Kenn Dahl says he has always been a careful driver. The owner of a software company near Seattle, he drives a leased Chevrolet Bolt. He’s never been responsible for an accident.

So Mr. Dahl, 65, was surprised in 2022 when the cost of his car insurance jumped by 21 percent. Quotes from other insurance companies were also high. One insurance agent told him his LexisNexis report was a factor.

LexisNexis is a New York-based global data broker with a “Risk Solutions” division that caters to the auto insurance industry and has traditionally kept tabs on car accidents and tickets. Upon Mr. Dahl’s request, LexisNexis sent him a 258-page “consumer disclosure report,” which it must provide per the Fair Credit Reporting Act.

What it contained stunned him: more than 130 pages detailing each time he or his wife had driven the Bolt over the previous six months. It included the dates of 640 trips, their start and end times, the distance driven and an accounting of any speeding, hard braking or sharp accelerations. The only thing it didn’t have is where they had driven the car.

On a Thursday morning in June for example, the car had been driven 7.33 miles in 18 minutes; there had been two rapid accelerations and two incidents of hard braking.

      • It will be cat and mouse, but I would imagine for the time being, disconnecting the cell antenna on the board would stop it. Who knows what kind of, if any bullshit extra errors and codes that will keep popped up but I’m guessing if it became a popular thing, they would start making cars that will create bullshit errors and codes. I wouldn’t do anything permanent until the warranty period is over.

      • Most likely the module, if it is a separate module and not part of the SoC of the infotainment system or whatever, works over CAN bus and the car will throw errors when it doesn’t detect its presence, or doesn’t detect the SIM card. Might even refuse to start if that module is missing. Might be possible to remove the antenna so the car thinks it’s just outside of the service area, but if it’s built into the PCB and the PCB is cast into resin/silicone for waterproofing, even this might be extremely difficult. Probably the module is also serialized* so replacing it with a “dummy” module or a module from a junkyard won’t spoof the system, either.

        *Manufacturers have been serializing even airbags for years, making replacing a faulty one with one from a junkyard impossible.

        •  IllNess   ( @IllNess@infosec.pub ) 
          link
          fedilink
          English
          24 months ago

          Maybe we can trick it forever that it is far away from a cell tower. That way the car has to start without connection.

          Who knows, maybe they force you to use their app and after driving and connecting to the internet, that sends data back to the manufacturer.

      • I’m sure it varies widely. In Toyota’s you can call in to disconnect (I did it while waiting for a tire pressure machine) but to do it physically you pull a single fuse and the trade off is losing the microphone.

        Others have pulled the dash and disconnected antennae but it just reduces the range of the box since it’s a cellular radio like a phone.

          • in this case that’s Toyota specific and it means likely loss of phone calls on the go (but nothing else) even though the data can’t leave your vehicle anymore. It all depends on how they wire up the system. Maybe it’s easier, maybe it’s tied to something random.

        • Do you have any resources that I can use to learn more about about removing telemetry from a vehicle? Is there a good forum that could help me potentially do this to my car?

          • There’s no easy one-stop solution since it can vary widely.

            I would look at subreddits (yuck, reddit!), or dedicated forums for your model if they exist, you’d probably be surprised what’s out there. (Example, there’s Piloteers (Honda Pilot), Kia-Forums (Kia), 4Runners and Toyota-4Runner, etc. But information may be scattered.

            First objective is figuring out if it’s even on your vehicle or applicable. Older 3G radios are done since the networks that connected to them are gone now. My '16 Kia had no cellular radio. Maybe you have an SOS button or they advertise a phone app to control your vehicle remotely?

            Edit: And if you can’t find specific model/year information for your vehicle, you can look for information for related vehicles and see if it’s relevant. Ex: Honda Passport, Pilot, Ridgeline sharing a lot of engineering.

    • I can’t wait to see tuturials. I don’t know much about cars and would love to see people disable these, or perhaps do something malicious. Not that I have a new enough car yet, but I know one day it’s going to be unavoidable.

  •  kbal   ( @kbal@fedia.io ) 
    link
    fedilink
    604 months ago

    Last time I drove a rental car I was constantly aware that it was probably tracking everything I did, sending that data back to its owners, who would then sell it on to data brokers and insurance companies and whoever else wanted it.

    It was sort of tolerable on a temporary basis, until I got to driving along a road where the speed limit had recently changed. The car helpfully displayed what it thought the speed limit was, and suddenly I had to choose between driving safely and driving according to what the computers presumably wanted to see.

    Drivers of the world, do not let your cars have Internet access. No good can come of it.

  • I still have my 2010 Mazda 3. The only tech it has is Bluetooth connectivity for phone and music and some voice commands for calls.

    The day I will change cars will be the day my car completely dies and there’s nothing I can do about it, or it becomes illegal to drive, or it gets wrecked in an accident.

    I don’t ever want the new cars. I hate hate hate the stupid touch tablets they’ve put to control everything instead of physical knobs, and now this fucking crap where your car spies on you and rats you out to you insurance company.

  •  JIMMERZ   ( @JIMMERZ@lemm.ee ) 
    link
    fedilink
    English
    264 months ago

    My auto insurance rose 27% this year. My cars sit in a locked garage 20ft away from me practically all week long as I work from home. I was shocked to find my rates rose so high as I barely even drive at all anymore. Their solution was for me to get their data collection puck. What a fucking racket!

  • Kinda like those who choose to be in the Progressive Insurance “Snapshot” program where you install an OBD2 dongle that reports a lot of data about your driving habits back to Progressive in the dim chance you drive so well that they will lower your rates.

  • Is that the whole text of the article? (paywall) Was there any investigation as to the source of the data on the report? As this is a leased vehicle, I would not be surprised if the data came from a dealer module that they use to immobilize and locate the vehicle if you miss a payment or otherwise violate your lease.

    According to the report, the trip details had been provided by General Motors

    https://archive.ph/lmMp9

    • I’m not surprised it happened, but a little surprised how quickly it happened. Most insurance companies still offer a plan where you voluntarily plug in a tracker to monitor your driving in exchange for lower rates if you’re a good driver, so it’s extra fucked that they’re doing the same thing to presumably everyone with an internet connected car without even telling them upfront, let alone getting consent.

  •  dubyakay   ( @dubyakay@lemmy.ca ) 
    link
    fedilink
    2
    edit-2
    4 months ago

    I work in fintech and I had glimpses of raw API data that credit agencies, Mastercard and LexisNexis provide (among others). It’s crazy detailed. Even just our query increases the query count by one and provides at least ten data points on the why and when.

    I’m not surprised that the car manufacturers are selling this data to LexisNexis who in turn sell it to insurance companies.