Showing posts with label car privacy. Show all posts
Showing posts with label car privacy. Show all posts

February 25, 2008

The black box in your car

Event Data Recorders, EDRs, have been used by car manufacturers on fleet vehicles since the 1970s to collect data about performance of airbags and other safety features in the event of a vehicle impact. Much like an aircraft "black box", current EDRs record vehicle speed, engine RPM, whether the driver's seat belt is latched, and the position of brake and accelerator pedals, as well as information about the status and deployment of the air bag.

General Motors started including black boxes on higher-end models, like Cadillacs, in 1994, and was putting them in all passenger car models by 1999. Some other makes, like Toyota and Ford, have been using them in some cars since 1996, and Ford has included event data recorders in all models since 2000. Approximately 64% of model year 2005 cars have event data recorders.

IIHS says "General Motors, Ford, Isuzu, Mazda, Mitsubishi, Subaru, and Suzuki voluntarily equip all of their vehicles with EDRs, according to NHTSA's estimates. More than half of Toyotas have the devices, too. Passenger vehicles from BMW, Daewoo, Honda, Hyundai, Kia, Mercedes, Nissan, Porsche, and Volkswagen don't have what NHTSA defines as EDRs, according to the agency's estimates of 2004 and 2005 models."

Tools are available to download Ford and GM EDR data, but only Toyota can read Toyota data recorders. One vendor provides an online list of cars with event data recorders accessible by their crash data retrieval tool. NHTSA has mandated manufacturers provide tools to download EDR data within 90 days.

The biggest privacy issue is from police or accident investigators, working on behalf of lawyers or insurers, using these tools to download data without consent from one or more vehicles involved in a crash. Police or private investigators could seek the recorded data for other types of cases, though, such as car theft or chops shop busts. It's not even hard to imagine a high-profile, high-stakes custody case where one parent is looking for evidence that their ex-partner was speeding with the kids in the car.

Recent legislation or court orders could force disclosure of EDR data even if laws give ownership of that data to vehicle owner or lessee.

Insurers Encouraged to Harvest Data

[T]he Texas-based company offers insurance carriers the ability to retrieve, harvest, and store data concerning the events of a collision and provides analysis and interpretation of the data. [...] "for use in claims adjudication".

The initial question which springs to mind is how insurers are obtaining the data in the first place. If the vehicle is repairable and the information is coming from a vehicle intended to be returned to the owner, is the insurer, body shop, or someone associated with Injury Sciences LLC extracting the information? Searching the company's website does not provide the answer, but it suggests that insurers and/or body shops are accessing the information themselves. Otherwise, the company offers "access to a network of service providers" who are equipped to harvest the data.

If insurers are mining data without disclosing that activity to the insured or the third party, they may well be engaging in unfair claims practices or violations of privacy rights under individual state law. If insurers use this data against their own insureds, that action could easily be the basis for a bad faith insurance claim and could have broader implications as well.

Event Data Recorders and privacy



  • Experts agree that EDRs are extremely impractical to disable, because they are almost always integrated into the car's existing computers. They are factory installed and are not optional features on the cars that are built with them.
  • Know if any cars you drive regularly have EDRs. Toyota, Ford and GM currently disclose the existence of the recorder in the vehicle owner's manual. NHTSA has ruled that all manufacturers will have to disclose EDRs included in their cars made after September 1, 2010.
  • Check auto insurance and car rental contracts for stipulations requiring you to give the access to an EDR, or turn over EDR data in the event of an accident, perhaps under general provisions requiring you to cooperate with your insurer.
  • Don't consent to anyone downloading data from the EDR unless advised to do so by your lawyer. In this event, keep copies of your signed consent form.
  • Assume that even if your car has no EDR, any modern car involved in an accident is likely to have one, and any collision is likely to be recorded by traffic surveillance cameras.
  • EDR data belongs to the car's owner or lessee. Until served with a court order, there is no compulsion to turn EDR data over to any investigators, insurance companies or lawyers. You might be able to contract to have the EDR data preemptively erased before any such court order is issued, if you feel that erasure would protect your rights.

January 16, 2008

Outfits mine Voter Registration records

Vanity Fair reports that database broker Aristotle is amassing, cross-referencing and selling voter registration and political donation information:

“People are getting hassled by marketing firms and hassled by consultants, and much of that information comes from signing petitions or off the voting databases."



In most states, voter registration databases are public information, by law. The governments sell this information, along with driver's license data.

"One such [commercial data] supplier is Acxiom, the Arkansas-based behemoth that stores unimaginable quantities of data. In 2003, a single hacker stole Acxiom records on 20 million people, according to Washington Post reporter Robert O’Harrow’s 2005 book, No Place to Hide."



Aristotle's data gatherers might soon be taking photos in public and harvesting data-rich magstripe information from credit cards and identity cards:

"Phillips picks up one of the custom-designed pocket-P.C. scanners that go with the Aristotle 360 system. With them, canvassers working for campaigns will swipe credit cards and driver’s licenses, take pictures of voters using an embedded micro-camera, and instantaneously feed all of the resulting information into the database."




The inescapable conclusions I draw from this are that voting and making political donations are much more likely to result in an individual's inclusion in a database, whether the data mining effort is governmental, political, or for more direct monetary profit. The magnetic-strip scanners are a reminder about how electronic cards can facilitate mass surveillance of a type unintended by their issuers.

In situations when Social Security Numbers and Social Insurance Numbers can't be used as database keys or for matching individuals, mailing addresses and date-of-birth (DOB) is frequently used. Therefore, remember to keep your full name, DOB and mailing address (hopefully it's not the same as your street address!) to yourself as much as possible.

November 22, 2007

WSJ: Home invasions target wealthy

The Wall Street Journal reports that the higher-profile rich are being targeted for home invasion robberies:

One reason for the rise in home invasions is demographic: The numbers of rich people with homes to plunder has risen fast in recent years. But police and security experts say robbers are hitting homes more because their traditional targets -- banks, stores and offices -- have been hardened with closed-circuit video surveillance, alarms and guards. By comparison, security at many private homes remains lax, they say.

Increasingly, wealthy and high-profile individuals must step up security at home and be vigilant in their cars to avoid becoming victims, security experts and police say. They may also need to reduce the amount of information they reveal about themselves on the Internet in places like Facebook, and in the media. And perhaps most importantly, they should thoroughly investigate the background of anyone who has access to their home, because many robberies are inside jobs.
Several security and alarm experts say crimes like these can be prevented with a perimeter motion-detection system that sounds whenever someone drives or walks onto a property. Many alarm systems wire only the doors and windows of a home; the problem with that, security experts say, is that by the time someone trips the alarm, it can be too late. Moreover, any alarm system has to be armed to work, and often, they aren't.


Home-invasion robbers also pick their victims by staking them out in public and following them home.

Police and security experts say that to avoid this type of robbery, people should be alert to whether they are being followed before driving onto their property, and if they are, to call the police or drive to a police station. Houses should be well-lighted with automatic exterior lights. Additionally, security experts advise clients to avoid drawing attention to money and possessions while they're out and about. They also recommend reducing the amount of detailed personal information that can be found on the Web.

While at home, it is a mistake to open the door without verifying the identity of a visitor first and to accept unscheduled deliveries. Security experts say homes should be equipped with a voice-video intercom system with cameras trained on the doors and the grounds, and deliveries should be sent to a post-office box or family office instead of to the residence.

June 13, 2007

How Insurance companies price your Car Insurance

Insurance can be an adversarial business relationship, unfortunately. In some circumstances, the more your insurer knows about you, the higher the rate they will charge you. This gives them every incentive to ferret out information pertinent to your insurance risks -- or what they believe affects your insurance risks, anyway.

A Consumerist article gives insight into the privacy implications and pricing strategy of auto insurance.

Note that insurance companies access the following databases to actuarially determine liklihood of an insurance claim: CLUE report, credit report, and driving history.

As with credit reports, a critical source of information is what you tell the insurance company:

Driving histories go back 36 months, except in New York (which is 40 months). Your history is composed from three reports; your MVR or Motor Vehicle Report, the state database of your ticketed driving history; your CLUE report, a collection of previous insurance companies reports stating the numbers of claims you've had, and YOU. If you say you got in an accident, were never sited for it and never claimed it on your insurance, but you still tell us, it'll be put on your record with an approximate date.


Credit score and insurance rates


It is illustrative how your credit report affects your insurance score, and thus your insurance rates. By 2001, 92% of insurers were considering credit scores when quoting insurance.

Remember that information you give to an insurance company may well end up on your credit report. Along with the usual distinguishing characteristics (name, date of birth, SSN or other national number), insurers will likely report your submitted information to the credit reporting bureay. This could happen even if you're just getting an insurance quote, and needs to be taken into account if you're keeping your street address confidential.

Complete truthfulness doesn't always pay when it comes to dealing with insurers who will collect every personal detail to accurately assess you with their actuarial tables.

Bermuda to track road vehicles with RFID

RFID Journal reports that the Caribbean nation of Bermuda plans to tag registered cars and trucks with RFID transponders to increase road registration compliance and revenues.

The ISO 18000-6B standardized, 915 MHz tags will be embedded in tamper-resistant windscreen stickers, and are made by 3M. The laser readers placed by the side of the road are made by Transcore.

Sabotaging the RFID tag is ineffective because the RFID interrogation is combined with an ANPR system:

If a car arrives at an intersection and no interrogation of an RFID tag can be performed, the system will take a picture of the car's license plate. Using optical character recognition software, the system will read the vehicle's plate numbers and input them into a database so a citation can be automatically issued. The same system will be employed to detect commercial vehicles operating in restricted areas during rush hour without permits.


Bermuda's Transport Control Department expects that all of the island nation's registered cars should be RFID tagged by June 2008. Motorcycles will be exempt from the RFID tagging requirement, though authorities may later decide to being them into the program.

The privacy implications of the mandated RFID transponders are profound. It is very feasible for groups unassociated with Bermuda's Transport Control Department to develop the ability to read the RFID tags and track specific automobiles by their electronic ID. In fact, an older version of this technology was used by a United States intelligence agency during the Cold War to track Soviet attaches whenever they crossed one of a handful of Washington, D.C. bridges and passed outside the 20-mile unrestricted transit limit.