Live data from Hacker News

Modern cars are spying on you. Here's what you can do about it

apnews.com

241–250 of 373 posts

Re: Modern cars are spying on you. Here's what you can do about it

#241
post #178
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

You think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?

Guessing URLs is equivalent to ordering an item not on the menu in a restaurant. The request may or may not be granted.

Re: Modern cars are spying on you. Here's what you can do about it

#242

Remove the antennas. Do not give in to the mirage of convenience. Use a stand alone generic GPS. Vehicle GPS devices are anti privacy for so many reasons. Listen to stored music from an SD card if terrestrial radio (NO SATELLITE). Did you know almost ALL late model cars can play a TURN YOUR PHONE OFF. Your phone does more than track you - the Bluetooth and wifi beacon scanners are always running. When you come across…

Yeah that’s great if you’re a CIA intelligence officer but what normal person can do this and still function in the modern world? Do the people who say this stuff leave their homes regularly?

And what’s the benefit of it all? Fewer targeted ads?

Re: Modern cars are spying on you. Here's what you can do about it

#244
post #192

Earlier quoted context omitted.

Sure, I have the same attitude when it comes to the government telling me that I'm not allowed to use drugs. Doesn't mean I'm in the clear from a legal point of view. However, it's worth clarifying that the important detail isn't generating the data, but sending it. Particularly the clearly stated malicious intent of "poisoning" their data. This seems like exactly what the lawmakers writing CFAA sought to criminalize…

Could you argue the computer was unprotected? No encryption is wild.

No, "protected computer" refers to computers protected by the CFAA.

>(A) exclusively for the use of a financial institution or the United States Government, or, in the case of a computer not exclusively for such use, used by or for a financial institution or the United States Government and the conduct constituting the offense affects that use by or for the financial institution or the Government; or

>(B) which is used in interstate or foreign commerce or communication, including a computer located outside the United States that is used in a manner that affects interstate or foreign commerce or communication of the United States.

Re: Modern cars are spying on you. Here's what you can do about it

#245

Earlier quoted context omitted.

TPMS doesn't need to be unencrypted like that, although many car manufacturers do like to save a buck. If you get a car old enough, you won't need to worry about TPMS (but that car will not have been tested against recent crash test scenarios).

TPMS is over the air, each sesnor has a 32 bit unique ID. you have 4 per car... its easy to identify

Depends on the TPMS implementation to be honest. Most of the UHF ones are impossible to receive unless you're using some optimally placed/pretty powerful equipment. Even then, the protocol is entirely up to the vendor, as long as the system is reliable.

My car is old enough that it doesn't have TPMS sensors but I have looked into third party ones. It looks like there's all kinds of systems, from custom UHF to Bluetooth LE. No idea what your car uses.

Re: Modern cars are spying on you. Here's what you can do about it

#246
post #200

Earlier quoted context omitted.

Are you sure about that? My understanding was that the eCall self test does not connect to a network. That’s stated on the eCall page linked above. Do you have a source that contradicts that?

Yes, I am sure. Annex VII only rules out connecting to the PSAP/112 side, not routine network attaches. To detect faults in the “means of communication”, the IVS has to verify that the SIM, baseband and RF path are actually usable, and you can’t test that without a network attach. In practice that’s what all current eCall implementations do. The modem attaches to the cellular network at each ignition so it can confir…

Does that mean the modem used for eCall is the same that is used to transmit telemetry? Because that's a level of shitty I hadn't even considered. That said, it would go against the spirit of the law as I read it.

There are always workarounds, of course, but that does pose an annoying problem to patch.

Re: Modern cars are spying on you. Here's what you can do about it

#247
post #193

Earlier quoted context omitted.

>(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; If your goal is to deliberately "poison" their data as suggested before, it's kind of obvious that you are knowingly causing the transmission of information in an effort to intentionally cause damage to a protected computer wit…

Any reasonable programmer (a peer) would say an unencrypted system that doesnt validate data is an unprotected system.

It's a legal term, has nothing to do with technical protections.

Practically any device connected to the internet is a "protected computer". The only case I can think of where the defendant prevailed on their argument that the computer in question was not a "protected computer" was US v Kane. In that case the court held that an offline Las Vegas video poker machine was not sufficiently connected to interstate commerce to qualify as a "protected computer".

Re: Modern cars are spying on you. Here's what you can do about it

#248
post #178

Earlier quoted context omitted.

You think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?

Guessing URLs is equivalent to ordering an item not on the menu in a restaurant. The request may or may not be granted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability.

How do you propose the line should be drawn?

Re: Modern cars are spying on you. Here's what you can do about it

#249
post #179
post #91

Earlier quoted context omitted.

> Remove the antennas. Do not give in to the mirage of convenience. ERROR: unable to start engine.

Please drink a verification can. Actually I wonder if cars will just adopt "oh-you-need-anti-theft" like phones do. To prevent auto theft, all cars will be tracked and all parts must match serial numbers.

> To prevent auto theft, all cars will be tracked and all parts must match serial numbers.

Well, I suppose that's one way to end third party repairs. Just refuse to turn on if the chip in the new part doesn't match up with a code in the ECU. Like printer ink, but for every major component.

'Error, cannot start engine: Authorised mirror not found. Please visit BMW for an authentic replacement. Driving with non-authentic mirrors may harm user safety.'

Post reply on HN