Privacy Nightmare on Wheels’: Every Car Brand Reviewed by Mozilla
foundation.mozilla.org
foundation.mozilla.org
Internet-connected cars fail privacy and security tests conducted by Mozilla
3 days ago|632 comments
Am I reading this correctly? I could be a passenger in my friend's Subaru, or even in an Uber, and they claim they have a right to my personal data? Surely this isn't legal, there's no way they could claim to have consent for this...
How is this data tracking any different from what google, twitter, or Facebook use? If it’s legal for tech companies to collect user data, why would it be illegal for car companies?
To use an application from one of these providers, you explicitly have to agree to their terms and services: a contract between you and the company is established. How is that equivalent to taking an uber?
The Services may be made available or accessed in connection with third party services and content (including advertising) that Uber does not control.
https://www.uber.com/legal/en/document/?country=hong-kong&la...
What’s different here is that car manufacturers are claiming that, say, sitting in that Uber gives them the right to record your audio and sell it to advertisers. That’s illegal in many places such as the EU or states with two-party consent laws, and it’s unlikely that courts would accept it elsewhere without some kind of informed consent.
you accepted the tos, you've been informed, that's not unlawful if you gave your consent and the data is kept in the EU.
Moreover, the article is claiming that the manufacturer can "maybe even sell" the recordings but the official statement is that they are only collecting the data, not selling it (it would be stupid to claim otherwise).
The blog post specifically use the sentence and maybe even sell, because it is not stated anywhere.
> and it’s unlikely that courts would accept it elsewhere without some kind of informed consent.
meanwhile the advertisers already used your data, and there's nothing you could do about it.
Except not using Uber (that's why I never used one, even though cabs in my Country and especially in my city, are a big "mafia style" mob)
Are you seriously saying that everyone who gets in an Uber signs a form the driver gives them saying that the car manufacturer might resell all of their data?
No, I am saying that Uber can collect that data itself through the app.
I was replying to "To use an application from one of these providers, you explicitly have to agree to their terms and services: a contract between you and the company is established. How is that equivalent to taking an uber?"
It is equivalent because to use Uber you have to accept their license agreement.
Nobody ever explicitly said "resell" because it would be stupid.
It's allegedly proposed by the blog post, but it's not officially stated anywhere.
BTW as written in the part of the Uber TOS I've quoted, they explicitly says that the service can be provided by third parties "outside of their control" and you accept their terms of services by accepting the service provided on the Uber platform.
So yeah, you could be accepting to have your conversation recorder by the driver (or by an autonomous vehicle which is considered a third party provider) or your orders being linked to your persona by the restaurant.
Third-Party Services and Content.
While many Third-Party Services are available in the Uber App, certain Third-Party Services or content are only accessible by exiting the Uber App (“Out-of-App Experiences”). Once you click on a link to access Out-of-App Experiences, you will be subject to the terms and conditions and privacy policy of that website, destination, or Out-of-App Experience provider, which are different from Uber’s
Don't use Uber, it's all I'm saying,
But you are right that this is illegal, because just sitting in a car is not a “specific, informed and unambiguous indication of the data subject's wishes”, which mandatory for consent (GDPR article 4(11)). Neither it is “transparent” (GDPR article 6(1)a).
You can write anything you want, but no that doesn’t make it a valid contract.
Seems very similar to me.
- collected by FB
- without even the pretense of consent
- sold to the highest bidder
I don’t think FB is arguing they have consent for shadow profiles. Where Subaru’s argument would presumably extend to secretly uploading and selling conversations that took place in a car they no longer own.
An unsuspecting person (Alice) ends up with a shadow FB profile because someone (Bob) who actually created an account (therefore having an opportunity to read terms of service) decided to take a photo of Alice and send it to Facebook.
An unsuspecting person (Alice) ends up with Subaru having an audio recording of what they said because someone (Bob) who actually bought the car (therefore having an opportunity to read terms of service) decided to invite Alice into the car.
In both cases, the company receiving Alice's information would likely say that Alice should take issue with Bob's behavior, not the company's behavior, if they don't like the situation.
Whether it’s legal or not is menaingless given the power imbalance.
you might upset the status quo.
worse, you might succeed, proving all the naysayers to be both negative and wrong.
1. Certain rights cannot be easily waived depending where you live — this requires "informed consent". Informed consent means you laid out what you are collecting and for which purposes clearly and in easy language — and that I consented to that.
2. Implying consent through action ala "by entering these doorsteps you have signed away your firstborn child" doesn't work.
3. At least under the GDPR not consenting shall not lead to a worse service.
If I enter the car of some guy and his cars manual (available only as pdf download) says on page 234 that he automatically consents to this by using the car, the manufacturer did neither gain his, nor my informed consent.
This is illegal under the GDPR — a law that doesn't only apply to cookie banners and the internet, but to any form of data collection.
(In the EU of course)
I am assuming it doesn't go that far and is referring more towards eye/hair/skin color...maybe just a CYA in case they "accidentally" collect info that could be identifying on a level not allowed (discrimination/privacy laws?).
For example:
https://www.smithsonianmag.com/science-nature/scientists-pul...
Note, this is not a justification, but an attempt to understand how we got to now in hopes that by seeing where we've been, we can collectively make better decisions about where we are headed.
Widespread breach of privacy is not a valid excuse for companies to continue violating privacy and even collecting potentially illegal surveillance, right? Phone taps and home searches without a warrant have been illegal for decades, and the fourth amendment to the constitution prohibits government search without probable cause in general. So what I expect is that the existing and established laws and goals carry forward in obvious and reasonable and unsurprising ways from the consumer’s point of view, without vested interests trying to pretend like digital devices’ ability to communicate are somehow radically different from any other type of communication. The only thing that’s changed is that recording and sharing and searching got much, much faster and easier. People who stand to benefit from that are arguing that because it got easier, it should be allowed, but from the privacy perspective it’s the opposite: because it got easier it means we need to actually enforce privacy, and put a stop to the contorted arguments that try to justify data collection without explicit consent.
This is slowly changing, but with 50 member states and aging union leadership, there is no GDPR equivalent yet for citizens of the US.
(And, CCPA protections are only offered to citizens of California, which demonstrates the corporate incentives to keep it fractured and at the state level nicely.)
The most effective way to get this changed would be to identify the cars used by every US senator, and then write them letters pointing out that their cars have granted a sometimes-foreign corporation permission to record every conversation they have, keep a file on who they meet, and document their sexual activities. This is standard espionage tactics, and as awareness of it should be spread in Washington DC in particular.
US corporations now demand you give up all rights that the law permits you to give up, and they do so by shrinkwrap licenses that are “take it or leave it”, while denying the ability to deactivate a reasonable and small subset of functionality if the buyer disagrees.
This is typically where regulation steps in, and does so quite successfully in the EU but not the US, to say that consumers may not contractually give up their right to privacy without express, plainly-sought consent — so, not just shrinkwrap licenses — and that refusal or revocation of that consent shall not deny someone access to functionality that can be reasonably delivered without it. The US has its work cut out for it to catch up here.
It sounds like it's no longer even an option to buy a car that doesn't come with a bunch of uplinks to the car company, maybe to the insurance company airplane-black-box-style, etc.
If the tech exists, it will be abused.
We—as in most people on this forum—can do much more than that. We can actually refuse to work for these companies, and to build such features. We can implore our colleagues to do the same, and inform our family and friends of these features, and suggest alternatives.
Yet many of us don't think twice about working for an adtech company, because of the prestige, compensation, or some other personal benefit.
For sure the Tesla recording while parked feature is illegal. I dont know why nothing is done about it. Probably just slow moving government. Especially now in Switzerland with the new privacy law. Private survalance of public grounds is illegal. Survalance of private property requires posting a clear sign of such including data retention, where data is stores and contact information.
This isn't something tne Tesla owner can sign in the ToS because the people in the footage are others. Tesla probably uses the excuse that you the operator are in violation not them but then again a Tesla owner has only limited control over this. I can legally buy a surveillance camera but it is my responsibility to use it legally.
But why do you think dashcams are illegal in the EU?
It's been ruled by multiple courts in the EU that dashcam recordings can be done legally because everyone is aware that they might be recorded in traffic at any time (e.g. by traffic cameras). That said, you have to comply with some restrictions. For example, you are probably not allowed to publish these recordings on Youtube. But they can definitely be used as legal evidence in court.
Secondly, I don't think Tesla's dashcam footage leaves the car in the EU (unless there is an accident, perhaps).
As far as I know, they don't even transmit or save any recording unless there is an accident or the user presses a button to save the footage into a USB drive inside the car.
In the accident scenario, it is quite clear that it's legal to keep this recording, because these can be used in court as legal evidence. As far as I know, there are many situations in which you are not allowed to film someone or something in the EU in general, but you are allowed to do so if you intend to use it as legal evidence, as that purpose trumps the other privacy concerns.
In the "user presses a button" scenario, it would be the user's responsibility to make sure that the recording is used legally. But again, if the user does not publish the recording and is only filming traffic, this is quite likely to be legal, especially if you only use it in reasonable scenarios (such as recording an accident in which you are not involved, or someone driving drunkenly).
It's not like anyone is going to be pressing the button every 10 minutes. And even if they were, it would be their responsibility to make sure it's legal to do so. It wouldn't be dashcams themselves that are illegal, but rather, what you do with them and the saved footage (if there's any).
Edit: I'm talking about the normal usage of the dashcams, not the Sentry mode functionality which has additional concerns (as you're not recording traffic, but rather people in the immediate surroundings of the car, when the car detects movement around it). As far as I know, courts have already decided that it's legal to have Sentry mode as well, but Tesla was required to warn users that they have to comply with data protection regulations when they use this functionality.
That said, I'm not sure what are the exact requirements for using Sentry mode legally.
Years ago, before smart phones became ubiquitous, I worked for a company that had a contract to provide kiosks containing travel planning software to bus and rail stations. As part of this, one of the jobs I had to do was create a method of recording information from an onboard camera in the case of the kiosk being vandalised.
How it worked is I made a rolling cache of the last 30 seconds of video; this was never saved unless an onboard "shock sensor" was activated. If the shock sensor was activated then I would save the last 30 seconds of video plus another minute or so. This could then be used as evidence by the police to help catch the vandals.
I have no insight into how the Sentry Mode functionality works, but it could very easily use a similar sensor to car alarms to only actually save the recorded video if there is some sort of "impact" on the car.
A state court in Landgericht ruled that everyone who is participating in traffic is aware of being seen and recorded [1], so apparently it's different from being near a parked Tesla in public in which you might be recorded without your knowledge.
There have been similar decisions by other courts, apparently.
However, the law is probably a bit tricky, in that it might be legal to use the recorded video as evidence in court (or perhaps insurance purposes?), but probably not for other purposes such as posting it on Youtube.
Last time I checked, in Spain (and probably other EU countries) similar reasoning applied for recording videos in public places, e.g. while you're walking on the street: I think you can record other people in public without their consent as part of your interactions with them, as long as you safeguard the recorded video and not publish it (and probably only for as long as it might be needed). You could use these recordings as evidence in court, but probably not for almost any other purpose.
You might, however, be prone to being punched in the face, as many people find that to be quite aggressive behavior. Police may even arrest you and confiscate your equipment as they're not all necessarily aware of all the intricacies of data protection laws.
[1] According to a reddit comment: https://old.reddit.com/r/teslamotors/comments/d2uzkd/sentry_...
If you watch news footage you will see street footage but as soon as a person is too close or start being the focus they will blur it out.
However there are exceptions, for example a large public gathering that is broadcast on television you can not expect privacy. For example the street parade.
I ended up in a CD album art booklet without my knowledge or consent but it was at the street parade at which you can't expect privacy if you are attending.
Probably I didn't make this very clear, but in the specific scenario I mentioned, it is legal to record a specific person without their consent but only if:
1. You are interacting with that person, and
2. You don't publish the recording (without the person's consent).
And I think there are other restrictions as well, although I don't remember exactly, e.g. you might be required to delete the recording if it's no longer needed and/or you might only be allowed to record it if you intend to use it as legal evidence and/or you might be required to take reasonable steps to protect the recording (i.e. not allow other people to access it). But again, I'm not sure about these latter restrictions.
Also, there is a distinction between recording someone (or some place) and just keeping the recording vs publishing the recording. The latter has more restrictions than the former, obviously.
Although I have no clue how live streaming fits into all of this, as you're not (necessarily) saving the recording? So I'm not sure how the GDPR laws come into the live streaming scenario, if at all.
If Mozilla really wanted to be helpful they could suggest legal terms to cover the manufacturer for features people want, such as crash reporting or locating stolen vehicles - except I suspect that Mozilla would feel obligated to issue a scathing review of Mozilla's suggested privacy policy were they to do so.
If contrarians really wanted to be helpful, they'd not downplay risks inherent in the utter lack of basic privacy legislation in the US and pretend this is all fine and normal. But instead they shill for car manufacturers, pretend adtech is harmless and try to portray anyone who has a problem with these things as weirdos.
Don't you think Mozilla's message would be much stronger if their privacy guide had an example of what the legal agreement should look like? I didn't see anything like this, maybe I missed it. Clearly manufacturers have gone overboard in some cases, but I don't believe it's that easy to make you guys happy.
There are lawyers in the audience here, how about post some legal contract that protects manufacturers from a passenger pressing the OnStar button while the driver is in the gas station bathroom and being liable for anything resulting from that, and every other possible liability from OnStar. I'll take my -4 and your lack of constructive counterargument as the answer I know it is.
People carry phones in their pockets equipped with mics and running operating systems that have secret source code. If you think the mic can never turn on without you knowing you are in for a big surprise.
It's in a totally different class.
Whether you believe them or not, it's a completely different situation from reserving the right to record everything and sell the recordings to whoever they want.
Are you sure there aren't local data privacy rules elsewhere that this also violates? GDPR itself basically just unified the existing privacy laws across ~EU member states.
I mean, yes, the terms are insane, but I'd also never agree to a silly monthly subscription Internet/entertainment/whatever thing from a car company. I'd never even pay for Sirius.
How do you know that? There's a 5G modem.
Ditto (eventually) for several other spy agencies around the world.
Given Apple's and Google's emphasis on security, I'm doubtful the same is happening for phones... but with targeted use of zero-days (assuming the right ones exist) it's at least possible in theory.
Or, you know, your telco provider, who then bundles and sells such data in aggregation to third party services. They've been caught doing it with location services over and over; it wouldn't take much for them to include audio recordings, as long as they have their terms & conditions sorted out
Presumably this includes GPS data, so they know if you frequent Starbucks or McDonald's. And sell your data appropriately.
"Why is it acceptable on any level for my car to become a spyware device on par with Facebook, when I paid an enormous sum to be its owner and controller for my own benefit, and not to become a residual profit stream for ${CAR_COMPANY}?".
What's a dossier like that with on the market when it includes location, Bluetooth IDs of all occupants and private conversations? $5/mo? $10$?
(not to excuse ISP data collection, but implying that a car is as critical for network access as an ISP is nonsense)
Signal for example, is also subject to US law. They can be compelled to reveal everything they have in a person. Which they happily do: they hand over a page with the date of account creation and the day it last connected. Which is all they have.
Don't collect information, and you don't have a problem.
Privacy is not about what someone _might_ do with your data, it’s what they _can_ do with your data.
It’s also that they have your data, which means it can be exposed to staff or the world as the result of a breach.
On the second point, sure, but so we have knowledge of what, how, and for how long, the carmakers are storing?
What they do with the data changes based on leadership (should we sell to 3rd party data brokers to increase our revenue or not?)
It’s also out of their hands once a subpoena for that data comes from law enforcement.
It's important to know what they do with that data today.
It's also important to know what they could do with that data tomorrow.
Even if a company provides assurances and pledges never to mishandle your data or use it for nefarious purposes, there remains a risk that your data could still end up in the wrong hands.
Your real time location data (and everything else) from phone apps is sold on a semi-open marketplace to bill collectors, marketers, spies and PI's.
It's worse than that. The way the law works is that you'll only have standing to sue if you're harmed in some way. But since your data is slurped into a big black box, and then passed around and used by 3rd parties, the connection back to the original ingress point is tenuous at best. Some of those 3rd parties, arguably the most harmful, will themselves be law enforcement, and in the US they have qualified immunity, section 720, and a vast array of a) excuses to snoop and b) immunity from consequence. So, it's worse than illegal because you'll never have standing to sue them and find out.
Of course, the solution is to not buy their products or, if you do, substantially modify them to remove all owner-hostile features after-market. Indeed, I predict a healthy secondary car (and phone!) market where trusted 3rd parties "sanitize" the product to protect the owner.
Looking at the MySubaru app, it looks like I can cancel any subscription. There is also this opt-out setting to “Send Vehicle Location at Ignition-Off”:
Vehicle Location
If you choose to opt out of this service, MySubaru will not collect your vehicle location when you turn your ignition off. You will still be able to locate your vehicle by sending a remote command through the MySubaru app. Salesman: "Do you have a Google account?"
My dad: "Yes, why?"
Salesman: "It's mandatory for purchasing a car with us."
How is that even legal?Or "give me one moment while I set up an account that I will never look at again"
KYC outside of industries like banking frustrates me to no end because when it comes to things like money laundering, they still drop the K. I'm reminded of an anecdote from a book I read a while ago, that some rich European had a really big account with either Chase or JP Morgan and his name wasn't attached to that account in any of their internal systems because he requested it.
The manufacturer has a checklist for "delivering" the car to the customer. Usually that's stuff like taking off the shipping labels and checking the systems. But now it also includes training th customer on the car's infotainment system and the mobile app.
The dealer doesn't get credit for the car unless the checklist is complete. So they demand the customer log in so the training can be held.
I created a dummy gMail account at the dealer to get this done. Haven't used it since.
There's probably a way to opt out of all of it, but I have no idea how or where you do it.
The infotainment may use Android, and the salesman may help you set it up but this is definitely not the red flag you think it is
I have an AAOS Volvo. At no point was I ever asked by a dealership to create or log in with a Google account. Google accounts are not required unless you want to use Google Assistant or download things from the Play Store. If you want to use the Volvo On Call app then you need a Volvo ID instead, which the dealership did offer help with.
Until I said, oh well that sucks and tried walking out. "Wait let us see what we can do."
Just wait until it gets so tighly coupled to the car that when google bots decide to cancel your gmail account, the car won't start anymore.
To me the reasons for this pressure seemed quite obvious: to ensure that I was fully enrolled in the data collection.
> All 25 major car brands reviewed in Mozilla’s latest edition of Privacy Not Included (PNI) received failing marks for consumer privacy, a first in the buyer's guide’s seven-year history.
Porsche is reportedly concerned over the Android Auto collecting too much data.
https://www.theguardian.com/technology/2015/oct/07/google-de...
https://www.motorbiscuit.com/porsche-models-still-not-androi....
Car manufacturers will see how ineffective and dangerous the ABS/ESP can be in some situations, just like flappy paddle gear boxes still need a clutch pedal to engage the clutch when driving over low grip situations like oil, ice, snow and rain, and the car gets out of shape, because few are perfectly balanced.
Dipping the clutch to bring the car under control and pointing in the direction you want to travel is essential in these situations.
Here [1] Misha could have dipped the clutch or knocked the gears up from 4 to 5 or 6, to prevent the engine and rear wheels acting like a hand brake.
Whats also interesting to note is the traction didnt kick in for a second or two, once he was already getting more side ways.
Now I know the Mercedes AMG have had their traction control setup for at least a decade with drift mode tolerances, but in this situation, the traction should have cut in more quickly to bring the speed down and apply the front brakes only.
So whilst the driver waits for the traction to kick in, having a clutch peddle to dip is the next best thing if the flappy paddle gear box cant knock the gearbox up a couple of higher gears quickly enough, even being able to change the brake bias quickly on the fly like in rally cars could help.
Its also why when a car gets sideways, it invariably leaves skid marks on the road before a crash. Some people are capable of driving with faster reaction times than the systems can react.
I know this because I've had to switch my traction control off "mid situation" to avoid a crash and now as a default switch mine off religiously when driving.
I object to the data being shared, just like the UK Govt shares the names and addresses of every person who is eligible to vote with people who stand in a parliamentary election when they can stump up a £500 deposit which is far cheaper than any mailing list! Makes me wonder about the Monster Raving Loony Party!
And other entities can also get this data which shows the law is not fit for purpose in some areas in todays day and age.
So there should be a default data cant be shared unless opting in imo.
Until this comes to be understood et large as a basic contributing doctrine of our basic value exchange system, this type of thing will continue to be more and more pervasive.
Given the multiple years we’ve been at it, I think a basic doctrine of privacy as a counterweight is too squishy to really settle in the public’s mind and countermand the negative effects of the surveillance at large.
A new counter doctrine will need to take place. I’m not sure what it would be.
"So you're saying everyone does it, no one really complains, all our competitors do it, it's legal... and highly profitable?"
I mean, of course they're doing it.
I can just see a board meeting "LG even records you when you watch TV?!?", uh, OK I guess, let's do it.
This has gotten to a point that we cannot let free markets resolve this, it requires government regulation and laws. I'm fortunate enough to live in EU.
The ones providing data are being farmed. We call that something as well, when animals are being farmed for profit.
The surveillance capitalists sell your data to the highest bidder, with the agreement that the source of the data is not revealed.
Parallel construction allows the govt. to avoid judicial checks and therefore public scrutiny.
So it's a self-reinforcing cycle where companies get govt. favors at least as money if not policy, and the companies override constitutional limitations of the state.
https://www.reuters.com/world/us/google-delete-location-hist...
Might be CYA, but I suspect it's more like "If we hit up 23andMe (who definitely sells deidentified genetic data and in all likelihood also sells the same tracking info from using their site as everyone else) maybe we have enough inference to figure out your generic makeup."
Even on an intellectual level, I'm curious if this can be done. So yeah, pretty sure Kia's data science team is more than encouraged to crack that code
Whoever makes these policies must get a chuckle knowing people will never do this.
Willingness to violate manufacturer warranty is the #1 barrier. If you don't care, there isn't much to stop you from figuring it out on your own. Angle grinder will get you into anything. Just be careful with those high voltage systems in EVs...
Just like how warranty void if removed stickers are a lie under: https://en.m.wikipedia.org/wiki/Magnuson–Moss_Warranty_Act
So removing the roof antenna might do it...but then again it may render the system unable to start entirely (in the future it likely will). I suspect this is going to need to be reviewed on a car by car basis. And all of this assumes there isn't another antenna hidden somewhere else in the vast wiring loom (or on a pcb).
[0] https://www.toyotanation.com/threads/disabling-the-dcm-in-my...
In good news, if your car is old enough and came with a 3G transmitter, data transmission won't work anymore since most 3G networks have been shut off [2]
If someone knows of a wiki somewhere that lists the years/car models and what types of tracking they actually perform (not just what's theoretically in their privacy policy) that would be much appreciated. It would be nice to know if, when I get in someone's car, the conversation might be recorded and sent somewhere. Or which car models are sending the recordings of the cameras installed on the outside (or inside?) that can be viewed by the employees and shared around the office (not theoretical) [3]
[1] https://www.mavericktruckclub.com/forum/threads/experience-w...
[2] https://jalopnik.com/here-are-the-ways-shutting-off-3g-is-go...
[3] https://www.reuters.com/technology/tesla-workers-shared-sens...
For most people, even those who don't subscribe to the internet requiring service, there is no way to disable it. Especially when the radio device is inaccessible.
On a separate note, I recently got a CPAP machine. It comes with a copy of the terms and conditions that i had to sign and return to the doctor. Before you connect it, you must attach an external radio device.
Luckily, they botched the delivery and the device was 4 months late. Then when they finally sent it, it went to the wrong address. I called and said i never received it, before the neighbors brought my package. That's when i learned that the $1000 device i got was actually a subscription for $50 a month after the insurance contribution. I never plugged the radio device and the machine works just fine.
I paid $1000 for a fan with a tube, but at least I'm not paying for the subscription and never connected the spying component.
Less luck with my CPAP. The one I got through my doctor was subject to the same issues, and they even tried to charge me after I sent it back. The replacement I purchased off Craigslist had been used in a smoking household, which I didn't think would be a problem, but turned out to be a huge problem. Even after disassembling the thing, soaking every part I could in bleach, and meticulously cleaning the pump, it still pumps out air that smells faintly of tar and soot. It would be nice to live in a country where healthcare was accessible.
[1]: https://boulter.com/blog/2008/08/20/the-mattress-industry-is... (This does not reference the affiliate review hustle that has blown up since it was published.)
My dad just bought a Nissan Qashqai (I hate it, but wathever). For legal reference, I'm on Spain, so EU GDPR framework. Every single time you start the car it shows a consent screen for data aquisition. By memory... "Driving data, location, statistics, blablabla for the Nissan Connect program."
- I haven't connected nor I have a user or anything at all in the Nissan Connect apps
- You can't disable the dialog, not even in the service menu
- I've been digging in forums and everyone says you have to bear with that for the whole life of the car
That's not ethical, and probably not even legal.Presumably they don't harrass users to accept the agreement once already accepted.
They may have to, as long as they can't identify who's behind the wheel: a single driver can't (legally) accept those terms for all future drivers of the car.
Also, people will put up with a lot to have that BMW that marketers have programmed them to associate with success and status.
My parents new Hyundai does this too. You cant say no, and you cant store your reply. Incredible. I'll never ever purchase such a vehicle.
Sounds illegal indeed, GDPR requests the possibility to refuse the data and you can't just ask in a loop, that wouldn't be informed consent.
I would argue that they're at step 1, yes, but that step 1 is telling you these manufacturers have no respect for your privacy, period.
Regardless of current active data collection, I think it’s wise to read these policies as a declaration of intent.
When they're actually doing it: "don't care, it was in the privacy policy, of course they do it"
I think it's good to resist at every step.
https://foundation.mozilla.org/en/privacynotincluded/subaru/
There’s probably other sensor gathering happening around the vehicle and obviously you can’t hide things like driving habits but it feels like staying out of the manufacturer’s homegrown OS gets rid of a good chunk of the worst privacy nightmares
Also, will these brand track geolocation information, etc?
Insane that any regulator would approve of this. A car shouldn’t be smart, it should be hardware that knows nothing about you. You can then enhance the car with something like Apple car play since you already use that phone everywhere anyway.
750 billion a year industry? What kind of dystopia do we live in?
Should we move to a system where a company can only do things or make things that are in their direct industry? So a car company can only make and sell cars and not sell data?
I have no idea what the solutions are, but this sounds horrible.
1. One time payment
2. Subscription payments
3. Usage-based payments
4. Selling personal data (to other _products_)
5. Showing ads (based on data collected by the product itself or bought)
If Google makes a car in this world, they'd have the option of making the thing free and in turn it sells data they can use for their ad business, basically how I'd say they monetise Chrome (beyond that sweet web monopoly they get out of it).
I think that could potentially be a lot more honest, consumers would know exactly what price they pay. And it'd make it a bit harder to build and maintain a monopoly through strategic product portfolios.
Seems like there's an argument there that complex/hidden pricing schemes and the illusion of free are too much to ask the typical consumer to untangle, it'd therefore classify as consumer protection in my book.
I noticed that companies that run most of their business units as profit centers (where units also generate revenue from other units) seem to do better than those that have mostly revenue and cost centers and lots of politics in-between. So maybe we'd even get better products this way.
Edit: Upon reflection, what's difficult is defining what a product is in this model. My spontaneous approach is that a product is anything than you can choose or decline to use. If my smart TV maker says "well the home menu is a different product from the TV" - totally fine. Give consumers the choice of using a different home menu and you got a deal. If those two things are inseparably (by practical means) intertwined, it's one product.
My straightforward guess is cameras pointed in the car, or collect information from the phones in the car and try to extrapolate using techniques perfected by Meta.
>Should we move to a system where a company can only do things or make things that are in their direct industry? So a car company can only make and sell cars and not sell data?
I would be interested in that just to see what happens to the FANGs. Google can pick between youtube and chromebooks; meta can't have its own VR headset; what even happens to Apple? It would at least get more people thinking about if hyper monopoly/monopsony and vertical integration into every area of life is actually desirable.
But the fact that we’re even discussing this is ridiculous.
I do think the data collection method seems puzzling, but if it were as simple as audio, I think that's what would be mentioned.
I wonder if Apple saw this coming when they started their automobile program, which seems less crazy to me the more time goes on. I always figured it had more to do with screen time and entertainment for when full autonomous driving becomes available. But the more I think about it, that will probably be less of a unique feature than privacy.
its been proven before: https://en.wikipedia.org/wiki/Chrysler#Chrysler_Uconnect
and will be proven again
just like with all tech don't buy anything made after 1990. corporations now see your vehicle as a smart phone that just gets a stream of alpha quality software piled onto it and updated whenever they are told of their mistakes
It would require a really huge uproar, boycotts, lawsuits, and a wide spectrum movement.
Hard to get that together in a world where political consciousness is constantly trapped in the tar pit of culture war trolling. The culture war pretty much guarantees no other issues can sway elections.
…and of course all that data driven microtargeting is used to drive culture war rage trolling to keep things this way. They know exactly what will make you mad, and thus distract you.
I drove my friends Subaru with lane assist and adaptive cruise control and such. It’s nice, but I figured with the level of data collection that’s going on in these cars plus the fact that there seemed to be a cellular internet connection baked into the car there had to be some fucked up nonsense going on
My daily driver, a 2016 smart fortwo, is not as fancy or practical. But it is through and through a “dumb” car despite the name. It has no real modern creature comforts aside from automatic windshield wipers and headlights. Otherwise it’s like a car from 1998 with modern crash safety and I love it for that. Maybe it collects a ton of data but I’m very confident it doesn’t phone home. Plus a rear engined manual! Although a 3 cylinder one lol. At least you can park it basically anywhere
You will have no choice to move freely once all cars are self driving.
You will be tracked even more than today with these cars.
Personally I think cars and freedom of movement are very important. And I do everything in my power to oppose self driving cars.
The fact that Nissan was the worst offender and Renault the least problematic is interesting and shows that GDPR has been helpful in getting European focused brands to take privacy seriously.
EDIT: Looked at a few privacy policies and the CCPA link is often hard to find. Keywords to look for: "CCPA", "California Privacy", some examples of links I found:
https://www.honda.com/privacy/your-privacy-choices
https://www.tesla.com/legal/privacy#data-sharing
https://www.ford.com/help/privacy/ccpa/
https://ksupport.kiausa.com/ConsumerAffairs/PrivacyManagemen...
Something interesting I found is also this: https://www.honda.com/privacy/CCPA-Metrics which shows how many requests Honda received. It seems not many are aware of CCPA rights and this number of requests is not enough to deter companies from gathering personal information. These metrics need to be orders of magnitude higher to make a difference in company behavior. It seems like an automated service to send these requests and more public awareness of CCPA could help here.
EDIT2: A lot of these forms ask whether you're submitting the request for yourself or you're an authorized agent doing it for someone else. I found more details on "authorized agents" on the CCPA FAQ: https://oag.ca.gov/privacy/ccpa. Maybe an organization like Mozilla or EFF could setup a service where you can authorize them to do this for you? Then you could just select a checkbox of companies that you want CCPA deletion requests for and it would be sent on a regular schedule (quarterly? yearly?). If such a service became popular, it could really disrupt the personal data gathering of companies.
My car (Honda EDM) is 2018 and is - if we want to make lousy parallels - essentially a "dumb phone". Sadly I will have to get rid of it and buy an electric or plug-in hybrid due to legislation. The only way not to get my soul sucked in would be to keep it airgapped, if that's even possible.
The whole situation is an all too perfect example of "if they can do it, they will": the moment there was an upstream link manufacturers jumped on the occasion to mass-enshitify their cars.
Of note, Mazda is conspicuously absent from the report, I would have been quite curious about their stance here given they were among the rare ones resisting the virtual-knobs-on-a-big-screen move.
What jurisdiction is forcing you to replace your ICE car with an electric or hybrid?
Mine is ranked tier 2 (EURO V petrol) and will be forbidden to drive starting January 2025.
The only ones allowed will be tier 1 (EURO VI petrol) and tier 0 (EV and PHEV).
There's no calendar yet for tier 1, but I'm sure as hell not going to buy a tier 1 car and find myself in the same spot of having a perfectly maintained and efficient car with a lot of mileage remaining that I can't resell or have to scrap in 3-5 years when (PH)EVs will be the only ones allowed.
OR your vehicle is hacked.
Better to just never create the data, if we can avoid it.
Google your car make and model for a specific version. You might be able to physically remove it by searching for “tcu replacement / repair” etc.
https://en.wikipedia.org/wiki/Telematic_control_unit?wprov=s...
> The Mozilla Foundation works to ensure the internet remains a public resource that is open and accessible to us all.
??
For those of you who think for yourselves and are still reading, I'll explain why.
They have the best practices of any connected car listed, it's all opt in, and they collect nothing tied to your ID. Privacy aside, also there's no haggling, and it's a better car with lower TCO and more efficient drive train and wicked fun. The leather and mahogany and built in cigar cutter is not there, but hey you have a charging network.
Back to privacy, to me it's a feature, not a bug, that you can view live video from your car's many cameras while you are far away from your car. I can check from the office whether my garage door is open. That's good, not bad. Mozilla is really amping up the hyperventilation to think of this as a negative.
If you read carefully it sounds like nobody contributing to the article actually sat in a Tesla and went through the experience of how choices are presented.
The way I look at it most of the negatives they tried very hard to come up with in the article for Tesla boil down to "it seems we aren't sure if we can trust them because look at us, doing business with Google, which is also a privacy nightmare, and if we posture like this, Tesla might too" which is all fair, but very weak.
You actually don't see Tesla posturing about privacy, although maybe they might after this article. That would be reasonable. When you do read the fine print, it is very good for consumer privacy.
Just buy a great car that you love, but also one that you won't regret buying later.
No. Because of the owner.
The Ukraine thing is more nuanced than the media makes it out to be. They are in the business of selling drama.