Live data from Hacker News

An insurance company’s API exposed customers’ car location histories

andreascarpino.it

61–69 of 69 posts

Re: An insurance company’s API exposed customers’ car location histories

#61

it's really sad how young online political activists have adopted privacy issues instead of adopting issues like workers rights, vacation time, pay, a strong welfare state, universal healthcare etc...

The guy who wrote this is Italian... maybe he's satisfied with the state of many of these things in Italy.

Re: An insurance company’s API exposed customers’ car location histories

#62
post #5

It's a shame he can't name the telematics company. I have a suspicion it's one I interviewed at a few years ago.

Funny, you don't name it either.

Really?

I went to an interview 3 years ago. The only 'evidence' I have is the UI looks vaguely similar, and my questions about their security posture were met with non-committal answers.

If you knew about the industry, they could have rebranded somebody elses software, bought a previous version, lots of things.

Why would I hold myself to something that may be libelous, without the evidence the OP has?

Re: An insurance company’s API exposed customers’ car location histories

#63

Earlier quoted context omitted.

That's a qualified statement, there is nothing irresponsible about that. Telematics companies bear close watching anyway. Right now it is as far as I'm concerned a content free statement.

It's absolutely irresponsible, even with qualifications, given what we now know about how people use that information. Witch hunts happen even with qualified statements, and down the road people who read qualified statements tend to forget the qualification and give the negativity more weight than it deserves.

Thank you.

Knowing like most industries, the layers of ODMs and OEMs etc, it's hard to pin down who exactly is responsible for a security cockup. And, funnily enough, having an interview there I wasn't inclined to do a recce on their infrastructure. Also, not having a device, I didn't have endpoints or traffic to test.

Re: An insurance company’s API exposed customers’ car location histories

#64
post #46
post #39

Earlier quoted context omitted.

I wouldn't want to know a company when, how often and which doctors I consult for one. If you don't want to share your search history you may not want to share your location data either. I would see these as equivalent.

> I wouldn't want to know a company when, how often and which doctors I consult for one. Depends. A lot of doctor's offices are in "medical parks," so it's entirely possible they don't know which doctor you are seeing or why. They have easier access to that information via your calendar (if you use it) than your location.

You're underestimating the google, my friend. This response also misses the point, just because this specific example may not be relevant to you (what about private practice doctors?), there are hundreds of others that are.

Re: An insurance company’s API exposed customers’ car location histories

#65
post #59

Earlier quoted context omitted.

The trouble I see coming is, right now it's "a discount" for sharing the data. Once these sorts of services become ubiquitous and well tested, it'll be "a surcharge" for not sharing the data. Explicit opt out, versus explicit opt in. Right now, it feels like you're getting value out of sharing your data, but in the future, you may have to pay more (relative to others) to keep your data private.

They're two sides of the same coin. Your situation is already the reality. A 40% discount for selling your information is a 67% surcharge for your privacy.

That's a matter of perspective, and I agree that that's what it will very rapidly become. However, right now, I would say it really is a discount - you get a rate that is lower than what you would otherwise have gotten before the technology was introduced. That's partially a reward for you being part of the early adopter group that will make it ubiquitous enough that they can justify raising the prices back up to the level the market can bear.

Re: An insurance company’s API exposed customers’ car location histories

#66
post #5

Earlier quoted context omitted.

Funny, you don't name it either.

Really? I went to an interview 3 years ago. The only 'evidence' I have is the UI looks vaguely similar, and my questions about their security posture were met with non-committal answers. If you knew about the industry, they could have rebranded somebody elses software, bought a previous version, lots of things. Why would I hold myself to something that may be libelous, without the evidence the OP has?

Because right now you are an anonymous entity on the internet making statements about other un-named entities which may or may not be the same as the one the article is about.

To me that's a content free statement, if you were either not anonymous or you named the company the statement would have some force as it is it is a big fat 0.

Re: An insurance company’s API exposed customers’ car location histories

#67

I can't believe that anyone would voluntarily sign up for this. Frankly, insurance isn't that expensive. Having a little third party controlled snitch hooked to your car is a security issue, period. The fact that the implementation is a shitshow is just icing on the cake.

> Frankly, insurance isn't that expensive.

I've had a driving license for about 10 years and I've never been in a collision, never gotten a ticket, and never filed an insurance claim -- neverthless, my insurance premium was $95 a month (likely due to my age, credit report, not being married) until I switched to a pay-per-mile insurance that requires a "third party controlled snitch" connected to my vehicle's OBD port -- which cut my premium significantly.

> I can't believe that anyone would voluntarily sign up for this.

It saves me money and I don't have much money. Hell, it's why people even bother with insurance companies in the first place -- it's cheaper than depositing $60,000 in a surety bond to the DMV.

Re: An insurance company’s API exposed customers’ car location histories

#68

Earlier quoted context omitted.

Really? I went to an interview 3 years ago. The only 'evidence' I have is the UI looks vaguely similar, and my questions about their security posture were met with non-committal answers. If you knew about the industry, they could have rebranded somebody elses software, bought a previous version, lots of things. Why would I hold myself to something that may be libelous, without the evidence the OP has?

Because right now you are an anonymous entity on the internet making statements about other un-named entities which may or may not be the same as the one the article is about. To me that's a content free statement, if you were either not anonymous or you named the company the statement would have some force as it is it is a big fat 0.

In that case we're no different to each other.

Re: An insurance company’s API exposed customers’ car location histories

#69

Earlier quoted context omitted.

Because right now you are an anonymous entity on the internet making statements about other un-named entities which may or may not be the same as the one the article is about. To me that's a content free statement, if you were either not anonymous or you named the company the statement would have some force as it is it is a big fat 0.

In that case we're no different to each other.

Actually, I'm not anonymous.
Post reply on HN