Live data from Hacker News

Toyota: Car location data and videos of 2M customers exposed for ten years

bleepingcomputer.com

91–100 of 314 posts

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#91
post #72

> It is important to note that the exposed details do not constitute personally identifiable information, so it wouldn't be possible to use this data leak to track individuals The data included timestamped GPS data, which has been demonstrated to be easy to de-anonymize.

Yeah, companies seem to think that "personally identifiable information" is basically just your name. That's clearly wrong because GPS data and VIN make it extremely straightforward to figure out who a car owner is. As far as I'm concerned, this is PII. That statement is a bald-faced lie and a state AG should bring charges over this - it's extraordinarily irresponsible for Toyota to collect this data and then leak it…

"Personally identifiable information" is a legal term with a legal definition[1], and location data is not PII. Companies think that PII is basically just your name because that's literally true: PII means name and government-issued ID number. That's it. Everything else is not PII.

Relatedly, PII sucks as a basis for privacy law. The laws enshrining PII were made in response to identity theft[2], and that's the "threat model" those laws are protecting against. They do a reasonable job protecting against that threat model, but are very narrowly-focused on that threat model.

Fine-grained location data is absolutely sensitive data, and any non-braindead privacy legislation would consider it as such. The US lacks such legislation. It would be considered Personal Data under GDPR, and Personal Information under CCPA.

[1] Actually like 400 definitions in 400 different laws, but there's a lot of similarity.

[2] Specifically, the first data breach notification law was made in response to lawmakers being the victims of identity theft. This is a common thread in US privacy laws. See also Robert Bork.

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#92
post #75
post #62

Owners may want to disable this in hardware rather than relying on a sketchy opt-out mechanism. The relevant part is the "data communications module". It has an LTE modem and a backup battery, so it's able to transmit even if the car battery is disconnected. It requires a little bit of dashboard disassembly to access. You can either remove it or disconnect the LTE and GPS antennas. Toyota has technical documents avai…

"tracker detection and removal" would be a great service for a local service garage to offer.

Vinyl wrap with Faraday cage on the inside layer? A modern "cone of silence"

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#93
There's some really active community discussions around disabling the Data Collection Module, discussing everything from simply pulling the DCM fuse to disabling only the antenna.

If you pull the DCM fuse, you'll loose the microphone and potentially one of the right-hand speakers - these can be fixed by jumping the wires in/out of the DCM.

What's concerning to me are reports of the car still uploading all the collected data if you attach a cell phone to the radio's bluetooth. Apparently the car just relays all the info.

I kinda want to snoop that data and see what it is, at least collect the encrypted packets... but my car is from 2007 and has no connected features, so...

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#94
post #63

Earlier quoted context omitted.

All car shrink-wrap licenses that I have looked at are similar. That's why I think it is funny when people freak out about Android Automotive. The Android Automotive terms are much, much better for customer privacy. The EULA for my Honda says that Honda can and will share all available data with itself and third parties, named and unnamed, for any or no reason.

Funny, I looked around and couldn't find an equivalent for Honda motorcycles. Perhaps Honda understands their customers better than we think. Honda seems perfectly willing to build tracking-free products when the customer base cares enough . I have never met any sportbike rider willing to share one iota of ongoing GPS data with anyone.

Well, the motorcycle community is overstocked with privacy lunatics, preppers, gun nuts and other extremists, so this makes sense. Also I can't think of any Honda motorcycle with a GPS aside from the Gold Wing, which stretches the definition of motorcycle in numerous ways. On the other hand every motorcyclist I ride with carries a Garmin inReach, which is the very definition of sharing your GPS with someone.

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#95
post #84
post #58

Earlier quoted context omitted.

But the VIN number was available, as it says right below that I mean does anyone think there HASN'T been a leak of VIN numbers and owners that would be trivial to join with this? It's also kind of staggering how long this was a problem Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and…

I don't think it's any indicative of how long this problem has been here? Unless I misunderstood, because after re-reading I guess I see how you did read it.

It could be read the other way, but the title and first sentence seems to imply that there was a bug for 10 years

Not that 10 years of data was exposed for a short period

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#96
post #63

Earlier quoted context omitted.

All car shrink-wrap licenses that I have looked at are similar. That's why I think it is funny when people freak out about Android Automotive. The Android Automotive terms are much, much better for customer privacy. The EULA for my Honda says that Honda can and will share all available data with itself and third parties, named and unnamed, for any or no reason.

Funny, I looked around and couldn't find an equivalent for Honda motorcycles. Perhaps Honda understands their customers better than we think. Honda seems perfectly willing to build tracking-free products when the customer base cares enough . I have never met any sportbike rider willing to share one iota of ongoing GPS data with anyone.

> https://www.honda.com/privacy/connected-product-privacy-noti...

~~~ Their's is a lot better, does still include Geolocation, audio recordings, navigation usage, however the usage looks limited to just Honda and the obviously required services: ~~~

> We will not use Geolocation Information for our own marketing purposes or disclose identifiable Geolocation Information with third parties (except our service providers) without your consent.

https://web.archive.org/web/20230512194748/https://www.honda...

EDIT: I just noticed the following:

> These companies may use Covered Information for their everyday business purposes, including marketing, customer service, fulfillment and related purposes. These disclosures may qualify as a sale under certain state privacy laws.

Also their definition of "Service Provider" is way too broad (see below comment). So I might need to retract my statement on their policy being good.

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#97
post #2

Japanese auto completely missed the memo on software. Many of them won't make the ev transition. It's hard to imagine what Japanese economy is going to be like once their auto industry is gutted.

Where are all these American companies getting their batteries from? Mostly Japan... Rivian, Tesla, Lucid, Gravity, Ford, GMC.

Mostly China. But the Korean and American contributions are also very significant. Cell source is not a geopolitical monopoly at all.

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#98
Car companies seem to just not be very good at things other than bending steel, marketing that bent steel on TV, pushing costs and risks into suppliers (and forgetting about it), and running the insurance companies that their corporate entities have become.

I'm sure their internal incentive structure also does not reward people to join/stay at the company who would focus on the problems that this story points out.

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#99

good lord. i'm so glad my toyota doesn't have any of those features. shout out to the lean method.

If it is anything after about 2012 it probably does. Also if this hack is out of the software I think it is, I am not surprised. Some of the main devs were more worried about what a function was named than how to make it work correctly and securely.

This is, effectively, a list of which cars and when:

https://www.toyota.com/audio-multimedia/support/3g-faq/

Re: Toyota: Car location data and videos of 2M customers exposed for ten years

#100
post #19

I hope regulators fine the hell out of these companies. Enough to make them think twice about offering these upload everything to the cloud services no one really asks for.

It's a simple equation: Revenue = (value of data per person) x (number of customers) - (probably of data loss) x (probability of fine) x (cost of fine). If that number is greater than zero, they'll do it, if it's less than zero, they won't.

Which company do you work for?
Post reply on HN