Automakers Sold Driver Data for Pennies, Senators Say
nytimes.com
nytimes.com
> said that the company had gotten the precise location of about 10 million G.M. cars up to every one to three seconds, but that the data did not include identifying details about the driver.
The word "Anonymously" means exactly nothing here. If one's exact location and movements are collected, wouldn't that include a lot of time and datapoints where the car is spending time at work and home locations?
Seems incredibly trivial at that point to deanonymize usage.
It kills me that I can’t remember where the article was exactly, because it’s one of mu favorite examples of why fighting indiscriminate tracking is important. I remember it being from a Scandinavian newspaper, maybe Dannish?
https://nrkbeta.no/2020/12/03/my-phone-was-spying-on-me-so-i...
The original in Norwegian https://www.nrk.no/norge/xl/avslort-av-mobilen-1.14911685 has some nice visualizations.
https://www.nytimes.com/interactive/2019/12/19/opinion/locat...
https://en.wikipedia.org/wiki/WOT_Services#Sale_of_user-rela...
https://www.technologyreview.com/2019/07/23/134090/youre-ver...
https://www.nytimes.com/2006/08/09/technology/09aol.html
https://techcrunch.com/2006/08/09/first-person-identified-fr...
AI is legalized intellectual theft and breaks so many laws (privacy, copyright) yet it's a magic box that randomizes who is stolen from so people accept it.
All the business-speak about data privacy is an attempt to hold the general public at bay.
AI and data processing algorithms can do more advanced things, like stylometric comparisons, biometrics, and doing the grunt work of filtering out data associated with a particular individual. You're known and modeled with higher resolution and greater detail than any intimate partner or therapist.
No problem here! This will certainly not end poorly. There's absolutely nothing that could go wrong.
It is possible to do data collection in a relatively anonymous way (it's never possible to do it in an entirely anonymous way), but there's no way for a person outside the company to know if it's actually being done that way, and there still has to be an entity somewhere that processes the non-anonymous form of the data.
I've often thought that cynically, the real motivation for having non-technical people in these public-facing roles (sales, marketing, media etc.) is so that they can honestly, earnestly, present their understanding of the product. An understanding, that is, which lacks the nuance to properly convey the implications of pretty much any aspect of the situation.
Then we can all analyze what they are collecting and can improve the visibility this issue gets. We really need better privacy laws in the US but laws can't move as fast as the tech sector does.
What company do I need to goto to buy this data?
fucking around and finding out is much less commendable when you fuck around with other people's lives and let them find out.
It's about the balance between those things.
It's totally possible that this action could result in someone uncovering a serial killer or organized crime ring.
This could save lives.
Why are you opposed to an action that could save lives and bring about desperately needed changes in privacy laws?
If it's legal it is so my choice to make.
If you don't like it lobby to make it illegal.
We see this all the time when someoe hurts another person to stop them from hurting another person. It's codified in the law.
Whether or not you're doing a bad thing isn't determined just by the nature of your action but also by your intention.
That's not acting like a bad person, though.
In the context of this discussion, acting like a bad person is intentionally harming victims in order to harm the entity that did the victimizing.
Its the continuation of https://techcrunch.com/2023/08/01/california-privacy-agency-...
https://gbhackers.com/toyota-data-breach/
"The in-vehicle GPS navigation terminal ID number / The chassis number / Vehicle location information with time data."
Toyota = Lexus = a lot of politicians and their families.
Maybe it's overly simplistic and definitely unrealistic but, there it is.
The money maker here is the scale of which it happens at.
I don't want to be paid for the collection and use of my personal data, I want for the collection and use to not happen without my informed consent.
You should not have any expectations of privacy today.
On the flip side smaller questionable used car dealers have definitely installed trackers to help with repoing a car in the event the buyer stops paying, or even worse lock down the car so it won't start.
That sounds like they gave me a free GPS unit that I could repurpose.
It's why car interiors are so cheap, when alternatives aren't expensive.
Looking at their revenues, this is just silly money. Honda pulled in $100B in revenue in 2022; Hyundai, $85B.
That they would even bother with this program given the potential backlash is bizarre.
I don't really care where Ms. Wilkins next door takes her cats during the day, but if I were looking to buy a small business I might like to know which grooming service is drawing people from further away.
Maybe if it was aggregated and restricted to average number of cars at X public locations at any given time. But it sounds like the individual data is being sold here.
The counter-example is the world where safe drivers much more heavily subsidize extremely bad drivers. If I have no accidents on my record in 10 years, and have every observable behavior that indicates low risk, why should I pay substantial amounts of money every year because the government does not want insurers to have the data to tell I'm not a high-risk driver?
For real security, I’d like to pull the modem fuse, but i know neither which fuse to pull, nor if other systems might stop working.
It wasn't GM that did this. GM is an abstract entity composed of people.
Who specifically did this? We need to name and shame them.
This is only correct course of action in these situations.
So who specifically did this?