Live data from Hacker News

Tesla Fleet Telemetry

github.com

91–100 of 136 posts

Re: Tesla Fleet Telemetry

#91
post #76

Earlier quoted context omitted.

> give them your Tesla account username/password (super bad) Only slightly related, but buying a Tesla they encourage you to use Plaid for payment. Which involves… giving your banking account username and password to a third party. Extremely bad. I can’t believe anyone would do this.

First off, Plaid uses OAuth when possible to do things the right way. So you really have nothing to worry about if your bank is competent. Second, Plaid will use app passwords if you have 2FA enabled and your bank supports them. This is the correct way to handle that scenario. Third, Plaid saves me a lot of trouble and I have come to trust them. I am happy to delegate responsibility to them. Why is it inherently bad…

I use a non-enormous regional bank. I have no idea if it qualifies as competent.

Also, have a quick look at the "data we collect" section of their privacy policy and see if you still feel the same way: https://plaid.com/legal/

It's shockingly broad, and 99% of it is stuff that they have no business collecting when all I'm trying to do is buy a car.

Re: Tesla Fleet Telemetry

#92

Earlier quoted context omitted.

And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…

I’m not ignorant of your concerns, but that’s what privacy laws are for. These third parties have been scrapping Tesla APIs at the behest of their customers for years. This is nothing new, simply more formalized. If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted t…

> I’m not ignorant of your concerns, but that’s what privacy laws are for.

It's a shame then that the few laws we have protecting consumer's privacy are not adequate to the task. It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved.

As an aside, how do you know that the apps you use aren't selling your data? Is it only because of their entirely non-legally binding statements and privacy polices? What do think could happen to that data when those apps/companies are sold or otherwise acquired by someone else? Even if they were telling the truth about not selling your data right now, do you think that means it isn't readily available to police or the discovery process in a legal dispute? Do you think that data collected or displayed by the apps could be exposed to Google or Apple and collected?

Re: Tesla Fleet Telemetry

#93

Earlier quoted context omitted.

I’m not ignorant of your concerns, but that’s what privacy laws are for. These third parties have been scrapping Tesla APIs at the behest of their customers for years. This is nothing new, simply more formalized. If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted t…

> I’m not ignorant of your concerns, but that’s what privacy laws are for. It's a shame then that the few laws we have protecting consumer's privacy are not adequate to the task. It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved. As an aside, how do you know that the apps you use aren't selling your data? Is it only because of the…

[deleted]

Re: Tesla Fleet Telemetry

#94

Earlier quoted context omitted.

The current situation for third party apps (which do exist, plenty of them) is you either give them your Tesla account username/password (super bad) or an access token that you get by signing into your Tesla account, which is less bad but still gives the app the same access as your full Tesla account. So yes, by building a framework to allow users to authorize third party apps to receive limited telemetry data withou…

Hard agree. I give my Tesla creds to other third party apps willingly, because I want the benefits those apps offer (we own several Teslas, and both the historical data and remote vehicle control has value add). The effort to move to a more secure auth mechanism is welcomed, and it's my data, so I don't get the outrage. This is part of the value in my purchase decisions, and within the risk appetite of my threat mode…

> both the historical data and remote vehicle control has value add

What value does it add?

Re: Tesla Fleet Telemetry

#95
post #86

Earlier quoted context omitted.

And if your local police department wants to buy that data? What if a large law firm wants to buy all the data for use in lawsuits? Once you have pass it on to "third parties" then there isn't much you can do to stop such things. It happened a few decades ago as in-car GPS rolled out. Some rental car companies started issuing speeding tickets. That game lasted about a week. >> Feb. 2002. A Connecticut man has taken a…

The police won't pay they will just subpoena any data they want, from Tesla or from whoever manufactures your car.

Some companies charge police for the work it takes to fulfill their requests. I suspect that once it becomes a revenue stream, they are less likely to pushing back against requests for data where they might otherwise.

Re: Tesla Fleet Telemetry

#96

Earlier quoted context omitted.

I’m not ignorant of your concerns, but that’s what privacy laws are for. These third parties have been scrapping Tesla APIs at the behest of their customers for years. This is nothing new, simply more formalized. If the laws are insufficient, that’s a call for better laws (which I agree are needed). The apps I use do not sell their customer data, but Tesla should probably stipulate API integrations aren’t permitted t…

> I’m not ignorant of your concerns, but that’s what privacy laws are for. It's a shame then that the few laws we have protecting consumer's privacy are not adequate to the task. It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved. As an aside, how do you know that the apps you use aren't selling your data? Is it only because of the…

To answer your questions (I could not tell if they were rhetorical or not), worst case outcome is that someone either legitimately or illegitimately has the history of my vehicles’ locations and commands issued to the vehicles. As mentioned, in my grandparent comment, within my risk appetite. It could happen, but I don’t care enough to worry about it.

> It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved.

Agree to disagree. If the cost of loss is low, to go without the product or service is more costly than potential data loss. The services I use within this context are very likely not actively lying about their privacy policies.

Re: Tesla Fleet Telemetry

#97
post #62

congratulations your motor vehicle is now dependent on kubernetes pov you are headed for a collision and something is wrong. you issue a describe command ... Type Reason Age ---- ------ ---- Normal Sync 100s (x3 over 100s) Is that an expected status for this component? The distance narrows ...

The Kubernetes implementation is on the server side, not the car. The only way to control the car is through Tesla's API,[1] and that doesn't let you do dangerous stuff like turn the wheel while someone is driving. Even if you could overwrite the software on the car, you'd still have to contend with the physical controls available to the driver. The steering wheel is physically connected to a typical rack and pinion…

The only concern is someone hacking Tesla's HSMs that sign their firmware and software updates, since then they could craft a malicious payload disguised as a software update that flashes new firmware onto the BMS and as such causes your car to explode the next time you plug into a supercharger, for example.

Re: Tesla Fleet Telemetry

#98
post #5

Earlier quoted context omitted.

The problem with data is that they can often reveal information you need , but didn't even know you need. The way I understand Tesla's meaning of "data they need" is the data that you know exists, know is useful, and has a predefined purpose. However, blind data mining can often bring insight that may give you an edge over competition, so the unethical data collectors have an advantage. On the other hand, collecting…

Then you get the weird software engineers that are very defensive of spying on their users lol.

I mean, it's all logging how users use your product. For things that aren't cloud-dependent, there are toggles in the car the user can click to turn them off, and it doesn't harm almost any functionality (of course disabling app camera access in the car will prevent you from seeing your live sentry cam in the app; it'll still record locally to the USB though).

Re: Tesla Fleet Telemetry

#99
Wow this is a surprising roll-out. The k8s recommended deployment seems a bit overkill, perhaps thrown over the fence, but it shouldn't be hard to knock out a much more manageable docker compose configuration instead.

Re: Tesla Fleet Telemetry

#100

Earlier quoted context omitted.

> I’m not ignorant of your concerns, but that’s what privacy laws are for. It's a shame then that the few laws we have protecting consumer's privacy are not adequate to the task. It's reasonable then to do our best to avoid products and services that exploit the weakness of our laws until that situation is improved. As an aside, how do you know that the apps you use aren't selling your data? Is it only because of the…

To answer your questions (I could not tell if they were rhetorical or not), worst case outcome is that someone either legitimately or illegitimately has the history of my vehicles’ locations and commands issued to the vehicles. As mentioned, in my grandparent comment, within my risk appetite. It could happen, but I don’t care enough to worry about it. > It's reasonable then to do our best to avoid products and servic…

> worst case outcome is that someone either legitimately or illegitimately has the history of my vehicles’ locations and commands issued to the vehicles.

That is hardly the worst case outcome. The worst case outcomes would be those where that data is used against you because it was sold/leaked/subpoenaed. There's no end to the ways it could be used against you either.

Maybe a future potential employer doesn't like how often you visit bars, or what church you attend, and you are passed over for a job you want.

Maybe your car's recorded proximity to where a crime took place makes you a suspect in a crime you had nothing to do with and it costs you tens of thousands in legal fees to clear your name. (similar to what happened to this guy: https://www.nbcnews.com/news/us-news/google-tracked-his-bike...)

Maybe that data gets pulled up in a divorce or custody battle. GPS records and toll transponders are already being used in such cases to show things like patterns of working late hours, visits to girlfriend's houses, or undisclosed income

Maybe that data is used by advertisers to more effectively manipulate you into parting with more of your money.

Maybe your insurance company (health or auto) buys it up and their algorithm decides to jack up your rates because you hit up a fast food drive thu once too often or you speed too much or drive to many hours.

Maybe you visit or even park too close to a gay bar, mosque, or planned parenthood and you get harassed by an extremist group or dragged into a Texas courtroom.

Because the data never goes away, it can follow you for the rest of your life and be used by others again and again at any time in whatever way the person who gets their hands on it feels will benefit them.

> Agree to disagree. If the cost of loss is low,

Everybody is free to decide for themselves what level of risk is acceptable to them. With some kids you can tell them that the stove is hot and they will leave it alone, while others have to touch it and get burned.

I hope that you never suffer a consequence that makes you regret the data you gave away, assuming that you can trace it back to that data in the first place. At least you can say you were informed about the dangers and made an informed choice to roll the dice. I worry a lot more about the folks who don't even realize what data is being collected, the ways that it can be used against them, or who assume that they can count on laws and privacy polices to protect them from harm.

Post reply on HN