Automakers are sharing consumers' driving behavior with insurance companies
nytimes.com
nytimes.com
I still had the sticker- I peeled it off and put it in the manual. The exact text is:
VEHICLE DATA TRANSMISSION IS ON! Your vehicle wirelessly transmits location, driving and vehicle health data to deliver your services and for internal research and data analysis. See www.toyota[.]com/privacyvts. To disable, press vehicle's SOS button.
https://www.theguardian.com/australia-news/2024/feb/08/toyot...
> We may modify this Privacy Notice by posting a new version at this website effective on the date of publication.
No actual notification needed. Are they screaming to be regulated?
https://www.facebook.com/groups/2066782386864241/
I was very surprised how many people there are who buy cars from the factory and immediately stored them, in the 1990's. In some cases the owners did not even remove any of the factory stickers or plastic.
This group must be showing just the tip of the iceberg.
Consent Centre
E-privacy: Your car data
Help us improve our products by sharing car data and diagnostic info.
We don’t currently have your consent to use this data. This may be for the following reasons:
Your car doesn’t have Connected Services. Contact your dealer to check if they can be added.
No (connected) car has been added to your account. Go to My Vehicle, add a car if needed, then connect your car via the Connected Services card.
You have a connected car but have yet to consent. Go to My Vehicle, and open the chosen car. You will be requested to give your consent.
Toyota thanks you for helping us to improve our products.
FWIW, their smartphone app contains a "consent" section with various toggles for the usual reasons (e.g. "sharing data to improve products") and these are all turned off.I had a friend who worked with call centers, taking orders over the phone. they had a script for everything, and after they quickly took your order, they started with a scripted upsell. If the person balked, they had responses for everything so they could continue. The only way out of the script was if the customer said "I will cancel my order". The call center person would be fired if they did not follow the script.
Examples:
1- "God told me to..."
While canceling Time Warner Cable I tried cancelling a few times prior. Always met with rebuttals, put on hold to research the account. Either waited on hold for 20 minutes or the call was disconnected. Tried again and gave the reason for cancelling "God told me to" account cancelled immediately. (I have also heard simply saying you're moving out of the service area works too.)
2- "Moment to pray" - Buying time or dissuade an aggressive salesperson.
My wife just recently gave birth to our first child. When her water broke she wanted to go to the nearest hospital which was within walking distance instead of getting a cab across town to the hospital where she was originally being seen. She remained adamant that she wanted a natural birth unless it would potentially endanger her health or our daughters. She has two friends who were pushed into C-sections both of which ended up having complications due to the procedure.
After six or seven hours after her water broke an administrative nurse came in with a shot and said she was going to start inducing labor. My wife pushed against this as she was worried about complications from a C-section. The administrator had a rebuttal to everything, to the point she even started crying. When I continued to hold ground they brought up concerns of spousal abuse.
This registered an immediate red flag and luckily I defaulted to "God mode"
I asked if we could have a moment to "pray". This bought us enough time to speak with the doctor face-to-face who agreed to wait a few more hours before inducing labor to avoid a C-section. We had a successful natural birth with no side effects.
(Hospitals' make 2-3x from a C-section as they do from a natural birth.)
(*When asked if it was medically necessary the administrative nurse would only say it was hospital policy and they do the same for everyone else who was on the floor.)
It should be illegal to manipulate people by implying they’re breaking the law.
A bit outdated but: https://www.theatlantic.com/ideas/archive/2019/10/c-section-...
https://archive.is/4jj0h#selection-761.59-761.224
Also once you have one c-Section, the chances of a second increase significantly. It is not suggested to have more than two c-Sections, so if you want three kids you are out of luck.
Friends suggested bringing in a Doula. They are really good at patient advocating for patient's rights.
These people are paid to follow scripts and strict protocols. At best, this may suggest that ChatGPT answers are as good as a call center representative's answers.
1) People don't understand they're being monitored. I think this is a good reason to be mad. People should have some understanding of the agreements they make. It's part of being a functional adult in the world. It's also annoying that the companies keep spinning this as a tool to improve your driving, when it's clearly an attempt to price insurance against a person's actual driving habits.
2) The system's assessments are opaque. I don't have a good sense of how accurate any of these measurements are, nor what system is in place to ensure that. If the information collected is consequential enough to double a person's insurance costs, there should be some effort expended to be confident that the collected metrics actually reflect reality. I didn't see anything like that in the article, maybe I missed it, but it shouldn't just be some random team in a private company doing their best.
3) People's driving habits shouldn't be shared with insurance companies. This one ... this one I think is not great. It looks like the shared data at least tries to be anonymous -- they share driving behavior and times, but not actual location data. Heck, I'd be fine with scrubbing the times and just sharing the hard start and stop and speeding numbers (assuming point 2 above is addressed). I get that a knee-jerk defensiveness about privacy would make Thomas Jefferson proud or whatever, but we strike balances on public welfare and private freedom all the time. If you're itching to manufacture 1 gram of ricin to put in a sealed glass vial above your mantle, too bad, you can't. Cars aren't ricin, but they are the shortest path between most humans and homicide. If this kind of intervention induces people to be more careful to keep their current insurance rates, I think that's reasonable. Driving like a maniac is not a human right or a protected characteristic.
Both styles of driving would be... Alarming from a telemetry perspective.
Afaik neither is covered by regular auto insurance anyways so it really shouldn't factor into rates. There's specific racing insurance, but it's quite pricey.
Not that I want them sharing location data, but pure acceleration/velocity data won't show areas like that.
I'm also not sure how well regionalized the data is. Though neither is good, there's a very big difference between going 15 over on the highway and going 15 over on back country roads with blind turns. Or between going 15 over on the highway vs in a shopping center parking lot.
Speeding is contextual.
For example the road I live off of according to the speed limit the car thinks goes from 40 to 65 to 25 to 65 to 40 in about a 4 mile span. Spoiler it does not. It is 40 the whole way. But according to the car I am either going 25 under, 15 over, or exactly the right speed.
(And the 65 section in the middle? Blind corner. Idk where it’s getting its data but it is very very wrong)
Iirc, though, I think I read something about this and they were more interested in average speed (regardless of posted speed), and the rate/frequency of acceleration/deceleration (especially deceleration).
The idea being that speed increases accident severity, regardless of posted speeds. Rapid deceleration is indicative of reacting late to something you should have seen and responded to earlier (eg following too closely and having to slam the brakes, not seeing someone merging, not slowing down for a yellow light, etc).
Basically that a safe driver would have a fairly smooth acceleration/deceleration profile because they're aware of what's happening around them and pre-plan accordingly. If someone wants to merge in, give them room and then back up enough that you can brake slowly if something happens.
I still don't want to be tracked, but their metrics seemed sane at first pass.
Insurers aren't trying to determine how good of a driver you are (conditional probability of you being in a collision given conditions). They're trying to determine how likely it is that you're going to be involved in a collision that results in a claim (unconditional probability of you being in a collision). If you frequently drive through deer infested forests, it seems reasonable that your insurer is going to expect more claims compared to someone who doesn't do that.
It's similar to how driving late at night results in higher premiums. You can be the same good driver at night and during the day, but if you're frequently driving at 3 a.m., you're a higher risk.
The terrible drivers are often those with the most timid inputs, especially with regards to acceleration. It is perfectly normal here to need to merge into heavy, 60mph+ traffic from a dead stop, or to need to quickly match speed and identify an appropriate merge spot to not wind up stuck at the end of a ramp.
And it's not like they sit there for 15 minutes waiting for some exceptionally large gap to match their acceleration habits - that would be very annoying to other drivers, but theoretically "safe". They enter in the same length gap as someone that actually uses their gas pedal - but rely on oncoming traffic to hit their brakes/evade, as they fail to get up to speed quickly enough for the small gap they've entered in.
-----
Hard braking is something with fewer reasons it should happen regularly - but I'm still reminded of the usual adage about metrics. Do you really want people to be mentally reluctant to hit their brakes as hard because of the insurance hit? That seems like a recipe for increasing decision time and accidents.
I haven't been cited for anything in decades, and have never been in an at-fault accident. I drive the speed limit and have a dashcam. With the deer, I was actually 10 MPH under the limit.
So should my rates go up for these incidents where I successfully avoided hitting something? Insurers are unscrupulous and would use any excuse.
No, thanks. I'll share nothing.
I won't be an Amazon driver in my own car.
Unfortunately legislation representing anything other than big money interests is difficult and rare to pass.
All in all, I think it was useless for actually policing driving behavior, but I did get identified (read: randomly selected) as the safest driver in the branch one month and got a bonus, so I guess that was nice?
People do not engage in meetings of the minds on these types of things. Manufacturers/insurance companies enter into agreements (and leave stickers that are unlikely to be read) which is a clear violation (imo) of contract law.
It's one thing to be aware of agreements you make, it is another to navigate a corporate surveillance hellscape of on by default consentless surveillance a bunch of psychopayhic corporate types greenlit.
I think it's a combination of two strategies.
1) searching for a reason to not pay a claim.
2) searching for a reason to increase your pricing, while hiding average driver behavior from you to increase their bargaining power
One of the main points of the article is that insurance companies are using the data to raise drivers' rates. How can they do that if the data is anonymous?
Then the insurance company grabs the vehicle registration number when you ask for a quote and looks up the VIN on their side based on a security database to prevent resale of stolen cars or similar.
Anonymous data becomes identifiable data...
That's hardly anonymized data! It's more obscured.
- Willis Towers Watson (WTW) aggregated driving data
- Verisk (afaik this was mostly around vehicles, not people)
- Various reports directly from state governments
- LexisNexus (multiple different report types)
Really any mobile app that has accelerometer or gyroscope access (even without GPS) can estimate driving safety. Using phone movement and angle, you can estimate driver vs passenger.
Cambridge Mobile sells equipment a lot of insurers use and afaik also data
The magic keyword to look for is "telematics"
Your Responsibilities
Your responsibilities include: (1) informing passengers and drivers of your vehicle that data is collected and used by us, and (2) notifying us of a sale or transfer of your vehicle. If you do not notify us of a sale or transfer, we may continue to send data about the vehicle to the subscriber's Account Information currently on file, and we are not responsible for any privacy related damages you suffer.99% of the time the rep doesn't care, and if the company can't be bothered to put someone on the other side of the table who is actually paying attention or has bargaining power then they deserve it.
Of course the company can say, "If you don't like our product, don't buy it." If I want to keep up with the latest safety upgrades to my vehicle to protect myself and all car companies have the same tracking software, my only option is to look for a "dumb" vehicle. This is blatantly unsafe and irresponsible. So, they're saying that my safety comes with a price other than the $40K I shelled out?
Ownership is a bad framework for this issue—it’s too ambiguous. You can “own” a vehicle all you want, that doesn’t give you the right to fuck with its odometer or catalytic converter.
You should own your car and be able to do as you wish. You should also be able to turn on or off any tracking. There are just consequences for some of the things you might want to do.
Ownership is a legal concept. What it means, what that package of rights tied to a piece of property entails, is entirely dependent on the law. Using ownership as a guideline for rule-making is bad form because it’s tautology; I can justify and condemn anything on the basis of my or adjoining persons’ purported ownership rights.
The machine languages of ownership are control and possession. That’s what we’re delineating, and unfortunately it generally must be done piecemeal. In this case, the pieces are the data cars beam home. Currently, the manufacturer controls it. You and I agree—I think—that it should be the user, which we—by this conjecture—make its owner. The ownership flows from control, not the other way.
(The problem is trebled with cars given they’re typically driven on roads the driver doesn’t own nor control.)
Not really. The common definitions either fall back to control or invoke the term property, another legalistic word. What ownership means is incredibly fluid and context dependent; consider how ambiguous it is when it comes to its classic form, real estate.
how about "legal absolutism"? If it's not codified in law it doesn't exist and therefore cannot be a part of people's vernacular.
Once this takes over we can update all our dictionaries to stop marking specific definitions as being legal definitions as they'll all, by definition (heh) be the legal definition.
Or, to put it another way, this is the internet, where you're free to say whatever you want but that doesn't mean you'll be taken seriously.
Within the context of lawmaking, for social constructs like ownership, absolutely. It’s sort of like starting with legality when writing drug regulations; outside the lawmaking context, that makes sense, within it, it’s nonsense.
I’m not saying never use the word ownership in common parlance. But when discussing a new law, yes, it pays to be precise. Because starting from ownership will result in a law that is ineffective or misdirected.
> You should own your car and be able to do as you wish.
no "new law" was being discussed, you yourself tried to limit the scope to the legal definition and now you're trying to argue that no one should be discussing anything but the legal definition (well, for the second time, just with different words).
It's a normative statement. And I'm not solely talking legal definitions. But when we're debating the proper boundaries of ownership, it is tautological to invoke ownership in the definition.
The original phrase is stronger as "you should be able to do [with your car] as you wish." Which is not a commonly-held view even if we restrict ourselves to vehicles solely driven on private property--to the point of absurdity, you can't mow down pedestrians just because it's your car and land.
For example, you offer up that just because I own a car doesn't give me the right to murder people with it (stupid, but you went for it so let's roll with it). The level of control being exerted by software is such that I couldn't _stop it_ from happening regardless of my ownership status if a 3rd party decided it wanted my vehicle to murder people.
the ownership thing is a red-herring from someone who is trying really hard to be smart but they're missing the point entirely.
Put another way, It's the tail wagging the dog. "You don't _really_ own it, therefore 3rd parties have the right to exert that level of control over you" when what's being protested is the level of control being afforded 3rd parties. ownership is just the mechanism.
you can't legally create a contract that allows you to charge 50% interest on a loan. You shouldn't be able to create a contract that allows a 3rd party to dictate what you can, and cannot do, with a vehicle they sold you. That should remain solely in the hands of the government (which is why your car murdering people analogy was stupid).
For a long time this was just a fact of buying any car that lived long enough. I have bought several cars where the transaction went something like: "so the odometer has rolled over twice; so there's actually 376,000 miles on the frame... but only 118,000 of those are on this motor and I swapped the transmission with a reman 76,000 miles ago."
Of course we've added a few significant figures to odometers since then, and in the era of digital odometers I imagine "rolling over" behaves very differently. (Will the chassis survive 4 billion miles? Seems unlikely. Do the display and storage have different bit resolutions? Is it a saturating counter internally? Externally?)
Sure it does.
This entire attitude is what's scary about software, actually. See, back in the ye olden days, no one disputed your right to remove the catalytic converter on a vehicle you purchased.
It was no longer legal to drive and if you were caught you could get fined. But you absolutely had the right to do it.
But now with software, there's enough control that 3rd party entities are dictating with 100% success what an owner can do with the vehicle. And you're defending it as right.
Your key term here is control. When discussing a new rule, that is what you focus on. Use the word ownership when selling the rule, sure. My point is rules drafted starting from ownership tend to be trivial to circumvent. Because they presume ownership is a natural state when it is a social construct.
you purchase a video game from your religious friend and they decide you shouldn't be allowed to play the game between 8pm and 8am and they have the ability to ensure you can't.
their ability to limit you isn't a social construct, it's as strongly bound as physical violence, and that's the problem.
Where? When?
Say you own private property and a car. Does that mean you are allowed to leak diesel all over it? Most jurisdictions say no, in part because that affects your neighbours’ property values.
Ownership is not, and has never meant, absolute sovereignty. It’s a package of rights defined in terms of control. When we’re discussing amending what ownership means, giving the owner more control, it’s circular to start with ownership: you can do it. But it’s much more meaningful (and powerful) to talk about control.
Tesla is not the government. Toyota is not the government.
stop it.
I’m trying to avoid the miasma of conflicting rights. Somewhere in this thread I referenced a car spilling diesel on private land. This impact the value of neighbouring plots. On entirely private merits, the owner’s ability to operate their property, on their property, willy nilly, is curtailed.
Simpler, if more absurd example: someone’s pet or kid wanders on your property. This curtails what you can do, with your property on your property. You own both. But you don’t control everything which happens upon it.
Seizing on this distinction is immensely clarifying. It’s the difference between talking about computers in general and knowing the protocols.
I, and many others, disagree and think that's a heinous abuse despite the argument that both parties willingly entered into the agreement.
This is a total non sequitur. (And sure, if both participants are wealthy institutions and knowledgeable and uncoerced.)
There is no world in which two institutions with plenty of money, knowledge, and a lack of coercion are going to come to an agreement for a loan with 50% interest.
Theory vs practice. In theory what you're saying could happen, in practice it's only going to happen when one party has a severe imbalance against the other party (and you know this or you wouldn't have tried to head off that argument). Since contract law deals with practice, contract law disagrees with your assessment that it should be allowed.
Which goes back to the whole ownership thing.
Just because someone _can_ draw up a contract to muddy ownership to the point that the seller of a $30k+ USD vehicle can retain control and absolutely limit what the purchaser can do does not mean contract law should allow it.
And there's too much precedence for this sort of thing for you to have a leg to stand on (although I'm sure you'll try). Just because someone _can_ sign a non-compete with no expiration does not mean the law should allow it.
ad nauseum.
Arguing that because contracts today muddy ownership so you can't act as if the purchaser has certain rights is missing the point.
Varies by state.
It's even worse. Your car acts as a blackbox against you. A 1990's car? I can do whatever the fuck I want to, I can drive it offroad, I can speed, I can even be near a bank robbery or whatever.
A modern car? Someone robs a bank a few hundred meters from where I am, and now the police will come knock on my door because the IMEI of my car was near the bank when the robbery happened. I speed a little bit to overtake some dumbass driving 20 km/h below the limit, the police makes a dragnet subpoena against my insurance / the data processor from the manufacturer, and issues me a ticket.
Honestly I'm pretty tired of that "our way or the high way" nonsense. Society needs to make it so they actually can't say that. Make respecting us a precondition for their continued existence. As in they literally get liquidated if they say that even once.
That's how we deal with sociopaths leveraging these non-negotiable "terms" against us. They have zero empathy, they view us like cattle to be marked and monitored and turned into cash flow. So there is no reason to empathize with their nonsense viewpoints either. Just make whatever they're doing illegal. Doesn't matter how much money they lose.
At least the programs are (currently) opt-in.
This amusing anecdote is buried:
> One driver lamented having data collected during a “track day,” while testing out the Corvette’s limits on a professional racetrack. > [...] he was denied auto insurance by seven companies [...]
The worst part is that assumptions about who’s driving the vehicle.
The track day thing probably was the funniest thing in the article, though.
Pressing the SOS button to cancel [as sticker suggested] was met with so much difficulty that (while the operator was on the line still) I found the fuse panel and pulled out `DCS` to disconnect the call/tracking. This ended our trasmission.
The article makes clear that most people don't know what's happening with their data. They opt into something else and this data collection is included - that doesn't sound like much of an 'option'.
However, this being integrated into the vehicle in an absolutely intransparent way is a huge step up and a really unsettling privacy violation.
For this to be ethically viable imho, there need to be a few prerequisites
- it’s transparent what has been transmitted
- you can always easily opt out, but you may loose the discount you earned
- your driving can’t make your premium go up beyond the base premium without the discount (sensors will never paint an entirely accurate picture)
> I have I personally and it saves me around 300€/year on my cars insurance because I am a very defensive driver.
No, that should definitely be opt-in, with explicit consent to data collection and process purposes.
My sister had it, and it was biggest piece of crap imaginable. The system would send her emails warning her about "lack of smoothness" in her driving, because....the system would rate her down every time she went over a speed bump.
The biggest problem was that she would get emails saying "we've detected you were going 70mph in a 20mph zone, if this continues we will cancel your insurance", so we would call them and ask them to provide GPS logs, which they always would - and the logs would always show that she was going legal 70mph on the motorway, which at one point goes above a smaller 20mph road - and of course the system was stupid enough to just query the speed limit for every point, not realizing that this wasn't the road she was actually on. We would email them back explaining, and the warnings would go away until she went on that road again.
Absolute waste of time and money, I think the insurance company would need to pay me to have this fitted, the nerves it cost my sister to have that piece of crap in her car weren't worth whatever discount she got for it.
And after that they'll mandate it for everybody.
I already pay a premium for having more horses under the hood. I don't want to get dinged when I use my car's power.
There's somebody on YouTube describing the parts of the OnStar feature: https://youtu.be/TZILodhvjdw?feature=shared
Wonder if that would still work if you additionally shunted the antenna with some kind of impedance matched load.
a) Go off grid. Don't use The tech that these cars make.
The problem with this is that it is impractical for people that use see alot of value in using this tech.
b) Pass more regulation.
I am a Hayekian and I believe that regulation will not help with people that know the ins & outs of the regulation, also it's doesn't stop them. It just means corporations are willing to misbehave as long as they can play the legal gymnastics and pay rudimentary fines.
Now, The third option which I see would be the best but isn't talked much about is the promotion, and installation of homomorphic computing or homomorphic encryption.
I am not a cryptographer so I really don't fully understand it's limitations. But adopting this would simply make all these data abuse issues vanish.
Cryptographers, why hasn't homomophic Computing or homomophic encryption been massively adopted?
Homomorphic encryption is where you can compute on the encrypted data without ever decrypting it.
Logically, it sounds like a pipe dream to me, but apparently it's a thing.
The truth of the matter may be something other. Life is not always logical.
We can only do a limited set of operations homomorphically. Moreover, it’s more power intensive than conventional computation. In most cases, local computation is the more effective (and secure) solution.
Here is an example, I would for instance use Google Maps for Navigation but Google or any other third party would have no idea where I am going.
I used it in the first company I worked for and it works beautifully.
A) and B) work but they are not as effective as homomophic encryption.
You don’t need homomorphic encryption for this, just local route processing. In the case of car data, the auto companies aren’t doing any useful processing of the data for the user. Homomorphic encryption is irrelevant.
Homomorphic Encryption reduces the breadth of computations that can be ran on the gathered data, by making it inaccessible outside of the specific homomorphic scheme that was chosen. So yes, in that sense it cannot be used arbitrarily.
However, the results, i.e. knowledge derived, from the chosen computations can still be shared arbitrarily, which IMO is a much greater issue, as the need of the result sharing will inform the computations that can be done within the scheme.
Who defines the computations? Surely not the users, and lacking regulations, also surely not regulatory bodies.
For example the USG is forbidden from collecting communications from US citizens, but that does not keep it from buying this information from private domestic sources or from other governments.
Why is everyone so quick to say 'well, they are getting away with it, might as well let them' instead of trying to use our processes for the purposes which they were designed?
The problem with English law, is that you have to explicitly declare what is wrong a head of time. So we just end up with endless needs for regulation ls.
If we had legal systems like Hammurabi Codes, they work work way better.
You’re using one badly-written law to discard a category.
Why not look at the FDA? When was the last time you were poisoned?
Enforcement is fractured. It’s a mandatory-complaint driven model, which is both intensive (every complaint demands manpower on both the regulator and regulated’s sides) and prone to abuse (known tactic for quashing European competition: herding complaints). All that means it’s ambiguously burdensome, which means there is a fixed cost to compliance even if you aren’t doing anything wrong.
Sure. It was still prevalent prior to the F&DA of 1906.
How many deaths happened because of excessive regulation, extreme delays, and overall refusal to acknowledge other medical bodies' acceptance of treatment?
The CATO institute, a Republican think-tank, put a number on FDA drug law alone from 20000-120000 deaths per decade. (I was aiming at another more impartial org, but sigh)
https://www.cato.org/commentary/end-fda-drug-monopoly-let-pa...
That said, even though I agree with them in this case, that bolsters the case for regulation being effective. If the FDA were ineffective, pharmaceuticals could “play…legal gymnastics and pay rudimentary fines” to get around their power. In other words, the magnitude is undisputed; we’re debating the sign.
> Any use of personal data for an objective that is incompatible with the primary purpose of proces- sing is a misuse that is subject to administrative or criminal sanctions. > For example, a mechanic cannot sell the vehicle’s technical data to insurers to enable them to infer the driving profiles of their policyholders.
There may be a lack of enforcement, but it seems this type of data may be protected under GDPR.
[1] https://www.cnil.fr/sites/cnil/files/atoms/files/cnil_pack_v...
What do you have in mind to ensure standards that are good for end-users are put in my place?
And fines have been levied and are levied constantly. It's mostly a man power problem as to how many, but the fines pay for more man power in some places so it all works out. It's just slow, which is why people always complain that nothing ever happens.
The average buyer won't understand or care about it so there is no direct pressure from consumers. I think regulations is not optional (and homomorphic encryption may be mandated if viable?). Breaching regulations is often a "cost of doing business", but some recent regulations (such as GDPR) can actually create very large fines in many countries. So it seems that what may be needed is good enforcement and measured penalties. Another deterrent would be having penalties that are not money.
This is the issue with so many laws. Stricter fines basically never deter would be offenders from committing the crime. What deters people is a high chance of getting caught.
Sure, the car company will homomorphically encrypt your driving data when it sends it to its own servers.
You’re trying to solve a social problem with technology. That doesn’t work.
You can encrypt the data such that the insurance companies cannot target any particular individual (which is my problem her) but they can use the data to improve their insurance pricing models.
I have no problem with a health insurance company using population data to find out how many are susceptible to say cancer.
But I have a problem when they use this data to over price a particular individuals insurance because their gene say that they are susceptible to cancer.
We already have population claims statistics, a product of regulations that require reporting. What insurance companies want is discrimination within the variation.
a) Impractical because cars are needed for daily life and there’s no incentive for automakers to not sell your data.. so all cars will unless this becomes a compelling enough product difference to move the needle on profits,
b) Legislation/regulation that creates the right incentives isn’t easy, but certainly doable.
c) Impractical because homomorphic encryption is absurdly computationally expensive, is still not a fully unsolved problem, and.. in what universe do automotive companies implement this far fetched and expensive means of privacy without sone.. err.. regulation?
It doesn’t seem to be superior to option b)
So you try nothing and are out of ideas. Amazing.
> homomorphic encryption
Let me get this straight, you think regulation is too hard because corporations don't want it, but you don't see any problem with homomorphic encryption, which is difficult to implement, poorly understood by consumers, AND provides privacy guarantees that corporations don't want?
Really?
that is such a funny thing to say. Car industry is heavily regulated and car companies do work with the regulation. They are already regulated on safety, fuel standards, dimensions... Adding data protection into the mix makes sense.
Not only would they fight regulations like data safety that would open them to potential litigation when lose the data or sell it to the wrong player, but they would win. Privacy isn't the political football that the environment is, and you can't point to death statistics like you can with safety issues.
[1] https://www.the-rheumatologist.org/article/revisionist-histo... [2] https://texasclimatenews.org/2022/03/19/decades-of-lobbying-... [3] https://www.cbtnews.com/auto-lobby-group-warns-fuel-efficien...
I work in the automotive industry. It is very heavily regulated. The majority of people have never heard of ISO 26262 but it's keeping billions of people safe every day. Data privacy can work in the same way.
I would be happy to turn down the tech, but I wonder how long until I can't feasibly buy a car (or a car I want) without it...
I work in tech but as far as I am concerned, you can keep all your smart homes, cars and other gadgets and soul sucking (anti) "social" apps.
Somewhere along the way technology was hijacked to control us rather than empower us. And if you don't like it: shut up because "progress" is inevitable
Everyone has always said this since the dawn of farming. It’s not a particularly useful insight: the question is in how and how it is to be banned or balanced.
That’s a not what “since” means.
If a technology causes social change, it will create winners and losers. Those winners tend to autocorrelate (inversely to the magnitude of the shift). As a result, small technological revolutions tend to result in a shift against the broader “us” while broader ones disempower an elite that tries to gain sympathy by aligning itself with that broader “us”. If it doesn’t do either of those, it is—almost by definition—not a technological shift that resulted in social change.
As a result, complaining about technology working against a nebulous “us” is basically saying we had technology that caused social change. Which isn’t a novel point.
[1] https://www.edmunds.com/car-technology/car-black-box-recorde...
> "More specifically, automakers are selling access to the data to Lexis Nexis, which is then crafting “risk scores” insurance companies then use to adjust rates. Usually upward"
In an ideal world, such data-harvesting might lead to cheaper prices / a more efficient insurance market - which would make the privacy loss worth considering from a trade-off standpoint, at least in theory.Unfortunately it's instead likely to just lead to higher margins for insurance companies. And the only way to compete would be to harvest more data for better predictions.
Why? Insurance pricing is heavily regulated, and profit margins for insurers have always been very low.
If companies offered say a $50/month discount on car insurance premiums in exchange for gathering data, I imagine a large proportion of people would indeed opt in to that (setting aside issues of selection bias or trust in this ideal world)
In an ideal world (read: perfect information knowledge), this would lead to insurance being a bad deal for every consumer of it. In the theoretical position where insurance companies can accurately price each individual customer based on their habits, they will charge them exactly what they cost _plus_ a margin.
This is only useful for a consumer if they cannot access cash or a credit line to pay for a sudden large expense. Instead, insurance effectively becomes paying the credit line ahead of time.
Isn't that the main point of insurance?
Insurance can also socially redistribute bad things. Which fair enough it is in practice a result of insurance but I don't think that's what it was invented for. And indeed the better the insurer's crystal ball the smaller this effect is.
Although in practice I don't think there ever will be a crystal ball good enough to make insurance a bad deal for everyone like that. You always have to insure against another driver being bad or just plain bad luck.
No, insurance claim can be larger than sum of lifetime premiums, contrary to credit.
The trick is no one can know which side of the ledger we’ll fall on. You can be the world’s safest and best driver and still get t-boned by a driver with no assets and no insurance.
Because in general no, people buying insurance do not pay in what they will individually cost (plus margin). Rather most will be paying in much more than they will ever cost, whereas some will cost much more than they have, or ever will have, pay in. One total property loss or serious at-fault auto collision (say ~$400k) will dwarf a lifetime of premiums ($2k/year for 50 years?).
The point is that such things are rare, so most people will have zero of them over their lifetime. But even perfectly knowing the a priori chance that each person may suffer a catastrophic loss, you can't know which specific people it will be.
I did it and recommend everyone else does as well.
Do you have a link where one can opt-out of data sharing or deleting associated data? I cannot find anything on the LexisNexis site allowing for that.
https://www.lexisnexis.com/global/privacy/en/privacy-center-...
This looks like the Canadian page, made a request and let’s see where this leads to.
Edit: changed prescription “data” to “records”
My understanding of HIPAA (possibly incorrect) is that it's attached to the data.
If a covered provider is leaking HIPAA covered data to a non-covered business associate entity... that's a big no-no and a fine.
See https://www.hhs.gov/hipaa/for-professionals/covered-entities... and https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-...
In my experience, covered entities are really serious about signing BAAs with any of their hosting vendors and partners, as afaik the liability falls on the covered entity if they didn't have an agreement in place and data leaked from a vendor/partner.
I'm sure there are legal HIPAA data escape pathways (given the financial incentives for companies to find them), but I'm curious on the details.
Afaik, there's no way to make HIPAA-covered data non-HIPAA-covered, and absent that everyone in the custody chain is responsible for anywhere it eventually ends up.
That said, I expect the way this works in practice is more likely data that originates with non-HIPAA-covered entities, but can be massaged/combined into a similar product.
If it is insuring known or likely risks, then it becomes a subsidy or wealth transfer (which should be the domain of governments).
Besides why should less risky drivers subsidize riskier drivers?
Here is a car that sells your driving data. Here is one that won't
If you knew they were selling your data you could objectively demand a discount from one of the 2 .
They essentially do. If the safe drivers are never at fault, those premiums went somewhere. If the risky, repeat accident drivers aren't paying thr full price replacement vehicles, that money came from somewhere.
But when they use overly simplistic data (or use it in an oversimplified way) that makes the highest-skilled drivers appear in the same batch as low-skilled and high-risk drivers, that is not subsidy, it is unfair penalization by stupidity.
(see other comment on logging of g-forces)
Unknown to whom? To you, the insured? Or to them? Business thrives on customers with incomplete information.
Some merchants have multiple registers for the sale of different types of products, but generally if you receive only one receipt for your full purchase, it will be recorded under the category code for the merchant's primary business.
https://www.tidalcommerce.com/learn/what-is-level-3-data
On my American Express credit card statement, all the airline flights show the details of the flight and Staples.com transactions show the specific items that were purchased. And this has appeared for at least 6 to 8 years.
You can also get a sense of the scale of the problem by the reported revenue and growth rates (which they're always eager to highlight).
Sidenote: I wonder if they've considered close follow distance or frequent lane changes as a risk factor.
Unless the car has cameras staring at you, it doesn't know if you're checking your mirrors before lane-changes, going 10-under the limit in the far left lane on a busy highway, etc.
Even then, cameras aren't good because assuming people are telling the truth when they use test-taking software, there are false positives that have to be manually-reviewed by proctors when the computer thinks you're looking in the wrong place.
(Edit: it also doesn't know if your mirrors are positioned properly so you do not have a "blindspot". In every modern vehicle I've driven, it is possible to set the mirrors so you can continuously see cars in the left or right lane next you - from the rearview mirror to the sideview mirror to the side glass. Hint, if you can see the side of your own vehicle in your sideview mirror: it is set improperly.)
---
> frequent lane changes as a risk factor.
People not willing to change lanes is how you get more traffic and more dangerous driving overall. Traffic should stay right unless passing - which means once someone is done passing, they also need to move to the right. People crusing in the left lane is how backups happen and people trying to make more dangerous lane-changes to pass on the right. Less lane changes would be a bad thing to incentivise.
If more people used cruise control in general, that might help (don't know if any studies have been done about that). As it is now, most people's speeds ebb and flow and that causes traffic, especially when they either consciously or subconscious try to speed up to match someone trying to pass them, or whether it's curves, hills, narrower lanes due to automated tollbooths, bridges, etc.
This is false. Lane changing, causing others to slow down, is a leading cause of traffic waves.
https://www.sciencedirect.com/science/article/abs/pii/S01912...
"Frequent lane-changes in highway merging, diverging, and weaving areas could disrupt traffic flow and, even worse, lead to accidents."
Instead they market cars as exciting race track like vehicles, things that let you do what you want, when you want. And now they will collect data on the people who actually do that.
Personally I would prefer a car that helps me be a safer driver by following the law. Ensuring there are no pedestrians or cyclists in front of me, etc. But at the end of the day, automated enforcement is a good thing, so maybe this will help some people become safer drivers, though the reality that’s probably more likely is that fewer and fewer people will be able to afford/get insurance, and because our country is so car dependent, they will just drive without.
I was in a rental car that had this once. Was on the highway, needed to get around another driver who was being unsafe. Was unable to do so because of the limiter. It was easily the most unsafe vehicle I've ever driven as a result. These mechanisms lack situational awareness and nuance, and thus are a direct threat to my personal safety. They very much need to be banned as a matter of course until such a time as humans aren't allowed to drive at all.
The problem is in how is dangerous driving assessed. Simple to apply rules lack the understanding of conditions. Telematics are going to be low bandwidth data, almost certainly without enough data to form an understanding of conditions.
There must be some correlation between bad credit and likelihood to be in a collision.
Add in the fact that if you are not getting "growth" on the stock market, then you must be doing something wrong.
Then there is a lot of pressure to monetize the data. So from a consumer POV, it is better to not have anything collected.
My quip was to make a rather negative comparison, while noting that the whole collect-and-monetize industry is a net negative for both the economy and human society.
US lawmakers can put a stop to this and every other privacy scandal over the years at any time you know by passing a strong privacy law but nahhhhhh we can't do that!
It's yet another reason why people should buy older cars (preferably 2012 or older) since the automotive, insurance, and data broker industries don't give a total jack about your privacy and sadly the US aren't going to do jack about this either until we can elect more people in office that does care and pass a strong privacy law in the process.
The signs they consider to be "bad driving" are high-g braking and turning.
Yet these are EXACTLY the same signs created by highly-skilled driver or racer operating at the limit, as they would to avoid an accident (thus costing the insurer $0), where the same situation would catch 90% of the low-g drivers into a wreck that totals the vehicle and causes injuries. A core element of high-performance driving for accident avoidance and racing is to understand the limits of tyre traction, and how to operate the car up to those limits — but not over them — i.e., just under the limit of sliding (sliding friction is always less than static or rolling friction), and to choose lines that maximize available traction.
Distinguishing the signs to tell a high-skilled driver from a bad driver requires more than just "is that number high?". You must look at the circumstances, the frequency, the conditions, the rate of increase and decrease of pressure, the slip angle, the grip state of all 4 tires, and more. But of course, no one bothers to do this.
It is the same kind of institutional stupidity that causes a world-class weightlifter with 4% body fat to be classed as "obese" because s/he scores high on the stupidly simplistic BMI scale(a ratio of weight to height).
Except with BMI insurance companies are not allowed to re-rate people and doctors can instantly adjust treatment when they see the person is obviously not obese but highly trained.
With auto insurance, they can secretly re-rate us on bogus numbers that actually down-rate the highly skilled.
Seems more attractive with every passing year to rebuild older nice cars than get into the new rolling spyware contraptions.
My example is NOT about "self identified" "experts", but REAL experts who ACTUALLY have the skills. They also are typically very safe on the roads and know that race-like on-the-limit driving on the streets is idiocy.
The point is that people who ACTUALLY have these skills have a far wider margin of safety than the ordinary driver, and far better capability to avoid accidents. But, they will also — with that far wider margin of safety — often turn or brake with higher than ordinary G-forces.
For example, ordinary street tires and suspensions on modern cars can handle 0.9G lateral or braking acceleration. Ordinary people get uncomfortable at 0.2G lateral acceleration.
An unskilled driver approaching 0.25G lateral acceleration does risk exceeding adhesion limits and losing control because they are insensitive to inputs and feedback. In contrast, a skilled driver can turn at 0.25G all day with virtually no risk, as they are accustomed to driving at 3-4 times those Gs, and are situationally aware, sensitive to inputs and feedback, and choose lines and inputs that avoid the limit.
They are far less of a risk than an unskilled driver at 0.1G. Yet, the skilled driver will get flagged as "bad".
With deeper understanding and analysis, they could make the distinction between actual expert drivers vs overconfident idiots. But I see no indication that this will happen.
Now the dream car will soon be an electrified lada niva, no electronics, speeding impossible.
You do realize that wheel speed sensors and g-force sensors are already standard equipment in most cars, and that this is part of the data they are selling, right?
Electrified Lada Niva, eh? Depending on how it's electrified, it might go waaayy faster than would be sane... ;-)
If not, are there guides on disabling the modem without damaging diagnostics or infotainment?
I want a car that does not transmit data. Which means I may need to get my 2010s crossover rebuilt and reupholstered instead of getting a new car.
https://www.cx30talk.com/threads/thoughts-on-tcu-disable.374...
> Mazda CEC makes it quite difficult to actually request/disable your TCU. It can take many phone calls and escalations to get someout to understand the request and actually "push the button" to send the disable event to your car.
Honestly I’m just totally disinterested in just about every current new car model.
Is that a lot of money for GM? I would have guessed no, but it doesn't seem like very much for selling out their customers like this. Either it's more to GM's profits than I'd expect, or they really don't expect much PR blowback risk at all?
I don't know if they are right or wrong, but...
> Drivers who have realized what is happening are not happy. The Palm Beach Cadillac owner said he would never buy another car from G.M. He is planning to sell his Cadillac.
Some more discussion: https://news.ycombinator.com/item?id=39666976
In all seriousness though, no. I have no way of confirming the data transmission has stopped.
My old Jetta’s door once fell off.
- mandate FLOSS by law, starting from the first SLoC, meaning no company can sudden publish software to sell something with it, the software must be published since the day zero of it's development or the hw/sw/service can't be on sale;
- mandate local first for anything, so connected cars are ok, but they just offer a simple DynDNS mechanism the owner can add to it's own domain name as a subdomain like car.mydomain.tld and reach a relevant set of APIs the car offer. All data collected by the OEM must pass though the car owners systems, in an open and readable and documented form.
If this is not mandate, by popular acclaim, surveillance capitalism will stay, since it's the new tool to know and conform the masses. Surveilled people are known, and knowing they are surveilled try to behave in a "social norm" way, fearing the judgment/social score, as a result people evolve toward slaves who obey those who establish and update current social norms. We all know cooperation is needed to do anything, those who compete then need many who cooperate, obeying their orders, to craft anything. In the past was religion, then money, now social scoring the way to stiffen the masses. Such powerful tool is not something anyone accept to loose without a desperate and limitless fight. Only a large public reaction can force a change.
I would like to see a judge with sympathy for this sentiment fine them out of existence.
The problem with allowing this kind of data usage is you will also have other moral authoritarians that wish to use the data as well.
i would have guessed that this is making more money. Does anyone know why this is the case?
Imagine what your premium might be without this service.
For example, I drive less than 900 miles a year, have had no accidents, citations or thefts and keep my 10 year old car in a garage. Yet my payments are $1500 per year. And after getting estimates from several companies, this was the lowest we could find.
Even with this service, the inflation rate for auto insurance is higher than anything else in our family budget.
Thank the lord for data sharing.
It doesn't seem in the car company's interests to take on the reputational risk for this kind of financial reward.
Also, companies seem to work against their own interests quite often. The spyware is probably on some separate budget with separate bonuses attached. So "locally" in the department it might make financial sense to spy on the users.
Tell that to Boeing, they're on course to tank the entire company out of the financial shenanigans they pulled after 1997.
As soon as a company goes publicly traded, the incentives change - there is no more priority on long term, the only thing that matters is INVESTORS INVESTORS INVESTORS (read that one in your finest Steve Ballmer voice).
Data sharing with third parties is ubiquitous in almost all industries. Every single company that deals with financial products reports account information to third parties (Experian, Equifax, TransUnion, Early Warning Services, ChexSystems). If you return an item at a retail store it gets reported to fraud alert databases. Most medium to large employers report the contents of the paychecks of their employees to The Work Number. Insurance claims are reported to LexisNexis. Oil change companies report milage to CarFax, which insurance companies use to look up if you're reporting accurate mileage.
Data reporting and sharing is ubiquitous; it's standard operating procedure. Having a few "privacy nerds" complain about it on the Internet is not risking their reputation.
> a few "privacy nerds" complain about it on the Internet is not risking their reputation.
The news about GM's OnStar tattling (their words) on drivers is front page on several big news sites like CNN. This is not just some privacy nerds, this is a whole bunch of mainstream media outlets calling out GM by name.
I'm confident the PR team at GM is working overtime right now to try and find a mitigating spin.
Not necessarily. In many parts of the United States, a car is the only viable mode of transport. If you price the bad drivers out of the insurance market, they will forgo insurance all together. Then, if they cause a loss, they will be uninsured and the other driver's insurance will have to pay for the loss (or spend resources in costly suits) anyhow. So, then good drivers premiums will need to go up to compensate for the extra "bad drivers can't afford insurance" risk that good driver's carry. We end up in a similar situation in a roundabout manner but with the added element that now all our data is stored on everyone's servers.
Personally, I"m not opposed to dangerous drivers paying higher rates, but the devil is in the details.