Data collected by cars and sold to third parties(theverge.com) |
Data collected by cars and sold to third parties(theverge.com) |
https://youtu.be/Ft12aZffCEg?si=qP1J5k6RXAxmZChf
Talking as an eastern european: unless you live in a sunshine place (~Mediterranean) most of the 90s car already eaten by the rust + the salt used for defrosting on roads in the winter.
Also by my experience cars (except from SUVs) somehow never kept up with the road quality. Pot holes are a problem everywhere but you can see that certain brands for example japanese and korean ones never designed for deteriorating road quality (and I don't mean offroad) because... you know they just don't exist in the home market. So the tires, wheels, suspension are not as robust as they should be.
Sure _everything can be fixed_ but then your car becomes a hobby and might not everyone has an attitude and time for that.
You can still find good examples in the UK where we have salted roads. I've paid for mine to be dinitroled. Pot holes etc are a problem here and they will affect newer vehicles too and used to go through a tyre a winter.
But it never is economical or more environmental friendly.
Whatever I saved on my old car compared to a newer one will never be less than the theoretical fuel savings on a newer car. Repair costs will never be as much (assuming you buy a popular repair friendly car). And nothing new needs to be built for me either.
I have a seven year old Volkswagen, not financed. I'm security conscious and made sure to disable all the data collection I could find in the companion app before removing my account, turn off remote access services, dig through the infotainment to turn off what I could, etc.
Last year I requested a Carfax on it, and one of the fields in the request was current mileage. I entered an estimate like 75000 miles. On form submission, that field failed validation with red subtext along the lines of 'this is less than the last reported mileage of 75345, reported <5 or so days prior>'. Checking my odometer and looking at my past few days' trips, that was indeed accurate.
The car hadn't been to a shop or out of my possession in weeks, so I can only assume the telemetry was still dialing home and selling to third parties despite my best efforts to disable it.
There's an exceedingly common type of failure I have seen myself in industrial electronics and (has happened with Tesla at least once), that some module keeps a log of some kind in a nonvolatile flash, and this flash has a limited lifecycle, which the equipment reaches at some years into its life (or earlier, if the flash came from a bad batch, or more logging happens than planned).
At this point the board usually gets bricked and replacement is very hard due to cryptographic handshakes between components.
This is never enough. You can't trust a software switch. You need to remove the hardware capability if you want to make sure the car isn't spying on you. In the best case, the telematics box has it's own fuse, and that may be enough. In other cases, you need to find the box and unplug it. The service manual will have it's location. In some cars it's easily accessible, in others less so and you need to remove the glove box or part of the dash. Dealers will probably refuse to do it, my advice would be to DIY or find an independent mechanic who will do it.
You could probably find some interesting info if you send out some privacy requests through the chain. LexisNexis and Verisk are consumer reporting agencies, so they have to provide you a disclosure on request. Start there.
My car is from 2011 and I do wonder if there is any telemetry in it.
I thought, I wonder if it’s the same guy? Sure enough.
Stop it.
Every business likes data collection, until they don't.
My main motivation to get a better car was, DD goes to a super prestigious college and it seems degrading to put their bumper sticker on a 23 year old car! But I guess I won't get another car. Serves you right mfr mfrs!
Android Auto, Apple CarPlay, OEM mobile app...Bluetooth??
Consider the business case of leased Comcast (as the largest ISP in the US) modems broadcasting open side-channel xfinitywifi SSIDs...essentially everywhere.
I've been handed a Carfax on my own car that has a reported mileage much greater than the actual mileage on the car, and the car has not been out of my possession.
In other news, I think I'll be taking a trip to somewhere down south to find a nice, used 1999 F350 dually with a manual transmission, since they're going to cease to exist shortly...
You should have an empty glovebox as well when you take it in for service if you don't trust the shop.
If you have registration / insurance paperwork, you're now on that shop's mailing list and can expect to get "$15 off your next oil change ..." flyers in the mail.
Random Public data:
Honda sold data on roughly 97,000 cars to Verisk for $25,920—amounting to about 26 cents per car.
Hyundai sold data on about 1.7 million vehicles for roughly $1 million—about 61 cents per car
It would be cheaper to do nothing if that were true.
In my understanding, this pretty much makes this type of driver data illegal to sell or share. CalPrivacy's enforcement division has their eye on connected car manufacturers already, so we'll see what they do with that.
https://leginfo.legislature.ca.gov/faces/billHistoryClient.x...
The only data we need is if you’re at home and the charging metrics /w commands.
But the amount of unnecessary data that is available, is a real privacy concern.
Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.
Facts about the car: VIN, spec, recall status, odometer. Attested by someone other than the owner. Outlives every owner and the owner is the last to have it, if at all.
Facts about the driver: speed, location, timestamp. Thats what GM sold, the fix is to not collect it but OEMs seem to take 'anonymization' approach.
The DRIVER act treats both as the same which is why it fails to fix anything. The second needs a ban. The first needs the opposite - especially as we take the driver out of the vehicle - an authoritative record of the vehicle. How do we expect AVs to have adoption when the only safety certification is the company's press release?
Either via permanent 4G/5G link or during service intervals in the shop.
Source: I analyzed these data as an intern for one.
- Chat Control law, now all messaging must be intercepted and monitored.
- eIDAS law, mandating that web-browser vendors must now accept state issued root certificates, so that states can selectively and without any legal procedure deploy MITM attacks at will.
- ADDW law, mandating that all new cars must a permanent mandatory camera and microphone surveillance module inside a car, which can't be disabled by law (bye-bye insurance if you will). There also other fun things in it like mandatory autobraking, mandatory auto lane-assist etc.
- ProtectEU laws, demanding backdoors to emails and such (maybe it's the same as Chat Control, not sure).
- AI Act legalizes AI surveillance over CCTV recordings without any judicial approval.
- European Media Freedom (duh) Act legalizes deployment of shit like Pegasus against journalists.
I'm pretty sure I'm missing a lot here too. You get the picture. EU is getting fast track into Stazi 2.0, everyone is fine with it, "because children" /s
> third-party partners process information about you and how you use our services, including clicks and screen recordings, using first and third-party cookies, pixels, and similar technologies
Corporations have profiles on citizens that makes the Gestapo or the KGB seem uninformed in comparison. There is no freedom when the people in power know everything about you.
It's still better than other modern cars though? I think.
Can I disable all data collection from my vehicle?
Fair to say the verge don't really care about data being collected and sold they just want the clicks
All it can tell us is that maybe this is something tesla should market (if it’s true) rather than bullshit like “self driving”
You should go try it. Do a free test drive with FSD next time you have a free hour. You'll stop using the scare quotes.
And there are technological "advances" I would very much like to undo. One of them being social media, another being modern cars. Automobiles peaked when they were purely mechanical. An average American high schooler could understand all its systems, and many did. When they started becoming LANs on wheels beginning in the 90s, they became necessary millstones around their owners' necks, and these days they're as inscrutable as a smartphone, just as user-hostile, and just as tethered to vendor services. I think my father was speaking from a place of wisdom when he groused about computers in automobiles.
And no, EVs are actually simpler than ICE engines, their drivetrain being basically a battery, a set of electric motors, and maybe some variable resistors to control speed. An EV that is purely electromechanical and operable via analog controls would be a godsend, but it's not going to happen under current regulatory environments.
We need a solution, not a Band-Aid like the "Freedom Car Act." I believe that legislators are deliberately coming up with legislation that mildly hinders, but in no way resolves the issue in order to keep their sugar-daddies freewheeling.
Fuck you, data leeches ... you'll get nothing from me.
This is why I'm a vocal advocate for having an LLC own any vehicles you might drive. It protects you from the license-plate reading lookup as well from Flock et all. Though I don't know it guarantees you can't be looked up by insurance it's resistance by one more bit of friction. The vehicle I drive now is an old 2012 Lexus owned by Montana LLC and it also has no smart technology and very little insurance costs.
And they're stautorily exempted from a whole boatload of privacy laws, like HIPAA.
I'm going to pirate shit until this is fixed.
Unless you’re of the opinion that since it’s data, it’s not stealing?
Or: "All companies are essentially gigantic conglomerates eating each others' food by selling my own and others' data to each other, so I basically have rights to their claimed assets anyway."
Or: "No company or government respects my privacy or property rights, so why should I respect theirs?"
Some of that is a form of "I am going to steal, because others are stealing", and well, if stealing becomes the norm, yeah, I would say the comment has some validity in a few words for the common citizen.
It's wild how convenience trumps everything and then we look back to say, "we should have done better."
Never underestimate the risks of spousal dissatisfaction.
It can't. Not realistically.
It can be stopped by legislation. But that would require politicians who have our interests as a priority rather than the various industries. So not going to happen anytime soon.
It also seems to conflict with `right-to-repair` laws if the capability is legally required.
If you are a CA resident you can also get on the state's DROP platform to request that all registered data brokers delete your data, but it's only for deletion and not the other 4 types of data requests allowed under the CCPA (right to know, right to collect, right to opt out, and right to limit use).
Then someone offers them $1 each for a fleet of 1M cars, who is going to turn down $1M for a few TB of data?
Selling it is pure icing on top.
If your buyer is the end owner, probably increase a little bit unless they are surveillancemaxxing.
Easily reversible mods only affect price for suckers anyway.
isn't it not-funny that the super-invasive Google profiling and ID checks are also part of "Google Play" ?
I could see a fuse for cellular comms, be presumably that would also disable maps, contacting emergency services in an accident, etc. which might be an acceptable tradeoff.
Its only job is to detect harsh acceleration and brake events. Probably being sold to your insurer.
I appreciate Tesla's position on the matter, but I'd still rather have the collection and dissemination of the data more tightly regulated by law.
It works. Most people are happier focusing and holding forth on that and repeating familiar statements than they are talking to congressional staff about policy.
Your car that you paid a lot for and you like and have positive useful experiences with every day? That’s going to be way farther down the list of things to worry about.
There is no EU law that mandates "all messaging must be intercepted and monitored."
There is no EU law mandating permanent, non-disableable cameras and microphones in cars.
ProtectEU is not a law, not related to email and does not demand any "backdoors."
The AI Act bans real-time facial/biometric recognition in public places... which is a good thing. It does not "legalize AI surveillance"... quite the opposite.
EMFA does not authorize the deployment of spyware and they have publicly condemned the use of Pegasus specifically.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=PI_... https://medium.com/@shahadilh18/your-car-will-soon-watch-you...
ChatControl 2.0 is exactly "all messaging must be intercepted and monitored" ...
Some of it probably is a slippery slope argument however that slippery slope has materialized already in other areas ... And security plays a role here as well. Maybe the camera/software/system is mandated not to identify driver (as is written in ADDS "spec") but atrocious security the modern car has would probably allow for that somehow...
Right now I am repairing old car that does not track me, does not film me and doesn’t try to drive me. It’s a such a great joy to drive it without stupid beeping and automatic wheel movements. Especially without suicidal steering in construction sites when the modern system fails.
Chat Control - a) it is a law, mandatory in whole EU (because it is a "EU Regulation", and that is a law); b) I was indeed to broad and made a mistake, for now only not E2EE messages must be intercepted and monitored. E2EE is on a the chopping block in Chat Control 2.0 which is being drafted, in progress.
Advanced Driver Distraction Warning (ADDW) - a) it is EU Regulation and so it is a law; b) ADDW mandates a non-disableable surveillance camera (not sure about microphone) inside a car.
ProtectEU is indeed Chat Control plus extra, so here I was incorrect. Encrypted emails are temporarily safe, until Chat Control 2.0 is passed. And given how they bruteforced CC 1.0 in multiple blatant retries, it will eventually pass.
Regarding EU AI Act you are replying to something I didn't write. Sure it doesn't allow real-time surveillance. I wrote that it does allow surveillance over the recorded materials. This technicality allows passing all video through storage, then monitor suspects via AI programs all without judicial approvals.
And finally EMFA does authorize deployment of the spyware against journalists in cases of investigating a crime carrying 3= years penalty. Do I need to spell out how laughable that is? Practically any national security crime carry similar or heavier penalties and govt. can start a very broad and arbitrary investigation for any reason. This means that the matter of starting surveillance is a small technicality really with zero oversight.
Although it wasn’t worth the cost of the 3 year subscription so I now just estimate the charge status based on the charge’s power consumption.
If the car is at 10% battery, it may be worth charging at .15 or .3€/kWh. If it’s at 70% charge, I’ll wait until the price drops to .005€/kWh. The whole thing is automated in HA.
These cars are more software than hardware now. And like everything else in the software industry, every product gets released incomplete and patched later.
Although the correct solution would be a USB port somewhere to insert a patch file rather that over-the-air updates that might happen while driving.
Their is a cell modem in the car, so all these features are available anywhere the car has cell service.
Are any of those things more important than your security (e.g., against hackers) and privacy?
Regardless, taping some foil around the connectors with the foil making okay contact with the metal chassis is more than enough attenuation at sub GHz microwave to remove this concern without having to source specialty terminations and crimpers (or worse, non-reversible damage to the OEM cable assemblies by repurposing their terminations). I've done the foil+tape on some of my vehicles, but it hasn't made a difference in binary "does it connect or not?" testing.
If a hypothetical future owner feels strongly about it then replacing a telematics module in the dash is much easier than replacing harness runs. I somehow doubt I would sell one of my vehicles to someone who would do that though.
https://www.tacomaworld.com/threads/simpler-solution-for-dis...
The most reliable way to permanently silence the cellular modem is to pull the relevant fuse. In the above case, this also disables the microphone, which I think is a positive. Unplugging the DCM entirely, however, seems to disable to right speaker, which is wired through the DCM for some reason.
I'm cynical, but unnecessarily coupling the ability to send telemetry with some feature people definitely want seems like exactly the sort of thing that would be done intentionally.
(Yeah, technically horrible but I’m sure someone will find a way)
I thought GP was talking about if they had to reconnect the systems for some reason, would archived telemetry suddenly be uploaded. Which is a real possibility, so I was suggesting poisoning the data. Even if you correct the clock today, the previously recorded timestamps cannot be automatically fixed. Even better would be to reset the clock on every startup event.
Which is all still a band-aid solution - a targeted analysis could mostly correct the time-keeping. This just prevents getting scooped up in a simple drag net kind of search.
You can see a map of these nodes with https://wigle.net/
While LG TVs send a lot of private data when connected to the internet, I'm not aware of any credible reports that they automatically connect to open or partner-provided wifi networks without a user choosing to do so.
It's certainly a threat to keep an eye open for, but it seems manufacturers haven't quite stooped to that low yet.
This depends a lot on the region/country. IN the US, open WiFi is unusual but it's pretty common in parts of asia, for example.
Sometimes it helps to have someone with their priorities in order keeping a reality check on people who don't always stay grounded.
I think maybe being grounded has changed - I would be comfortable doing what I described but I imagine your comfort with your preexisting solution means your ground has shifted and a reality check means you woudl rather give away your data than take the higher friction option?
Yes there are many (maybe most) who will not give up their comforts or risk modifying their vehicle in order to make it more private... but trying to play the judge in a made-up internet game of altruism olympics is not going to convert many people either.
Manufacturers use this capacity as an excuse to push more adtech penny and dime data abuse, knowing half the world will blame the government.
1. https://learn.sparkfun.com/tutorials/gnss-chip-antenna-hooku...
One of the most extreme understatement in history.
[1] https://patents.google.com/patent/US3576576A/en
[2] https://patents.google.com/patent/US3611388A/en
It has not been demonstrated actively in use, only that it is possible and trivial to implement. Statement with regards to it being demonstrated retracted.
I stand by the concept that any consumer IoT device could join these networks, and the end user would never know. The only legal solution to this problem statement is to physically disable the radio on the device if assurance is desired.
Unless a new age of unconnected cars becomes a reality in the near future, I don't see this being a long-term solution.
The near universal proliferation of owner's associations and management groups and whatnot for developments larger than ~1ac (the EPA threshold, some states/towns have lower) is something you can lay at the feet of the Clean Water Act and it's implementation and precedents over the following decades.
The exact area of the buildings, the driveways, the community park and gazebo, etc, etc, are necessary features of the site plan that makes the math that is required to meet stormwater/environmental requirements. And and some legal entity has to be responsible for that in perpetuity. Enter the HOA. This is also why HOAs often won't allow you to expand your driveway or add a non-permeable patio, it could (prob not, but still) ruin the environmental calculations they're responsible for enforcing as a condition.
I'm not nearly as familiar with car regulatory stuff but I would bet a lot of money that they're using OTA telematics to check some sort of compliance box...
Developers don't do anything that costs money, like set up an HOA, without a reason. The developers create the HOA because you need your >1ac residential development to pass stormwater permitting. While you theoretically could make each individual .25ac parcel you're putting a house on compliant it's infinitely cheaper to just ignore all that, grade everything toward the road, dig a ditch, send the contents of the ditch through your stormwater treatment features, build in a little margin to those items, show the permitting authority the numbers that prove it passes with flying colors and when some jerk says "but what if X Y Z changes" you point to the excess you built in and tell them to GFY.
Now, where it really gets evil is when you start really pinching pennies or where the rules change over the course of the process making your numbers not work. Say you've got a lot of grade, a lot of rainfall, a lot of stormwater you gotta "treat". Well, you start adding rules to the HOA. Require certain parts of the lots remains grass or planter or whatever. Disallow patios, but do allow wood decks because the municipality considers those pervious, etc, etc. Or maybe the results you've got are marginal but you throw the bureaucrats a bone by saying you'll disallow car-ports and sheds in the HOA rules to prevent people from adding impervious surface. Or maybe you're uphill of some wetlands but not close enough to be regulated by default you promise to disallow working on cars and require people pick up their pet waste and not use lawn fertilizer or some other laundry list of certain things in order to make the local town's wetlands people comfortable not raising objection and claiming jurisdiction.
And of course, however these rules and plans shake out, the HOA is responsible for implementation in perpetuity.
An obvious thing may be to say the software must be published or the spec released, but we've had computers in cars since the 80s. It seems like a tall task but people can and do reverse engineer entire ECU systems (See Trionic Tuning)
Another seemingly very obvious one - requiring manufacturers to publish specifications regarding ALL OBD interface options. Of course this immediately runs into trouble. Saab for example gated features of the security system to prevent key reprogramming, swapping of certain components without a dial out to the internet using specific saab software that runs on a laptop and interfaces.
Strongly. You don't own the thing you purchased if you can't legally repair it or legally obtain the knowledge to repair it. At beat you're paying an overpriced lease and granting a liability waiver.
iPhone 14+ and Android 12+ https://en.androidsis.com/How-to-activate-automatic-accident...
Generally I read your comment that a dropped phone only hits the floor once, therefore there is only one vector and the car always overturns/flips/turns and therefore there are multiple vectors measurable in the car?
I am not convinced yet, it might be possible without GPS, at least to some degree of error (false positives and false negatives). The info in the link requires GPS to be switched on. hmm
In carving up the 5 acres the developer purchased, the 30 houses they squeezed in left some remainder that wasn't buildable or odd shaped, so this now becomes a lame 'park' or some other space that requires maintenance.
I read all my local municipal meeting minutes, and at least around here, permitting and ordinances control all the environmental/nuisance stuff, so I can't really explain why HOAs go beyond the collective expenses into the draconian rules.
Grass is really good at filtering/absorbing/treating stormwater so you might have to force everyone to keep their lawns lawn because the way you've got the lots graded you need that little bit of extra because it lets you make your "shit parcel" where the basin will go a little smaller and squeeze one extra house into the development.
Beyond that I think what a lot of it comes down to is that local governments are invariably run by a lot of the same kinds of busybodies that HOAs attract and the way rules are written these days the "normal permitting process" exists only to let the useful idiots think that just about everything isn't discretionary. There's always some gotcha or twistable phrase so everything goes through a special permit or variance of some sort. That opens up all sorts of off the record dealing wherein the developer agrees to throw everything and the kitchen sink into the initial HOA rules and the Karens in government make sure those things are in there before deciding how to exercise their discretionary approval.