Live data from Hacker News

Modern cars are spying on you. Here's what you can do about it

apnews.com

261–270 of 373 posts

Re: Modern cars are spying on you. Here's what you can do about it

#261
post #134
post #48

Earlier quoted context omitted.

They don’t want people modifying ADAS systems mostly, and the main requirement is SecOC, which is cryptographic authentication but the message is still plaintext. Basically they don’t want third party modifications able to randomly send the “steer left” message to the steering rack, for example.

The ADAS systems mandated in Europe are insanely intrusive. I had a few rental cars in Europe this summer and wanted to send them off a cliff. (and I'm not an auto tech luddite, I've had modern cars in the US with autopilot type systems, lane keep, blind spot warning, rear traffic assist radar, forward collision warning, etc. IMO rear traffic assist/FCW/AEB tend to work really well, autopilot pretty well, and lane ke…

So much this. We had a rental BYD in Greece this summer, and while it was actually great car in general the mandated “assistance” was awful.

It constantly got the speed limits wrong, constantly tried to tug me out of the correct lane, and was generally awful. It could be disabled but was re-enabled on each restart of the ignition because it’s mandated by EU regulation.

I appreciate a Greek island perimeter road may be a worst case scenario, but it did the same with roadworks on the freeway and many other situations.

Actively dangerous in my experience…

Re: Modern cars are spying on you. Here's what you can do about it

#262

Earlier quoted context omitted.

I see absolutely no reason not to completely unplug the cellular modem. The only thing that would stop me is an annoying error message or warning light in the gauge cluster. My car does not display any of these, but unplugging the modem results in losing the right speaker and microphone, unless a bypass harness is used.

The modem is usually in the sharkfin with the XM radio chipset and GPS. If you can unplug it at the sharkfin that's usually the best course of action. Some cars may bark at you, but mine just says it can't detect GPS if I attempt to use it (which I never use anyway).

Wouldn't it be better to connect resistive pigtails to the antenna connectors on the board? A little more work to get to, but less risk to damaging paint and weather seals, and would do a better job preventing signal leakage. I'm no expert on such things, but will definitely be looking at something like that for the next car I buy.

Re: Modern cars are spying on you. Here's what you can do about it

#263

Earlier quoted context omitted.

>(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer; If your goal is to deliberately "poison" their data as suggested before, it's kind of obvious that you are knowingly causing the transmission of information in an effort to intentionally cause damage to a protected computer wit…

A computer being supplied with false data which it then stores is not damaging the computer - hence there being a provision about fraud. But for this case it's not fraud either, as the person supplying the data is not obtaining anything of value from the false data.

>the term “damage” means any impairment to the integrity or availability of data, a program, a system, or information;

Deliberately inserting bad data to mess with their analytics does in fact fit that definition.

Re: Modern cars are spying on you. Here's what you can do about it

#264
post #61

Earlier quoted context omitted.

I mean if you consider that death rate per mile driven 'mostly fine'

Check your tire pressures when you get gas, along with your oil and other fluid levels. Eyeball the tires every time you get in the car. These habits are not hard to develop and they will work even when the sensors malfunction (which is not infrequently). All that these sensor-based systems do is train you to be an inattentive car owner.

Nonsense. Information is good.

I do have a walk around the car before I set forth, but stuff happens.

Some drives are very long -- hours and hours between stops. I've had tires that aired themselves down during a drive. TPMS can alert me to that issue before I get an opportunity to have another walk-around, so I can stop and address it before it becomes a safety concern.

It's fine if someone want to live in a world without monitoring systems; anyone is free to drive an old car with points ignition and a carb if they want (or mechanical diesel! with an air starter, even! no electricity needed at all!).

And sure, there's a certain joy to driving something of relative mechanical simplicity.

But I like modern cars. And I like things like temperature gauges, closed-loop electronic fuel injection, oil pressure indicators, ABS, traction control, backup cameras, and [I dare say] tire pressure monitoring. I like cruise control. I like headlights that turn themselves on when necessary, and off again when they're unnecessary.

And as one might correctly surmise: It doesn't have to be that way: There's other ways to live. A person can also choose to walk, ride a bike, use a horse, commit to a lifestyle that is centered around public transportation, or whatever. The world is full of options.

I've chosen my path, and you can also choose yours.

(And no, that doesn't make me inattentive. My path involves both a belt and suspenders.)

Re: Modern cars are spying on you. Here's what you can do about it

#265

Earlier quoted context omitted.

Guessing URLs is equivalent to ordering an item not on the menu in a restaurant. The request may or may not be granted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability. How do you propose the line should be drawn?

Probably somewhere short of incarcerating someone for what they typed in a browser's URL bar.

Re: Modern cars are spying on you. Here's what you can do about it

#267
post #178
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

You think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?

Guessing passwords is an attempt to access privileged information you have no right to access, and could not otherwise access without bypassing security measures.

Guessing a URL is an attempt to access (potentially) privileged information which was not secured or authenticated to begin with.

A password is a lock you have to break. An unlisted URL is a sticky note that says "private" on the front of a 40" screen. It's literally impossible for that information to stay private. Someone will see it eventually.

Re: Modern cars are spying on you. Here's what you can do about it

#268
post #65

Earlier quoted context omitted.

>It's connected to the Internet. Every car has a SIM card now. Maybe every new car, but the average car is 13 years old, and the OP made no clarification on whether his advice was for only new cars, or for a 2015 econobox as well.

My car is older than that and came with an embedded SIM card. Quite a few navigation consoles had "live traffic updates" (often in trial format, but sometimes "lifetime") that basically consisted of 2G clients occasionally updating traffic data along planned routes. Not quite bottom of the line at the time, but also not uncommon at that point either. It's probably slightly worse than the dedicated satnav screens peop…

There's other ways to get local traffic data, too. For instance: Traffic Message Channel, which can be broadcast with RDS on an FM station, exists.

As long as stations persist that transmit the data (it's sent over RDS), then it will continue to work. There's no subscription involved (or at least, there isn't for my car -- it works where it works, and there's no mechanism by which to pay for using it).

The Wiki has some further reading on the technology: https://en.wikipedia.org/wiki/Traffic_message_channel

Re: Modern cars are spying on you. Here's what you can do about it

#269

Earlier quoted context omitted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability. How do you propose the line should be drawn?

Probably somewhere short of incarcerating someone for what they typed in a browser's URL bar.

So if I deliberately exploit a bug on your website and download your customer database by typing things in my browsers URL bar, I should not be prosecuted?

Re: Modern cars are spying on you. Here's what you can do about it

#270
post #178
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

You think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?

I think criminalising both is unreasonable, what you do with the URL you accessed or the password you guessed however is different.
Post reply on HN