Tesla Fleet Telemetry
github.com
github.com
Complete non-sequitur.
“We care about your privacy”
“Here’s a way to share private information with others”
Also, un-stated “there ain’t nothing you can do about sharing your private data with us”
Cool that they give you a way to access some of your data at all though, I guess
FWIW there are settings in the car to disable certain things. Not sure how much it _actually_ disables though.
In reality though, I assume they still do it and merely pretend they comply with it.
You can turn off lots of data sharing and monitoring settings in the standard UI in the car, last I looked it wasn't even hidden behind any dark patterns.
The actual concept of privacy is entirely in line with their idea that you "should be able to decide what data [you] share with third parties, how [you] share it, and when it can be shared"
Seeing this after the whistleblower/leak regarding Tesla employees having unfettered access to onboard camera footage (and that embarrassing/compromising footage of customers was actively shared internally) is... rich.
While I understand the alarm, it was also completely unsurprising even based purely on the company's public statements about how they use data from the cameras.
Video footage being shared with/accessible by Tesla should be strictly opt-in - especially for "sentry mode", which is the most likely to catch someone in their skivvies (or worse) in their garage.
I'm not saying that it is right. There's a real lack of transparency here, especially considering how many people seem blissfully unaware.
I think it's apples and oranges though. With a photo lab the customer has deliberately handed over whatever images they want developed, whether the images are private or not. Tesla employees sharing images from cameras that some people may have plausibly not even known were there feels like much more of a violation.
If an vacation rental landlord planted secret cameras and...
Bad news all around.
Yes, secret cameras can get the host in trouble, but poke around at airbnb listings and you'll see cases where everyone reports highly visible internal cameras.
I'm not saying its good.
Remember the olden days of photo labs at the mall that would run the pictures visibly in front of the window?
They don't do that any more, but the employees still point and laugh while they are in their possession. Right or wrong, it is human nature, when they all technically have access.
The fact that they could share them amongst themselves is also not particularly surprising.
It's not that the could, it's that they did.- Murphy's Law of Sharing
Private information means the user controls their data. They will often do things privacy advocates don’t like or think are dumb. That’s the privacy advocate’s problem, not the user’s.
Are predditors now coming to this site to spread their "spaceship man bad" propaganda? There are obvious switches that toggle data sharing. A quick googling would have revealed that: https://electrek.co/wp-content/uploads/sites/3/2017/05/tesla...
So yes, by building a framework to allow users to authorize third party apps to receive limited telemetry data without handing over their full Tesla account keys this may allow for an improvement in privacy for those who want to use such apps.
This is also more efficient on Tesla infra (streaming telemetry data), vs aggressive polling (what current apps do, typically slow polling when vehicle updates are minimal, such as when parked, and then switching up to aggressive polling when traveling at speed).
It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week.
>> Feb. 2002. A Connecticut man has taken a local rental-car agency to court, after the company used Global Positioning System technology and fined him $450 for speeding.
https://www.cnet.com/culture/rental-car-firm-exceeding-the-p...
If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted to as extra guardrails (with violations being an API access death sentence, killing the app business).
The different OEM approaches between the US and EU show you how important legislation is. Especiqlly since Tesla's zrack record regarding privacy is abysmal.
Any particular examples you can share with us?
Also, why would I want cameras inside my car? But that question is off topic.
Probably not entirely legal no matter what EULA says, at least not in EU
> If it is in the EU, yes you do
Then complain about (the lack of) US consumer protections, not Tesla.Funny thing I wanted to point out though, you sound like one of those people who say "I will buy a car that runs on gas, I've never wanted a vehicle that runs on electricity and my next one won't either... Not if I have anything to say about it".
I feel like I've seen so many of those comments lately... I want to ask why?
It's like me saying something like "my phone doesn't have a screen. I've always had an analog connection and I've never felt the need to have a digital screen and any smart apps on my phone... Etc etc not if I have anything to say about it."
Or perhaps even something like not wanting an automatic transmission because a manual transmission is the only way to go lol..
The parent isn't rooting for ICE, he's rooting for having a vehicle that doesn't stream data to the outside.
There is nothing that mandates that a vehicle -whatever its technology-, must send all its data to external servers.
I, and many others, want to have the right to possess a car that isn't relying on external connections to work, and doesn't send all its data out.
It's more akin to wanting a TV that's not connected online. Some people like the added features of a smart TV, but some just want a dumb screen that doesn't sell their viewing habits, or screenshots of what's on the screen to third-parties.
It's a shame then that the few laws we have protecting consumer's privacy are not adequate to the task. It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved.
As an aside, how do you know that the apps you use aren't selling your data? Is it only because of their entirely non-legally binding statements and privacy polices? What do think could happen to that data when those apps/companies are sold or otherwise acquired by someone else? Even if they were telling the truth about not selling your data right now, do you think that means it isn't readily available to police or the discovery process in a legal dispute? Do you think that data collected or displayed by the apps could be exposed to Google or Apple and collected?
> It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved.
Agree to disagree. If the cost of loss is low, to go without the product or service is more costly than potential data loss. The services I use within this context are very likely not actively lying about their privacy policies.
That is hardly the worst case outcome. The worst case outcomes would be those where that data is used against you because it was sold/leaked/subpoenaed. There's no end to the ways it could be used against you either.
Maybe a future potential employer doesn't like how often you visit bars, or what church you attend, and you are passed over for a job you want.
Maybe your car's recorded proximity to where a crime took place makes you a suspect in a crime you had nothing to do with and it costs you tens of thousands in legal fees to clear your name. (similar to what happened to this guy: https://www.nbcnews.com/news/us-news/google-tracked-his-bike...)
Maybe that data gets pulled up in a divorce or custody battle. GPS records and toll transponders are already being used in such cases to show things like patterns of working late hours, visits to girlfriend's houses, or undisclosed income
Maybe that data is used by advertisers to more effectively manipulate you into parting with more of your money.
Maybe your insurance company (health or auto) buys it up and their algorithm decides to jack up your rates because you hit up a fast food drive thu once too often or you speed too much or drive to many hours.
Maybe you visit or even park too close to a gay bar, mosque, or planned parenthood and you get harassed by an extremist group or dragged into a Texas courtroom.
Because the data never goes away, it can follow you for the rest of your life and be used by others again and again at any time in whatever way the person who gets their hands on it feels will benefit them.
> Agree to disagree. If the cost of loss is low,
Everybody is free to decide for themselves what level of risk is acceptable to them. With some kids you can tell them that the stove is hot and they will leave it alone, while others have to touch it and get burned.
I hope that you never suffer a consequence that makes you regret the data you gave away, assuming that you can trace it back to that data in the first place. At least you can say you were informed about the dangers and made an informed choice to roll the dice. I worry a lot more about the folks who don't even realize what data is being collected, the ways that it can be used against them, or who assume that they can count on laws and privacy polices to protect them from harm.
Take this as my opinion only, and I appreciate that some people don't have the luxury of this opinion, but for me there is zero Venn diagram overlap between jobs I want and employers who are as creepily obsessed with my private life as that.
> Maybe that data is used by advertisers to more effectively manipulate you into parting with more of your money.
If you want to frame advertising as manipulation, then I suppose so. Personally I don't see it that way. If I see an advertisement for something I want and I end up buying it, that isn't any more manipulative than seeing a particularly attractive banana in the supermarket and buying it.
Advertisements are a way for people who make things or do things to find people who want those things. Successful advertising isn't a bad thing so long as it isn't dishonest. I think if there's a 1% chance that I'm more likely to become aware of a product that actually interests me, I see that as a win for me. I have finite money and I'd rather spend it on things I want more than things I want less.
> I hope that you never suffer a consequence
I'll happily wear that risk. I greatly prefer it to the alternative, which is the guaranteed suffering which results from being obsessively paranoid.
I feel the same way, but employers aren't going to tell you they're digging into your personal life or why you were turned down for the job. You just get ghosted. The problem isn't limited to employers either. It could be a landlord, or a bank. Part of the problem is that you aren't allowed to know when it's happening which makes it hard to avoid.
> If you want to frame advertising as manipulation, then I suppose so. Personally I don't see it that way.
Ads can be informative, but when was last time you saw an ad that wasn't in some way manipulative? If you can't even see that it's happening, you're likely more susceptible to the effects, but even you know it's happening you're still influenced by manipulation. We all are. Ads are carefully designed to exploit flaws in our brains. Ad companies have spent massive amounts of money and research to maximize the effects, even experimenting on children to learn things like how early a child can recognize a brand.
> I'll happily wear that risk. I greatly prefer it to the alternative, which is the guaranteed suffering which results from being obsessively paranoid.
You know what the say, it's not paranoia if they're really out to get you. The examples I gave of the harms that can result from abuse of your personal data are based on things that have already happened. People might be happier if they are blissfully ignorant or can convince themselves to ignore what's going on, but I feel better if I take some simple steps to avoid potential harms and stay aware of what's happening in the world. It's pretty easy to just not buy a car that collects your location 24/7 and even easier to avoid giving that data to unnecessary apps.
So I don't learn why I didn't get a job I definitely wouldn't want. Perhaps not the ideal outcome, but not far from it. I really don't understand what the problem is here.
Would I prefer if I accidentally ended up working for an awful person because I never gave them a chance to reveal their awfulness? Absolutely not. I don't want to work for an awful person even if they never get a chance to be awful to me personally.
> even [if] you know it's happening you're still influenced by manipulation
I reject your framing but to the extent there's any truth to it, I'm going to be manipulated by ads no matter what. Given that, I'd rather be manipulated by ads that are better targeted to me. This is an important point — manipulation is mostly orthogonal to targeting. Especially since hyper-targeting quickly becomes overtly creepy and loses its manipulativeness.
Considered holistically, there's no downside for me being targeted rather than broadcasted. In fact if targeting means that a company's customer acquisition costs are lower, there's a non-zero chance it could result in me paying a lower price for something I would have bought anyway.
Would you say the same about the house you wanted to buy/rent or the loan you needed? It just makes it easier to hide discrimination that would otherwise be illegal. At least the bigoted HR person in charge of screening applicants is probably not someone you'd interact with once hired.
> I'd rather be manipulated by ads that are better targeted to me.
I doubt I can change your preference for targeting advertising, but I will offer you a few perspectives on the subject you might not have considered:
It was manipulation through ad targeting that made that whole Cambridge Analytica situation such a problem.
Targeted ads artificially limit what new products and services you get exposed to only those things companies "think" you want, or what advertisers want you to buy, or whatever will make them more money vs things you might really be into or prefer if you'd had the opportunity to hear about them. It allows them to shape culture and segregate populations. This is a similar problem to the "filter bubble" found in search engines.
knowing that we're vulnerable to advertising, I'd much rather be tricked into forming an irrational association linking happiness, or acceptance, or well-being and a product that I know I'll never or rarely buy than have that kind of trickery influence my choice between two products of a category I buy often.
The real bonus is that it appears as if this update will help isolate the app from the vehicle. What I mean is that the current way these apps work is they poll the vehicle for data. This is bad because it (potentially) wakes up with vehicle and increases battery consumption. The way I understand it, this new method will allow apps to "poll" Tesla instead, which is a much better operation.
(zero points for anyone pedantically pointing out that this is technically first party sharing)
What value does it add?
Which is: Tesla doesn't even want collect telemetry and then re-share it to 3rd parties. Tesla wants to provide a mechanism for the car to connect directly to a customer-authorised 3rd party telemetry collection service. This relieves Tesla from having to function as a middle-man and facilitate things like claims in tokens and granular permissions.
In 2023, I'm amazed that this is still a thing. I'm also sad that users are so uncaring about their data that they are cavalier to just provide credentials to 3rd parties just because they pinky swear they'll not be evil and the use of their app is super worth it. I still remember the first time a coworker was singing the praises of some money/finance app that I decided to try. I immediately stopped and said nope when I realized they needed my user/password to all of the banks I wanted to connect. I feel sorry for people that feel the juice is worth the squeeze, especially when they get squeezed dry. Maybe it's not the 3rd party company, but the possibility of hackers that attack said 3rd party. Just too big of an ask
Only slightly related, but buying a Tesla they encourage you to use Plaid for payment. Which involves… giving your banking account username and password to a third party.
Extremely bad. I can’t believe anyone would do this.
Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario.
Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them.
Why is it inherently bad to trust a 3rd party?
US Banks not only use SMS for 2FA, many of them REQUIRE it for 2FA.
They also tend to require "security questions" that are usually easily guessed or researched. Again, information that makes it easier, not harder, to get into your account.
Good luck trying to find a bank that uses hardware tokens.
> Why is it inherently bad to trust a 3rd party?
Because doing so substantially increases the attack surface and historically third parties have done a terrible job.
For example: every app that uses SMS 2FA inherently trusts the customer's cell phone company. Companies which have done little to address identity thiefs porting out numbers, requesting replacement SIMs, etc.
You don't need to lecture me on how trust delegation works. I mean you use a bank right? You trust a 3rd party with your actual cash. Plaid hasn't demonstrated incompetence, have they? In fact it seems quite the opposite. There isn't any legitimate case against using them aside from "I literally don't trust anybody" which is hypocritical if you use a bank in the first place.
Why would I use them?
Anyway my bone to pick is with the “3rd party instantly bad” mentality. Your bank probably uses 1000 and 1 3rd parties too. Our banking regulations are focused on making sure money depositors aren’t taken advantage of and harmed by unhealthy or risky asset management practices. If you don’t find Plaid valuable then thats fine, you do you. I do wonder how you can know that without using them though…
Also, have a quick look at the "data we collect" section of their privacy policy and see if you still feel the same way: https://plaid.com/legal/
It's shockingly broad, and 99% of it is stuff that they have no business collecting when all I'm trying to do is buy a car.
Here's what happens:
Tesla says I want to verify that a human is purchasing a car, take a deposit, and get the information needed to pre-approve the customer for the loan required to buy it.
Plaid says, we can do that for you. Plaid has you link your bank account so it can 1) verify your identity, and 2) give Tesla the information needed to debit your account. Then Plaid pulls your account history and asks you to link additional accounts as needed to get the relevant information for the underwriting process.
This allows Tesla to complete this process entirely online without a dealership in about 2 minutes. If you've ever bought a car traditionally, applied for a loan, or even linked bank accounts into a budgeting app, this is an incredible UX win for the user. Shocking, even.
I.e. my own home server.
They also record the road and the way you drive it using cameras in the vehicle you own and paid for, upload it using your home internet connection and improve their self driving model which will no doubt represents $billion's, maybe $ trillions of enterprise value over time.
A Tesla is not a normal 'dumb' car, and you accept that going into it. Allowing consumers to have fair access to that data in a safe manner that doesn't involve sharing usernames and passwords is actually the right and responsible action on Tesla's part.
...can't activate a phone without connecting to apple
...privacy policy is hundreds of pages
...can't block apple
Fleet as defined in Oxford Dictionary: “A number of vehicles or aircraft working together, or under the same ownership.”
(edit: use actual Oxford definition)
That's a fleet. You may not like it, but that's what Tesla owners knowingly opt-in to.
> WASHINGTON, Dec 12 (Reuters) - The U.S. new vehicle automotive fleet's fuel efficiency was flat in the 2021 model year as automakers sold more sport utility vehicles and pickup trucks compared to cars, while the Detroit Three lagged behind foreign competitors and Tesla.
> The U.S. Environmental Protection Agency said on Monday the fleetwide real-world average was 25.4 miles per gallon in the 2021 model year, the same as in 2020. The EPA estimates the 2022 fleetwide efficiency average will rise to 26.4 mpg.
That's referring to every car in the United States with the collective noun "fleet". It implies no ownership.
Seems like this allows vehicles to connect directly to your own server instead of having a Tesla server act as intermediary. Will it be free to use then? I guess Tesla is still footing the bill for cellular bandwidth used, so it probably won't be free.
Also authentication tokens are done locally and refreshed nicely so no fear of leaking tokens/passwords.
I assume this means that Tesla devices can be configured to speak the client end of this protocol, and that fleet operators might enable it. If so, that’s kind of neat.
Of course, it would be nice if Tesla telemetry non-fleet vehicles worked the same way and could be turned off.
pov you are headed for a collision and something is wrong. you issue a describe command ...
Type Reason Age
---- ------ ----
Normal Sync 100s (x3 over 100s)
Is that an expected status for this component? The distance narrows ...[0] https://thenewstack.io/how-the-u-s-air-force-deployed-kubern...
hoping 'deployed in 45 days' doesn't mean what I think it means
Even if you could overwrite the software on the car, you'd still have to contend with the physical controls available to the driver. The steering wheel is physically connected to a typical rack and pinion setup. The brake pedal is physically connected to hydraulic lines just like every other car on the road. And like most cars, the brakes are more powerful than the motor.
1. There's no official documentation but a big chunk of it has been reverse engineered: https://tesla-api.timdorr.com/vehicle/commands
If only...
The way I understand Tesla's meaning of "data they need" is the data that you know exists, know is useful, and has a predefined purpose. However, blind data mining can often bring insight that may give you an edge over competition, so the unethical data collectors have an advantage.
On the other hand, collecting all available data makes you biased by the particular nature of data collected - not everthing that is measurable is important, and not everything that's important is measurable. Even 100% accurate data can lead you astray if it gives you an incomplete picture. That's how we got algorithms that optimize outrage, because outrage and stress create massive engagement.
I mean, in this case, it's not a "problem", it's a predetermined goal. It's not some sort of accident that they optimize for engagement, it's explicitly what they want to optimize for. The fact that it causes harmful interaction isn't an unwanted side effect, at least for the social media company, but a means to an end.
Not making people unhappy is good for business. Or at least I hope it is...
Also fuck the National Highway Traffic Safety Administration for telling auto makers to ignore a very well intentioned state law.
[0] https://github.com/teslamotors/fleet-telemetry/blob/main/pro...
[0] https://www.macmillandictionary.com/dictionary/american/on-a...
why do they do `helm repo add teslamotors https://teslamotors.github.io/helm-charts/` instead of
`helm repo add teslamotors https://github.com/teslamotors/helm-charts/` ?
isn't the first one a webpage rather than a repo?
I'm not sure which bits and pieces are included without poking through the code
https://www.reuters.com/technology/tesla-workers-shared-sens...