Live data from Hacker News

Modern cars are spying on you. Here's what you can do about it

apnews.com

161–170 of 373 posts

Re: Modern cars are spying on you. Here's what you can do about it

#161
post #79

Earlier quoted context omitted.

in a city that doesn't produce even 1/25 of microplastic thousand kilos vehicles produce? because that also has an impact on marine ecosystems, by the way, cars are linked as one of the highest if not the, pollutants of microplastic. in a city that doesn't have air pollution linked towards a bunch of disease? in a city that doesn't have noise pollution that also has a bazinga of negative impact? are you really naive…

You didn't answer his question: Would you be willing to have your bicycle brakes linked up with GPS and red light signals? Or loaded down with sensors monitoring and correcting your bicycling activity for your own safety?

Even just cycle number plates.

Re: Modern cars are spying on you. Here's what you can do about it

#162

Earlier quoted context omitted.

While eCall has some weak privacy protections (it's open to all the standard cellular network surveillance lawful in each country), it also means you cannot disable the vehicle's modem in most (maybe all) EU countries with failing roadworthiness checks and insurance policies.

eCall mustn't be active until an accident occurs. The lawful interception lobby tried hard to turn every car into a free data point they could sell to the government, but their efforts have failed. Last I heard they've shifted their efforts to making remote activation of on-board cameras part of the 5/6G smart car bullshit (which will of course be part of road safety requirments not long after).

No, that's not correct. The eCall spec requires self-checks that include registering with the network on at least every ignition.

However, more importantly, it means you can't lawfully disable the modem that the manufacturer uses for its own telemetry.

Re: Modern cars are spying on you. Here's what you can do about it

#163

Earlier quoted context omitted.

Prosecuting someone for deliberately injecting garbage data into another persons system hardly seems totalitarian. > You own the device, so anything you do within that device is authorized You're very clearly describing a situation where at least some of the things you're doing aren't happening on your own device. >I do know that the CFAA essentially gets interpreted to mean whatever the corpos want it to mean - it's…

My device. I generate whatever the fuck the data I want. If you log it, kiss my ass.

Sure, I have the same attitude when it comes to the government telling me that I'm not allowed to use drugs. Doesn't mean I'm in the clear from a legal point of view.

However, it's worth clarifying that the important detail isn't generating the data, but sending it. Particularly the clearly stated malicious intent of "poisoning" their data.

This seems like exactly what the lawmakers writing CFAA sought to criminalize, and is frankly much better justified than perhaps the bulk of things they tend to come up with.

>(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

Doesn't seem exactly unfair to me, even if facing federal charges over silly vandalism is perhaps a bit much. Of course, you'd realistically be facing a fine.

Re: Modern cars are spying on you. Here's what you can do about it

#165
post #68

Earlier quoted context omitted.

>Do not give in to the mirage of convenience. I sympathise. However, being able to start de-icing my car while still in bed at 5:30 on a January morning is a powerful feature. And I'm the kind of person who wraps his tin foil hat no less than 10 layers thick. Ideally this shouldn't involve the internet, because the car is in wifi range, but what can I do about it?

People are suggesting all over these threads what we can do about it, but we (as a population) aren't. When my 2009 car dies, I'm going to deliberately NOT buy a new trackingmobile, and try to find another 2009 car to keep running. Yea, that means I occasionally need to take 30 seconds to scrape ice off the windshield. Big deal.

Why 2009? I've been driving the same 2003 Audi TT all my life, never failed me.

Re: Modern cars are spying on you. Here's what you can do about it

#166
post #48

Earlier quoted context omitted.

They don’t want people modifying ADAS systems mostly, and the main requirement is SecOC, which is cryptographic authentication but the message is still plaintext. Basically they don’t want third party modifications able to randomly send the “steer left” message to the steering rack, for example.

I integrated SecOC on some ECU's at work. I hate myself for it. I frigging hate what they're doing with this. I think it's going to make cars less repairable, less modifiable. It's a horrible horrible stupid initiative in the name of "cybersecurity".

I understand notionally where they were going, but it all sort of went off the deep end somewhere along the line. A concern that someone buying some "mileage blocker" or whatever other shady device off of AliExpress might be vulnerable to the device steering their car into a wall is actually quite a valid one, but of course the solution is some overcomplicated AUTOSAR nightmare that doesn't solve for key provisioning in a way to make modules replaceable.

Re: Modern cars are spying on you. Here's what you can do about it

#167

Nothing you can realistically do about it. In America car ownership for most people is mandatory. It’s unfortunate we don’t have alternatives if you disagree with car manufacturers extra “features”.

The alternative is to be aware of this abuse and unplug the cellular modem. It requires more or less effort depending on the car, but it can and should be done.

Re: Modern cars are spying on you. Here's what you can do about it

#168
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

As a strictly logical assertion, I do not agree. Guessing URLs is crafting new types of interactions with a server. The built in surveillance uploader is still only accessing the server in the way it has already been explicitly authorized. Trying to tie some nebulous TOS to a situation that the manufacturer has deliberately created reeks of the same type of website-TOS shenanigans courts have (actually!) struck down.…

>(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

If your goal is to deliberately "poison" their data as suggested before, it's kind of obvious that you are knowingly causing the transmission of information in an effort to intentionally cause damage to a protected computer without authorization to cause such damage.

>Trying to tie some nebulous TOS to a situation that the manufacturer has deliberately created reeks of the same type of website-TOS shenanigans courts have (actually!) struck down.

This has very little to do with the TOS though, unless the TOS specifically states that you are in fact allowed to deliberately damage their systems.

And no, causing damage to a computer does not refer to hackers turning computers into bombs. But rather specifically situations like this.

Re: Modern cars are spying on you. Here's what you can do about it

#169
post #118

I thought about getting a traditional navigator to avoid even relying on phone navigation. Well, of course all the Garmins and Tomtoms available now have "built-in wifi for updates" and often BT for phone notifications too. Sure, I could just not configure either but what if I want a navigator _without any radios_ and with controlled updates via SD card. Maybe a dedicated Android phone in the car with offline OpenStr…

You could use a GrapheneOS phone without SIM and OSMand for that.

Re: Modern cars are spying on you. Here's what you can do about it

#170

I wonder what the extremely rich do to get a car that isn’t a security risk? I’ve heard you can throw money at high end car dealerships to disable spying, but I wonder what the internal process is.

It's easier than that, you can remove the cellular modem. Dealers won't generally accept to make this mod, but any independent shop should be able to. There are also plenty of videos on YT to DIY.
Post reply on HN