OnStar Begins Spying On Customers’ GPS Location For Profit

Thread Tools
 
Search this Thread
 
  #1  
Old 09-21-2011, 11:54 AM
libertyforall1776's Avatar
Overdrive Member
Thread Starter
Join Date: Nov 2006
Location: IL
Posts: 4,042
Thumbs down OnStar Begins Spying On Customers’ GPS Location For Profit

I didn't see this feature advertised... Time to disconnect that system if you haven't already...

OnStar Begins Spying On Customers’ GPS Location For Profit | Jonathan Zdziarski's Domain

OnStar Begins Spying On Customers’ GPS Location For Profit
Posted on September 20, 2011 by Jonathan Zdziarski

I canceled the OnStar subscription on my new GMC vehicle today after receiving an email from the company about their new terms and conditions. While most people, I imagine, would hit the delete button when receiving something as exciting as new terms and conditions, being the nerd sort, I decided to have a personal drooling session and read it instead. I’m glad I did. OnStar’s latest T&C has some very unsettling updates to it, which include the ability to sell your personal GPS location information, speed, safety belt usage, and other information to third parties, including law enforcement. To add insult to a slap in the face, the company insists they will continue collecting and selling this personal information even after you cancel your service, unless you specifically shut down the data connection to the vehicle after canceling.


The complete update can be found here. Not surprisingly, I even had to scrub the link as it included my vehicle’s VIN number, to tell OnStar just what customers were actually reading the new terms and conditions.

The first section explains the information that’s collected from the vehicle. No big deal. Sounds rather innocuous and boring. I imagine most people probably drool out and close the window by the time they get this far. Your contact information, billing information, etc. is collected. Nobody cares about tire pressure and crash information being collected – after all, that’s what OnStar is there for. Toward the end, you’ll read about how GPS data is collected, including vehicle speed and seat belt status. Again, in an emergency, this is very useful and most customers want an emergency services business to collect this information - when necessary. And the old 2010 terms and conditions only allowed OnStar to collect this information for legitimate purposes, such as recovering a stolen vehicle, or when needed to provide other OnStar services to customers on demand. As you scroll down the list of information collected, you see that once you get past important emergency services (what we pay OnStar for), OnStar now has given themselves the right to also use this information to stuff their pockets. OnStar has granted themselves the right to collect this information “for any purpose, at any time, provided that following collection of such location and speed information identifiable to your Vehicle, it is shared only on an anonymized basis.” – This provides carte blanche authority for OnStar to now track and collect information about your current GPS position and speed any time and anywhere, instead of only in the rare, limited circumstances the old contract outlined.

Anonymized GPS data? There’s no such thing! We’ve all seen this before – anonymized searches, for example, that were not-so-quite anonymized. But in this case, it’s impossible to anonymize GPS data! If your vehicle is consistently parked at your home, driving down your driveway, or taking a left or right turn onto your street, its pretty obvious that this is where you live! It’s like trying to say that someone’s Google Map lookup from their home is “anonymized” because it doesn’t have their name on it. It still shows where they live! What’s unique even more-so to OnStar is that the data they claim they sell as part of their business model is useless unless it’s specific; that is, not diluted to the nearest 10 mile radius, etc. This combination of analytics, and their prospective customers (law enforcement, marketers, etc) requires the data be disturbingly precise. Anyone armed with Google can easily do a phone book or public records search to find the name and address that resides at any given GPS coordinate.

So the GPS location of your vehicle and your vehicle’s speed are likely going to be collected by OnStar and sold to third parties. What kind of companies are interested in this data? OnStar would have you believe that respectable agencies, like departments of transportation and various law enforcement agencies (for purposes of “public safety or traffic services” – A.K.A ticket writing). I can imagine this data COULD be used for good, to create traffic based analytics to improve future road construction or even emergency response. But given that those types of decisions are only made once a decade in most cities, OnStar isn’t likely to benefit much financially from “respectable” companies.

What is more profitable to OnStar that your personal GPS data could be used for? Hmm, well how about the obvious – tracking you and your vehicle. It would be extremely profitable to be able to identify all vehicles within OnStar’s network that frequently speed, and provide law enforcement “traffic services” the ability to trace them back to their homes or businesses, as well as tell them where to set up speed traps. Or perhaps insurance companies who want to check and make sure you’re wearing your seat belt, or automatically give you rate increases if you speed, even if you’re never in an accident? How about identifying all individuals who shop at certain stores, and using that to determine whose back yard to put the next God-awful Wal-Mart store? How about employers who purchase these records from these third parties to see where their employees (or prospective employees) travel to (and how fast), sleaze bag lawyers who want to subpoena these records to use against you if you’re ever sued, government agencies who want to monitor you, marketing firms who want to spam you, and a long list of other not-so-squeaky-clean people who use (and abuse) existing online, credit card, financial, credit, and other analytics to destroy our privacy?

Add to this OnStar’s use policy of your personal information – the stuff that does identify who you are and ties it to your GPS records. While I have no problem using my personal information in events of an emergency, OnStar also uses my information to “allow us, and our affiliates, your Vehicle Maker, and Vehicle dealers, to offer you new or additional products or services; and for other purposes“. So not only is OnStar going to sell my vehicle’s GPS location data to a number of third parties, but they’re also going to use it and my personal information for marketing purposes. Imagine your personal data being sold to any number of their “affiliates”, and a few months later, you start to receive targeted, location-specific advertising based on where you’ve traveled. Go to Weight Watchers every week? Expect an increase in the amount of weight loss advertising phone calls. Go to the bar frequently? Anticipate a number of sleazy liquor ads to show up in your mailbox. Sneak out to Victoria Secret for something special for your lover? You might soon be inundated with adult advertising in your mailbox.

OnStar’s new T&C continues, explaining that part of the company may at some point be sold, and all of your information with it. It sounds as though OnStar is poising part of their analytics department to be purchased by a large data warehousing company, such as a Google, or perhaps even an Apple. Do you trust such companies with unfettered access to the entire GPS history of your vehicle?

This is too shady, especially for a company that you’re supposed to trust your family to. My vehicle’s location is my life, it’s where I go on a daily basis. It’s private. It’s mine. I shouldn’t have to have a company like OnStar steal my personal and private life just to purchase an emergency response service. Taking my private life and selling it to third party advertisers, law enforcement, and God knows who else is morally inept. Shame on you, OnStar. You disgust me.

To make matters even more insulting, it was difficult to ensure the data connection was shut down after canceling. I still have no guarantee OnStar did what they were supposed to. I had to request the data connection be shut down repeatedly, after the OnStar rep attempted to leave it on and ignore my requests.

When will our congress pass legislation that stops the American people’s privacy from being raped by large data warehousing interests? Companies like OnStar, Google, Apple, and the other large abusive data warehousing companies desperately need to be investigated.

These terms don’t go into effect until December 2011, and it takes up to 10 days to have the account fully cancel, and another 14 days for the data connection to be shut down… so if you want to get out of these new terms and conditions, you’ll need to do it soon.



Update:

Since writing this article, OnStar has reportedly told a few individuals that the contract requires them to obtain the customer’s consent in order to provide this information to anyone. Not true. In fact, the only mention of the word consent in their updated T&C is below:

We will comply with all laws regarding notifying you and obtaining your consent before we collect, use or share information about you or your Vehicle in any other way than has been described in this privacy statement.

Two points to make: first, this clause only applies to collecting and sharing information in any way that is not described in the privacy statement. All of the nefarious uses for your personal data are, quite clearly, described in the privacy statement, and so no consent would be required. Secondly, this paragraph makes it clear that they will only comply with all laws requiring consent, not that they will actually obtain your consent. I’m not a lawyer, but as far as I know, there are no such laws on the books in most (if not all) states that protect the consumer from having their private information shared or sold to third parties, especially when such sharing is disclosed in a contract. In other words, the above paragraph seems to do nothing to require OnStar to obtain your consent to do any of this – and it’s my firm belief that OnStar’s only real interest is in OnStar. If you doubt this, the older version of the terms and conditions had two more consent clauses that are no longer part of the new terms and conditions.

Old Consent Clauses – Now Removed:

In General, we do not share your personal information with third-party marketers, unless we have asked for and obtained your explicit consent.

Of course, we will notify you, and where required, ask for your prior consent if our collection, use, or disclosure of your personal information materially changes.
 

Last edited by libertyforall1776; 09-22-2011 at 12:27 PM. Reason: whole article
  #2  
Old 09-22-2011, 10:25 PM
libertyforall1776's Avatar
Overdrive Member
Thread Starter
Join Date: Nov 2006
Location: IL
Posts: 4,042
Post

Not surprising that OnStar/GM is not a member of the Digital Due Process (DDP) coalition, which is supporting amendments to ensure the government can't track your cell phone or obtain online content such as emails, photos, documents and backup files without first going to court to get a search warrant.

According to the EFF, the current version of the ECPA (Electronic Communications Privacy Act) is vague on whether these documents and information -- including the tracking of your cell phone -- are presently protected from government intrusion without any form of warrant.

OnStar is in part, basically a cell phone + GPS...

Digital Due Process :: Who We Are

 

Last edited by libertyforall1776; 09-24-2011 at 01:18 PM.
  #3  
Old 09-22-2011, 10:27 PM
libertyforall1776's Avatar
Overdrive Member
Thread Starter
Join Date: Nov 2006
Location: IL
Posts: 4,042
Default

1984 is not appealing. No cars will be tracked if we do not consent. Consent is required for anything like this to ever be done. Quite simple, really.

How to disconnect OnStar:
Camaro5 Chevy Camaro Forum / Camaro ZL1, SS and V6 Forums - Camaro5.com - View Single Post - How to disconnect OnStar?
or:
How to Take OnStar Out of a Car | eHow.com
 
  #4  
Old 09-23-2011, 11:27 AM
Dons's Avatar
Newbie
Join Date: May 2010
Posts: 6
Default

Was wondering what people thought about this? I have On Star and I don't want anyone having my personal information unless I authorize the release of such. I wonder if this going to result a whole bunch of subscriptions being canceled, like mine.
 
  #5  
Old 09-24-2011, 01:17 PM
libertyforall1776's Avatar
Overdrive Member
Thread Starter
Join Date: Nov 2006
Location: IL
Posts: 4,042
Default

More news on this topic:
GM's OnStar Unit Alters Privacy Policy, Drawing Senators' Wrath


Another related OnStar 'feature', video:

GM OnStar High Speed Pursuit Preventive Technology - YouTube

GM's OnStar Unit Alters Privacy Policy, Drawing Senators' Wrath
Eric Engleman, ©2011 Bloomberg News

Friday, September 23, 2011

Sept. 23 (Bloomberg) -- General Motors Co.'s OnStar vehicle navigation service revised its customer-data policy in a way that appears to "violate basic principles of privacy and fairness," two U.S. senators wrote in a letter to the company.

OnStar told customers in an e-mail this week that it may continue collecting data from vehicles of subscribers who have canceled the service. Customers must contact OnStar to halt the data collection under the policy change effective Dec. 1, according to the e-mail.

Democratic senators Al Franken of Minnesota and Christopher Coons of Delaware objected to the change in a Sept. 21 letter to OnStar that urged the company to reconsider its data policy.

"OnStar is telling its current and former customers that it can track their location anywhere, anytime -- even if they cancel their subscriptions -- and then give or sell that information to anyone as long as OnStar deems it safe to do so," the lawmakers wrote.

OnStar will respond directly to the senators, OnStar spokesman Adam Denison said. He declined to say when the company would reply or share details of its response.

OnStar delivers navigation and security features such as emergency assistance to GM cars using the global-positioning system. The service has more than 6 million customers in the U.S., Canada and China, according to the company's website.

Franken and Coons asked the company whether it has experienced any leaks of customer information and what it does to protect such data. The senators said OnStar's actions underscore the need for legislation to protect consumer information online including people's location.


Privacy Bill


"OnStar's actions appear to violate basic principles of privacy and fairness for OnStar's approximately six million customers -- especially for those customers who have already ended their relationships with your company," the senators wrote.

Franken introduced a bill in June that would require companies such as Apple Inc. and Google Inc. and mobile- application developers to obtain permission from mobile devices such as smartphones before collecting location data and sharing that information with third parties.

Franken, who chairs the Senate Judiciary subcommittee on privacy, technology and the law, held a May 10 hearing on mobile privacy with executives from Apple and Google.

His location bill is co-sponsored by Coons and Democratic senators Richard Blumenthal of Connecticut, Richard Durbin of Illinois, and Robert Menendez of New Jersey, along with Bernard Sanders of Vermont, an independent who caucuses with the Democrats, Coons spokesman Ian Koski said in an e-mail.



Read more: http://www.sfgate.com/cgi-bin/articl...#ixzz1Z6ZAaH00
 

Last edited by libertyforall1776; 09-26-2011 at 06:39 PM. Reason: added full text
  #6  
Old 09-28-2011, 03:22 PM
libertyforall1776's Avatar
Overdrive Member
Thread Starter
Join Date: Nov 2006
Location: IL
Posts: 4,042
Default

Now OnStar is backpedaling, until you forget about this...

TomTom was also caught selling customer data this year:
TomTom apologise for selling customer satnav data used for police speed traps | Mail Online

TomTom To Sell GPS Data To Road Authorities, Private Companies

It is not dead, this is a temporary measure to fool people. TomTom took the same tactic in the past where they were sharing/selling data, stopped, but guess what, reportedly they are doing it AGAIN.

So will OnStar!


Not only that, but Maryland is testing an in-car spy system, I'm sure other states are thinking similar 1984 schemes:


Maryland MVA Trials In-Car Spy System Alex Jones' Infowars: There's a war on for your mind!

This is real.
 
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Thompson Motorsports
93-02 General
0
06-11-2015 11:45 AM
Ragman
2010+ General
3
05-07-2012 11:20 PM
KIRK_ADAMS
Nitrous, Super Chargers, & Turbos
0
02-04-2011 10:53 PM
Moohaaa07
82-92 V8 Tech
3
03-29-2007 01:19 PM



Quick Reply: OnStar Begins Spying On Customers’ GPS Location For Profit



All times are GMT -5. The time now is 03:59 PM.