Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

331–340 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#331

Possibly the high-end ones more so. My new, relatively low-end Honda Civic EX-B appears not to have cellular connectivity (no HondaLink) and no Wifi connectivity. The only cameras are the ones looking out the front and back. Of course it does have an interior microphone for the Bluetooth. But all in all the car seems "old school" and not spying on me. Am I wrong?

It appears that Mozilla simply read the privacy policies of the manufacturers and did not actually test any cars.

Features vary widely among models, of course (as the owner's manual says repeatedly).

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#332

Also, as a PSA: Your local state government sells car registration data to data brokers and car manufacturers. It is often used for behavioral targeting.

Every time I've bought a car recently (which for Reasons has been a few times), I've ended up with utter scum sending mail designed to look "official" while skirting the actual reserved terms trying to scam me into extended warranties and so forth.

If I had more time I would use their free return address to ship boxes of broken bricks.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#333
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

My 2021 Wrangler has a very obvious antenna on top of the roll bar, very easy to unplug. (There's actually two - one for SIM stuff, and one for the XM Sat radio)

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#334

Earlier quoted context omitted.

I don't know about their markups, but Mazda has been pulling out touchscreens and putting back buttons for audio and climate control purposes. Not sure how far it's made it through their models.

Mazda always refused to go fully touchscreen. Instead they have somehow rationalized that a control wheel and featureless buttons down in the center console are safer for people to use while the vehicle is active. It's idiotic.

Mazda still has a ton of physical buttons in addition to the screen though. The following are all _dedicated_ buttons / switches / knobs:

- Volume up/down (knob), press to mute

- Hazard lights (button)

- Windshield wipers (stalk) including front/rear, speed, intermittent, etc

- Headlights/highbeams (stalk)

- Turn signals

- AC on/off, fan speed, fresh air/recirc, seat warmers

- Temperature up/down is a dedicated, physical knob

- Driver/passenger windows

- Side mirror adjust

- Trunk open/close

- Cycle through backup camera views

- Parking sensor enable/disable

- Cruise control on/off/speed/distance

- Media controls (ff/rw/mute)

- There are even dedicated physical buttons for the touchscreen,eg. a button that always takes you to whatever map you're using (google/apple), a button that takes you to whatever is playing music (spotify/apple/podcast/etc)

Sorry if this sounds like I'm a mazda shill but every time this topic comes up on HN I am incredibly glad that I prioritized physical controls and IMHO they're really doing it correctly.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#335

Earlier quoted context omitted.

If you want best in class safety tech and no dealer markups, you can just order a Tesla online

Not to mention the occasional automated drive into stationary objects. Guess that's partly why they have the "best in class safety tech".

You don’t have to enable self driving.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#336
post #128

Earlier quoted context omitted.

That's your choice. You can buy new, convienent, modern cars that spy on you and will be dead in ten years. Or you can buy old, reliable cars that lack most modern amenities but can be repaired forever with a metal lathe and a welder.

It's my choice not to learn how to use a metal lathe and a welder, or find someone with those skills to do it for me? How is that supposed to scale to millions of people who want the same privacy?

Not to mention the fact that most such cars are already gone - so if more people adopt the GPs position, the prices will go through the roof for him too.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#337

Earlier quoted context omitted.

When it comes to privacy data handling, the term "collecting" is a very specific term that means they are directly collecting it from you, so, unless they use the term in a non standard way, that means they supposedly collect your genetic material and sexual preferences _from you_. Which, erk, but also, how?

Sexual preference and genetic material are very different from sexual activity and genetic data . These privacy polices are always very broad (not saying this is a good thing). The multitude of microphones in cars can easily accidentally (or purposefully) record sex acts. A camera to detect driver awareness (for auto cruise or sleep alarms) can detect your eye color, which could be construed as genetic data. Idk if a…

Well 23andMe doesn't pay a bounty on DNA.

Yet.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#338
post #227

The more I read about these things, the more I think I'll be driving my 23 year old Toyota 4Runner until the end of my life

Except when you live in a city where they start to limit and ban transit of older cars, to force people transitioning into lower emission models, or public transit. Like in Spain (through rules ultimately coming from Europe) there is a class of vehicles which are gradually being kicked out (banned from crossing certain very ample boundaries around the city): gasoline cars made before 2001, and diesel powered cars mad…

American carbrains can’t imagine a society that doesn’t depend on huge ass vehicles for daily transportation.

A reminder that driving isn’t a right, it’s a privilege that you have to get a license to do, and many other places that aren’t America don’t design their cities and even their small towns [1] around the idea that you must own a vehicle.

Congestion taxes and pollution rules tend to affect city centers where personal vehicle ownership is unnecessary and even something that could be considered detrimental to society as a whole.

I didn’t agree to die early due to elevated pollution levels in my city just so you can drive your truck around downtown.

Approximately half of all global oil use is associated with roadways. Maybe draining the world’s oil is a solid plan for the oil states and geopolitically massive superpowers of the world, but many countries have to import all of their oil, so owning a 19mpg Toyota 4Runner in a country like Spain is arguably a national security issue.

[1] https://youtu.be/ztpcWUqVpIg

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#339

Note that this is all based on this source material. https://foundation.mozilla.org/en/privacynotincluded/categor... I haven't dug too much into the methodology, but it seems like it's done based on privacy policies rather than actually looking into the car telemetry traffic. It's also written in a very caaual and sensationalist "omagad" tone that doesn't serve well the seriousness of the topic or findings

The language also took me by surprise. Not a fan. Really, if you want to connect with people on this topic just mention "abortions", and "data sold".

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#340
post #312

Note that this is all based on this source material. https://foundation.mozilla.org/en/privacynotincluded/categor... I haven't dug too much into the methodology, but it seems like it's done based on privacy policies rather than actually looking into the car telemetry traffic. It's also written in a very caaual and sensationalist "omagad" tone that doesn't serve well the seriousness of the topic or findings

I own a VW ID.4. For reasons I wanted to reverse engineer some of the API. After authenticating to the account tied to my car, the landing page ( https://www.vw.com/en/owners.html ) makes calls to a lot of analytics trackers. I'll just list what pi-hole defaults block: analytics.tiktok.com sp.analytics.yahoo.com googletagmanger.com universal.iperceptions.com cdn4.userzoom.com snap.licdn.com secure-ds.serving-sys.com…

Just to be clear, these are trackers from the web page, not trackers called by your car, correct?

I'm never surprised by the web trackers (which my ad blocker generally filters too), but 3rd-party trackers called from devices/vehicles seems more insidious.

Although the car / IoT companies can just as easily outsource the data once they have it anyway.

Post reply on HN