11 ms·
It's perfectly legal for cars to harvest your texts, call logs
- SenAnder 3y ago> In other words, it's A-OK for your car to "automatically and without authorization, instantaneously intercept, record, download, store, and [be] capable of transmitting" text messages and call logs since the privacy violation is potential, but the injury not necessarily actual. So it's effectively legal to sell backdoored hardware and software to spy on people. I wonder what would happen if I sold backdoored phones to Volkswagen employees, execs, and their children. To judges and politicians and lawyers. A-OK until there was "actual injury", and even then, it is only the injury that would be wrong?
- smoldesu 3y ago> A-OK until there was "actual injury", and even then, it is only the injury that would be wrong? Hah! No, they argue that the injury is right. For example: https://www.cbc.ca/news/politics/sikh-nijjar-india-canada-trudeau-modi-1.6974607 https://www.cbc.ca/news/politics/sikh-nijjar-india-canada-tr... After the diplomat assassination kerfuffle, it appears that Canada invoked a communications backdoor for national security purposes. It's hard to feel bad for the dimwitted killers who plotted the entire thing on a smartphone, but it's also a statement about how widespread and de-facto surveillance is today. Even when backdoors surface, we shrug them off. So... yeah. Until there is actual injury, and the injury isn't someone who people don't like and also don't care about. Then it will be a problem, and God help us all then.
- supportengineer 3y agoLet's keep our older cars on the road as long as possible.
- bobim 3y agoLet’s face it, in an energy starved world the car of the future is an e-bike. Side effect it’s free of connected BS. So far…
- Night_Thastus 3y agoWe will not be "energy starved" anytime soon, short of an actual apocalypse happening. What we use for energy may change, but energy won't.
- bobim 3y agoWe live on free energy, free as in "dig a hole and voilà": energy. No nuclear, no solar, no wind can replace the sheer amount of energy we extract out of oil and coal. I’m afraid privacy in cars is going to be the least of humanity’s problems unless we make fusion working.
- JumpCrisscross 3y ago> No nuclear, no solar, no wind can replace the sheer amount of energy we extract out of oil and coal What are you basing this on? You realise we have localised grids that go 100% renewable regularly, and could easily keep doing that with electrified transport?
- bobim 3y agoWell, global surveys show how oil, gas and coal are going. https://ourworldindata.org/energy-production-consumption https://ourworldindata.org/energy-production-consumption
- JumpCrisscross 3y agoWell sure, we’re consuming more fossil fuels because they’re cheaper. Nothing I’ve seen suggests we can switch primary production to clean sources. It would be more expensive. But that’s far from a hard limit. I’m genuinely curious if someone is credibly speculating we are unable, versus economically unwilling, to replace fossil fuels with clean options.
- JumpCrisscross 3y agoThis is a decision made regarding Washington state law’s “statutory injury requirement” [1]. It says “a plaintiff must allege an injury to ‘his or her business, his or her person, or his or her reputation,’” with “a bare violation” of the privacy law being “insufficient to satisfy the statutory injury requirement.” It is particular to Washington state, not all Americans. And it may not apply to a prosecutor versus private plaintiff. [1] https://www.documentcloud.org/documents/24133084-22-35448 https://www.documentcloud.org/documents/24133084-22-35448
- drewcoo 3y agoSo post facto punishment and not consumer protection. WA has a referendum system, though, so if people in WA care about this, you can get something on a ballot and vote it into law.
- RHSeeger 3y agoThat sounds remarkably like saying "it's ok to drive drunk, as long as you don't hurt anyone"; which, clearly, is ridiculous. If you're breaking the law, there should be consequences even if you didn't _happen_ to hurt someone this time.
- lazide 3y agoMost civil law requires actual damages. It’s the same situation. If you haven’t actually been hurt yet, suing doesn’t result in anything.
- JumpCrisscross 3y agoTo underline why, consider the consequences of letting anyone sue anyone for potential violations. Every minor perceived violation would result in a cascade of lawsuits. You could bankrupt a competitor by baselessly speculating on their wrongdoing. Generalised lawbreaking is a public concern. It’s prosecutors’ and regulators’ jobs to protect consumers ex ante.
- 3y ago
- nonameiguess 3y agoI'm not an attorney, but I think a lot of the Internet misunderstands the law. It is legal to do this, apparently, but that doesn't mean the court is saying it's okay or they should do this, and it certainly doesn't mean anyone would be okay with you doing it. But if you managed to, then yes, it would apparently be legal. The court can only rule on what the law actually says and it says you only have grounds to sue once you've suffered an actual injury, not because the party you're trying to sue has done someone that might harm you in the future. This is frankly a shortcoming of trying to use civil law for something like this. As far as I'm aware, this is nearly always the case that you have no grounds to sue unless you've suffered quantifiable monetary damage from someone's actions. If we just want this kind of thing to be generally illegal, then it needs to be made illegal according to criminal law or it needs to violate some law overseen by a government regulatory body with the power to levy its own fines.
- QwertyPi 3y ago[dead]
- SenAnder 3y ago> It is legal to do this, apparently I am extremely skeptical of this, no matter what this judge says. This seems to be a clear case of illegal wiretapping [1]. Having an illegal act perpetrated upon one, whether it is wiretapping or assault, seems a very clear "injury". It is baffling that there would have to be some kind of financial price attached to be recognized as harm by a court. A disgusting reduction of justice to mere finance, something I would expect from the cartoonishly greedy Ferengi of Star Trek, than a real court. [1] https://en.wikipedia.org/wiki/Wiretapping#United_States https://en.wikipedia.org/wiki/Wiretapping#United_States
- mistrial9 3y agoagree and - the crux here appears to be .. when you are in a moving vehicle on public roads then you have no expectation of privacy -> slippery slope -> license plate readers run by govt 24x7; license plate readers run by parking lots or retail shopping malls; interception of cell traffic via stinger units in strategic locations; interception of the driver's cell phone communications.. etc. Gov Gavin Newsom preparing to run for President, is OK'ing these uses quickly and without public discussion
- QwertyPi 3y ago[dead]
- olliej 3y agoNo, it's saying that because none of the information is transmitted there isn't a privacy violation - the law requires that a privacy violation actually occur, not that it "could". e.g. that fact that there's a local call/message log on the car, and the car also has a mechanism for transmitting some data, does not mean that there's a privacy violation given that the car does not transmit the call/message log. That's the only reason this lawsuit got thrown out. It would be like saying "my phone receives messages, and stores those, and could transmit them to apple/google, therefore I should be able to sue them for the privacy violation they could do".
- SenAnder 3y agoThank you for the correction. This makes the judgement much more reasonable.
- adrianmonk 3y ago> the car also has a mechanism for transmitting some data As far as I can tell, the car itself doesn't have a mechanism for transmitting data. It just stores the data. Transmitting only happens if/when someone gets some Berla "vehicle forensics" hardware and physically connects it to the car. The Berla equipment would do the transmitting. From the complaint linked to by The Register[1]: > 26. Third party Berla Corporation (“Berla”), based in Annapolis, Maryland, manufactures equipment (hardware and software) capable of extracting stored text messages from infotainment systems in Honda vehicles. > 27. Berla also manufactures equipment capable of extracting stored call logs from infotainment systems in Honda vehicles. > 28. Honda infotainment systems thereby transmit stored text messages and call logs to Berla. And from Berla's web site[2]: > An acquisition may require systems to be removed from a vehicle and disassembled or be performed in place in a vehicle. In either case, acquisition hardware must be attached to the vehicle or system to acquire data. --- [1] https://regmedia.co.uk/2023/11/09/honda-infotainment-class-action-suit.pdf https://regmedia.co.uk/2023/11/09/honda-infotainment-class-a... [2] https://berla.co/ecosystem/ https://berla.co/ecosystem/
- olliej 3y agoI thought the original lawsuit (in addition to the Berla/diagnostics tools extraction method) was also trying to claim that the system supported transmission of a data (which seems a thing in many new cars? crashes and what not?) even though it was in no one transmitting any of this information.
- hoosieree 3y agoJeep owners will be upset if they can't take the backdoors off.
- keep_reading 3y agoI have never seen a car do this without asking you if you want to sync contacts, calendar, and messages upon connecting to Bluetooth. iPhones also let you control this per Bluetooth connection. Where is this being done without authorization?
- lotsofpulp 3y agoThis is why I would not consider connecting my phone to anything other than CarPlay/Android Auto.
- arjvik 3y agoBoth of which require Bluetooth pairing (or at least auto-pair without asking you if I recall correctly) which allows the head unit to siphon data!
- galleywest200 3y agoApple CarPlay works over my USB-C cable, at least in my 2018 Subaru Crosstrek on an iPhone 15. No Bluetooth required I am fairly certain. I also have to unlock the device every so often with my Face ID -- unsure what triggers this as it is not 100% of the time.
- lotsofpulp 3y agoI always connect to CarPlay with a wire, and have never connected with bluetoooth. It has not auto paired Bluetooth either with iPhones. I have not used Android Auto, but if it does auto pair Bluetooth, that would be a shame. I thought the whole point was that the car just provides a screen your phone can extend a display to, and no data ever leaves.
- freedomben 3y ago
- luhn 3y agoAnother reason to prefer Apple CarPlay and Android Auto.
- thorncorona 3y agousing AA/CP won’t prevent your car from being exploited.
- QwertyPi 3y ago[dead]
- luhn 3y agoIt means my infotainment system is a dumb screen, so no opportunity for irresponsible development practices to leave an unsecured text message database lying around. I'm not going to go as far as to say it can't be exploited, but that is a significantly smaller risk surface.
- greentea23 3y agoExcept that to run those in the first place you need to be running non-private spyware on your phone (iOS or vendor issued android ROM), so you give up all ability to maintain privacy in or out of the car.
- hn92726819 3y agoNo, it isn't all-or-nothing. iOS does not leak messages to cars. Just by using iOS doesnt mean Toyota, Subaru, Chrysler, etc suddenly have access to your messages. Using iOS with carplay only is strictly better than using iOS and sharing your messages with the car.
- bri3d 3y agoI dug into the technical details here over the last few days and as usual it's not quite as sinister as the hand wringing: * Automotive head units are just embedded computers. Most run Linux, QNX, or Windows CE, with some proprietary UI system on top. * These machines usually store data in an onboard database in flash (sometimes just SQLite). * Sometimes, phone data is captured using standard Bluetooth mechanisms (Message Access Protocol MAP and Phone Book Access Protocol PBAP) which require authorization on the phone side. Some vendors implement an additional "are you sure you want to share your information" check on the head unit side, and others don't. * This data is cached on the head unit so that finding a contact to call or reading a text message doesn't require 10 minutes worth of Bluetooth nonsense. * Some vendors inadequately purge this cached data when a Bluetooth pairing is removed from the head unit. * Berla sell data extraction exploits to law enforcement, just like other forensics vendors do for mobile phones. Sometimes this can extract latent data and sometimes active data. My advice: * Never authorize a head unit to download your contacts or SMS. * If you use a rental car, Factory Reset the head unit when you leave. That's decent protection for most people. I didn't find any evidence pointing to a central server upload, a conspiracy to build an LE database, etc. It's just typical crappy hardware manufacturer-made software leaving data around that shouldn't be left around, creating an opening for forensic vendor exploits to slurp the data.
- deleted 3y ago[deleted]
- Caboose8685 3y agoI think an argument should be made against normalizing this, which could then lead to OEMs building in internet assisted data export functionality in new cars and people won't know until a lawsuit (likely) starts years after the fact and the harm is done.
- zlg_codes 3y agoThis is why I've taken a more and more grim look at technology and software, in particular. Stallman was right, about nearly everything concerning power, companies and governments using it, and the role the citizen is viewed to have in such a limited capitalist view. Without government mandates to open the source of every chip and firmware, none of the modern hardware we use is trustable.
- almatabata 3y ago> store each intercepted, recorded, and downloaded copy of text messages in non-temporary computer memory in such a manner that the vehicle owner cannot access it or delete it, You might think why care if its your own car. But if you rent cars this can become an issue where if poorly implemented the next driver could access the information. It is such an easy feature to implement and suppliers in Europe already do this due to GDPR. I remember working for an automotive supplier where we implemented this feature. The whole phonebook was actually downloaded onto the unit in an encrypted Database. The system would decrypt it on the fly as needed. When GDPR came around we had to implement a wipe feature that would allow the user to delete their profile which included that database. I feel like GDPR for all its flaws had a positive impact in that it forced the supplier to actually care about this use case.
- InCityDreams 3y agoWhat are the flaws in GDPR?
- graphe 3y agoMy Toyota asks for permission and if I grant it then it'll "harvest" my texts and calls. How horrible and unexpected. The title and the conclusion are biased and of poor quality. It should be "car manufacturers didn't get fined for the way their old head units worked".
- hammock 3y agoI was in a rental car this week and pure accidentally (1 in 1000) hit “yes sync contacts.” Didn’t know how to reverse/revoke that decision. Wish I did/could
- graphe 3y agoIt probably helps that this isn't exploited often. You're fine. To attack someone requires so much effort the clickbait article didn't deserve the views.
- InCityDreams 3y agoHow often isn't it exploited often? Additionally: if you were a person travelling for an abortion, not in your car because your state is all fucked up(!), can the cops request copies of texts you've received/ sent?
- salawat 3y agoYes, if they have probable cause sufficient to attain a warrant. Or they ask the rental company nice enough for a few monutes they may not even need that, as a prosecutor would argue that you waived 4th Amendment protections by not taking sufficient measures to "ensure your privacy". Third Party Doctrine.
- client4 3y agoI've been trying to figure out how to disable my trucks cellular antenna without disabling any other systems. It's proven more difficult than I thought.
- Caboose8685 3y agoCould potentially Faraday cage it if you can find the exact spot it's at.
- zeteo 3y agoCareful with that or it might just eat up your battery trying to contact cellular towers at maximum power with a short retry interval.
- bri3d 3y agoThe module should go to sleep, and the battery management should also load-shed it if it detects the battery draining. I suspect this is probably not implemented correctly on some cars (because what is), but it's definitely something that's tested for regularly (since cars can be expected to be taken camping, off the grid, or even just purchased by owners who live outside of cellular coverage).
- OneLeggedCat 3y ago> The module should go to sleep lol tell Subaru owners about this. There are tons of them complaining of batteries going dead the last few years, just from sitting a few days in the driveway, while the always-on cellular is at edge of range, hunting. Subaru's solution to this has been to in some cases pay for a bigger battery for those customers.
- bonton89 3y agoMaybe an other way around solution? Is is possible to build some kind of dummy cell tower that supersedes real ones?
- acd 3y agoNot in eu
- andix 3y agoProbably not even if you voluntarily "agree" to it via some button and a very long incomprehensible legal text. And especially not if you're forced to agree to use a specific feature. But nobody really knows if car vendors really follow the laws. Facebook/Instagram seem to collect a lot of data anyways, and probably will just pay a huge fine in many years, when they get sentenced for it.
- tzs 3y agoWould GDPR actually do anything in this situation? From what I understand the data the car acquires is not being sent anywhere. It just gets uploaded to the car and is used to speed up operations that would be slow if the car had to talk to the phone over Bluetooth when it needed the data. The car vendor is not processing your data. They are selling you a device that processes your data. I'd have guessed then that you are the controller for this data processing and so you are the one responsible for GDPR compliance. In the case of a rental car, I'd have guessed that the rental company is the controller, and their GDPR obligation would be to tell you that the car caches data if you pair your phone with it and for them to erase that data when you return the car.
- forrestthewoods 3y agoI can believe iOS doesn’t offer protection against this garbage. There’s no way to connect a phone to something and on the device side say “this is an untrusted connection; don’t give it shit”. It’s especially frustrating with rental cars. But I don’t even trust my own personal car!
- bri3d 3y agoFor what it's worth, in the iOS Bluetooth settings, "Show Notifications" is code for Message Access Protocol and "Sync Contacts" is code for Phone Book Access Protocol. It would be nice if they'd add an extra "Pair but Don't Trust" button, though.
- DANmode 3y agoThe feature you're looking for doesn't really sound like the nontechnical "it just works" experience they're advertising. Check out GrapheneOS if you have yet to!
- olliej 3y agoIf you read the original lawsuit, the issue is that the car's infotainment system is set to forward/display messages and calls from your phone, and that that information is stored or logged persistently, and that can't be deleted/cleared by the user. The claimed invasion of privacy is that a person with the diagnostic tools and physical access to your car can extract those logs. Presenting this as "car manufacturers can steal your text and call logs" is disingenuous. Don't get me wrong, it's clearly not a great thing for the car to be doing (especially in the context of rental cars for instance) but it isn't the catastrophe people are claiming.
- karaterobot 3y ago> "To succeed at the pleading stage of a WPA claim, a plaintiff must allege an injury to 'his or her business, his or her person, or his or her reputation,'" the judges ruled. "Contrary to Plaintiffs' argument, a bare violation of the WPA is insufficient to satisfy the statutory injury requirement." I think the title is misleading. Unless I'm missing something, it sounds like the decision wasn't that it's legal to harvest text and call logs, it was that these cases did not demonstrate an injury was caused as a result of doing so. Presumably if the plaintiffs proved some injury other than not wanting it to happen, things could have been different.
- andersrs 3y agoReading these stories makes me love my shitty old 16 year old Civic. It's modern enough to have cruise control, AC and a fairly decent engine. But not so modern that reliability is compromised in the name of fuel economy and it's also not a "rude-ass car" with dumb features nobody asked for. I could afford a better car of course but I don't drive much and I'm not inspired by these rude-ass features.
- kleene_op 3y ago> "To succeed at the pleading stage of a WPA claim, a plaintiff must allege an injury to 'his or her business, his or her person, or his or her reputation,'" the judges ruled. So.. It's okay if I record private conversation from high ranking states officials as long as I don't harm their reputation with it? It's okay if I stole state intelligence as long as I don't harm my country with it?
- tzs 3y agoNo and no. Those cases would be brought by a prosecutor under criminal law where mere violation of the law counts as harm to the state. This was a civil case. Civil cases tend to have more concrete harm requirements.
- zzzcsgo 3y agoThey do ask first as far as I know
- john61 3y agoOne more reason to use the bicycle.
- robbywashere_ 3y agoIt’s perfectly legal for your car to taunt and harass you. What are you going to do ? sue your car!?