763
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
this post was submitted on 28 Dec 2024
763 points (99.9% liked)
Privacy
32525 readers
110 users here now
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
founded 5 years ago
MODERATORS
A Volkswagen id4 was the best choice I had from work (Belgian companies give company cars for personal use as perks because of tax benefits).
I completely disagreed to all terms involving internet access in the vehicle, but I have no doubt they are tracking me without my consent too...
If they are, make a complaint to your local governing body. See if they'll investigate it. Because it's not okay for them to agree to terms for you or to try to end around the agreement you made.
There's no way to know though...
Sure there is. Most people don’t have the hardware handy to do it, but at the end of the day it’s just a computer sending IPv4 traffic through an LTS cellular modem to an S3 bucket.
And if you know your car’s UDID you can probably look it up in said S3 bucket, since it was open to the public.
You are aware that encryption exists, right?
And the decryption key is stored… where?
Sure, they COULD be using a TPM in the cars and PKI so that having the public key still only lets them encrypt the data and not decrypt it… but in that case, we wouldn’t have this article, because they’d have properly secured the data.
Since they only really value that telemetry in bulk and have to foot the compute bill, I’m pretty confident they don’t actually do that, but instead depend on the S3 bucket and the connections to it being encrypted.
Take your car into a dealer and ask them if the modem is connected. Frame is as you think it's malfunctioning and they'll look to see.
I mean, they could disconnect it for you, but there's still no way to know if it's been transmitting data you don't want it to in the meantime
If they don't know that you want it disconnected or never wanted it connected in the first place they're likely to just tell you if it's active or that it's not at the request of the owner and then ask if you want it connected. If you play dumb and non-accusatory. That's all I'm saying.
It's a shame that they deleted their data after their evaluation.
Should have checksummed the e-mail addresses and put a haveibeenpwned-like website up where car owners can check if they are affected.
Sounds like you could start a lawsuit!