Earlier quoted context omitted.
Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…
And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…
Tesla Fleet Telemetry
81–90 of 136 posts
Re: Tesla Fleet Telemetry
#82Earlier quoted context omitted.
> give them your Tesla account username/password (super bad) Only slightly related, but buying a Tesla they encourage you to use Plaid for payment. Which involves… giving your banking account username and password to a third party. Extremely bad. I can’t believe anyone would do this.
First off, Plaid uses OAuth when possible to do things the right way. So you really have nothing to worry about if your bank is competent. Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario. Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them. Why is it inherently bad…
US Banks not only use SMS for 2FA, many of them REQUIRE it for 2FA.
They also tend to require "security questions" that are usually easily guessed or researched. Again, information that makes it easier, not harder, to get into your account.
Good luck trying to find a bank that uses hardware tokens.
> Why is it inherently bad to trust a 3rd party?
Because doing so substantially increases the attack surface and historically third parties have done a terrible job.
For example: every app that uses SMS 2FA inherently trusts the customer's cell phone company. Companies which have done little to address identity thiefs porting out numbers, requesting replacement SIMs, etc.
Re: Tesla Fleet Telemetry
#83Every time Tesla refers to the cars they sold to customers as their ‘fleet’, I get the feeling they don’t really recognise they are no longer the owner of those vehicles. Fleet as defined in Oxford Dictionary: “A number of vehicles or aircraft working together, or under the same ownership.” (edit: use actual Oxford definition)
"fleet" is also just used as a collective noun for cars, ships or aircraft.
> WASHINGTON, Dec 12 (Reuters) - The U.S. new vehicle automotive fleet's fuel efficiency was flat in the 2021 model year as automakers sold more sport utility vehicles and pickup trucks compared to cars, while the Detroit Three lagged behind foreign competitors and Tesla.
> The U.S. Environmental Protection Agency said on Monday the fleetwide real-world average was 25.4 miles per gallon in the 2021 model year, the same as in 2020. The EPA estimates the 2022 fleetwide efficiency average will rise to 26.4 mpg.
That's referring to every car in the United States with the collective noun "fleet". It implies no ownership.
Re: Tesla Fleet Telemetry
#84Earlier quoted context omitted.
The current situation for third party apps (which do exist, plenty of them) is you either give them your Tesla account username/password (super bad) or an access token that you get by signing into your Tesla account, which is less bad but still gives the app the same access as your full Tesla account. So yes, by building a framework to allow users to authorize third party apps to receive limited telemetry data withou…
Why not just an access token that only has certain perms?
Which is: Tesla doesn't even want collect telemetry and then re-share it to 3rd parties. Tesla wants to provide a mechanism for the car to connect directly to a customer-authorised 3rd party telemetry collection service. This relieves Tesla from having to function as a middle-man and facilitate things like claims in tokens and granular permissions.
Re: Tesla Fleet Telemetry
#85Earlier quoted context omitted.
Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…
And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…
(zero points for anyone pedantically pointing out that this is technically first party sharing)
Re: Tesla Fleet Telemetry
#86Earlier quoted context omitted.
Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…
And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…
Re: Tesla Fleet Telemetry
#87Earlier quoted context omitted.
I’m not ignorant of your concerns, but that’s what privacy laws are for. These third parties have been scrapping Tesla APIs at the behest of their customers for years. This is nothing new, simply more formalized. If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted t…
Or forget the laws. I will buy a car that doesn't stream data. My current vehicle doesn't and I have never felt the need. My next one wont either ... not if I have anything to say about it.
Re: Tesla Fleet Telemetry
#88Earlier quoted context omitted.
If an employee at a hotel planted secret cameras and... If an vacation rental landlord planted secret cameras and... Bad news all around.
You can go to jail for having a surveillance system in your own home: https://www.cbsnews.com/news/navy-doctor-guilty-of-making-se...
Re: Tesla Fleet Telemetry
#89Earlier quoted context omitted.
That sounds like a subtle mischaracterization of the leak to me. The leak sounded more like, "the teams responsible for tagging data uploaded by Teslas had access to data uploaded by Teslas". The fact that they could share them amongst themselves is also not particularly surprising. While I understand the alarm, it was also completely unsurprising even based purely on the company's public statements about how they us…
The fact that they could share them amongst themselves is also not particularly surprising. It's not that the could , it's that they did .
- Murphy's Law of Sharing
Re: Tesla Fleet Telemetry
#90Earlier quoted context omitted.
First off, Plaid uses OAuth when possible to do things the right way. So you really have nothing to worry about if your bank is competent. Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario. Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them. Why is it inherently bad…
> So you really have nothing to worry about if your bank is competent. US Banks not only use SMS for 2FA, many of them REQUIRE it for 2FA. They also tend to require "security questions" that are usually easily guessed or researched. Again, information that makes it easier, not harder, to get into your account. Good luck trying to find a bank that uses hardware tokens. > Why is it inherently bad to trust a 3rd party?…
You don't need to lecture me on how trust delegation works. I mean you use a bank right? You trust a 3rd party with your actual cash. Plaid hasn't demonstrated incompetence, have they? In fact it seems quite the opposite. There isn't any legitimate case against using them aside from "I literally don't trust anybody" which is hypocritical if you use a bank in the first place.