Your Car Is Tracking You Just as Much as Your Smartphone Isand Your Data Is at Risk – The Drive
Most modern cars know their locations better than their owners do. As suites of connected-car apps become mainstream for both emergency functionality (such as General Motors' OnStar) or for owner conveniences such as remote start or parking guidance, new vehicles are overflowing with data needed to support always-on connectivity.
While most owner concerns (and popular attention) have been fixed on unallowed hacks into such systems by bad actors, there are still massive troves of automatically generated data open to anyone with the knowledge to access it, and even the "proper" use of this data can be a risk to consumers who seek privacy. Your home, your work, every trip you've taken no matter how private: it all can be seen by companies, countries, and individuals you've never given permission to follow your travels, and completely legally.
Struggling to think of a need for privacy besides what's already been extensively reported and debated? One recent example: As certain states attempt to make previously legal medical care (such as abortion, contraception, and basic trans-related medication and care) illegal to access, the modern connected car and its troves of data have the potential to become a governments unintentional best friend and a driver's worst enemy as prosecution intensifies. Even if you're not immediately affected by your car tracking your habits, state law has been changing increasingly rapidlyfamilies in Texas found their access to trans care restricted within a week of the governor's directive to eliminate itand you may find yourself criminalized a week from now unexpectedly over some other arbitrary decision.
The good news is there's already proposed legislation to combat the current freewheeling fate of our privacy. The bad news is we don't know how long that legislation will take to pass, if it does at all.
To understand how driving a car could incriminate someone, its worth examining just what kind of data the car itself collects and transmits.
In 2021, 90 percent of cars sold in the United Statesand around 130 million total cars sold worldwidecontained some form of embedded connectivity. This built-in connectivity can take many forms (built-in Wi-Fi connectivity, infotainment systems that connect to cellular networks, and even Bluetooth systems) but all of them share a few things in common: They collect (and transmit) massive amounts of data, they are usually truly embedded in the physical car (and comprise some core functionality of it), and owners rarely have control of where it ends up. This trove of data is known as telematics, and its a multi-billion-dollar industry with wide-reaching implications for consumers.
Most consumers never have an inkling of just how powerfuland plentifulthis telemetry data is. The raw amount of information itself is overwhelming to consider; a case study by the Washington Post on a 2018 Chevrolet Volt showed that the car generated up to 25 gigabytes per hour of data across every category imaginable; for context, browsing Instagram for an hour uses a mere 720 megabytes. This deluge of data the Volt created included location specifics, even when the GPS was not being actively used by the driver. In the case of the Chevy that was studied, researchers even bought a used Volt navigation system on eBay and were able to construct the previous owners daily life and routine down to their home, workplace, and oft-frequented gas station, simply by poring through stored location data that the infotainment system automatically logged.
An earlier study from 2017, undertaken by a student at the University of Ontario Institute of Technology, pulled similar location data from a variety of late-model vehicles infotainment systems that logged exact coordinates even when the GPS was not engaged. In certain versions of Fords Sync infotainment system installed in mid-2010s-era Fords, the researcher found that vehicle and system generated events also generated GPS coordinates which can further be used to prove the vehicle users exact location at specific times (for e.g. when the vehicle shifts gear and vehicle doors are opened/closed, GPS coordinates are generated).
An example demonstration log in the study, pulled from a 2013 Ford F-150, shows GPS coordinates being stored when opening or closing a car door. With this frequency and precision, its easy to retrace exactly where that truck has been.
But it's not just the data inside your infotainment system that's a concern. All of the data discussed abovethe GPS coordinates of every gear change, the location of every ECU bootis not just stored onboard the car itself, but is frequently sent back to an automaker for storage and analysis.
This massive dataset has extremely advantageous, non-invasive uses for a host of businesses, including the automakers and drivers themselves. Telematics can help professional drivers spot and avoid traffic by analyzing previous patterns; urban planners can use similar data to identify roads prone to jams and create more efficient streets; insurance companies can use it to spot fraud or dangerous driving habits; and manufacturers or fleet owners can identify potential malfunctions to repair (if engines report misfires or check engine lights after driving at high altitudes, for example).
All of this is possible thanks to OEMs sharing these troves of telematics data with other companies, which then provide their own unique analyses. One example of a company like this is Otonomowhich, according to internal presentations shown to investors, is partnered with nearly a dozen automakers including Kia, BMW, Ford, Toyota, Stellantis, GM, and even heavy equipment manufacturer Bobcat. Otonomo offers an array of services all underpinned by its large collection of automobile data to a variety of consumers, which include tech behemoths Amazon and Microsoft, smart-city planners such as BeMobile, and parts manufacturers such as Hella and Continental.
Yet, with this billion-dollar business comes massive privacy implications. Even in massive data sets comprised of millions of different peoples' locations, all of whom are theoretically anonymous, identifying any one person out of those millions is a simple job without a strict concern for data privacy. In a 2019 feature story, The New York Times studied the difficulty of anonymizing location data as it relates to phones, and discovered individuals identities with ease in supposedly anonymous data sets containing timestamped locations of cell phones. Connected cars face the same issues that anonymization cell phones suffer from because the underlying premise of location tracking is that it is deeply difficult to anonymize, especially when the device in question travels with a person to their work and home.
How hard could it really be to anonymize this data? Well, a 2013 study published in Nature showed that four spatio-temporal [GPS locations with a timestamp] points are enough to uniquely identify 95 percent of the individuals," even while using a dataset of 1.5 million people. That is, even with millions of generic data points without a name attached to them, having four from a single person is enough to identify one of them. The only way the researchers found to add back any privacy to users that were anonymously tracked was to coarsen both location and timestamp data: making it less accurate by reducing the accuracy of location logging and giving wider time ranges for each timestamp. This, of course, reduces the usefulness of that data.
But companies have very little incentive to reduce the usefulness of location data because often its specificity is what makes it so valuable. McKinsey, a business strategy group, estimates the telematics data market will be worth a staggering $750 billion dollars by the time the decade is out. The best way to get a share of that lucrative market is with accurate data so that advertisers, police states, and corporations can get the most use from it.
Thats not to say some companies dont try to protect consumer privacy; Otonomo specifically employs what it calls data blurring," which ideally hides the privacy of drivers in compliance with European GDPR laws while still offering useful data for its customers. Otonomo acknowledged a request for comment from The Drive regarding how its data blurring works but was unable to provide technical details on what exact steps it takes for anonymity.
But there are no laws in the U.S. requiring that manufacturers anonymize any of the telematics they collect, and some third-party companies sell services explicitly offering to track specific, targeted vehicles. Not only can this be used by less-than-scrupulous buyers, but previous court precedent in the U.S. allows for federal agencies to buy location datasets to sift through personally identifiable data that would otherwise require a warrant.
With this in mind, The Drive reached out to four auto manufacturersFord, Honda, Kia, and BMWthat all offer modern connected-car functionality in many of their models, and whose privacy policies for use of their vehicles leave the possibility of third-party sale of telematics open. I asked, specifically, what their policies were on third-party data sale and sharing and, if they do share telematics with outside companies, how easily consumers can opt out of it at will.
Ford declined to comment. BMW acknowledged the request but did not provide any details on its data practices in time for publication.Honda referred to its privacy policy and owners manual disclosures for information regarding its telematics policies. In the policy, Honda noted that it can collect trip log information, including trip start time and end time, trip start and end location and that this information can be shared with third parties. The document also noted that this data is generated and transmitted automatically regardless of whether drivers use connected technologies such as HondaLink, although, in the past, the company has declined to track unsubscribed cars without a warrant.
Kia had a stronger approach to data protection. In a statement to The Drive, the company stated that Kia America collects geolocation data only on consumer-owned vehicles in the United States that are equipped with connected vehicle technology and have been enrolled by the owner in our Kia Connect service. Furthermore, the automaker noted,[Kia America] does not aggregate vehicle geolocation data, nor do we sell such data to third parties. While affiliated global Kia companies may have a working relationship with Otonomo, [Kia America] does not share vehicle data with that company. The company said that the only time that geolocation data is shared with law enforcement is when presented with a valid court order or warrant, or if an owner consents to share it during an active vehicle-theft investigation.
Separately, a Genesis representative assured us in another story that the biometric data the GV70 can collect for the SUV's fingerprint unlock and startup capabilities stays with the car itself and does not get shared with the company.
With this level of data on hand, few safeguards legislatively in place, and a very scattered set of privacy policies that can vary widely by manufacturer, the potential for a car to betray a persons privacy in a newly fraught legal landscape is clear. For example, there are already states that have not just banned care but also made it legally questionable to travel to another state for it, with Texass anti-abortion and anti-trans-care laws being the most obvious.
The states anti-abortion law weaponizes civil courts against anyone suspected of assisting in abortion (including, for example, driving someone out of state to a clinic where abortions are legal to obtain). Its anti-trans-care laws are somewhat differently formatted, but they allow state Child Protective Services to investigate any parents suspected of confirming their childs gender identity, which includes driving out-of-state to clinics where puberty blockers or trans-specific therapy are offered to minors. Idaho recently attempted to pass a similar bill punishing parents with up to life in prison for traveling out-of-state to get their children trans-related care; the bill died in the state Senate, but lawmakers indicated that they would be willing to pass a more narrowly targeted bill in the future.
With the troves of data offered by patients cars, however, theres a very clear risk, as what was once considered basic medical care becomes criminalized. Even assuming every other step for data privacy is takensuch as not traveling with a cell phone and avoiding digital communication while seeking carehaving a car automatically log that its doors were opened at an out-of-state Planned Parenthood could be enough to potentially be enough to warrant investigation, civil lawsuits, or even criminal proceedings. To make matters worse, data like this is already out there in the open on the public market, specifically targeting people who've been to clinics such as Planned Parenthood. Poland, for example, is strictly anti-abortion and recently created a registry to track every person who becomes pregnant and seeks any care. The location data for every pregnancy clinic a patient has visited would be a valuable addition to those lists.
Even more shockingly, accessing this data does not require a warrant. The techniques discussed above have already been put into practice by U.S. Customs and Border Patrol, which has been deemed exempt from needing a warrant to search digital devices in general at the border. Thanks to a loophole in the Fourth Amendment (the amendment that prohibits unreasonable search and seizures), state police can also download telematics data during routine police stops if they feel the need to, which means that a traffic stop could quickly become an examination of every place a driver has been for weeks.
However, this still relies on direct access to the car in question, which means that for such searches of telematics to be effective, state action would need to be targeted at specific, already-on-the-radar individuals such as activists and doctors (or used against already marginalized groups who are more frequently pulled over). But what if a police agency could just browse through everywhere cars have been, looking for interesting patterns, and tying back specific locations to individuals?
While Kias approach is much more likely to protect drivers privacy, the patchwork manufacturer-driven state of vehicle security means that while a Sorento may be able to glide under the radar, other vehicles may not. The easiest solution to unify the current state of driver privacy would likely come from the top downthat is, closing the Fourth Amendments loophole allowing vehicle telematics to be accessed without a warrant. While there is proposed bipartisan legislation that would do just that and prohibit warrantless vehicle surveillance by U.S. authorities, it hasnt been voted on since its introduction late last year.
In the meantime, I spoke with Mary Stone Ross, the chief privacy officer at the privacy-focused technology firm OSOM and a former employee of the CIA, for thoughts on how consumers could protect themselves. Unfortunately, despite her familiarity with the issue, there wasn't much comfort to be offered.
"I saw how powerful information was from a government perspective [at the CIA], where there actually was quite a bit of oversight and regulation. And then, what these companies had was so much more intrusive and they could do whatever they want," she explained. While she noted that she worked on California's data privacy law, the CCPA, in the pastwhich is currently the strongest privacy law in the nationshe also pointed out that most companies can still do what they want with personal data as long as any use of it has been disclosed in the fine print of a privacy policy.
Even then, it's still better than living elsewhere, as "all of the laws that you've seen passed by [other] states are so much weaker," Ross went on. "And then, there's been really no movement on the federal level... The tech companies are spending so much money, and any sort of privacy regulation they see as an existential threat to their business model, whether it is or isn't."
When I asked if there's anything consumers can do to protect themselves in the absence of strong federal law, she said, "I don't even know what my advice is [to consumers], because even with the rental cars, without safeguards on consumer data at the manufacturer level, its a free-for-all." Yet, in a world where privacy is likely to rapidly go from an afterthought to a central legal battle, her hope is still "that it actually puts pressure on Congress to pass federal privacy laws."
Until legislation is passed, then, consumers should be aware that their car could be an incredible weak point for their personal safety and privacy. If you can, perhaps stick with the ancient beaters, whose most advanced technology is fuel injection.
Got a tip? Send it to tips@thedrive.com
Originally posted here:
Your Car Is Tracking You Just as Much as Your Smartphone Isand Your Data Is at Risk - The Drive
- Permissibility of Cross-Border Share Swap: Understanding the Fourth Amendment of the NDI Rules and its Implications - SCC Online - November 23rd, 2024 [November 23rd, 2024]
- Does the Fourth Amendment protect smartphone users? - Lewiston Morning Tribune - October 12th, 2024 [October 12th, 2024]
- The Fourth Amendment shouldn't stop once you get up to drone level: Albert Fox Cahn - Fox Business - September 21st, 2024 [September 21st, 2024]
- The Reasonableness of Retaining Personal Property Post-Seizure and the Ascendancy of Text, History, and Tradition in Fourth Amendment Jurisprudence -... - September 21st, 2024 [September 21st, 2024]
- Gujarat's Proposes Fourth Amendment To Net Metering Regulations For Rooftop Solar Systems Up To 100 KW - SolarQuarter - July 26th, 2024 [July 26th, 2024]
- Nearly 96% of Private Property Is Open to Warrantless Searches, New Study Estimates - Reason - March 15th, 2024 [March 15th, 2024]
- Heres what to do (and not do) if you get pulled over in California. What are my rights? - Yahoo Movies Canada - December 12th, 2023 [December 12th, 2023]
- FBI Seized $86 Million From People Not Suspected Crimes. A Federal Court Will Decide if That's Legal. - Reason - December 12th, 2023 [December 12th, 2023]
- Digital justice: Supreme Court increasingly confronts law and the internet - Washington Times - December 12th, 2023 [December 12th, 2023]
- MCHS goes on lockout after weapons found on campus - Mineral County Independent-News - November 19th, 2023 [November 19th, 2023]
- Cops Stormed Into a Seattle Woman's Home. It Was the Wrong ... - Reason - November 19th, 2023 [November 19th, 2023]
- Ron Wyden, U.S. Senator from Oregon The Presidential Prayer ... - The Presidential Prayer Team - November 19th, 2023 [November 19th, 2023]
- Bill Maher Slams Critics of the West Amid Israel Conflict: Marginalized People Live Better Today Because of Western Ideals (Video) - Yahoo... - November 5th, 2023 [November 5th, 2023]
- Surveillance authority change could harm ability to stop attacks, FBI ... - Roll Call - November 5th, 2023 [November 5th, 2023]
- New York's progressive chief judge joins with conservatives to ... - City & State - November 5th, 2023 [November 5th, 2023]
- Should domestic abusers have gun rights? | On Point - WBUR News - November 5th, 2023 [November 5th, 2023]
- The Biden administrations latest executive order calls for a ... - R Street - November 5th, 2023 [November 5th, 2023]
- DPS Presents Purple Hearts, Medal of Valor and Other Prestigious ... - the Texas Department of Public Safety - November 5th, 2023 [November 5th, 2023]
- Senators Katie Britt and John Kennedy Call for Investigation into ... - Calhoun County Journal - October 15th, 2023 [October 15th, 2023]
- Trump and Section 3 of the Fourteenth Amendment: An Exploration ... - JURIST - October 15th, 2023 [October 15th, 2023]
- Expert Q&A with David Aaron on FISA Section 702 Reauthorization ... - Just Security - October 15th, 2023 [October 15th, 2023]
- A Constitution the Government Evades - Tenth Amendment Center - October 15th, 2023 [October 15th, 2023]
- Imagine If Feds Hunted More Real Terrorists, Not Conservatives - The Federalist - October 15th, 2023 [October 15th, 2023]
- Lake Orion Voters Could Decide Removing TIF Funding for ... - Oakland County Times - August 24th, 2023 [August 24th, 2023]
- A marriage of convenience: Why the pushback against a key spy program could cave in on progressives - Yahoo News - August 24th, 2023 [August 24th, 2023]
- Iowa Public Information Board accepts one complaint against ... - KMAland - August 24th, 2023 [August 24th, 2023]
- Burleigh County weighs OHV ordinance to crack down on reckless ... - Bismarck Tribune - August 8th, 2023 [August 8th, 2023]
- AI targets turnstile jumpers to fight fare evasion, but experts warn of ... - 1330 WFIN - August 8th, 2023 [August 8th, 2023]
- As of July 1, police won't be able to stop people for smell of cannabis - The Baltimore Banner - May 20th, 2023 [May 20th, 2023]
- Baby Ninth Amendments Part V: Real Life, Potpourri, and the Big ... - Reason - May 20th, 2023 [May 20th, 2023]
- COA affirms SVF firearm conviction, finds stop and search by police ... - Indiana Lawyer - May 20th, 2023 [May 20th, 2023]
- BARINGS BDC, INC. : Entry into a Material Definitive Agreement, Creation of a Direct Financial Obligation or an Obligation under an Off-Balance Sheet... - May 20th, 2023 [May 20th, 2023]
- Column: : Justice, tyrants and the mob (5/19/23) - McCook Daily Gazette - May 20th, 2023 [May 20th, 2023]
- Alabama appeals court reverses murder conviction of Ala. officer ... - Police News - May 20th, 2023 [May 20th, 2023]
- Oakland narrows town manager search to five | West Orange Times ... - West Orange Times & SouthWest Orange Observer - May 20th, 2023 [May 20th, 2023]
- The Durham Report Is Right About the Need for More FBI Oversight - Reason - May 20th, 2023 [May 20th, 2023]
- Hashtag Trending May 19- U.S. government use invasive AI to track refugees; OpenAI releases iOS ChatGPT app; Microsoft bets on nuclear fusion - IT... - May 20th, 2023 [May 20th, 2023]
- Collective knowledge doctrine applies to a traffic stop - Police News - May 18th, 2023 [May 18th, 2023]
- Privacy and civil rights groups warn against rapidly growing mass ... - TechSpot - May 18th, 2023 [May 18th, 2023]
- There Is No Defensive Search Exception to the Fourth Amendment ... - Center for Democracy and Technology - May 8th, 2023 [May 8th, 2023]
- Napolitano: Does government believe in the Constitution ... - The Winchester Star - May 8th, 2023 [May 8th, 2023]
- Constitution might as well be abandoned if amendments are not ... - Washington Times - May 8th, 2023 [May 8th, 2023]
- One police officer opens a car door, and another looks inside. Did ... - SCOTUSblog - May 8th, 2023 [May 8th, 2023]
- Biden retains option of invoking 14th Amendment to avoid default - Geo News - May 8th, 2023 [May 8th, 2023]
- North Carolina Legislature Pushing Bill That Would Allow Cops To ... - Techdirt - May 8th, 2023 [May 8th, 2023]
- Letter: Threat to our freedom | Opinion | news-journal.com - Longview News-Journal - May 8th, 2023 [May 8th, 2023]
- Parents file lawsuit alleging civil rights violations after children were ... - The Boston Globe - May 8th, 2023 [May 8th, 2023]
- Nevada moves to strengthen protections around use of sexual ... - This Is Reno - May 8th, 2023 [May 8th, 2023]
- Feds rethink warrantless search stats and oh look, a huge drop in numbers - The Register - May 8th, 2023 [May 8th, 2023]
- Its literally cost me everything. Missouri man gets jail time in Capitol riot case - Yahoo News - May 8th, 2023 [May 8th, 2023]
- Board Member Rallies to Student Who Vandalized LGBTQ Posters - FlaglerLive.com - May 8th, 2023 [May 8th, 2023]
- 4th Circuit upholds $730K award to Black Secret Service agent - Virginia Lawyers Weekly - April 19th, 2023 [April 19th, 2023]
- Suspected drug dealer who used alias to rent condo wins reversal in ... - Indiana Lawyer - April 19th, 2023 [April 19th, 2023]
- Do Priests Have a Right to Privacy? - Commonweal - April 19th, 2023 [April 19th, 2023]
- This Deceptive ICE Tactic Violates the Fourth Amendment - ACLU - April 13th, 2023 [April 13th, 2023]
- LDF Appeals Grant of Qualified Immunity in Case Involving Invasive ... - NAACP Legal Defense and Educational Fund - April 13th, 2023 [April 13th, 2023]
- Livestreaming police stop constitutionally protected - North Carolina Lawyers Weekly - April 13th, 2023 [April 13th, 2023]
- F.B.I. Feared Lawmaker Was Target of Foreign Intelligence Operation - The New York Times - April 13th, 2023 [April 13th, 2023]
- Houston police officer who opened fire in Family Dollar parking lot also shot Mario Watts in separate 2021 incident, HPD confirms - KTRK-TV - April 13th, 2023 [April 13th, 2023]
- Jayland Walker: What's legal and what's illegal during protests - Akron Beacon Journal - April 13th, 2023 [April 13th, 2023]
- IMPD officers indicted for death of Herman Whitfield III - WISH TV Indianapolis, IN - April 13th, 2023 [April 13th, 2023]
- You can support Second Amendment and want gun reform, too ... - Straight Arrow News - April 13th, 2023 [April 13th, 2023]
- Does the five-second rule apply to extending a traffic stop to permit a ... - Police News - April 13th, 2023 [April 13th, 2023]
- Charlotte moves to dismiss lawsuit from man injured during 2020 ... - Carolina Journal - April 13th, 2023 [April 13th, 2023]
- TRAVEL & LEISURE CO. : Entry into a Material Definitive Agreement, Creation of a Direct Financial Obligation or an Obligation under an Off-Balance... - April 11th, 2023 [April 11th, 2023]
- Socialism and the Equal Sharing of Misery | Business ... - The Weekly Journal - April 11th, 2023 [April 11th, 2023]
- Top 10 Court Cases That Changed the U.S. Justice System - Listverse - April 11th, 2023 [April 11th, 2023]
- A new look at the lives of ultra-Orthodox Jews: Shtetl.org provides ... - New York Daily News - April 11th, 2023 [April 11th, 2023]
- VERISK ANALYTICS, INC. : Entry into a Material Definitive Agreement, Creation of a Direct Financial Obligation or an Obligation under an Off-Balance... - April 11th, 2023 [April 11th, 2023]
- Power Of Arrest In India, USA And UK - BW Legal World - April 11th, 2023 [April 11th, 2023]
- Jalil Muntaqim: The time to end prison slavery is now - The Real News Network - April 11th, 2023 [April 11th, 2023]
- Race and the Fourth Amendment: Defendants Raise Issue in ... - Law.com - April 9th, 2023 [April 9th, 2023]
- Why Founding Fathers passed the Third Amendment to the ... - Tennessean - April 9th, 2023 [April 9th, 2023]
- The journey of the Constitution - Pakistan Observer - April 9th, 2023 [April 9th, 2023]
- Former MPD officer sued - McMinnville - Southern Standard - April 9th, 2023 [April 9th, 2023]
- No, the RESTRICT Act wouldnt give the government access to data from your home devices - WCNC.com - April 9th, 2023 [April 9th, 2023]
- Analysis: How Strict Enforcement of Strict Gun Laws Begets ... - The Reload - April 9th, 2023 [April 9th, 2023]
- New York Court Rules Due Process Must be Considered for 'Red ... - National Shooting Sports Foundation - April 9th, 2023 [April 9th, 2023]
- Opinion: Democracy can't exist without "legal technicalities" - The Connecticut Mirror - April 9th, 2023 [April 9th, 2023]
- Commentary: Police and District Attorneys Dont Want to Give Up ... - The Peoples Vanguard of Davis - April 9th, 2023 [April 9th, 2023]