Earlier quoted context omitted.
Prosecuting someone for deliberately injecting garbage data into another persons system hardly seems totalitarian. > You own the device, so anything you do within that device is authorized You're very clearly describing a situation where at least some of the things you're doing aren't happening on your own device. >I do know that the CFAA essentially gets interpreted to mean whatever the corpos want it to mean - it's…
No it does in fact seem totalitarian. I support repealing the CFAA.
Modern cars are spying on you. Here's what you can do about it
341–350 of 373 posts
Re: Modern cars are spying on you. Here's what you can do about it
#342Earlier quoted context omitted.
NYC is the absolute best case in the US, if you're talking about the ability to exist without a car. It's not that no one talks about those millions of households, it's that they are all concentrated on a few standout islands (literally!) in a sea of the nearly identical car-only supermajority of cities. It's the exception to all exceptions.
Most people live on a few islands of density in a sea of nearly empty land in the US.
Re: Modern cars are spying on you. Here's what you can do about it
#343Re: Modern cars are spying on you. Here's what you can do about it
#344Earlier quoted context omitted.
The question can be easily inverted for the other side: if any user accidentally damages a service's functionality in any way, can they always be criminally liable? Can this be used by companies with no security or thought put into them whatsoever, where they just sue anyone who sees their unsecured data? Where should the line be drawn? To me, this is subjective, but the URL situation has a different feel than someth…
>The question can be easily inverted for the other side: if any user accidentally damages a service's functionality in any way, can they always be criminally liable? Can this be used by companies with no security or thought put into them whatsoever, where they just sue anyone who sees their unsecured data? Where should the line be drawn? I don't think the question can be inverted like that, not meaningfully anyway. T…
This is why I tried to make the clarification that I was referring to the address part of the URLs only, not the parametrized part. In my mind, something like /users?key=00726fca8123a710d78bb7781a11927e is quite different from /logins-and-passwords.txt. Although, parameters can also be baked into the URL body, so there's some vagueness to this.
> I think you've reached the essence of it. Now, let's say you just accidentally find an open folder on a bank's website exposing deeply personal KYC information of their customers. Or even better, medical records in the case of a clinic.
I guess if I try to distill my thoughts down, what I really mean is that there should be a minimum standard of care for private data. At some point, if being able to read restricted data is so frictionless, the fault should lie with the entity that has no regard for its information, rather than the person who found out about it. If a hospital leaves a box full of sensitive patient data in the director's office, and getting to it requires even the minimal amount of trespassing, the fault is on whoever did so. But if they leave that box tucked away in the corner of a parking lot, can you really fault some curious passer-by that looked around the corner, saw it and picked it up? Of course, there's a lot of fuzziness between the two, but in my mind, stumbling into private data by finding an undocumented address doesn't clear the same bar as bruteforcing or using a security vulnerability to gain access to something that's normally inaccessible.
Re: Modern cars are spying on you. Here's what you can do about it
#345Earlier quoted context omitted.
You are construing "integrity" to mean lining up with their overarching desires for the whole setup of interconnected systems regardless of who owns each one. By that measure, stopping the collection of data is impairing its availability on their system. I would read that definition as applying only to their computer system - the one you aren't authorized to access. This means the integrity of data on their system ha…
Why do you think the CFAA is unjust? What specific activities does it unjustly criminalize?
But if you're not - the fact it's putting a chilling effect on this activity right here is a problem.
Another big problem is the complete inequity. It takes the digital equivalent of hopping over a fence and turns it into a serious federal felony with persecutors looking to make an example of the witch who can do scary things (from the perspective of suits).
Another glaring problem is that if the types of boundaries it creates are noble, then why does it leave individuals powerless to enforce such boundaries against corpos, being easily destroyed by clickwrap licenses and unequal enforcement? Any surveillance bugs/backdoors on a car I own are fundamentally unauthorized access, and yet I/we are powerless to use this law to press the issue.
Re: Modern cars are spying on you. Here's what you can do about it
#346Earlier quoted context omitted.
My 2003 s-10 has AC and crank windows, my 2007 Ranger did too. Power windows sure are nice when you want to talk to someone out the passenger side and you don't have a passenger though. Or if you want a breeze regardless of AC.
> Power windows sure are nice when you want to talk to someone out the passenger side Presumably the fundamentalists think you just need to yell louder. With neo-luddite opposition like this, its no wonder the surveillance society is winning.
Re: Modern cars are spying on you. Here's what you can do about it
#347Earlier quoted context omitted.
I think they're saying "I don't want to self-incriminate so I don't want to put myself in a situation where I have to lie". I'm not sure it's entirely consistent, but I also don't think it's entirely inconsistent.
If you believe you are at fault in a collision where police, insurance, etc. are involved, they are going to ask for your statement, and at that point you will be forced to choose between lying or admitting fault. If you're glad that no dashcam footage exists, presumably you are going to lie about what happened! I don't see why this is any different than popping the SD card out of your dashcam and lying about that to…
Obviously 99.999% of traffic collisions never get this far, but I'm speaking more of the world of courtroom legal drama where you'd rather not have your in-car conversations recorded, or the fact that you drove around the block of the house where the murder occurred at 3am.
I think there's a huge asymmetry between the upside of the dash cam and the downside of self-surveillance. I'm much more likely to be in a fender bender than accused of murder, but I also _simply don't care_ if the police say I'm at-fault when I don't think I was, driving my insurance rates up for a few years. But I'm deeply uncomfortable with the idea of recording myself 24x7 whenever I'm in my car.
Re: Modern cars are spying on you. Here's what you can do about it
#348Earlier quoted context omitted.
If you believe you are at fault in a collision where police, insurance, etc. are involved, they are going to ask for your statement, and at that point you will be forced to choose between lying or admitting fault. If you're glad that no dashcam footage exists, presumably you are going to lie about what happened! I don't see why this is any different than popping the SD card out of your dashcam and lying about that to…
I think this is a pretty black and white and simple view of things, fault is not always 100% clear, and CLAIMING fault is different from explaining what happened _from your perspective_, and letting the other driver do the same. But I'm not actually speaking about simple fault in a basic traffic collision. Obviously 99.999% of traffic collisions never get this far, but I'm speaking more of the world of courtroom lega…
Seems like having video (and GPS speed, etc.) can only make it clearer who (which may include both parties) is at fault? I still don't see how that can be a bad thing if you also aren't interested in lying about what happened.
> I think there's a huge asymmetry between the upside of the dash cam and the downside of self-surveillance.
I almost addressed the generalized surveillance angle in my original comment, but didn't since it seemed that your comment was focused exclusively on the context of having been in a traffic collision.
Addressing it now, I guess I am just not too worried about this angle when my dashcam simply records videos onto an SD card that I have complete control over. If I was a person likely to be targeted by my authoritarian government, I would probably think twice about having such an unencrypted SD card sitting around where it might be swept up in a bogus search and used to gin up additional bogus charges against me, but that is currently not my situation. Really, I can only imagine the video evidence collected by my dashcam being used to exonerate me in a scenario like the one you describe, e.g. if an LPR tagged me on the block where the murder happened but my dashcam clearly showed that I was just passing through.
In fact, this exact thing recently happened (https://www.cbsnews.com/colorado/news/flock-cameras-lead-col...) to a woman who was falsely accused of theft based on LPR data and used her Rivian's dashcam recordings (among other data) to get the police to drop the charges. It's insane that this happened in the first place, but that's beside the point here.
Of course, people using cloud-based dashcams are certainly exposing themselves to dragnet surveillance—which I do have a problem with simply on principle—but the data on my dashcam's SD card are fundamentally inaccessible to law enforcement until they obtain it in a physical search of my car.
Re: Modern cars are spying on you. Here's what you can do about it
#349Re: Modern cars are spying on you. Here's what you can do about it
#350Earlier quoted context omitted.
Why do you think the CFAA is unjust? What specific activities does it unjustly criminalize?
I had assumed you were coming from a similar position, and your argument was more of a reductio-ad-absurdum. But if you're not - the fact it's putting a chilling effect on this activity right here is a problem. Another big problem is the complete inequity. It takes the digital equivalent of hopping over a fence and turns it into a serious federal felony with persecutors looking to make an example of the witch who can…
>But if you're not - the fact it's putting a chilling effect on this activity right here is a problem.
I've personally had my own CFAA-related criminal troubles in the distant past, but I still have a hard time seeing the big problems with CFAA so often touted on HN.
The activity of childish vandalism by flooding Mazda servers with garbage data? There's no chilling effect on simply not sending any data to Mazda.
The activity which was proposed earlier was explicitly malicious in intent, why shouldn't there be a chilling effect put on it? Do you not think the government should generally protect you from people taking explicitly malicious actions aimed at causing you harm?
In this context it is the motivation that makes the crime. You could absolutely modify your car in a way where the data sent to mazda is replaced with zeroes or random data, but you would need to do so in good faith.
Of course, when the activity is explicitly malicious as stated above ("poison their databases and statistics with fake data") it's not surprising that you'd be in violation of the law.
>Another big problem is the complete inequity. It takes the digital equivalent of hopping over a fence and turns it into a serious federal felony with persecutors looking to make an example of the witch who can do scary things (from the perspective of suits).
I just don't think this is actually happening. The cases often spoken of here are Auernheimer and Swartz.
I have a hard time believing that anyone can read the court files in the Auernheimer case and argue in good faith that such behavior should be legal. Among other things, the court papers contain a chat log of the co-conspirators discussing how to they should use the data they've scraped from buggy AT&T site to spam AT&T customers with malware. In the end that was too complicated, so they arrived at trying to leak the data in most damaging way possible to hurt AT&T share prices.
Swartz performed an admirable act of civil disobedience and faced up to 6 months in prison for that (realistically, he'd most likely never have spent a day in prison). I think what Swartz did is admirable, but that doesn't mean what he didn't shouldn't have been illegal. Just as what Snowden did was admirable, but legalizing such activities would have catastrophic consequences.
>Another glaring problem is that if the types of boundaries it creates are noble, then why does it leave individuals powerless to enforce such boundaries against corpos, being easily destroyed by clickwrap licenses and unequal enforcement?
I feel like this is conflating the problems that CFAA seeks to address with a completely different set of problems.
Corporations are bound by the CFAA just as much as you are, it's just that companies are rarely in the business of doing this sort of crime. Just as companies are rarely in the business of selling heroin.
> Any surveillance bugs/backdoors on a car I own are fundamentally unauthorized access, and yet I/we are powerless to use this law to press the issue.
The fact that CFAA mostly does not address these particular issues is not a problem with the CFAA, people (or companies!) buying devices with software they don't like was never something CFAA was intended to address.
There are reasonable, effective legal solutions to surveillance like this, like the GDPR.