Live data from Hacker News

A CBP contract shows the risks in connecting your vehicle and your smartphone

theintercept.com

21–30 of 253 posts

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#21

Looks like I'm switching back to AUX. I had no idea cars were scooping up this much data. I wish the article went into more detail about what the attack vector is, what permissions, if any can mitigate this, etc but I understand that's not the point of this piece.

If it has a USB port, it can get data. If you have Android auto or native iOS integration, same story.

People need to understand, despite the efforts of sticks in the mud like me, industry should be considered malicious by default. If you don't pay attention to what people are doing and call it out, nobody even raises a finger. Those that do are ignored, or told there's a place for people like them with a condescending smirk.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#22
post #14

“Your phone died, you’re gonna get in the car, plug it in, and there’s going to be this nice convenient USB port for you. When you plug it into this USB port, it’s going to charge your phone, absolutely. And as soon as it powers up, it’s going to start sucking all your data down into the car.” That used to be just something seen in hostile devices. Now it's standard equipment.

You can get a USB Condom [1] for this purpose.

[1] - https://www.amazon.com/PortaPow-3rd-Gen-Data-Blocker/dp/B06X...

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#23
post #5

One day, I hope radios / networking off, telemetry off and logs off and still as functional as possible with those options off will all be legally mandatory options in any device that can do any of those things.

You better fight for it. Otherwise industry is likely to lobby those become mandatory to prevent competition from heopardizing potential revenue streams by couching them as public safety and sustainibility features.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#24
Is there a reliable list of cars that do not surveil me, or that can be modified to not surveil me? I read a Bruce Schneier article a little while ago (maybe the article was much older) where he said that he looked, but didn't find one that met his other needs.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#25
post #8

I live in Washington State, where the state legislature recently voted to ban sales of gasoline powered cars after 2030. Aside from the fact that I enjoy drives through some pretty empty parts of the country, especially in the Southwest, where range is a concern (e.g., I drove the Great Basin Highway a few years ago), what bothers me about that measure is this sort of data collection thing. I wouldn't mind a move to…

California is running an experiment that collects all of your location data while in a car to collect a gas tax. Of course once they have it they will make it available for any government agency.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#27

From the marketing material: iVe currently supports AUDI, BMW, Buick, Cadillac, Chevrolet, Chrysler, Dodge, FIAT, Ford, GMC, HUMMER, Hyundai/Kia, INFINITI, Jeep, Lincoln, Mercedes-Benz, Maserati, Mercury, Nissan, Pontiac, Ram, Saturn, SEAT, Skoda, SRT, Toyota and Volkswagen Now you know which brands to avoid!

So that leaves Hot Wheels.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#28

From the marketing material: iVe currently supports AUDI, BMW, Buick, Cadillac, Chevrolet, Chrysler, Dodge, FIAT, Ford, GMC, HUMMER, Hyundai/Kia, INFINITI, Jeep, Lincoln, Mercedes-Benz, Maserati, Mercury, Nissan, Pontiac, Ram, Saturn, SEAT, Skoda, SRT, Toyota and Volkswagen Now you know which brands to avoid!

Any one left out of that list? Should I assume if I see one PSA-owned brand (for example), all PSA will be under contract and just not named because the list was too big? I'm just confused...

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#29
post #27

From the marketing material: iVe currently supports AUDI, BMW, Buick, Cadillac, Chevrolet, Chrysler, Dodge, FIAT, Ford, GMC, HUMMER, Hyundai/Kia, INFINITI, Jeep, Lincoln, Mercedes-Benz, Maserati, Mercury, Nissan, Pontiac, Ram, Saturn, SEAT, Skoda, SRT, Toyota and Volkswagen Now you know which brands to avoid!

So that leaves Hot Wheels.

Honda, Subaru, Tesla too.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#30

Is there a reliable list of cars that do not surveil me, or that can be modified to not surveil me? I read a Bruce Schneier article a little while ago (maybe the article was much older) where he said that he looked, but didn't find one that met his other needs.

https://ondatashop.com/ive-vehicle-system-forensics/

says "iVe currently supports BMW, Buick, Cadillac, Chevrolet, Chrysler, Dodge, Fiat, Ford, GMC Hummer, Jeep, Lincoln, Maserati, Mercury, Pontiac, Ram, Saturn, Seat, Skoda, SRT, Toyota and Volkswagen vehicles generally as far back as 2008 models" - so older might be better :)

Post reply on HN