this post was submitted on 11 Mar 2024
757 points (98.8% liked)

Privacy

32177 readers
636 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

Kenn Dahl says he has always been a careful driver. The owner of a software company near Seattle, he drives a leased Chevrolet Bolt. He’s never been responsible for an accident.

So Mr. Dahl, 65, was surprised in 2022 when the cost of his car insurance jumped by 21 percent. Quotes from other insurance companies were also high. One insurance agent told him his LexisNexis report was a factor.

LexisNexis is a New York-based global data broker with a “Risk Solutions” division that caters to the auto insurance industry and has traditionally kept tabs on car accidents and tickets. Upon Mr. Dahl’s request, LexisNexis sent him a 258-page “consumer disclosure report,” which it must provide per the Fair Credit Reporting Act.

What it contained stunned him: more than 130 pages detailing each time he or his wife had driven the Bolt over the previous six months. It included the dates of 640 trips, their start and end times, the distance driven and an accounting of any speeding, hard braking or sharp accelerations. The only thing it didn’t have is where they had driven the car.

On a Thursday morning in June for example, the car had been driven 7.33 miles in 18 minutes; there had been two rapid accelerations and two incidents of hard braking.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 178 points 8 months ago (5 children)

I think this should be legally prohibited. Also is it possible to physically disconnected the network modules so they can't send anything?

[–] [email protected] 71 points 8 months ago (2 children)

If it doesn't already, that's probably going to put you in the high-risk group with other car modders.

[–] [email protected] 15 points 8 months ago

It will be cat and mouse, but I would imagine for the time being, disconnecting the cell antenna on the board would stop it. Who knows what kind of, if any bullshit extra errors and codes that will keep popped up but I'm guessing if it became a popular thing, they would start making cars that will create bullshit errors and codes. I wouldn't do anything permanent until the warranty period is over.

[–] [email protected] 9 points 8 months ago* (last edited 8 months ago)

How dare you demand privacy!

[–] sugar_in_your_tea 24 points 8 months ago (1 children)

Simple answer that should always work: surround the chip/antenna with a faraday cage. The hardest part is finding the chip, not in disabling it.

[–] [email protected] 2 points 8 months ago (1 children)

Why not to just break the antenna (or whatever it has) in half? It's much simpler and shouldn't cause damage to the chip itself

[–] [email protected] 11 points 8 months ago (1 children)

The antennae only likely won’t reduce range enough. Check for an opt-out procedure prior to purchase since that’s easiest, then look for what fuse powers the connection (also easy), but worse case, lay eyes on the module itself and evaluate.

[–] [email protected] 2 points 8 months ago

Yea I guess it's a better choice

[–] [email protected] 14 points 8 months ago (2 children)

I can't wait to see tuturials. I don't know much about cars and would love to see people disable these, or perhaps do something malicious. Not that I have a new enough car yet, but I know one day it's going to be unavoidable.

[–] sugar_in_your_tea 8 points 8 months ago (2 children)

As long as you know where they are, a simple faraday cage should work perfectly. Basically, surround the module with an electrically conductive material to catch radio waves.

[–] [email protected] 6 points 8 months ago

If you're using android auto or something like that this information is going to be transmitted on the same connection used for navigation and internet so you better learn the map of the city again if you want to scape the Spyware.

[–] [email protected] 4 points 8 months ago (1 children)

I was thinking something like free data plan till they disable the transmitter or at least an unplug. Never bought a new car, do you agree to terms and conditions or sign a contract specifically mentioning/consenting to the tracking?

[–] [email protected] 3 points 8 months ago

In Toyota’s there’s a red sticker on the dash talking about it and how to opt-out. (or at least I’ve seen it in a rental and a new car - but it might also be yanked by dealer’s PDI)

[–] andrew_bidlaw 1 points 8 months ago (1 children)

Feeding it ideal driving data is probably what would be the best case scenario.

[–] [email protected] 2 points 8 months ago (1 children)

Until your insurance finds out

[–] andrew_bidlaw 2 points 8 months ago (1 children)

Or when you repair it in service. Yep. Just like with rolling back miles driven before reselling, there would be a a weapon race between tweakers and investigators.

[–] [email protected] 2 points 8 months ago* (last edited 8 months ago)

The issue is you get busted once doing that with your insurance, you’ve completely fucked your coverage. Rolling back (at least a while ago) you could bounce around/getting caught wasn’t likely to follow you around lol

[–] [email protected] 6 points 8 months ago (2 children)

I'm sure it's possible, but I'm sure they've made it as painful as it can be.

[–] [email protected] 23 points 8 months ago (2 children)

Most likely the module, if it is a separate module and not part of the SoC of the infotainment system or whatever, works over CAN bus and the car will throw errors when it doesn't detect its presence, or doesn't detect the SIM card. Might even refuse to start if that module is missing. Might be possible to remove the antenna so the car thinks it's just outside of the service area, but if it's built into the PCB and the PCB is cast into resin/silicone for waterproofing, even this might be extremely difficult. Probably the module is also serialized* so replacing it with a "dummy" module or a module from a junkyard won't spoof the system, either.

*Manufacturers have been serializing even airbags for years, making replacing a faulty one with one from a junkyard impossible.

[–] Patches 4 points 8 months ago (1 children)

You're approaching it in the wrong way. You don't need to stop the Data Collection just the phone home. Find the antenna and Faraday Cage it.

[–] [email protected] 5 points 8 months ago (1 children)

Yeah, some aluminum foil on the inside of those shark fin antennas will probably stop all communication. Just have to use your phone for radio & navigation, which isn’t a big deal on CarPlay or whatever the androids use.

[–] [email protected] 3 points 8 months ago

If you use foil, it'd be best to connect it to ground. The metal shell of a car is usually connected to the ground terminal of the battery.

[–] [email protected] 1 points 8 months ago

Maybe we can trick it forever that it is far away from a cell tower. That way the car has to start without connection.

Who knows, maybe they force you to use their app and after driving and connecting to the internet, that sends data back to the manufacturer.

[–] [email protected] 5 points 8 months ago (2 children)

I’m sure it varies widely. In Toyota’s you can call in to disconnect (I did it while waiting for a tire pressure machine) but to do it physically you pull a single fuse and the trade off is losing the microphone.

Others have pulled the dash and disconnected antennae but it just reduces the range of the box since it’s a cellular radio like a phone.

[–] [email protected] 9 points 8 months ago (1 children)
[–] [email protected] 4 points 8 months ago

in this case that's Toyota specific and it means likely loss of phone calls on the go (but nothing else) even though the data can't leave your vehicle anymore. It all depends on how they wire up the system. Maybe it's easier, maybe it's tied to something random.

[–] [email protected] 3 points 8 months ago (1 children)

Do you have any resources that I can use to learn more about about removing telemetry from a vehicle? Is there a good forum that could help me potentially do this to my car?

[–] [email protected] 5 points 8 months ago* (last edited 8 months ago)

There's no easy one-stop solution since it can vary widely.

I would look at subreddits (yuck, reddit!), or dedicated forums for your model if they exist, you'd probably be surprised what's out there. (Example, there's Piloteers (Honda Pilot), Kia-Forums (Kia), 4Runners and Toyota-4Runner, etc. But information may be scattered.

First objective is figuring out if it's even on your vehicle or applicable. Older 3G radios are done since the networks that connected to them are gone now. My '16 Kia had no cellular radio. Maybe you have an SOS button or they advertise a phone app to control your vehicle remotely?

Edit: And if you can't find specific model/year information for your vehicle, you can look for information for related vehicles and see if it's relevant. Ex: Honda Passport, Pilot, Ridgeline sharing a lot of engineering.

[–] [email protected] 1 points 8 months ago (1 children)

Somebody could go to jail for this. You.

The DMCA makes it a felony to circumvent protections in services. If they wanted to push this and depending on the system disabling or using some hack to bypass could be illegal.

I don't think that anyone would actually bring the case against an individual, but a company selling any sort of device or instructions to make it easier for people could be targeted.

[–] [email protected] 2 points 8 months ago

If they make disabling spyware illegal, I'll do it anyways because human rights. If they decide to charge me for it, I'll just consider it a violation of my freedoms