Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

121–130 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#121

I want to know how these license agreements work, legally speaking? We bought a new car and signed the purchase agreement. Nowhere was there anything resembling a software license. Some months later, the display has a pop-up "our terms and conditions have changed". Um...which terms would those be, and when did we ever agree to them? Anyway, how can they make a one-sided change to a contract?

Here's the relevant legalese from Toyota: "By purchasing or leasing a vehicle equipped with an active Connected Services system, you specifically consent to our electronic collection and use of your account information and vehicle data and our storage of such data wherever we designate."

"Fun" right?

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#122

Earlier quoted context omitted.

My insurance company has a phone app that collects the same info - speed, deaccelation (gyroscopes), etc. the app is optional but qualifies you for a discount after 3 months of app history, if your driving pattern meets their standards. They told me they do not impose rate increases based on the app’s reporting, only discounts. I did not install it but the point is: You don’t need a car device anymore.

You at least bought a burner device to do this, right?

I did not install the app.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#123

Earlier quoted context omitted.

I actually wanted to go with an insurer that installs a black box. My dealer, however, doesn't do those (and their standard package is pretty good, so with a new car it was stupid to go with someone else).

My insurance company has a phone app that collects the same info - speed, deaccelation (gyroscopes), etc. the app is optional but qualifies you for a discount after 3 months of app history, if your driving pattern meets their standards. They told me they do not impose rate increases based on the app’s reporting, only discounts. I did not install it but the point is: You don’t need a car device anymore.

My insurance company's app sometimes detects commuter train rides as car trips. As far as I can tell, there's no way to tell it "No, I'm not actually driving now".

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#124
post #6

I think it will be a good differentiation factor in a few years, that a brand comes up with an offline car, i.e. a car that you just refuel/charge and drive - no telemetry/connected features involved. It may be a niche thing in future, but certainly something that would be appealing to me as a consumer.

Open source Car!!

Oh, this would be an expensive hobby that I would embrace.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#125
post #93
post #70

How does GDPR affect this issue for cars bought/sold in EU market? Is the opt out complete? Does the right to be forgotten after the fact apply?

IANAL but this is clearly not even close to being legal under GDPR. Especially those collecting article 9 stuff (biometrics, genetics, sexual orientation, race, etc). I think its just a matter of time before someone buys a new car that does this and takes the manufacturer to the EU courts. The argument that concent is given when you buy/use the car will not hold up for one second. Car manufactors will have to allow y…

My guess is that Mozilla only looked at the US market, and the article does not mention that this is US-only.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#126
Once you normalize this state of affairs in one digital sector (social media, search, whatever), you've normalized it, period.

You can't say: X and Y can milk this, but Z and W cannot. Everybody will want to get a piece of action from such a lucrative scheme.

In turn once the managing elites of all these formerly non-tech sectors that get increasingly digitized (mobility, finance, insurance, health etc) get satisfied that their legal / reputation risk is manageable they will invest further in this direction and lobby hard to preserve their investment value against "intrusive and innovation limiting regulation".

It all follows logically and it is a dystopic downward spiral that has no bottom.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#127
post #66
post #22

Earlier quoted context omitted.

All new EU cars since 5 years ago are obligated to have 'eCall' which contacts emergency services in case of a crash. Most manufacturers solve that problem by including a 4G module. Older cars also collect information. Most dealers read out the nav computer drive at service intervals so they also know where you've been, who you called etc, only a bit later.

Another reason to do my own service or find a trusted independent shop.

The car companies won't let that information out to independent repair shops (except where mandated by laws). The "right to repair" movement is one attempt to make it possible.

The worst offender is John Deere and their newer farm tractors. Only authorized repair centers can get the software needed to troubleshoot the vehicles. Part of why Deere does not want details out there is that some tractor models have the exact same engine, but different power outputs based on how much the customer paid. One could "unlock" a more powerful engine without paying corporate. The really big "implements of husbandry" (as my state calls them) can cost $500k. At peak planting/harvesting time, you can wait weeks for a technician to come to your farm. Or spend a few thousand dollars having it driven to the dealership by truck.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#128
post #71

Earlier quoted context omitted.

I also have an '54 Chevy, a '62 CJ, a '69 wagon, a '68 Suburban, and a '84 Ford. I have a pretty good track record of keeping old things running well. Eventually my new cars (01 and two 03s) will cease to be repairable, but I have invested time and money in a very well maintained fleet of older vehicles, it's one of my only practical hobbies.

I guess you’re all set then and the rest of us are screwed?

That's your choice. You can buy new, convienent, modern cars that spy on you and will be dead in ten years. Or you can buy old, reliable cars that lack most modern amenities but can be repaired forever with a metal lathe and a welder.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#129
I have a 2019 Subaru Outback. I also use GrapheneOS on a Pixel 3A. I have noticed that, when my phone is plugged in and I have location services enabled (for navigation), when I'm NOT using navigation, the icon in the top bar indicating location services being used pings once every 30 seconds.

I'm sure onboard cell modems can be used to triangulate well enough, but just knowing that my car likes to hitch a ride on my phone's sensors has creeped me out forever. I'll definitely be looking for an old beater car as my second when the time comes.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#130

Earlier quoted context omitted.

But that won’t be an option in a few . How many 2015 cars will be on the road and for sale in 2035?

Strongly doubt gasoline powered cars will be street legal in 2035.

They will be rare but do you really think Big Oil's lobby will let that one go thru?
Post reply on HN