Live data from Hacker News

An insurance company’s API exposed customers’ car location histories

andreascarpino.it

51–60 of 69 posts

Re: An insurance company’s API exposed customers’ car location histories

#51

Earlier quoted context omitted.

Wow! Being part of a late 30s couple with pretty boring driving history in a small city pays I guess. I pay like $700-850 (depending on how you break out umbrella liability cost) for maxed out coverage in an above average cost US state. I think I paid around $1200 when I was a dumb kid with tickets. :) Even if there were siginifciant savings, it wouldn't be worth it to me to have that kind of telemetry being gathered…

Over here there's no choice in the limit of cover - EU mandates that every car insurance has to cover 5 million Euro in personal damages and 3 million in property damage. The only "optional" thing is whether you want to get comprehensive insurance which covers your own car for the damage caused by yourself - but 3rd party liability is always set to that 5 and 3 million by law. I guess you could buy some specialist in…

Interesting, that's nowhere near the level of insurance (it's significantly higher) than what even non-cut-rate insurers will recommend for most drivers in the states. After changing providers, we pay $1400 for two cars with $100,000/$300,000 (individual/total) injury and $100,000 in property coverage.

Re: An insurance company’s API exposed customers’ car location histories

#52
Having worked in the connected car/telematics industry for a while as a contractor, I can very well relate to this and can confirm that the security systems in place inside the car's telematics unit is not good enough. For example, in one of the oauth process of authenticating a car with the cloud, the VIN was passed around as a client secret and MDN of the modem as the username ! We recommended to immediately stop this practice, but the "IT" dept of the automotive maker said, " You know we sell cars, not security software." There is no budget to rewrite the mechanism, and the telematics unit cannot be updated OTA. The upgrade requires customers bringing the car to a dealer and USB stick updates etc.

I believe the frequent bursts of data from the car was given to insurance companies. Or they were trying to package insurance deal along with the car sale or something.

Re: An insurance company’s API exposed customers’ car location histories

#53
post #49
post #42

Note that with the latest changes to Android, using mitmproxy to analyse the behaviour of apps has become impossible: apps refuse to accept personally-installed certificates. In the future, we'll see less revelations about this sort of thing, not because it has become rarer but because Google have chosen a course of action which obscures it. (it also breaks things like personal or corporate CAs, but that's a differen…

It's also hardening against malware basically doing the same thing that mitmproxy does though.

For Android Your point is valid, but I think it's a negligible improvement that comes in hand with severe implications for privacy research.

Re: An insurance company’s API exposed customers’ car location histories

#54

I can't believe that anyone would voluntarily sign up for this. Frankly, insurance isn't that expensive. Having a little third party controlled snitch hooked to your car is a security issue, period. The fact that the implementation is a shitshow is just icing on the cake.

[deleted]

Re: An insurance company’s API exposed customers’ car location histories

#55
post #51

Earlier quoted context omitted.

Over here there's no choice in the limit of cover - EU mandates that every car insurance has to cover 5 million Euro in personal damages and 3 million in property damage. The only "optional" thing is whether you want to get comprehensive insurance which covers your own car for the damage caused by yourself - but 3rd party liability is always set to that 5 and 3 million by law. I guess you could buy some specialist in…

Interesting, that's nowhere near the level of insurance (it's significantly higher) than what even non-cut-rate insurers will recommend for most drivers in the states. After changing providers, we pay $1400 for two cars with $100,000/$300,000 (individual/total) injury and $100,000 in property coverage.

I think a big difference in the US is that there's usually no fault for personal injury, so the liability is pooled.

Re: An insurance company’s API exposed customers’ car location histories

#56
When my insurance company offered a discount to use one of these devices a few years back, I smelled a rat. I figured they would use it to observe how fast I drive vs the speed limit so they can decide how "safe" of a driver I am or whatever. But also my insurance is very inexpensive so discounts on it are not a big motivator.

I guess location tracking would make sense too, so they can bust you if the car stays in a place other than where it's insured for. Or god knows what else. All of this shit is only going to get worse, a lot worse.

Re: An insurance company’s API exposed customers’ car location histories

#57

I can't believe that anyone would voluntarily sign up for this. Frankly, insurance isn't that expensive. Having a little third party controlled snitch hooked to your car is a security issue, period. The fact that the implementation is a shitshow is just icing on the cake.

Well, it seems a lot more reasonable than the popular default of trading all your data for free services that either have very cheap alternatives, or would have if there was a market for it.

I'm speaking from guilt.

Re: An insurance company’s API exposed customers’ car location histories

#58
post #36

Earlier quoted context omitted.

Because he is getting up to a 40% discount in exchange for sharing his location data while he is using his car, he should also run Google Play Services and share his location the whole time too? What?

Exactly. Being concerned about privacy doesn't mean that you don't have a price at which you'll sell specific data of yours. We need these "personal data for discount" transactions to become more explicitly consensual. Despite the well-tuned sensitivities of those in this community, we have a long way to go before most consumers are informed about this unwitting marketplace.

The trouble I see coming is, right now it's "a discount" for sharing the data. Once these sorts of services become ubiquitous and well tested, it'll be "a surcharge" for not sharing the data. Explicit opt out, versus explicit opt in. Right now, it feels like you're getting value out of sharing your data, but in the future, you may have to pay more (relative to others) to keep your data private.

Re: An insurance company’s API exposed customers’ car location histories

#59

Earlier quoted context omitted.

Exactly. Being concerned about privacy doesn't mean that you don't have a price at which you'll sell specific data of yours. We need these "personal data for discount" transactions to become more explicitly consensual. Despite the well-tuned sensitivities of those in this community, we have a long way to go before most consumers are informed about this unwitting marketplace.

The trouble I see coming is, right now it's "a discount" for sharing the data. Once these sorts of services become ubiquitous and well tested, it'll be "a surcharge" for not sharing the data. Explicit opt out, versus explicit opt in. Right now, it feels like you're getting value out of sharing your data, but in the future, you may have to pay more (relative to others) to keep your data private.

They're two sides of the same coin. Your situation is already the reality. A 40% discount for selling your information is a 67% surcharge for your privacy.

Re: An insurance company’s API exposed customers’ car location histories

#60
post #46
post #39

Earlier quoted context omitted.

I wouldn't want to know a company when, how often and which doctors I consult for one. If you don't want to share your search history you may not want to share your location data either. I would see these as equivalent.

> I wouldn't want to know a company when, how often and which doctors I consult for one. Depends. A lot of doctor's offices are in "medical parks," so it's entirely possible they don't know which doctor you are seeing or why. They have easier access to that information via your calendar (if you use it) than your location.

Also, even if you did go to a doctor's office in the middle of nowhere with nothing else around and only one doctor working there, that doesn't mean you are there to see the doctor.

For that matter, your location data couldn't be proven to be yours on merit alone. Anyone can be using my car, and anyone can have my phone, at any given time.

Post reply on HN