically track you and store the information in some on-vehicle storage. No one seems to know, but they all think if any did, it would be manufacturer- and model-specific.
Privacy doesnt exist .. until its Politicians privacy on the line https://edition.cnn.com/2022/06/14/politics/house-vote-supre...
What other options are there? I would SO willingly pay thousands of dollars specifically to have these features disabled on a new car, but it seems like they're actually designed for that to be impossible.
What options are there for acquiring and driving a car with no internet or satellite connections?
(I'm not trying to stop some other-purpose satellite from being able to see my car if it wanted. I'm trying to prevent a car company--which is NOT a security company--from having a record of everywhere my car has been at every moment of every day where someone can steal it.)
I guess that’s a long way of saying that if we ever have to get new cars, all we need to do is find the wireless antenna and disconnect it.
Note that if your car is new enough to have CANbus, it surely has software too.
However, you can disable this by following a procedure explained in the owner’s manual (basically, you call Mazda and give them your VIN.)
I’ve also seen similar “opt-out” procedures listed in a Toyota GR86 owner’s manual.
I’d prefer to just pull the car’s SIM card to be absolutely sure :-)
I'm sure their internal incentive structure also does not reward people to join/stay at the company who would focus on the problems that this story points out.
Please don’t say “they’re tracking your location anyway” unless you have evidence. This is Hacker News not Conspiracy News.
I wonder how long they hold onto the data before erasing it or if they hold onto to it indefinitely. I don't remember seeing specifics in the EULA about the length of time they hold your data - only that they can and will sell it to 3rd parties.
I would love to be able to download the whole shebang of telemetry so I could reassess the quality of my driving, but no, no can do, secrets much.
I need to have a whole dashcam of my own to film my trips, run the cables for it myself, while Toyota is just hoarding this data for itself and some random dude on the internets can just view it.
Won’t nobody think of GDPR these days?
I am one of those loons who doesn't carry a cell phone, so this is important to me =D
Also, why should Toyota store location data in the first place?
Just this would reduce the value of obtaining such data.
The privacy aspect is harder to deal with, but it's not obviously clear that a majority of people care. GDPR helps focus minds in large corporations s and maybe that's enough.
You know what wasn’t a problem before some idiots decided to hook cars to the internet?
None of this. Unbelievably stupid choices top to bottom.
Still going to keep my cars
As long as they don’t start trying to charge me for the seat warmer
Enough to make me not buy a new Toyota ever again.
So: CASH purchases, only.
In the EU: cannot disable (legally)