Posted by bookofjoe 14 hours ago
I have a seven year old Volkswagen, not financed. I'm security conscious and made sure to disable all the data collection I could find in the companion app before removing my account, turn off remote access services, dig through the infotainment to turn off what I could, etc.
Last year I requested a Carfax on it, and one of the fields in the request was current mileage. I entered an estimate like 75000 miles. On form submission, that field failed validation with red subtext along the lines of 'this is less than the last reported mileage of 75345, reported <5 or so days prior>'. Checking my odometer and looking at my past few days' trips, that was indeed accurate.
The car hadn't been to a shop or out of my possession in weeks, so I can only assume the telemetry was still dialing home and selling to third parties despite my best efforts to disable it.
There's an exceedingly common type of failure I have seen myself in industrial electronics and (has happened with Tesla at least once), that some module keeps a log of some kind in a nonvolatile flash, and this flash has a limited lifecycle, which the equipment reaches at some years into its life (or earlier, if the flash came from a bad batch, or more logging happens than planned).
At this point the board usually gets bricked and replacement is very hard due to cryptographic handshakes between components.
Manufacturers use this capacity as an excuse to push more adtech penny and dime data abuse, knowing half the world will blame the government.
This is never enough. You can't trust a software switch. You need to remove the hardware capability if you want to make sure the car isn't spying on you. In the best case, the telematics box has it's own fuse, and that may be enough. In other cases, you need to find the box and unplug it. The service manual will have it's location. In some cars it's easily accessible, in others less so and you need to remove the glove box or part of the dash. Dealers will probably refuse to do it, my advice would be to DIY or find an independent mechanic who will do it.
https://www.tacomaworld.com/threads/simpler-solution-for-dis...
The most reliable way to permanently silence the cellular modem is to pull the relevant fuse. In the above case, this also disables the microphone, which I think is a positive. Unplugging the DCM entirely, however, seems to disable to right speaker, which is wired through the DCM for some reason.
(Yeah, technically horrible but I’m sure someone will find a way)
You could probably find some interesting info if you send out some privacy requests through the chain. LexisNexis and Verisk are consumer reporting agencies, so they have to provide you a disclosure on request. Start there.
I thought, I wonder if it’s the same guy? Sure enough.
Stop it.
So fucking do it! Who died and made you the style police?
> Stop it.
He's making reasonable points, in a readable fashion.
You, on the other hand...
What's your point? AI bad? Srsly, is that all you've got?
>The fuse stops it but the real issue is the owner is the only one without the record.
>Your mileage went from VW->telematics vendor->broker->carfax, thats the chain it usually follows. The fuse stops it but the real...
Prior commentary advised removing the fuse to stop the telemetry. This comment points out that the chain of information flow precludes the owner of the car.
I don't understand what "the record" is referring to here. The mileage is presumably still on the odometer of the car. So what is "the record" that the owner does not have and how is that causing the owner an issue?
You don't really think they added all that circuitry and a cell connection just to collect odometer information, do you?
> how is that causing the owner an issue?
Welp, it was a huge issue for a lot of owners when GM OnStar started sharing real-time driving data with insurance companies.
Supposedly they're stopping that, but a lot of the damage is done.
I read this as:
"Removing the fuse that provides power to the telematics module can stop data collection from a vehicle, but the real issue is that the putative owner is the only one who isn't instantly privy to all of the collected data."
In any case, the complaint above was obviously about AI usage, and there are a lot of good reasons to use AI for editing your words, starting with (for example) if you're not a native speaker.
My car is from 2011 and I do wonder if there is any telemetry in it.
I could see a fuse for cellular comms, be presumably that would also disable maps, contacting emergency services in an accident, etc. which might be an acceptable tradeoff.
Its only job is to detect harsh acceleration and brake events. Probably being sold to your insurer.
Every business likes data collection, until they don't.
My main motivation to get a better car was, DD goes to a super prestigious college and it seems degrading to put their bumper sticker on a 23 year old car! But I guess I won't get another car. Serves you right mfr mfrs!
You can see a map of these nodes with https://wigle.net/
While LG TVs send a lot of private data when connected to the internet, I'm not aware of any credible reports that they automatically connect to open or partner-provided wifi networks without a user choosing to do so.
It's certainly a threat to keep an eye open for, but it seems manufacturers haven't quite stooped to that low yet.
It has not been demonstrated actively in use, only that it is possible and trivial to implement. Statement with regards to it being demonstrated retracted.
I stand by the concept that any consumer IoT device could join these networks, and the end user would never know. The only legal solution to this problem statement is to physically disable the radio on the device if assurance is desired.
This depends a lot on the region/country. IN the US, open WiFi is unusual but it's pretty common in parts of asia, for example.
In other news, I think I'll be taking a trip to somewhere down south to find a nice, used 1999 F350 dually with a manual transmission, since they're going to cease to exist shortly...
isn't it not-funny that the super-invasive Google profiling and ID checks are also part of "Google Play" ?
I've been handed a Carfax on my own car that has a reported mileage much greater than the actual mileage on the car, and the car has not been out of my possession.
You should have an empty glovebox as well when you take it in for service if you don't trust the shop.
If you have registration / insurance paperwork, you're now on that shop's mailing list and can expect to get "$15 off your next oil change ..." flyers in the mail.
Random Public data:
Honda sold data on roughly 97,000 cars to Verisk for $25,920—amounting to about 26 cents per car.
Hyundai sold data on about 1.7 million vehicles for roughly $1 million—about 61 cents per car
It would be cheaper to do nothing if that were true.
It works. Most people are happier focusing and holding forth on that and repeating familiar statements than they are talking to congressional staff about policy.
Your car that you paid a lot for and you like and have positive useful experiences with every day? That’s going to be way farther down the list of things to worry about.
In my understanding, this pretty much makes this type of driver data illegal to sell or share. CalPrivacy's enforcement division has their eye on connected car manufacturers already, so we'll see what they do with that.
https://leginfo.legislature.ca.gov/faces/billHistoryClient.x...
Facts about the car: VIN, spec, recall status, odometer. Attested by someone other than the owner. Outlives every owner and the owner is the last to have it, if at all.
Facts about the driver: speed, location, timestamp. Thats what GM sold, the fix is to not collect it but OEMs seem to take 'anonymization' approach.
The DRIVER act treats both as the same which is why it fails to fix anything. The second needs a ban. The first needs the opposite - especially as we take the driver out of the vehicle - an authoritative record of the vehicle. How do we expect AVs to have adoption when the only safety certification is the company's press release?
Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.
It's wild how convenience trumps everything and then we look back to say, "we should have done better."
Sometimes it helps to have someone with their priorities in order keeping a reality check on people who don't always stay grounded.
I think maybe being grounded has changed - I would be comfortable doing what I described but I imagine your comfort with your preexisting solution means your ground has shifted and a reality check means you woudl rather give away your data than take the higher friction option?
Never underestimate the risks of spousal dissatisfaction.
Regardless, taping some foil around the connectors with the foil making okay contact with the metal chassis is more than enough attenuation at sub GHz microwave to remove this concern without having to source specialty terminations and crimpers (or worse, non-reversible damage to the OEM cable assemblies by repurposing their terminations). I've done the foil+tape on some of my vehicles, but it hasn't made a difference in binary "does it connect or not?" testing.
If a hypothetical future owner feels strongly about it then replacing a telematics module in the dash is much easier than replacing harness runs. I somehow doubt I would sell one of my vehicles to someone who would do that though.
If your buyer is the end owner, probably increase a little bit unless they are surveillancemaxxing.
Easily reversible mods only affect price for suckers anyway.
These cars are more software than hardware now. And like everything else in the software industry, every product gets released incomplete and patched later.
Although the correct solution would be a USB port somewhere to insert a patch file rather that over-the-air updates that might happen while driving.
Although it wasn’t worth the cost of the 3 year subscription so I now just estimate the charge status based on the charge’s power consumption.
If the car is at 10% battery, it may be worth charging at .15 or .3€/kWh. If it’s at 70% charge, I’ll wait until the price drops to .005€/kWh. The whole thing is automated in HA.
Their is a cell modem in the car, so all these features are available anywhere the car has cell service.
Are any of those things more important than your security (e.g., against hackers) and privacy?
It also seems to conflict with `right-to-repair` laws if the capability is legally required.
The near universal proliferation of owner's associations and management groups and whatnot for developments larger than ~1ac (the EPA threshold, some states/towns have lower) is something you can lay at the feet of the Clean Water Act and it's implementation and precedents over the following decades.
The exact area of the buildings, the driveways, the community park and gazebo, etc, etc, are necessary features of the site plan that makes the math that is required to meet stormwater/environmental requirements. And and some legal entity has to be responsible for that in perpetuity. Enter the HOA. This is also why HOAs often won't allow you to expand your driveway or add a non-permeable patio, it could (prob not, but still) ruin the environmental calculations they're responsible for enforcing as a condition.
I'm not nearly as familiar with car regulatory stuff but I would bet a lot of money that they're using OTA telematics to check some sort of compliance box...
Developers don't do anything that costs money, like set up an HOA, without a reason. The developers create the HOA because you need your >1ac residential development to pass stormwater permitting. While you theoretically could make each individual .25ac parcel you're putting a house on compliant it's infinitely cheaper to just ignore all that, grade everything toward the road, dig a ditch, send the contents of the ditch through your stormwater treatment features, build in a little margin to those items, show the permitting authority the numbers that prove it passes with flying colors and when some jerk says "but what if X Y Z changes" you point to the excess you built in and tell them to GFY.
Now, where it really gets evil is when you start really pinching pennies or where the rules change over the course of the process making your numbers not work. Say you've got a lot of grade, a lot of rainfall, a lot of stormwater you gotta "treat". Well, you start adding rules to the HOA. Require certain parts of the lots remains grass or planter or whatever. Disallow patios, but do allow wood decks because the municipality considers those pervious, etc, etc. Or maybe the results you've got are marginal but you throw the bureaucrats a bone by saying you'll disallow car-ports and sheds in the HOA rules to prevent people from adding impervious surface. Or maybe you're uphill of some wetlands but not close enough to be regulated by default you promise to disallow working on cars and require people pick up their pet waste and not use lawn fertilizer or some other laundry list of certain things in order to make the local town's wetlands people comfortable not raising objection and claiming jurisdiction.
And of course, however these rules and plans shake out, the HOA is responsible for implementation in perpetuity.
In carving up the 5 acres the developer purchased, the 30 houses they squeezed in left some remainder that wasn't buildable or odd shaped, so this now becomes a lame 'park' or some other space that requires maintenance.
I read all my local municipal meeting minutes, and at least around here, permitting and ordinances control all the environmental/nuisance stuff, so I can't really explain why HOAs go beyond the collective expenses into the draconian rules.
An obvious thing may be to say the software must be published or the spec released, but we've had computers in cars since the 80s. It seems like a tall task but people can and do reverse engineer entire ECU systems (See Trionic Tuning)
Another seemingly very obvious one - requiring manufacturers to publish specifications regarding ALL OBD interface options. Of course this immediately runs into trouble. Saab for example gated features of the security system to prevent key reprogramming, swapping of certain components without a dial out to the internet using specific saab software that runs on a laptop and interfaces.
Strongly. You don't own the thing you purchased if you can't legally repair it or legally obtain the knowledge to repair it. At beat you're paying an overpriced lease and granting a liability waiver.
I'm not sure what the solution is, but it's not going to be market based if you look at any recent trends. Interest in privacy is unfortunately a niche concern outside of places like HN.
Anyone who has tried to market a privacy oriented product knows what I am talking about.
I imagine its friction and not indicative of interest itself.
Just like musk, props on the consistency
Either via permanent 4G/5G link or during service intervals in the shop.
Source: I analyzed these data as an intern for one.
- Chat Control law, now all messaging must be intercepted and monitored.
- eIDAS law, mandating that web-browser vendors must now accept state issued root certificates, so that states can selectively and without any legal procedure deploy MITM attacks at will.
- ADDW law, mandating that all new cars must a permanent mandatory camera and microphone surveillance module inside a car, which can't be disabled by law (bye-bye insurance if you will). There also other fun things in it like mandatory autobraking, mandatory auto lane-assist etc.
- ProtectEU laws, demanding backdoors to emails and such (maybe it's the same as Chat Control, not sure).
- AI Act legalizes AI surveillance over CCTV recordings without any judicial approval.
- European Media Freedom (duh) Act legalizes deployment of shit like Pegasus against journalists.
I'm pretty sure I'm missing a lot here too. You get the picture. EU is getting fast track into Stazi 2.0, everyone is fine with it, "because children" /s
If you are a CA resident you can also get on the state's DROP platform to request that all registered data brokers delete your data, but it's only for deletion and not the other 4 types of data requests allowed under the CCPA (right to know, right to collect, right to opt out, and right to limit use).
It's still better than other modern cars though? I think.
I thought GP was talking about if they had to reconnect the systems for some reason, would archived telemetry suddenly be uploaded. Which is a real possibility, so I was suggesting poisoning the data. Even if you correct the clock today, the previously recorded timestamps cannot be automatically fixed. Even better would be to reset the clock on every startup event.
Which is all still a band-aid solution - a targeted analysis could mostly correct the time-keeping. This just prevents getting scooped up in a simple drag net kind of search.
Can I disable all data collection from my vehicle?
> third-party partners process information about you and how you use our services, including clicks and screen recordings, using first and third-party cookies, pixels, and similar technologies