Live data from Hacker News

Internet-connected cars fail privacy and security tests conducted by Mozilla

gizmodo.com

81–90 of 660 posts

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#81
The best way around this for those wanting an EV car is to get a classic car that's been well-maintained and do an electric conversion. The only 'infotainment system' anyone needs is a tablet or phone; a charging system for electronic devices shouldn't be too hard to set up either.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#82

Earlier quoted context omitted.

It is already the case today (at least in the UK). If you accept having a "black box", then you have a discount. I already pay the premium to not have that installed. PS: I understand we're talking about the future here, just wanted to clarify that paying a premium for less telemetry is already here and not a hypothetical case.

I actually wanted to go with an insurer that installs a black box. My dealer, however, doesn't do those (and their standard package is pretty good, so with a new car it was stupid to go with someone else).

My insurance company has a phone app that collects the same info - speed, deaccelation (gyroscopes), etc. the app is optional but qualifies you for a discount after 3 months of app history, if your driving pattern meets their standards. They told me they do not impose rate increases based on the app’s reporting, only discounts. I did not install it

but the point is: You don’t need a car device anymore.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#83

I connect my phone to my 2015 Nissan's bluetooth, but just for music. GrapheneOS lets me prevent its access to my contacts, call history, active calls, text messages - anything but music audio. To me (but not the less tech literate, I know), if you're connecting your car to your phone, it's obvious that it is able to gather things about you. That said, because I don't know much about cars, I don't know if the car is…

The hell! You got a 2015 Nissan with Android Auto? I got a 2017 Infiniti that some trims did even come with Bluetooth, needless to say none had carplay or Android Auto. Damn you Nissan.

But I bought that car because its something for me to tinker with and I plan to replace that proprietary head until with an after one. And also use an Arduino 4 inch LCD to tap into the Can bus to show Hvac settings.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#84

The more I read about these things, the more I think I'll be driving my 23 year old Toyota 4Runner until the end of my life

I am still driving my '09 4Runner. Cheap to own/maintain, ridiculously reliable. And no touch screen. Perfection!

Anything made after about 2015 feels WAY over-engineered, for my tastes at least.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#85
post #76

Car dealerships are notoriously horrible about privacy as well. The last time I bought a car at a dealership they wanted me to sign a release that allowed them to use photos and videos of me as part of their television and online advertisement. They were stunned when I refused and threatened to nix the whole deal and I challenged them to do exactly that before (of course) a manager was summoned and eventually I was t…

And then you get about six years of SiriusXM mailers because they sell your data to them.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#86

Earlier quoted context omitted.

Don't Android and iOS by default prevent bluetooth from accessing your contacts and calls. I know on Android you have to click a permission popup when connecting to bluetooth to allow contact and call access

Same on iOS.

But then you have Android Auto getting full access to the cars OBD. One more reason to use Bluetoth, but Googpe, and I assume Apple as well, aren't any better.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#87
post #2

I've got a 2018 Jeep Grand Cherokee and I've been searching for where the sim card is for the built in cellular modem so I can rip it out. It astounds me that there aren't more people interested in cutting off the constant telemetry and to be honest it wouldn't surprise me if the car refuses to operate correctly when I do figure out where it's at and pull it.

There probably isn't a physical SIM card anymore. It probably just has an eSIM.

Just gotta break out the soldering iron then.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#88
post #43

Earlier quoted context omitted.

overwhelm the brain with input. to hold onto threads like this one, you have to be fairly healthy or fairly mad. not strapping on tin foil hat, this likely isn’t some massive coordinated effort. it could be done “better.” this is just making the most of the situation. at scale. if you simplify the question, “Who wants to let their car manufacturer surveil them?” - the answer is also simple. very few hands are going t…

I'm not sure what you're suggesting here.

people are tired, stretched thin, even in the most powerful nations. information access has become so ubiquitous that it has become more challenging to filter than to find.

for many people, there are far more pressing concerns to address than if nissan knows how the back seat was used last night. they would need the time and space to slow down and consider the information, and likely have means to do something, for it to elicit a response. some people would love to have the issue, that would imply having means to get a new car. no, they wouldn’t love the issue, but it is out of reach, so it isn’t deemed worth the effort spent.

right now it’s like saying your cell phone spies on you. most people won’t be getting rid of their phones. some might get foil bags.

faraday cage around your car, on the other hand, isn’t happening.

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#89

It almost feels silly to ask, but is this legal even in the United States with its comparatively weak privacy laws? In many states, a vehicle is legally an extension of the home. So legal rights and protections that apply in one's home also apply in one's vehicle. Is the idea that, buried somewhere in the legalese, is a statement that the buyer is granting the automaker the right to spy?

Yeah, it's pretty sketchy but it seems the courts are allowing most it, even for second owner and non-subscribers (OnStar).

Re: Internet-connected cars fail privacy and security tests conducted by Mozilla

#90
post #76

Car dealerships are notoriously horrible about privacy as well. The last time I bought a car at a dealership they wanted me to sign a release that allowed them to use photos and videos of me as part of their television and online advertisement. They were stunned when I refused and threatened to nix the whole deal and I challenged them to do exactly that before (of course) a manager was summoned and eventually I was t…

I bought a used vehicle at a dealership back in 2018. A couple of years later my daughter was looking for her first car and so we went to the same place. We were just browsing, and were met by a different sales rep. He had to excuse himself to tend to a different customer and during that time we left to go check out other places.

While we were at a different dealership I get an unexpected phone call. It was the sales rep at the first dealership, who I had never met before, and had certainly not given my phone number. I asked him how in the fucking hell he even knew my name, let alone my phone number, and he explained that the rep that sold us our vehicle in 2018 recognized me. I told him that was a very creepy and off-putting experience, that I do not consent to unsolicited phone calls from them, especially in such a creepy situation, and that I won't ever be purchasing another vehicle from them.

Post reply on HN