Monday edition of *Car privacy is an absolute nightmare*:

Subaru's employee portal holds a year's worth of location data for all internet-connected cars.

We know this because it was vulnerable (now fixed). You could pull a year's worth of driving just with a license plate.

Props to Sam Curry & Shubham Shah for exposing it. Pic is a years' worth of Sam's mom's #Subaru locations.

I seriously doubt any owner has a clear idea that this data is being collected on them.

But the same thing is replicated for almost every car mfr (see the #Mozilla foundation report on car privacy link)

Literally no car owner has asked for their whip to be turned into a surveillance portal.

And yet..

Car companies feel basically no pressure to do right by customers, but experience a lot of incentives to mine their movements for money.

Sidenote: same (now closed) vulnerability also enabled remote unlocks & starts and a bunch of other highly undesirable things.

Reading list:

The Subaru research: https://samcurry.net/hacking-subaru

News report on it: https://www.wired.com/story/subaru-location-tracking-vulnerabilities/

Mozilla Foundation's key investigation into car privacy: https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/

Reply to this note

Please Login to reply.

Discussion

Curry is about to have her mind blown when she finds out about phones. 😂

🤯

I wonder what it would look like to build an open source car...

The closest to that right now are Chinese EV.

Really?? Open source but full of spyware? Or am I being unfair?

unfair.

The most open companies now are Chinese.

Look at deepseek

nostr:npub1qcmnx8qmnz75l6jq7jklk2zgsfc25jtjkk6vu29esjc3rxz8famsh04u92

Another surveillance car manufacturer exposed. I like it. Drag them into the light 👌

meanwhile mozilla foundation still makes a browser that nags you to enable privacy destroying DRM

Government is not the solution it’s the problem. Get rid of huge cost drivers like all these unnecessary “safety” requirements and allow free imports without much paperwork so we can import $12k brand new tuck tucks.

And watch these surveillance nightmares go out of business.

any listings of instructions to disable it on different makes and models? I think I disabled something buried hidden deep in the menu of my dashboard settings

A friend told me he found a sim card in his car and removed it, he also managed to turn off the power to the 4G modem, possibly by removing a fuse IIRC.

Worth investing if that's a valid approach for your make & model

nostr:nprofile1qyv8wumn8ghj7mn0wd68ytnzv43kkmt909jhytn4wvq3yamnwvaz7tmsw4e8qmr9wpskwtn9wvqzpcrkealnenawa0dq7nelp7nkk4e8ty9vpj2rn3k92uned6t5j7zw3qws6a

The engineers and managers responsible for this should spend the rest of their lives in prison, or be executed.

We do not want people willing to do this in society. It's obviously reckless and evil.

Quite likely this would mean the end of Subaru as a functioning company – good chance that knowledge and involvement of this goes all the way to the C-level management. That's fine. Fuck them.

nostr:nevent1qqsgy6dyfpncphwlzc7vthjtvhra6pwajn7nzfsc5pqup8ljuw3jq5spz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygrqnuvxegpr6evvplspj4cywt6e2ewghcwuzca32s06e8vs4f8g4upsgqqqqqqsfweue9

and i need a new (to me) car right now. convincing a woman to avoid modern cars is gonna take years off my life. 🤣

After reading all that, I'd be fine if my man were to suggest a donkey

☠️

Just another reason to love my old shitbox car.

Privacy and anti-telemetry "de-storations" of modern cars will be worth the sats at some point. Who will be first to market?

Meanwhile Tesla: (it can even tell if you are overweight based on your stature, and what you had for Bfast… probably).

Fuck cars