Live data from Hacker News

Modern cars are spying on you. Here's what you can do about it

apnews.com

291–300 of 373 posts

Re: Modern cars are spying on you. Here's what you can do about it

#291
post #81

Earlier quoted context omitted.

It would be an extremely totalitarian dynamic to be persecuted with the CFAA for modifying a device you own based on part of it having been (nonconsensually!) programmed by a third party to upload data to their own server. You own the device, so anything you do within that device is authorized. And the code that uploads the data is authorized to do so because it was put there by the same company that owns [controls]…

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

The DoJ lost the case they went after for someone guessing URLs.

Re: Modern cars are spying on you. Here's what you can do about it

#292
post #264

Earlier quoted context omitted.

Check your tire pressures when you get gas, along with your oil and other fluid levels. Eyeball the tires every time you get in the car. These habits are not hard to develop and they will work even when the sensors malfunction (which is not infrequently). All that these sensor-based systems do is train you to be an inattentive car owner.

Nonsense. Information is good. I do have a walk around the car before I set forth, but stuff happens. Some drives are very long -- hours and hours between stops. I've had tires that aired themselves down during a drive. TPMS can alert me to that issue before I get an opportunity to have another walk-around, so I can stop and address it before it becomes a safety concern. It's fine if someone want to live in a world w…

Nonsense. People are still driving cars without TPMS, they can feel the difference while driving and do tire pressure checkups regular intervals depending on run. No issue.

Re: Modern cars are spying on you. Here's what you can do about it

#293
post #178
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

You think criminalizing guessing URLs is unreasonable. What about guessing passwords? Should someone be prosecuted for just trying to bruteforce them until one works?

It depends on stuff.

Sometimes a URL can have a password in it.

But when it's just a sequential-ish ID number, you have to accept that people will change the ID number. If you want security, do something else. No prosecuting.

Re: Modern cars are spying on you. Here's what you can do about it

#294
post #258
post #201

Earlier quoted context omitted.

How do I know which URLs of a website are legal to visit and which are illegal?

I can't say I've ever struggled to make this determination, but I don't make a habit of trying random ports, endpoints, car doors, or brute-force guessing URLs.

But it was very tempting when i saw that my national exam results were sent to us in a mail as nationalexam.com/results/2024/my-roll-number. Why would i not try different values in the last part.

Re: Modern cars are spying on you. Here's what you can do about it

#295
post #240

Earlier quoted context omitted.

So you're telling me that simply walking out to the car and hitting a button inside the car is just too much of an "inconvenient experience"? You know we used to have to drive the car... sometimes many miles... to a station, get out, and fill it up with a liquid fuel that costs many times more, and then drive home... Seriously now- The perceived 'inconvenience' you have is the reason that so many of these connected f…

But you’re also using this technological convenience to reply to me. You know we used to have pen and paper and horses.

False equivalence: you're saying you want the convenience of remote access without the price the manufacturer is charging (full data collection)

Re: Modern cars are spying on you. Here's what you can do about it

#296
post #59

Earlier quoted context omitted.

I suspect this data is made "anonymous" and sold to insurance companies and misc data brokers. If it's linked to my insurance company, I don't want to jack my rates. Further, I've thus far avoided a CFAA conviction and I'd like to keep it that way.

It would be an extremely totalitarian dynamic to be persecuted with the CFAA for modifying a device you own based on part of it having been (nonconsensually!) programmed by a third party to upload data to their own server. You own the device, so anything you do within that device is authorized. And the code that uploads the data is authorized to do so because it was put there by the same company that owns [controls]…

It might be interesting for an enterprising lawyer to try to flip this around. Suppose you send a letter to your car manufacturer saying that, as the owner of the car, you are prohibiting them from accessing the location of the car or performing unauthorized software updates and that any attempt to circumvent this will result in criminal prosecution for unauthorized access to your computer.

Re: Modern cars are spying on you. Here's what you can do about it

#297

Earlier quoted context omitted.

Guessing URLs is equivalent to ordering an item not on the menu in a restaurant. The request may or may not be granted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability. How do you propose the line should be drawn?

The question can be easily inverted for the other side: if any user accidentally damages a service's functionality in any way, can they always be criminally liable? Can this be used by companies with no security or thought put into them whatsoever, where they just sue anyone who sees their unsecured data? Where should the line be drawn?

To me, this is subjective, but the URL situation has a different feel than something like SQL injection. URLs are just references to certain resources - if it's left unsecured, the default assumption should be that any URL is public, can be seen by anyone, and can be manipulated in any ways. The exception is websites that put keys and passwords into their URL parameters, but if we're talking solely about the address part, it seems "public" to me. On the other hand, something like wedging your way into an SQL database looks like an intrusion on something private, that wasn't meant to be seen. It's like picking up a $100 bill of the street vs. picking even the flimsiest, most symbolic of locks to get to a $100 bill you can see in a box.

Re: Modern cars are spying on you. Here's what you can do about it

#298
post #221

Earlier quoted context omitted.

Then do the opposite. Poisoned data that can improve your insurance rates

they use the data mostly to charge you more, you can't really get the price all that lower I've had a clean driving record for 30 years and I'm still paying the junk rates most other people get

So, it's like credit scores, basically? Advertise a happy, meritocratic future for consumers, where the "better"/more responsible ones will reap massive rewards at the expense of the "worse" consumers, and then keep adjusting the brackets until the system is only used punitively - you don't really get anything from a high score nowadays, your only goal is clearing a certain low bar to avoid negative consequences.

Re: Modern cars are spying on you. Here's what you can do about it

#299
post #80
post #20

My 2025 Mazda Miata has a CAN connected Telematics Control Unit that sends a bunch of data to Mazda on ignition off. Among this data is acceleration and velocity data along with coordinates sampled for where you were. It is also used as a gateway for the Mazda app to start your car, query your vehicle's tire pressure, etc. It is claimed that you can opt out of this by calling Mazda and being persistent. The CAN traff…

Have you posted any writeups or other information about how you built this? I'm eyeing a Mazda as a next car (I've never owned a car newer than a 2014, and outside of that one, any newer than 2006, but family safety needs may lead to getting a newer car soon), and telemetry seems like one of the few downsides to an otherwise good carmaker. Would be very interested to learn more!

> (I've never owned a car newer than a 2014, and outside of that one, any newer than 2006, but family safety needs may lead to getting a newer car soon)

I don't know much about automotive safety, but has much actually changed since 2014 in terms of safety standards? I had thought that by the 2010s, basically everyone big had already figured out how to build a relatively safe car from a structural standpoint. Or are you only talking about electronic assistive features, like proximity sensors or lane assist?

Re: Modern cars are spying on you. Here's what you can do about it

#300
post #240

Earlier quoted context omitted.

But you’re also using this technological convenience to reply to me. You know we used to have pen and paper and horses.

False equivalence: you're saying you want the convenience of remote access without the price the manufacturer is charging (full data collection)

Yes, because it's entirely possible to do. Hell, the manufacturer even charged a price when you bought the car, or I can pay the $20 for my lifetime share of server usage.
Post reply on HN