Earlier quoted context omitted.
> Teslas use stronger ssh keys than you do SSH !?! This supports my point - a remote command prompt is much more functionality than what is required to unlock doors. It's not really appropriate to talk about this level of control as if it's merely a necessity for remote door unlocking. You're the one engaging in histrionics here - sour grapes about the lopsided relationship that was included with functionality you en…
I'm not sure if you're aware, but SSH is a flexible protocol of which "terminal emulation" is just one use case (you can implement bespoke command/response actions, I've written an SSH server before FWIW). I don't have the specifics on hand, but even assuming they can get a "terminal to your car", the resulting access is only capable of doing what the environment allows it to do. I highly doubt `spyontheuser -vvvvvvv…
I had hoped we weren't going to go down this path. It's not the responsibility of the free world to try to pry the exact details from closed systems to demonstrate their exact insecurities. Based on the functionality they have (remote update) plus the various bits that have been reported about their infrastructure (remember that reddit post about MSWin+bubblegum?) plus the general pattern when any proprietary system says "trust us we're sooper sequre", Tesla (any every other centralized system) really does not deserve any benefit of the doubt that they have done work to actually design a telemetry/privilege minimizing system.
> If the evidence shows Tesla is being dishonest and operating in a way that is not in accordance with their privacy policy
Meh. The penalty for violating privacy policies in the US is zilch, and even if it weren't such policies are generally non-binding and can be retroactively changed at any time. Without a privacy law ala the GDPR, the sensible thing to do is to assume that any piece of information you feed into the surveillance industrial complex will be stored indefinitely and may eventually be used against you.
> What I'm advocating for is making [trust] decisions based on facts and evidence
I feel like we could have some common ground here, but your previous arguments have carved off way too much in defense of lazily-implemented centralized control, based on seeing no evil. If it's possible to architect systems such that they don't backhaul information to their manufacturer or give their manufacturer ongoing control, then we should criticize those that do - regardless of the pragmatism of using them anyway because they are the least worst option and/or beneficial in other aspects.
I myself use many things that compromise my own privacy through suboptimal implementations, but I'm not going to sit here and defend the companies because they haven't been caught doing anything too hostile at the moment. Rather I accept that they're inherently attackers that I've chosen to trust (NSA definition) with some amount visibility into and control over my activities due to other benefits they provide - while remaining generally interested in more secure alternatives.