When are people going to wake up and stop accepting this totalitarianism?!
When are people going to wake up and stop accepting this totalitarianism?!
You are forgetting the car. With internal microphones cameras, locators and wireless connections to distribute collected data, a "spying system" is installed in your own property (which some do not really consider "property" anymore), and it is more difficult to remove it compared to mobile computers.
They can also come with an embedded kill-switch (planned apparently so that rented vehicles can be disabled if the service is unpaid): so you may be driving a vehicle with a subsystem intended to remotely stop it from working, planned to be outside the control of the driver.
Software, features and data - which could change outside the control of the owner - are a further step.
This is not "ownership". (Further to the privacy and security issues.)
EDIT: I also note that there was another topic on HN not too long ago about car manufacturers being accused of not doing enough about theft (apparently "smart" locks are easy enough to bypass). So a "locate my car/laptop if stolen" feature is a trade-off against privacy and other risks. Personally I think the choice should be with the device owner in the end, but obviously, a remote tracking feature that a thief can easily disable is not much use for end-users who do want the feature.
No, you misunderstood the point: the "kill-switch" feature was implemented in case the car is for rental, but the result is that bought cars also contain it. So you would be driving something with an embedded kill-switch - because the manufacturer saw it would be useful under some cases, so it just installed it as part of the bundle.
For that matter - as you also point out -, it can also come useful in case the car is stolen. Unfortunately, it also represents a security issue, pretty clearly: it is there, accessible by those who can gain access to it... So,
> the choice should be with the device owner in the end
And apparently it is not. How would you remove that module, if you want to?
Are there any documented cases of kill-switch misuse though? If it's actually happening, then that's a stronger argument to me than a hypothetical one.
I'm pretty sure most laptops have something like this too, though on some models you may be able to disable this in the BIOS?
EU in general advocates for monitoring, not against it. If you think GDPR is an example of anti-monitoring regulation, read it carefully - there are exceptions for monitoring, practically every clause says "unless required to track by law" and "doesn't apply to the state".
> Your eCall system is only activated if your vehicle is involved in a serious accident. The rest of the time the system remains inactive. This means that when you are simply driving your vehicle, no tracking (registering your car's position or monitoring your driving) or transmission of data takes place
the problem is, implementation is left to manufacturers, so it has to be verified whether each eCall card actually, really «remains inactive».
It's similar to how PSD2 demanded specific payment flows and thus Google Pay was born - yeah they could have implemented it in a more privacy-friendly way (like Apple did), but they didn't - and EU demands the flows, so card-like payments without an online backend are no longer possible with your phone. Thanks EU!
Actually, the directive specifies that the eCall must be implemented so that it cannot be disabled by the user but can be disabled by the manufacturer.
> specific payment flows ... online backend
Similarly, europe's demand that the feature of internet services are provided for all payment channels seems to be one of the reasons why channels that did not use NFC - simpler ones - have disappeared. Forcing the model "money can be taken from you without your actful, explicit consent", through radio-enabled cards. The european union has destroyed a good amount of civilization.
Destruction of a good amount of civilization indeed! Now Google gets my payment data, I have to be online to pay with my phone, and I have to tolerate Google spyware on my phone instead of using a clean AOSP without any Google apps/services like I used to.
Thanks EU, you're keeping my data safely in Google's hands!!!
That is a different point, and it reinforces the main one.
You must have noticed that car manufacturers have implemented car remotes that broadcast keys continuously. They are everywhere now.
If this is the awareness and focus that manufacturers adopt when planning a product, how concerned should you be with the rest of the involved "sensitive issues"?!
- Internet-connected cars fail privacy and security tests conducted by Mozilla https://news.ycombinator.com/item?id=37404413
- ‘Modern cars are a privacy nightmare,’ the worst Mozilla’s seen https://news.ycombinator.com/item?id=37401563
- It’s Official: Cars Are the Worst Category We Have Ever Reviewed for Privacy https://news.ycombinator.com/item?id=37401563
That’s unacceptable
when would this feature have started in Android (versions etc.), which are the most important events showing what they can do or not, etc.
It is not just «remov[ing]», it is also planting. (You should remember the case of remotely installing free music albums - which woke up a number of people about "they can plant files on my phone?!".)
You can remotely wipe them, install or uninstall applications from a browser logged into your Google Account and Google has already deleted apps from users phone since at least over a decade ago [1].
[1] https://android-developers.googleblog.com/2010/06/exercising...
This feature was built to kill malware and viruses. Not even all malware in case of mobile devices, only the particularly bad malware that a "this app is infected with a virus" popup isn't enough for to get rid of.
It's not exactly a novel technique either. Most game cracks for Windows are part of one malware database or another, which is why every crack comes with instructions to disable your antivirus software for that particular binary. At some point only the actually infected cracks were being flagged, and in some cases the cracks employ malware-like mechanisms to redirect control flow, but many of these programs will be flagged by AV databases simply for being cracks.
Most of the topics where people complain about these types of remote uninstalls are based on pirated games from sketchy sources. It's hard to say if there's actually a virus at play in those situations, but based on the symptoms described ("all APKs I install are marked as viruses") I would think there is some kind of malicious APK modification process going on in a few of these cases.
https://support.mozilla.org/en-US/kb/add-ons-cause-issues-ar...
There needs to be a law against this.