Live data from Hacker News

A CBP contract shows the risks in connecting your vehicle and your smartphone

theintercept.com

41–50 of 253 posts

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#41
post #25
post #8

I live in Washington State, where the state legislature recently voted to ban sales of gasoline powered cars after 2030. Aside from the fact that I enjoy drives through some pretty empty parts of the country, especially in the Southwest, where range is a concern (e.g., I drove the Great Basin Highway a few years ago), what bothers me about that measure is this sort of data collection thing. I wouldn't mind a move to…

California is running an experiment that collects all of your location data while in a car to collect a gas tax. Of course once they have it they will make it available for any government agency.

I really, really hate this. Why not just require an annual odometer reading and multiply by vehicle weight to determine how much should be owed to cover road and transportation infrastructure costs?

Far easier than maintaining a complex system to track every drivers' location over time. Ugh.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#42

Is there a reliable list of cars that do not surveil me, or that can be modified to not surveil me? I read a Bruce Schneier article a little while ago (maybe the article was much older) where he said that he looked, but didn't find one that met his other needs.

Unlikely. Based on the article, it sounds like the data they are "vacuuming" up is telemetry data captured and stored by the car itself. Every manufacture is different, but they all are storing at least some information. I suspect there are regulatory requirements to keep such information for the purposes of public safety (see: analysis of Toyota unintended acceleration situations)

This information has been captured, stored, and made available for analysis since at least the early 00s. I remember the first time I hooked up VAGCOM to my 03 VW, it has data from so many sensors available for the tech to look up and could turn on and off hundreds of different features, it was like going into the VW equivalent of chrome://flags. And this was in a 2003 car!

You'd probably have to go back to pre-ODBII days (mandated in 1996 for the US) to really get away from this. In my experience (which is not comprehensive) 90s cars tended to keep telemetry mostly on engine performance (timing advance, cam/crank sensor positions, throttle position, etc).

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#44
post #41
post #25

Earlier quoted context omitted.

California is running an experiment that collects all of your location data while in a car to collect a gas tax. Of course once they have it they will make it available for any government agency.

I really, really hate this. Why not just require an annual odometer reading and multiply by vehicle weight to determine how much should be owed to cover road and transportation infrastructure costs? Far easier than maintaining a complex system to track every drivers' location over time. Ugh.

Because the goal is as much to collect the location data as it is the tax.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#45
post #34
post #8

I live in Washington State, where the state legislature recently voted to ban sales of gasoline powered cars after 2030. Aside from the fact that I enjoy drives through some pretty empty parts of the country, especially in the Southwest, where range is a concern (e.g., I drove the Great Basin Highway a few years ago), what bothers me about that measure is this sort of data collection thing. I wouldn't mind a move to…

You can't really buy a "dumb" gas car anymore either. I'm holding onto my 2011 Nissan Versa to the bitter end.

Your Versa isn't exactly dumb either. It's younger than the iPhone.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#46

Earlier quoted context omitted.

Honda, Subaru, Tesla to name some.

Mazda, Mitsubishi, Nissan

Nissan is in the list but Datsun is not... I really think they trimmed down the list to the bigger brands.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#47
post #21

Looks like I'm switching back to AUX. I had no idea cars were scooping up this much data. I wish the article went into more detail about what the attack vector is, what permissions, if any can mitigate this, etc but I understand that's not the point of this piece.

If it has a USB port, it can get data. If you have Android auto or native iOS integration, same story. People need to understand, despite the efforts of sticks in the mud like me, industry should be considered malicious by default. If you don't pay attention to what people are doing and call it out, nobody even raises a finger. Those that do are ignored, or told there's a place for people like them with a condescendi…

Via USB you can still use a USB blocker, but if you connect via Bluetooth, nothing can protect you, correct?

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#48

From the marketing material: iVe currently supports AUDI, BMW, Buick, Cadillac, Chevrolet, Chrysler, Dodge, FIAT, Ford, GMC, HUMMER, Hyundai/Kia, INFINITI, Jeep, Lincoln, Mercedes-Benz, Maserati, Mercury, Nissan, Pontiac, Ram, Saturn, SEAT, Skoda, SRT, Toyota and Volkswagen Now you know which brands to avoid!

Well, at least that leaves Honda & Acura as well as Subaru and probably a bunch more regional brands I'm unaware of. Also I suppose Tesla...but we all know how much telemetry data those cars send back to base.

Subaru is partially owned by Toyota and is slowly being absorbed into the company.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#49
post #4

Is there any surprising data? I'm not surprised it records destinations entered into satnav for example. I mean that's a fairly common trick in TV shows. > MSAB claims that this data can include “Recent destinations, favorite locations, call logs, contact lists, SMS messages, emails, pictures, videos, social media feeds, and the navigation history of everywhere the vehicle has been.” MSAB even touts the ability to re…

> I seriously doubt my car has records of my emails, pictures, videos, and social media feeds even though it has Android Auto.

Even if you car does not, your phone does. So the phone being connected to the car during the time when the accident occurred, could lead to checking that you were in fact, watching unboxing videos on Netflix at the moment the wreck occurred while you were in the driver's seat.

Re: A CBP contract shows the risks in connecting your vehicle and your smartphone

#50
post #34

Earlier quoted context omitted.

You can't really buy a "dumb" gas car anymore either. I'm holding onto my 2011 Nissan Versa to the bitter end.

Your Versa isn't exactly dumb either. It's younger than the iPhone.

You mean older?
Post reply on HN