Live data from Hacker News

Modern cars are spying on you. Here's what you can do about it

apnews.com

311–320 of 373 posts

Re: Modern cars are spying on you. Here's what you can do about it

#311

Earlier quoted context omitted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability. How do you propose the line should be drawn?

The question can be easily inverted for the other side: if any user accidentally damages a service's functionality in any way, can they always be criminally liable? Can this be used by companies with no security or thought put into them whatsoever, where they just sue anyone who sees their unsecured data? Where should the line be drawn? To me, this is subjective, but the URL situation has a different feel than someth…

>The question can be easily inverted for the other side: if any user accidentally damages a service's functionality in any way, can they always be criminally liable? Can this be used by companies with no security or thought put into them whatsoever, where they just sue anyone who sees their unsecured data? Where should the line be drawn?

I don't think the question can be inverted like that, not meaningfully anyway. The CFAA specifically requires one to act knowingly. Accidentally navigating to a page you're not supposed to access isn't criminal.

>To me, this is subjective, but the URL situation has a different feel than something like SQL injection.

I don't think the url below is necessarily that different.

> GET wordpress/wp-content/plugins/demo_vul/endpoint.php?user=-1+union+select+1,2,3,4,5,6,7,8,9,(SELECT+user_pass+FROM+wp_users+WHERE+ID=1)

> if it's left unsecured, the default assumption should be that any URL is public, can be seen by anyone, and can be manipulated in any ways

It can be, but not lawfully so. It's not possible to accidentally commit a crime here, for example in the IRC logs related to the ATT case the "hackers" clearly understood that what they were doing wasn't something that AT&T would be happy with and that they would likely end up in court. They explicitly knew that what they were doing was exceeding authorized access.

> On the other hand, something like wedging your way into an SQL database looks like an intrusion on something private, that wasn't meant to be seen

I think you've reached the essence of it. Now, let's say you just accidentally find an open folder on a bank's website exposing deeply personal KYC information of their customers. Or even better, medical records in the case of a clinic.

Lets say those files are discoverable by guessing some URL in your browser, but not accessible to normal users just clicking around the website. If you start scraping the files, I think it's pretty obvious that you're intruding on something private that wasn't meant to be seen. Any reasonable person would realize that, right?

Re: Modern cars are spying on you. Here's what you can do about it

#312

Earlier quoted context omitted.

This same logic is easily extended to SQL injection, or just about any other software vulnerability. How do you propose the line should be drawn?

>How do you propose the line should be drawn? there is a line drawn for such things. a fuzzy line. see: https://en.wikipedia.org/wiki/I_know_it_when_I_see_it same as this famous case, in which a supreme court justice is asked "what is and is not pronographie" - of course he realizes if he defines "what is not" people are going to make all kinds of porn right on the boundary (see: japanese pronographies where they do…

Do you think the current line, where it's based on you "knowingly" exceeding your access or deliberately damaging the operation of a computer system, is excessively vague?

Re: Modern cars are spying on you. Here's what you can do about it

#313

Earlier quoted context omitted.

Yes, I am sure. Annex VII only rules out connecting to the PSAP/112 side, not routine network attaches. To detect faults in the “means of communication”, the IVS has to verify that the SIM, baseband and RF path are actually usable, and you can’t test that without a network attach. In practice that’s what all current eCall implementations do. The modem attaches to the cellular network at each ignition so it can confir…

Does that mean the modem used for eCall is the same that is used to transmit telemetry? Because that's a level of shitty I hadn't even considered. That said, it would go against the spirit of the law as I read it. There are always workarounds, of course, but that does pose an annoying problem to patch.

Yes, unfortunately in all modern calls there's a single Telematics Control Unit with a modem, GPS/GNSS, eCall (where required) and whatever OEM telemetry stack.

Like you say, there are always workarounds, but none that the home-gamer can safely or legally modify without taking eCall out of compliance.

Re: Modern cars are spying on you. Here's what you can do about it

#314

Earlier quoted context omitted.

So if I deliberately exploit a bug on your website and download your customer database by typing things in my browsers URL bar, I should not be prosecuted?

No, and I would support a law explicitly making it illegal for prosecutor to prosecute you for this.

I'd be totally down for that, but I reckon it would be kind of shitty for the vast majority of the people who are not CTF enthusiasts.

Re: Modern cars are spying on you. Here's what you can do about it

#315
post #81

Earlier quoted context omitted.

If you can be prosecuted for guessing urls you can be prosecuted for sending garbage data in a way you know will be uploaded to a remote system.

The DoJ lost the case they went after for someone guessing URLs.

They lost it because they charged in the wrong jurisdiction.

Also come on, you can't reasonable describe that case as being about "guessing urls". It's the associated chat logs that really make the case.

Re: Modern cars are spying on you. Here's what you can do about it

#316
post #258

Earlier quoted context omitted.

I can't say I've ever struggled to make this determination, but I don't make a habit of trying random ports, endpoints, car doors, or brute-force guessing URLs.

But it was very tempting when i saw that my national exam results were sent to us in a mail as nationalexam.com/results/2024/my-roll-number. Why would i not try different values in the last part.

Try it once to see if it works, you'll probably be fine.

Find out that it works, and then proceed to look up various other people? Whether you're fine depends entirely on whether or not you genuinely believe that you're supposed to be accessing that stuff.

Re: Modern cars are spying on you. Here's what you can do about it

#317
post #260

Earlier quoted context omitted.

> Everyone who is in the industry providing IT services is supposed to know that basic security measures are necessary. And everyone who doesn't have wool for brains knows to not carry large rolls of cash around in a bad part of town, but we can still hold the mugger at fault.

Nevertheless, URLs are as public as door knobs. If someone is merely observing that a door is unlocked and they have not stolen anything, they have done nothing wrong. People being prosecuted over discovery and disclosure of horrible design flaws based on URLs should never be prosecuted. If they use the information to actually cause damage, we can be in agreement that they are responsible for the damage.

>People being prosecuted over discovery and disclosure of horrible design flaws based on URLs should never be prosecuted. If they use the information to actually cause damage, we can be in agreement that they are responsible for the damage.

That's literally the current state of things.

Re: Modern cars are spying on you. Here's what you can do about it

#318
post #281

Earlier quoted context omitted.

> Social media -> /dev/null That made me chuckle, absolutely right though!

I love how these comments are made on a social media website.

HN is not a social media platform in the traditional sense. For one, it is completely anonymous, unless your "handle" is somehow linked to a real identity (by choice or otherwise). It's very, very different from posting every aspect of your life on a platform like Facebook.

Re: Modern cars are spying on you. Here's what you can do about it

#319
post #264

Earlier quoted context omitted.

Check your tire pressures when you get gas, along with your oil and other fluid levels. Eyeball the tires every time you get in the car. These habits are not hard to develop and they will work even when the sensors malfunction (which is not infrequently). All that these sensor-based systems do is train you to be an inattentive car owner.

Nonsense. Information is good. I do have a walk around the car before I set forth, but stuff happens. Some drives are very long -- hours and hours between stops. I've had tires that aired themselves down during a drive. TPMS can alert me to that issue before I get an opportunity to have another walk-around, so I can stop and address it before it becomes a safety concern. It's fine if someone want to live in a world w…

Information is good but the number of "slow leak on a long drive" failures made less inconvenient by TPMS almost certainly pales in comparison to the inconvenience of maintaining the system for the average consumer.

Acting like all this is a safety concern is just textbook internet comment section lying through ones teeth type behavior. Yes, anything can be a safety concern at the limit but even tire failures on the road to not typically elevate to that level. The following framing of "well just drive an old car if you don't like it" is more of the same sort of dishonesty with a veneer of plausible deniability on top. There's no reason these systems need to be built in a way that they can't be disabled and leak PII. There's no reason just about all the systems you're trying to frame as a "bundle" have to be bundled in the first place.

Re: Modern cars are spying on you. Here's what you can do about it

#320

Here is something else you can do about it. By an older low mileage car. If we all did that the manufacturers would change tack soon enough

I did do this, but I also want a reasonable modern and safe car and in the EU, since 2018, that means a car with eCall. I have a 2017 that I will keep going as long as is economical, but after that, it will be nearly impossible to avoid these systems.

> that means a car with eCall

It can be removed/disabled. Given that we're talking about a used car, the warranty being void is not a problem either.

Post reply on HN