Live data from Hacker News

Tesla Fleet Telemetry

github.com

81–90 of 136 posts

Re: Tesla Fleet Telemetry

#81

Earlier quoted context omitted.

Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…

And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…

No one is forcing anyone to use a data logging app for their Tesla. It’s not only purely opt in, you usually have to buy them

Re: Tesla Fleet Telemetry

#82
post #76

Earlier quoted context omitted.

> give them your Tesla account username/password (super bad) Only slightly related, but buying a Tesla they encourage you to use Plaid for payment. Which involves… giving your banking account username and password to a third party. Extremely bad. I can’t believe anyone would do this.

First off, Plaid uses OAuth when possible to do things the right way. So you really have nothing to worry about if your bank is competent. Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario. Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them. Why is it inherently bad…

> So you really have nothing to worry about if your bank is competent.

US Banks not only use SMS for 2FA, many of them REQUIRE it for 2FA.

They also tend to require "security questions" that are usually easily guessed or researched. Again, information that makes it easier, not harder, to get into your account.

Good luck trying to find a bank that uses hardware tokens.

> Why is it inherently bad to trust a 3rd party?

Because doing so substantially increases the attack surface and historically third parties have done a terrible job.

For example: every app that uses SMS 2FA inherently trusts the customer's cell phone company. Companies which have done little to address identity thiefs porting out numbers, requesting replacement SIMs, etc.

Re: Tesla Fleet Telemetry

#83
post #74
post #18

Every time Tesla refers to the cars they sold to customers as their ‘fleet’, I get the feeling they don’t really recognise they are no longer the owner of those vehicles. Fleet as defined in Oxford Dictionary: “A number of vehicles or aircraft working together, or under the same ownership.” (edit: use actual Oxford definition)

"fleet" is also just used as a collective noun for cars, ships or aircraft.

For example... U.S. auto fleet fuel efficiency flat in 2021 as Detroit Three lag https://www.reuters.com/business/autos-transportation/us-aut...

> WASHINGTON, Dec 12 (Reuters) - The U.S. new vehicle automotive fleet's fuel efficiency was flat in the 2021 model year as automakers sold more sport utility vehicles and pickup trucks compared to cars, while the Detroit Three lagged behind foreign competitors and Tesla.

> The U.S. Environmental Protection Agency said on Monday the fleetwide real-world average was 25.4 miles per gallon in the 2021 model year, the same as in 2020. The EPA estimates the 2022 fleetwide efficiency average will rise to 26.4 mpg.

That's referring to every car in the United States with the collective noun "fleet". It implies no ownership.

Re: Tesla Fleet Telemetry

#84
post #52

Earlier quoted context omitted.

The current situation for third party apps (which do exist, plenty of them) is you either give them your Tesla account username/password (super bad) or an access token that you get by signing into your Tesla account, which is less bad but still gives the app the same access as your full Tesla account. So yes, by building a framework to allow users to authorize third party apps to receive limited telemetry data withou…

Why not just an access token that only has certain perms?

Tesla doesn't provide this. Also, its beside the point...

Which is: Tesla doesn't even want collect telemetry and then re-share it to 3rd parties. Tesla wants to provide a mechanism for the car to connect directly to a customer-authorised 3rd party telemetry collection service. This relieves Tesla from having to function as a middle-man and facilitate things like claims in tokens and granular permissions.

Re: Tesla Fleet Telemetry

#85

Earlier quoted context omitted.

Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…

And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…

In my case, the third party I'd most be interested in sharing with is my local home assistant instance.

(zero points for anyone pedantically pointing out that this is technically first party sharing)

Re: Tesla Fleet Telemetry

#86

Earlier quoted context omitted.

Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…

And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…

The police won't pay they will just subpoena any data they want, from Tesla or from whoever manufactures your car.

Re: Tesla Fleet Telemetry

#87

Earlier quoted context omitted.

I’m not ignorant of your concerns, but that’s what privacy laws are for. These third parties have been scrapping Tesla APIs at the behest of their customers for years. This is nothing new, simply more formalized. If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted t…

Or forget the laws. I will buy a car that doesn't stream data. My current vehicle doesn't and I have never felt the need. My next one wont either ... not if I have anything to say about it.

That doesn't change the fact that this framework is an improvement on the status quo for Tesla owners. And presumably most Tesla owners are not like you, so what you would do is not super relevant to this discussion.

Re: Tesla Fleet Telemetry

#88

Earlier quoted context omitted.

If an employee at a hotel planted secret cameras and... If an vacation rental landlord planted secret cameras and... Bad news all around.

You can go to jail for having a surveillance system in your own home: https://www.cbsnews.com/news/navy-doctor-guilty-of-making-se...

Hidden surveillance of the unsuspecting in restrooms, bathrooms, and bedrooms -anywhere where people can expect to have privacy- should of course be illegal. Nannycams in living rooms and other "public" rooms in private homes probably should be legal for obvious reasons.

Re: Tesla Fleet Telemetry

#89
post #15

Earlier quoted context omitted.

That sounds like a subtle mischaracterization of the leak to me. The leak sounded more like, "the teams responsible for tagging data uploaded by Teslas had access to data uploaded by Teslas". The fact that they could share them amongst themselves is also not particularly surprising. While I understand the alarm, it was also completely unsurprising even based purely on the company's public statements about how they us…

The fact that they could share them amongst themselves is also not particularly surprising. It's not that the could , it's that they did .

Anything that can be shared, will be shared.

- Murphy's Law of Sharing

Re: Tesla Fleet Telemetry

#90
post #76

Earlier quoted context omitted.

First off, Plaid uses OAuth when possible to do things the right way. So you really have nothing to worry about if your bank is competent. Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario. Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them. Why is it inherently bad…

> So you really have nothing to worry about if your bank is competent. US Banks not only use SMS for 2FA, many of them REQUIRE it for 2FA. They also tend to require "security questions" that are usually easily guessed or researched. Again, information that makes it easier, not harder, to get into your account. Good luck trying to find a bank that uses hardware tokens. > Why is it inherently bad to trust a 3rd party?…

Sorry that US Bank leaves you exposed to a sim-jacking attack which, if they use Twilio, is mitigated by their verify API. I don't need hardware tokens and full custody of my financial information. I Just Don't. That's literally the entire point of a bank. They do that for me.

You don't need to lecture me on how trust delegation works. I mean you use a bank right? You trust a 3rd party with your actual cash. Plaid hasn't demonstrated incompetence, have they? In fact it seems quite the opposite. There isn't any legitimate case against using them aside from "I literally don't trust anybody" which is hypocritical if you use a bank in the first place.

Post reply on HN