I'd like to point out that the CA assembly has passed AB-1542 and it is likely going to be signed by the governor this week. This would make the sale and sharing of "sensitive" personal information illegal, and one of the sensitive personal categories is geolocation data that can map an individual to within a 1850-ft radius.
In my understanding, this pretty much makes this type of driver data illegal to sell or share. CalPrivacy's enforcement division has their eye on connected car manufacturers already, so we'll see what they do with that.
https://leginfo.legislature.ca.gov/faces/billHistoryClient.x...
Two different things are getting called "car data" here.
Facts about the car: VIN, spec, recall status, odometer. Attested by someone other than the owner. Outlives every owner and the owner is the last to have it, if at all.
Facts about the driver: speed, location, timestamp. Thats what GM sold, the fix is to not collect it but OEMs seem to take 'anonymization' approach.
The DRIVER act treats both as the same which is why it fails to fix anything. The second needs a ban. The first needs the opposite - especially as we take the driver out of the vehicle - an authoritative record of the vehicle. How do we expect AVs to have adoption when the only safety certification is the company's press release?
How can this be stopped, from a technical perspective? Can I wrap the comms in a Faraday cage?
Obviously it would be better to have this action be illegal. But with legal privacy protections eroding in the US and other countries, it seems prudent to have a better understanding of the systems involved in the immoral surveillance.
That‘ll happen when you don‘t have meaningful data protection laws.
In my GM car I have the wonderful opportunity to pull the OnStar fuse and disable all cellular connectivity. However, I am concerned the telematics information are stored in long term storage and if I have to reconnect the fuse, all my driving will be batch uploaded. I hope not!! And the GPS still works. Maybe I can find some dummy loads as well or the antennae.
It's still better than other modern cars though? I think.
How to stop this on Subaru ?
Apparently Rivians can be prevented from doing this:
Can I disable all data collection from my vehicle?
Terms of use to even read the article:
> third-party partners process information about you and how you use our services, including clicks and screen recordings, using first and third-party cookies, pixels, and similar technologies
If you'd like to buy this data, go talk to the guys over at Inrx. They will happily give you a product demo showing point to point trips recorded by connected onstar or whatever corresponding manf connected car service.
I notice that not one comment here, nor the article, notes that this doesn't happen with a Tesla.
Like I've said here before: we need to push for legislation that bans the sale of consumer data collected by websites and manufacturers to third-parties.
We need a solution, not a Band-Aid like the "Freedom Car Act." I believe that legislators are deliberately coming up with legislation that mildly hinders, but in no way resolves the issue in order to keep their sugar-daddies freewheeling.
Just don’t get a car with connected internet, or smart X in any way, which is most modern cars unfortunately, and if you do, disable the telemetry. I have a clean, cool, low mileage ~15yo car, has no screen or apps, no internet, no back camera or even digital dashboard. I put a screen that has offline CoMaps app, if I ever needed it, and its OBD connected to a local app that does usual diagnostics. Sure, there’s logging I see and it happens, but it’s all local and never shared let alone connect things gas or odometer or driving habits.
And the DMV (Department of Motor vehicle Services) has also sold registration data. In California, and Texas, they have been fined for this - I'm unsure they aren't completely barred from using a loophole to still do that.
This is why I'm a vocal advocate for having an LLC own any vehicles you might drive. It protects you from the license-plate reading lookup as well from Flock et all. Though I don't know it guarantees you can't be looked up by insurance it's resistance by one more bit of friction. The vehicle I drive now is an old 2012 Lexus owned by Montana LLC and it also has no smart technology and very little insurance costs.
How is this not stealing?
I'm going to pirate shit until this is fixed.
I drive a restored 2002 Citroen C5.
Another reason to use a car from 90's or 2000's.. Also they wont burn oil like a modern car + more durable and repairable metal parts.
https://youtu.be/Ft12aZffCEg?si=qP1J5k6RXAxmZChf
[dead]
[dead]
[dead]
Contrary to the HN bias, but a way to avoid this if you want to get a new car full of tech gadgets is to get one that runs on Android Automotive. The privacy policy is a normal tech company privacy policy. Other cars come with privacy notices that just say they can give your data to anybody.
BREAKING: The water found in the ocean
I posted a flavor of this comment on an article a few months ago, but it's relevant here:
I have a seven year old Volkswagen, not financed. I'm security conscious and made sure to disable all the data collection I could find in the companion app before removing my account, turn off remote access services, dig through the infotainment to turn off what I could, etc.
Last year I requested a Carfax on it, and one of the fields in the request was current mileage. I entered an estimate like 75000 miles. On form submission, that field failed validation with red subtext along the lines of 'this is less than the last reported mileage of 75345, reported <5 or so days prior>'. Checking my odometer and looking at my past few days' trips, that was indeed accurate.
The car hadn't been to a shop or out of my possession in weeks, so I can only assume the telemetry was still dialing home and selling to third parties despite my best efforts to disable it.