Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

131–140 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#131

Earlier quoted context omitted.

But that won’t be an option in a few . How many 2015 cars will be on the road and for sale in 2035?

Strongly doubt gasoline powered cars will be street legal in 2035.

Highly unlikely in the US as a whole. California, maybe. Most other states this won't be the case.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#132
Of all the horrible things go on with privacy these days, this is the one I hate the most. I’m a “car guy”, but not the sort that obsesses over old cars (although I do love 60s and 80s cars). I like new tech, I like the advances in engineering we’ve made in new vehicles, I like EVs even.

Nonetheless I’ve been in the market for a new car for months and haven’t bought because it’s hard to find any cars that meet my requirements (after all most companies primarily make trucks and shitty crossovers, not even cars). The two things that consistently hold me back are either things like this (crazy telemetry / touchscreens everywhere / half-ass safety tech) or insane dealer markups. I’ve pretty much figured out the new Toyota GR Corolla is the perfect car for my needs, but you can’t find them anywhere without a $25K+ dealer markup and many dealers won’t sell them to out of state residents.

It’s truly a crazy time in the new car markets and the used market isn’t really any better.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#133
post #76

Car dealerships are notoriously horrible about privacy as well. The last time I bought a car at a dealership they wanted me to sign a release that allowed them to use photos and videos of me as part of their television and online advertisement. They were stunned when I refused and threatened to nix the whole deal and I challenged them to do exactly that before (of course) a manager was summoned and eventually I was t…

[deleted]

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#134
post #93

Earlier quoted context omitted.

IANAL but this is clearly not even close to being legal under GDPR. Especially those collecting article 9 stuff (biometrics, genetics, sexual orientation, race, etc). I think its just a matter of time before someone buys a new car that does this and takes the manufacturer to the EU courts. The argument that concent is given when you buy/use the car will not hold up for one second. Car manufactors will have to allow y…

My guess is that Mozilla only looked at the US market, and the article does not mention that this is US-only.

I think you are correct about the article. But I still think a lot of cars on the EU market collects (top much) information. But thats just a guess for sure

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#135

Okay so you wanna hear something absolutely horrifying? My new CPAP machine has a 4G modem and it shares all my sleep data with the company. There’s some people at the local office who can tell precisely when I’m asleep and how asleep I am. Could you possibly want any better data for when to rob someone? I’ve put the thing in airplane mode and they called saying they can’t get the data needed for the first month, req…

[deleted]

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#136

Also, as a PSA: Your local state government sells car registration data to data brokers and car manufacturers. It is often used for behavioral targeting.

I used to work for a state motor vehicle agency.

Federal law requires the manufacturers get your up to date mail address for recall purposes.

Legislators make sure that the agencies sell that data (this is the source of those "we've been trying to reach you about your vehicle's warranty" letters/calls). Sometimes they interfere to ensure that their buddies/lobbyists don't pay for it.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#137

Okay so you wanna hear something absolutely horrifying? My new CPAP machine has a 4G modem and it shares all my sleep data with the company. There’s some people at the local office who can tell precisely when I’m asleep and how asleep I am. Could you possibly want any better data for when to rob someone? I’ve put the thing in airplane mode and they called saying they can’t get the data needed for the first month, req…

I had to look it up: CPAP = continuous positive airway pressure; to treat sleep apnea disorder

I do have sleep apnea disorder but probably a mild one as I don't feel exhausted at all. Reading your comment sparked the idea that it might be a good idea to verify the severity. If there will be any CPAP machine involved I will for sure think of its privacy impact.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#138
This article doesn't go into any benefits to the driver/user, if available. With all the cameras and microphones in cars these days they can at least send the insurance companies all the data when an accident occurred. Were you on the phone? Driving the speed limit? Have your seat belt on? Braking hard to avoid (or cause) an accident? Heck, give me a monthly riding report with information such as how fast I accelerate, how hard I brake, how often I speed, and stuff like that. Then provide tips on how to improve my driving. At least that would be useful.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#139
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

Check out the manual, find where the fuse is for the cellular modem, and remove it.

That’s quite a big assumption to think that it would be clearly labeled, and also that it would have a dedicated fuse. It’s not like that would be such a huge power draw that it needs its own fuse. Pulling the fuse would likely cause the whole infotainment system to go down.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#140

Earlier quoted context omitted.

I am pretty sure that is (or soon will be) illegal in EU. Car needs to be able to call emergency, if accident is detected.

The manufacturer may have to legally include the functionality in cars they sell but in pretty sure the owner isn’t obligated to use or keep the functionality untouched. By comparison if your seat belts are all frayed and you don’t wear them anyway that’s on you, manufacturer sold you a car with seat belts in good condition and that as far as the “compliance” requirement goes.

Might depend on the wording of the law and how that system is tied into the rest of the car. For example in the states, it is illegal to tamper with any part of the emissions control system on your car. This is mostly about making sure emissions testing via OBD II can’t be gamed, but it also would target modifications like “rolling coal” or turbos and superchargers that allow user controlled fuel mapping. But in the crossfire it catches completely reasonable reasons to modify your emissions system like a flex fuel upgrade, or replacing the computer of your old car with an aftermarket one because the engine immobilizer unit died and they’re paired together and OEM computers and immobilizer kits are either too expensive or not obtainable anymore.

Laws against tampering with vehicle safety devices would easily have a similar effect on your built in phone home systems.

Post reply on HN