Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

91–100 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#91
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

I am pretty sure that is (or soon will be) illegal in EU. Car needs to be able to call emergency, if accident is detected.

"Oops, how did that happen..." ;)

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#92
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

There's likely five Sims at various places and even 3d printed into the frame.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#93
post #70

How does GDPR affect this issue for cars bought/sold in EU market? Is the opt out complete? Does the right to be forgotten after the fact apply?

IANAL but this is clearly not even close to being legal under GDPR. Especially those collecting article 9 stuff (biometrics, genetics, sexual orientation, race, etc).

I think its just a matter of time before someone buys a new car that does this and takes the manufacturer to the EU courts. The argument that concent is given when you buy/use the car will not hold up for one second.

Car manufactors will have to allow you to use the car without collecting anything.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#94
Okay so you wanna hear something absolutely horrifying?

My new CPAP machine has a 4G modem and it shares all my sleep data with the company. There’s some people at the local office who can tell precisely when I’m asleep and how asleep I am.

Could you possibly want any better data for when to rob someone?

I’ve put the thing in airplane mode and they called saying they can’t get the data needed for the first month, required for insurance purposes. Nope. My last machine had an SD card. How about you do that instead?

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#96
I have a new EV (a modest MG ZS long range 2022) and I'm not much concerned about privacy BUT much, much, much more about remote controls ability from the factory AND potentially someone else due to some crapware vulnerabilities who happen to be vast https://samcurry.net/web-hackers-vs-the-auto-industry/

My take is simple:

- all cars can be connected BUT the connection must be user controllable, meaning the car must run on FLOSS easily installable by the formal owner;

- all cars can offer remote controls BUT in a classic ssh-alike fashion, meaning it's ok to have a web(cr)app for end users, but not proxyed by the OEM only. OEM might act as a proxy to circumvent NAT, but the user is free to choose a DynDNS and other P2P/distributed solution hosted alone.

In mere privacy IMVHO my car can snoop videos of me/anything surrounding / capture audio no more and no less than an Android or iOS macrospy also know as smartphones. So I'm equally concerned BUT so far such smart devices can't potentially lock me outside in the middle of anything, making me crash on some people and than state I'm a terrorist crushing on purpose and so on. Witch limit much the risk surface.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#97

The more I read about these things, the more I think I'll be driving my 23 year old Toyota 4Runner until the end of my life

I switched to a motorbike that has almost nothing ‘fancy’ about it--along with public transportation.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#98
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

You'd probably have more success finding the external antenna and clipping the leads at the sharkfin.

Just make sure you do something, like use a resistor to ground the antenna lead, because I did that, and would still get connectivity at times.

EG if the cell tower was very close.

Was fine after I used a resistor to turn that power into mild heat.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#99

The more I read about these things, the more I think I'll be driving my 23 year old Toyota 4Runner until the end of my life

Yo fellow 3rd gen driver!

Bought my 2000 SR5 in 09 and it’s gone way up in value since then.

Have had 3 random people ask me over the last few years how much I’d take for it and the answer is always “not for sale.”

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#100
I want to know how these license agreements work, legally speaking?

We bought a new car and signed the purchase agreement. Nowhere was there anything resembling a software license. Some months later, the display has a pop-up "our terms and conditions have changed". Um...which terms would those be, and when did we ever agree to them? Anyway, how can they make a one-sided change to a contract?

Post reply on HN