Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

21–30 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#22

I connect my phone to my 2015 Nissan's bluetooth, but just for music. GrapheneOS lets me prevent its access to my contacts, call history, active calls, text messages - anything but music audio. To me (but not the less tech literate, I know), if you're connecting your car to your phone, it's obvious that it is able to gather things about you. That said, because I don't know much about cars, I don't know if the car is…

All new EU cars since 5 years ago are obligated to have 'eCall' which contacts emergency services in case of a crash. Most manufacturers solve that problem by including a 4G module.

Older cars also collect information. Most dealers read out the nav computer drive at service intervals so they also know where you've been, who you called etc, only a bit later.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#23
post #12

Earlier quoted context omitted.

How do you buy a car that meets those criteria?

You don't.

In some places, this is not an option. I have a mechanical Euro-5 car without sim card nor infotainment system that I would not be able to use where I live by end 2024.

Welcome to the EU and its low-emissions zones that span over many of its big cities.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#24
post #6

I think it will be a good differentiation factor in a few years, that a brand comes up with an offline car, i.e. a car that you just refuel/charge and drive - no telemetry/connected features involved. It may be a niche thing in future, but certainly something that would be appealing to me as a consumer.

Open source Car!!

That a good idea in theory, but that has a very high bar for non-advanced users.

What I meant is kind of just a regular brand that offers you a regular car with convenience features, but no telemetry/services involved. All local and offline - that's the catch for them, because what brands want is to monetize services...

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#25
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

You'd probably have more success finding the external antenna and clipping the leads at the sharkfin.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#26

I think it will be a good differentiation factor in a few years, that a brand comes up with an offline car, i.e. a car that you just refuel/charge and drive - no telemetry/connected features involved. It may be a niche thing in future, but certainly something that would be appealing to me as a consumer.

I think the insurance co will be the main lever in this story. If you have cameras & telemetry: standard insurance, open source offline car: pay premium.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#27
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

There's often times a small cellular modem in the sharkfin on vehicles but I believe Jeeps still have whip antennas.

Could use an SDR or emf reader. It'll take a while since you need to catch a cellular keep alive but otherwise should be fine.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#28

China is now the biggest car exporter, thanks to the electric car boom. Are there state security issues with Chinese cars too?

Yeah, we ban Huawei 4/5G infrastructure, and ban them fr using western / US tech, but are totally fine with whatever data BYD and EV OEMs do. But then TikTok and Xaomi are totally fine still, so what do I know...

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#29
post #5

Yes, and that is why I will never buy new unless in the contract I have; 1. No data harvesting 2. If I or anyone discovers any kind of data harvesting, at any time, I get a full refund of the original purchase price plus interest plus 2000 USD from the manufacture. If not received in 6 months, it double ever 6 months. But from what I understand, I heard due to Massachusetts "Right to Repair", all of that is turned of…

How do you buy a car that meets those criteria?

I've heard of a few very-low-tech models, which are manufactured for NGO's to use in extremely remote places. Dunno if any of 'em would be street legal in a "normal" country. Those might qualify, and their sales process might be so customized that he could get such a contract. Maybe.

Otherwise, I'd guess it'll be "whatever it costs" vehicles aimed at the uber-rich, and their personal security details.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#30

It almost feels silly to ask, but is this legal even in the United States with its comparatively weak privacy laws? In many states, a vehicle is legally an extension of the home. So legal rights and protections that apply in one's home also apply in one's vehicle. Is the idea that, buried somewhere in the legalese, is a statement that the buyer is granting the automaker the right to spy?

Yes, the US is pretty nearly lawless when it comes to privacy issues. Half the protections we have today are "it's legally required in the EU but low cost enough to just do globally".
Post reply on HN