Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Several years ago, a German company whose name rhymes with "rowdy" sought permission from a Middle Eastern government to collect location and other information (e.g., speed) from its sold automobiles. The government asked them what they wanted to do with the information. They dithered and dawdled and failed to come up with an answer beyond "improved consumer experience." They failed to mention thay planned to sell the collected information to third-parties.
  • That‘ll happen when you don‘t have meaningful data protection laws.
  • Two different things are getting called "car data" here.

    Facts about the car: VIN, spec, recall status, odometer. Attested by someone other than the owner. Outlives every owner and the owner is the last to have it, if at all.

    Facts about the driver: speed, location, timestamp. Thats what GM sold, the fix is to not collect it but OEMs seem to take 'anonymization' approach.

    The DRIVER act treats both as the same which is why it fails to fix anything. The second needs a ban. The first needs the opposite - especially as we take the driver out of the vehicle - an authoritative record of the vehicle. How do we expect AVs to have adoption when the only safety certification is the company's press release?

  • The "genie out of the bottle" argument has been used in the ongoing AI-or-no-AI, we're-so-cooked/we're-so-back debate among software engineers, something like: you can't undo technological advances nor would you want to, so best cope with this new reality.

    And there are technological "advances" I would very much like to undo. One of them being social media, another being modern cars. Automobiles peaked when they were purely mechanical. An average American high schooler could understand all its systems, and many did. When they started becoming LANs on wheels beginning in the 90s, they became necessary millstones around their owners' necks, and these days they're as inscrutable as a smartphone, just as user-hostile, and just as tethered to vendor services. I think my father was speaking from a place of wisdom when he groused about computers in automobiles.

    And no, EVs are actually simpler than ICE engines, their drivetrain being basically a battery, a set of electric motors, and maybe some variable resistors to control speed. An EV that is purely electromechanical and operable via analog controls would be a godsend, but it's not going to happen under current regulatory environments.

  • How can this be stopped, from a technical perspective? Can I wrap the comms in a Faraday cage?

    Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.

  • It's a complete shadow economy, users don't want it and mostly don't know it. But sometimes it surfaces, ie we had a public gathering in my village about the plans to restructure one of our main streets, since people don't feel safe walking an biking there naturally we want it 1 way or 30 km/u. In response rhe person from the municipality whipped up some graphs with speed profiles along the street as it is now. Naturally I ask how they get that data and he says "you can just order it online, I think from Google and Apple originally? Oh, yeah sometimes you can identify things, like a cop once speeded along this road and he could see his datapoint (a far outlier)!" Nobody saw any problem with this. And it's such a small step away from direct actions based on this data (although people would probably take action themselves the moment they understand there are direct downsides for them.)
  • I'd like to point out that the CA assembly has passed AB-1542 and it is likely going to be signed by the governor this week. This would make the sale and sharing of "sensitive" personal information illegal, and one of the sensitive personal categories is geolocation data that can map an individual to within a 1850-ft radius.

    In my understanding, this pretty much makes this type of driver data illegal to sell or share. CalPrivacy's enforcement division has their eye on connected car manufacturers already, so we'll see what they do with that.

    https://leginfo.legislature.ca.gov/faces/billHistoryClient.x...

  • I posted a flavor of this comment on an article a few months ago, but it's relevant here:

    I have a seven year old Volkswagen, not financed. I'm security conscious and made sure to disable all the data collection I could find in the companion app before removing my account, turn off remote access services, dig through the infotainment to turn off what I could, etc.

    Last year I requested a Carfax on it, and one of the fields in the request was current mileage. I entered an estimate like 75000 miles. On form submission, that field failed validation with red subtext along the lines of 'this is less than the last reported mileage of 75345, reported <5 or so days prior>'. Checking my odometer and looking at my past few days' trips, that was indeed accurate.

    The car hadn't been to a shop or out of my possession in weeks, so I can only assume the telemetry was still dialing home and selling to third parties despite my best efforts to disable it.

Explore Birbla archives