您的汽车正在出售您的数据
Data collected by cars and sold to third parties

原始链接: https://www.theverge.com/column/994172/your-car-is-selling-your-data

现代车辆已演变成复杂的资料收集机器,经常追踪驾驶行为(如车速和位置),并将这些资讯出售给第三方资料代理商和保险公司。近期一项备受瞩目的调查揭露,通用汽车(GM)曾暗中共享此类数据,导致不知情的客户保费上涨。尽管美国联邦贸易委员会(FTC)已禁止通用汽车的此项做法,但Mozilla基金会与《消费者报告》的研究人员证实,这是一个行业性的普遍问题。 与隐私设定集中的智能手机不同,车辆的数据收集过程不仅不透明,还分散在复杂且重叠的系统中。尽管消费者愈发不满并呼吁改革,但如《驾驶员法案》(DRIVER Act)等立法努力仍显不足,因为它们侧重于资料存取权,而非从源头遏制数据的收集量。在数据经济的巨额利益驱动下,汽车制造商几乎没有动力缩减规模。因此,消费者对“离线”车辆的需求日益增长,以逃避持续的监控;然而,想要找到不具备先进追踪功能的汽车正变得越来越困难。归根结底,保护个人隐私的重担依然落在个人身上,被困在了一个旨在将每一英里路程都货币化的系统中。

最近的一场 Hacker News 讨论凸显了人们对“智能”汽车日益增长的担忧,这些车辆会收集驾驶员的遥测数据(如位置、速度和里程)并将其出售给第三方数据经纪商和保险公司。用户们对现代汽车像“带轮子的手机”一样运作表示不满,因为它们往往会绕过用户通过软件设置禁用跟踪的尝试。 该讨论帖的主要内容包括: * **无处不在的监控:** 即使用户主动选择退出或禁用相关设置,车辆也经常继续传输数据。这些遥测数据往往以低得惊人的价格被售出,从而助长了一个利润丰厚的“影子经济”。 * **硬件层面的担忧:** 许多人认为软件开关不可靠。一些用户提倡采取“硬核”方案,例如拔掉远程信息处理保险丝、断开蜂窝模块,或者使用 50 欧姆电阻终止天线连接。 * **“二手车”替代方案:** 许多评论者选择维护旧款的非联网车辆,或购买 20 世纪 90 年代和 21 世纪初的二手车,以彻底避免现代隐私侵犯。 * **系统性问题:** 参与者指出,当前的隐私法律尚不完善,许多人呼吁制定强有力的法规,禁止制造商出售消费者数据,并强制执行真正的数字所有权。
相关文章

原文

This is The Stepback, a weekly newsletter breaking down one essential story from the tech world. For more on cars, data privacy, and autonomous vehicles, follow Andrew J. Hawkins. The Stepback arrives in our subscribers’ inboxes at 8AM ET. Opt in for The Stepback here.

Earlier this year, the Federal Trade Commission issued an unprecedented penalty against General Motors: a five-year ban on selling customer data to consumer reporting agencies and third-party data brokers.

For years, GM had been collecting all sorts of data on its customers — such as how often they sped or whether they drove at night — and selling it to brokers to generate risk profiles for insurance companies. More often than not, drivers were unaware of the degree to which their data was being collected. Many had unknowingly consented to it by signing up for an OnStar connected services plan, which activated a feature called Smart Driver that collected their driving data.

GM was then turning around and sharing that data with two data brokers, LexisNexis and Verisk, both of which work with the insurance industry. In a 2024 blockbuster investigative report by The New York Times, some drivers said their insurance rates went up as a result of the data collection. The enrollment process was so confusing that many vehicle owners had no idea their data was being shared. Under the settlement with the FTC, GM has to make it easier for drivers to turn off location tracking, as well as enable them to access and delete their data collected by the automaker.

But GM isn’t the only automaker vacuuming up data on its customers. A team of researchers from the Mozilla Foundation spent months examining the privacy policies of all the major car companies for a report they were working on in 2023. Their conclusion: Every single one had “horrible privacy and security,” said Jen Caltrider, who helped author the study. Not only that, but customers were forced to accept overlapping policies for the car, the connected services, the smartphone app, and the financial services through which they received their loan — all of which included data collection provisions.

“And so it was really overwhelming trying to understand what was going on,” Caltrider said.

There has been plenty of corroborating evidence for this. Consumer Reports published its own investigation last year that concluded “nearly every automaker that sells cars in the U.S. is similarly collecting and sharing so-called ‘driver behavior data’ with other companies and continues to do so.”

Cars are particularly problematic compared to phones because the privacy controls are less intuitive. A smartphone owner can generally find and tweak their privacy settings. With a vehicle, the data collection is spread across multiple systems and policies, making it much harder for consumers to understand what is happening. It feels like a free-for-all because automakers are collecting enormous amounts of information without much public scrutiny.

After GM was penalized as a result of the Times investigation, the issue of data privacy and cars appears to finally be getting some scrutiny. But as is often the case, policymakers may be missing the mark on how to address it.

Last December, a trio of House Republicans introduced the Data Rights for Information and Vehicle Electronics in Real-time, or DRIVER, Act. According to these lawmakers, the bill “reaffirms a basic principle: if you own the vehicle, you should own the data it generates.”

But while the bill would give vehicle owners a bit more control over their data, it would also allow automakers to continue gathering and selling it to third-party data brokers, which makes it a nonstarter for privacy advocates. As Caltrider notes, access and deletion rights are not the same thing as preventing excess collection in the first place. If an automaker can collect enormous amounts of information and the consumer must then go through an arduous process to discover what was collected and request that it be deleted, the burden remains on the individual. Most privacy advocates would rather see a system in which automakers simply do not collect so much information to begin with.

The issue has even risen to the level of MAGA World. Last July, Donald Trump’s Transportation Secretary, Sean Duffy, sent a letter to Congress outlining the administration’s policy priorities for the upcoming surface transportation reauthorization bill. Tucked in the letter was a new concept called “the Freedom Car,” which Duffy described as Americans’ right to “drive disconnected and non-automated” vehicles. The proposal would ban the government from requiring that vehicles be equipped with automated driving systems or have the capability to transmit data wirelessly — which, to my knowledge, no one is trying to do.

It’s unclear whether the DRIVER Act or the Freedom Car will ever clear the hurdles in Washington to become real policies. What is clear is that there is significant demand for simpler vehicles. People are asking why they can’t just buy a car without all the sensors and data collection. They look at new concepts like the Slate Truck and wonder whether they could also use something more bare-bones.

Sure, consumers may accept useful safety equipment such as backup cameras, but many don’t want their vehicle tracking everything they do — and they definitely don’t want to see ads on their vehicle screens. (BMW, I’m looking at you.) Nor do they want Flock cameras tracking their every movement while they drive down the street.

But automakers have every incentive to keep collecting data because there is money to be made from it. As long as the broader data economy rewards companies for gathering and monetizing information, there’s little reason for automakers to voluntarily abandon the practice.

  • Every automaker has its own privacy page where vehicle owners can submit requests, including opting out of data collection. Of course, they’re all buried under mountains of legalese, so good luck finding it.
  • Same goes for all the smartphone apps for connected car services. Changing your privacy settings in those apps is generally a little easier.
  • The New York Times’ investigation into GM’s data collection program is worth a read, if just for the flabbergasted reactions from drivers who couldn’t understand why their insurance rates were going up.
  • Edmunds and Consumer Reports both did the work to ask every automaker for their data collection policies. There’s a lot of variety across the industry.
  • These Redditors are crowdsourcing a list of new cars (from 2019 onward) that aren’t digitally connected and/or transmitting data to the car company’s servers. Spoiler alert: It’s a pretty short list!
Follow topics and authors from this story to see more like this in your personalized homepage feed and to receive email updates.
联系我们 contact @ memedata.com