Live data from Hacker News

Data collected by cars and sold to third parties

theverge.com

131–140 of 280 posts

Re: Data collected by cars and sold to third parties

#131
post #112

Earlier quoted context omitted.

[flagged]

That’s a lot of words coming from a very angry place. Frankly I’m surprised and disappointed that this hasn’t been flagged yet.

Congrats you free speech absolutist! You got my comment flagged, but the good thing is everybody with above room temperature IQ can infer what a [flagged] comment probably said based on context :)

Re: Data collected by cars and sold to third parties

#132
post #6

How can this be stopped, from a technical perspective? Can I wrap the comms in a Faraday cage? Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.

It definitely can be stopped. For example, China sells cars internally at cheaper prices, but they are locked to prevent using them outside the country. However, there are people who can hack and unlock them allowing operating in any country. But maybe it would be illegal in the West, I don't know. Removing the modem is an easier task.

Re: Data collected by cars and sold to third parties

#133
Just don’t get a car with connected internet, or smart X in any way, which is most modern cars unfortunately, and if you do, disable the telemetry. I have a clean, cool, low mileage ~15yo car, has no screen or apps, no internet, no back camera or even digital dashboard. I put a screen that has offline CoMaps app, if I ever needed it, and its OBD connected to a local app that does usual diagnostics. Sure, there’s logging I see and it happens, but it’s all local and never shared let alone connect things gas or odometer or driving habits.

Re: Data collected by cars and sold to third parties

#134

Earlier quoted context omitted.

Cable ISPs such as Spectrum sell capacity on their customers routers for such situations, including ‘smart’ appliances.

Xfinity (Comcast) does the same, and the LG TV data leak demonstrated it joining these open “xfinitywifi” SSIDs to transmit telemetry home (edit: retracted, see below subthread). You can see a map of these nodes with https://wigle.net/

Please provide a source for this claim.

While LG TVs send a lot of private data when connected to the internet, I'm not aware of any credible reports that they automatically connect to open or partner-provided wifi networks without a user choosing to do so.

It's certainly a threat to keep an eye open for, but it seems manufacturers haven't quite stooped to that low yet.

Re: Data collected by cars and sold to third parties

#135
post #105

Earlier quoted context omitted.

Your mileage went from VW->telematics vendor->broker->carfax, thats the chain it usually follows. The fuse stops it but the real issue is the owner is the only one without the record. You could probably find some interesting info if you send out some privacy requests through the chain. LexisNexis and Verisk are consumer reporting agencies, so they have to provide you a disclosure on request. Start there.

Is there usually a fuse that just turns off the telemetry? I would be surprised if that is the case. I could see the design being "if you turn this fuse off to turn off telemetry, you'll also lose these functions: ..." and if they did it "right" they'd make the car non-functional. My car is from 2011 and I do wonder if there is any telemetry in it.

There’s probably a fuse to turn off the cellular radio that transmits the data. Whether that’s all it covers may vary from car to car. Or in some models it’s probably possible to just disconnect the radio entirely.

Re: Data collected by cars and sold to third parties

#136

Earlier quoted context omitted.

Xfinity (Comcast) does the same, and the LG TV data leak demonstrated it joining these open “xfinitywifi” SSIDs to transmit telemetry home (edit: retracted, see below subthread). You can see a map of these nodes with https://wigle.net/

Please provide a source for this claim. While LG TVs send a lot of private data when connected to the internet, I'm not aware of any credible reports that they automatically connect to open or partner-provided wifi networks without a user choosing to do so. It's certainly a threat to keep an eye open for, but it seems manufacturers haven't quite stooped to that low yet.

I stand corrected and misremembered comment https://news.ycombinator.com/item?id=49604765 and thread https://news.ycombinator.com/item?id=49592375

It has not been demonstrated actively in use, only that it is possible and trivial to implement. Statement with regards to it being demonstrated retracted.

I stand by the concept that any consumer IoT device could join these networks, and the end user would never know. The only legal solution to this problem statement is to physically disable the radio on the device if assurance is desired.

Re: Data collected by cars and sold to third parties

#137
post #20
post #6

How can this be stopped, from a technical perspective? Can I wrap the comms in a Faraday cage? Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.

[flagged]

lol sure - provide their terms and maybe we can believe this trust me bro attitude

Re: Data collected by cars and sold to third parties

#138

I notice that not one comment here, nor the article, notes that this doesn't happen with a Tesla.

why do you think this? can you provide a written terms or similar to hold this belief? i would think they are absolutely selling all the data

Re: Data collected by cars and sold to third parties

#139
post #78

Earlier quoted context omitted.

> turn off remote access services, dig through the infotainment to turn off what I could This is never enough. You can't trust a software switch. You need to remove the hardware capability if you want to make sure the car isn't spying on you. In the best case, the telematics box has it's own fuse, and that may be enough. In other cases, you need to find the box and unplug it. The service manual will have it's locatio…

Find the telematic's antenna, and put a 50ohm resistor across it. It can scream into it's own private void.

It seems like this is not enough:

https://www.tacomaworld.com/threads/simpler-solution-for-dis...

The most reliable way to permanently silence the cellular modem is to pull the relevant fuse. In the above case, this also disables the microphone, which I think is a positive. Unplugging the DCM entirely, however, seems to disable to right speaker, which is wired through the DCM for some reason.

Re: Data collected by cars and sold to third parties

#140

I posted a flavor of this comment on an article a few months ago, but it's relevant here: I have a seven year old Volkswagen, not financed. I'm security conscious and made sure to disable all the data collection I could find in the companion app before removing my account, turn off remote access services, dig through the infotainment to turn off what I could, etc. Last year I requested a Carfax on it, and one of the…

Your mileage went from VW->telematics vendor->broker->carfax, thats the chain it usually follows. The fuse stops it but the real issue is the owner is the only one without the record. You could probably find some interesting info if you send out some privacy requests through the chain. LexisNexis and Verisk are consumer reporting agencies, so they have to provide you a disclosure on request. Start there.

So I first read this comment and thought is looked like AI and thought I’d give the benefit of the doubt. Then I saw this where there is no doubt: https://news.ycombinator.com/item?id=49687774

I thought, I wonder if it’s the same guy? Sure enough.

Stop it.

Post reply on HN