Category Archives: Security

Massive Tesla Privacy Breach Exposes Culture of Cruelty and Customer Abuse

Privacy in a Tesla vehicle is non-existent, apparently. Interesting to think Tesla customers actually paid for this treatment.

…between 2019 and 2022, groups of Tesla employees privately shared via an internal messaging system sometimes highly invasive videos and images recorded by customers’ car cameras, according to interviews by Reuters with nine former employees.

Some of the recordings caught Tesla customers in embarrassing situations. One ex-employee described a video of a man approaching a vehicle completely naked.

Also shared: crashes and road-rage incidents. One crash video in 2021 showed a Tesla driving at high speed in a residential area hitting a child riding a bike, according to another ex-employee. The child flew in one direction, the bike in another. The video spread around a Tesla office in San Mateo, California, via private one-on-one chats, “like wildfire,” the ex-employee said.

Video recordings were being made and then viewed by Tesla staff even when a car was parked, even when a car was turned off. In other words, the cameras are billed as safety devices, yet they potentially were on all the time and without Tesla owners being aware.

Tesla states in its online “Customer Privacy Notice” that its “camera recordings remain anonymous and are not linked to you or your vehicle.” But seven former employees told Reuters the computer program they used at work could show the location of recordings – which potentially could reveal where a Tesla owner lived.

One ex-employee also said that some recordings appeared to have been made when cars were parked and turned off. Several years ago, Tesla would receive video recordings from its vehicles even when they were off, if owners gave consent. It has since stopped doing so.

It has stopped? Prove that is true.

[Investigators have not been] able to determine if the practice of sharing recordings, which occurred within some parts of Tesla as recently as last year, continues today or how widespread it was.

There is no reason for Tesla staff to be pulling up videos of the inside of people’s garages from parked cars that have been turned off, especially given personally identifiable data and how the frames will have absolutely nothing to do with safety. It seems like a culture of abuse and little more.

If this were a hospital, for example, we’d be talking about doctors and nurses who engage in grossly negligent safety practices, violating patient privacy at large scale.

“We could see inside people’s garages and their private properties,” said another former employee. “Let’s say that a Tesla customer had something in their garage that was distinctive, you know, people would post those kinds of things.” […] About three years ago, some employees stumbled upon and shared a video of a unique [object] inside a garage, according to two people who viewed it.

Stumbled? Like the employees were drunk?

Two ex-employees said they weren’t bothered by the sharing of images, saying that customers had given their consent or that people long ago had given up any reasonable expectation of keeping personal data private. Three others, however, said they were troubled by it.

“It was a breach of privacy, to be honest. And I always joked that I would never buy a Tesla after seeing how they treated some of these people,” said one former employee.

Another said: “I’m bothered by it because the people who buy the car, I don’t think they know that their privacy is, like, not respected … We could see them doing laundry and really intimate things. We could see their kids.”

Drunk with cruelty from abuse of power. In related news, Gartner is strongly advising companies to “weaponize” privacy — encouraging competitors to shoot Tesla dead.

“Weaponise privacy as a prospect conversation tool and a competitive advantage,” said Neubauer. “By making privacy a key part of your customer value proposition, privacy has become a conviction-based motivator for buyers. Just as people reach for organic or cruelty-free products, consumers are willing to go out of their way, and in some instances, pay a premium for a product they believe will care best for their data.”

Cruelty-free products? Pretty sure Gartner just defined Tesla as a cruel and worthless product that doesn’t care for privacy.

Data Integrity Breaches Are Killing Trust in AI

Here’s the money quote from Roger McNamee

So long as we build AIs on lousy content, the results are going to be lousy. AI will be right some of the time, but you won’t be able to tell if the answer is right or wrong without doing further research, which defeats the purpose.

I generally disagree with a GIGO (garbage in, garbage out) meme, but here I love that McNamee calls out the lack of value. You ask the computer for the meaning of life and it spits out 42? Who can tell if that’s right unless they do the math themselves?

Actually, it gets even better.

Engineers have the option of training AIs on content created by experts, but few choose that path, due to cost.

Cost? Cost of quality data?

That’s a symptom of the last decade. Many rushed into an unregulated “data lake” mentality to amass quantity (variety and volume at velocity), with a total disregard for quality.

Get as many dots as possible so you can someday connect them (a sort of rabid data consumption and hoarding mindset) gradually has given way to collect only the things you can use.

While McNamee claims to be writing about democracy, what he’s really saying is that the market is ripe for a data innovation revolution that reduces integrity breaches.

Technology solutions desperately need to be brought into such “save our democracy” discussions, rooted in practical solutions.

A simple example is the W3C Solid protocol. It’s technology that gives real and present steps towards the right thing to do; gets AI companies far ahead of the baseline of safety now looming from smart regulators like Italy.

Taking regulatory action against one of the worst abusers of users, OpenAI, is definitely the right move here.

Last week, the Italian Data Protection Watchdog ordered OpenAI to temporarily cease processing Italian users’ data amid a probe into a suspected breach of Europe’s strict privacy regulations. The regulator, which is also known as Garante, cited a data breach at OpenAI which allowed users to view the titles of conversations other users were having with the chatbot. There “appears to be no legal basis underpinning the massive collection and processing of personal data in order to ‘train’ the algorithms on which the platform relies,” Garante said in a statement Friday. Garante also flagged worries over a lack of age restrictions on ChatGPT, and how the chatbot can serve factually incorrect information in its responses. OpenAI, which is backed by Microsoft, risks facing a fine of 20 million euros ($21.8 million), or 4% of its global annual revenue, if it doesn’t come up with remedies to the situation in 20 days.

It’s the right move because breach reported by users of OpenAI is far worse than the company is admitting, mainly because integrity failures are not regulated well enough to force disclosure (falling far behind confidentiality/privacy laws).

20 days? That should be more than enough time for a company that rapidly dumps unsafe engineering into the public domain. I’m sure they’ll have a fix pushed to production in 20 hours. And then another one. And then another one…

But seriously, systemic and lasting remedies they need (such as building personal data stores so owners can curate quality) have been sitting right in front of them. Maybe the public loss of trust from integrity breaches, coupled with regulatory action, will force the necessary AI innovation.

Ukrainians decisively reject Russian narratives of internal divisions

Here’s some context in a new Carnegie Europe report for the recent Russian Telegram star assassination.

Established within the National Security Council in 2021, the Center on Countering Disinformation debunks Russia’s manipulative and misleading narratives, including through social media platforms. This is a formidable task as many of these platforms, especially Telegram, have become a safe haven for disinformation due to lack of scrutiny and proper moderation policies.

Especially Telegram.

The tone of this report emphasizes how Ukraine easily regulates and rebuffs disinformation using curated sources of trusted information.

Investigative journalists and civil society organizations, such as StopFake and Detector Media, complement governmental efforts in checking facts and providing accurate information. A December opinion poll found that Ukrainians, including in the most vulnerable southern and eastern regions, decisively reject Russian narratives of internal divisions and Western betrayal of the country.

We see Ukraine described in terms of protecting the most vulnerable and preventing harms.

The report continues to say heavy regulation, including forced breakup of oligarchial control over media, is Ukraine’s charted path for freedom of speech.

Ukraine’s resilience in the information war has created momentum for deepening reforms to preserve media freedom and pluralism of views. As a part of the conditionality for membership, the EU called for introducing legislative norms that would regulate the media sector in accordance with its directives in this field. In December 2022, the parliament passed the required law. If properly implemented, the law would not only strengthen the instruments to counter Russian disinformation but also develop norms to ensure transparency and the independence of media from undue political influence.

All of this points towards Russia being the most likely motivated assassin of its own journalists.

First, it’s the common tool of Putin. Second, the Russian victim early could have stepped over a line that triggered the dictator’s press-killing secret police. Third, internal divisions in Russia are growing severely over bungling mismanagement of war with Ukraine.

The question about the assassination is really how could it not be Russians killing each other? Ukraine hasn’t needed to resort to such tactics, given its commanding control over the information domain.

While Ukrainians show steady resistance to narratives of internal division, Russia (like a Tesla factory) viciously attacks its own top performers to kill speech about obvious internal fragmentation.

That being said, an explosion is uncommon and unusual for Russian state assassins. It’s somewhat significant for being in a Russian city lounge being “guarded” by far-right miltants.

The attack carries hallmarks of Russian domestic anti-war extremists.

The primary target wasn’t a journalist or reporter in the usual sense. He had been a coal miner and jailed in Ukraine for bank robbery. In 2014 he “escaped” with Russian help to become a militant separatist within Ukraine. His Telegram role essentially was Russian puppet coddled by military handlers inserting him into high-risk war zones to generate disinformation. You can see why he thought he was safe and where.

Obviously the victim being targeted while in a plainly vulnerable Petersburg cafe, surrounded by at least two dozen of his fans (13% of Russian Telegram users are in that city, second only to Moscow), sends a strong message of resistance to Russians.

Or as Ukrainians have expertly explained:

“Spiders are eating each other in a jar,” Ukrainian presidential adviser Mykhailo Podolyak wrote in English…. “Question of when domestic terrorism would become an instrument of internal political fight was a matter of time.”

A Ukrainian pro-Russian militant extremist propaganda leader, who promoted killing civilians (“we will kill everyone, we will rob everyone”), seems to have been killed in a civilian setting by Russian anti-war militant extremists.

An assassination doesn’t fit within increasing Ukrainian success in disarming disinformation at every level. I mean they wouldn’t have any real need to expend the kind of heavy effort to physically target such a mediocre blogger from Moscow visiting his Petersburg fans.

That doesn’t mean it wasn’t Ukraine, just that it has stronger hallmarks of local action. And if Russian authorities crack down even harder on expression now, it becomes increasingly difficult to argue any increase in incidents inside Russia isn’t inevitable domestic resistance.

I’ve been asked about the explosive, and it seems far too early to make that kind of call. I’m reminded of giving a talk at a mystery writer’s conference about how to hack into computers, where the distinguished speaker immediately before me was an explosives expert describing how to assassinate people (mostly with cars). Apparently there’s some kind of shared theme here? My, how times change.

We certainly know the target was killed with 30 people around him injured, suggesting very high precision planning. Since the statue was unexpected as a shiny gift in a box, and in the image of the target himself, it seems an obvious play on a Telegram star’s glaring insecurity — curated, not just plain explosives. And there does seem to be a thread that suggests the statue was part of a compound attack, somehow causing the target highest proximity harm from an earlier planted incendiary.

But what do I know about those things, I’m just the computer guy who studies information integrity.

“Pontiac Aztek of Trucks”. Eight Tesla Semis Already Broken Down. Operators Pan Dumb Design

Any big rig is going to require maintenance.

Truckers, much like farmers, expect repairs and breakdowns to come with the complexity of their machinery.

I mention farmers because of their right-to-repair precedent and ongoing litigation.

In that context you’d think the Tesla Semi being observed broken down wouldn’t cause any concern beyond the usual $10-20K annual operating schedule.

Except there’s a giant problem.

Tesla promoted its trucks as far less or even no maintenance, and then required any work be done only by them. Breaking down often (even if it is still less than a diesel) immediately undermines their entire value pitch, especially because it was built on a monopolist cost model (artificial scarcity).

If your truck is towed every month for a $20K repair that you can’t argue with… that’s just a slimy snake-oil subscription model you didn’t sign up for. Tesla right now looks like a dangerous trap.

Indeed, the reported breakdown of at least eight Tesla Semi in just the past couple months is related to dumb, distracting and totally vulnerable “infotainment” systems. What trucker is being trained to work on those? Tesla probably just throws them away and installs new ones they hope will break down soon, depending on a notoriously unreliable foreign supply chain. Everything operational runs on fragile wiring harnesses to a set of low quality screens prone to go blank. Screen failures then cause complete system shutdown until another big repair bill is footed.

Tesla failed to find qualified technicians inside the company, despite three years of delays in a closed monopolist model where everything is centrally planned. They have desperately posted ads for public help fixing breakdowns. Source: Tesla Public Contempt Departmenr

Again, breakdown should have been something normalized and modeled for highly distributed field repairs a long time ago. The Tesla Semi was announced in 2017 with fanfare to revolutionize transit by 2019. Instead in 2018 they were… breaking down.

Tesla could have said back then that breakdowns are common and they are working on an “open road” plan so truckers are self-sufficient and unburdened.

Although, let’s be honest, if a trailer full of spare parts can’t help keep the truck running then something really, really stinks. Good thing they don’t build ships.

Instead of opening up more about the issues, Tesla used a top-down centrally planned tone to argue breakdowns aren’t real for them (not asleep at the wheel just driving eyes closed), that electric inherently should be easier to keep running (a lie — most vehicle fires are electrical), and that everything about their repairs has to be a giant, freedom-sucking secret.

Which national security desk is being briefed right now on country-wide Tesla hacks shutting deliveries down for weeks?

And thus, in these crucial first few months of “production” operations, their breakdowns are actually a giant ugly problem. A business and engineering disaster. It’s not really new, either.

They launched three years late, slowly delivering something they said was going to be amazing and worth the loooong wait, yet out of the gate it can’t stay on the road.

On top of truckers pointing out how backwards and stupid a monopolist repair model is for long-hauling (e.g. none of the tow trucks are controlled by Tesla), they also have a huge list of basic complaints.

That giant greenhouse window collecting sun and precipitation yet impossible to shade or clear, inability of greenhouse windows to open fully, door awkwardly shifted behind the seat, mirrors stuck like an afterthought in a position too far to clean, lack of rest space, center seating stupidly buried away from everything, depending on touch screens for everything… the obvious trouble list goes on and on.

Everything I have read so far suggests nobody at Tesla understood Semi driving before designing this. Fun fact? The head of Tesla Semi claims zero experience in the trucking industry. Semi announced 2017 for a 2019 release? Sheltered inside Tesla almost his entire five year career, Semi is his first real project after graduating college (BS 2009), ladies and gentlemen.

Source: Microsoft

I guess this cartoonish thing answers the question of what Stanford teaches?

I’m still looking at those mirrors sticking out awkwardly and thinking about the CEO spreading “no exterior mirrors” disinformation about the future, encouraging owners to break laws by removing them. Tesla often promotes breaking the laws today as their concept of becoming “future proof” for a fantasy world they dream about. If only they had learned why mirror safety isn’t even remotely solved by vulnerable screens that abruptly fail unsafely… they wouldn’t have had to stick those giant ugly bandaids over the problems they created.

Such fantasy games are downright dangerous. The sheer fact that Tesla again created an intentionally deceptive video (refusing to disclose details about Semi) to keep investors hooked on a trucking fantasy should be treated as criminal (e.g. Advanced Fee Fraud). Hello, FTC?

In conclusion, Tesla has created the Pontiac Aztek of trucking. Except it will cost 10X any other truck because of a hidden subscription system that is designed for abuse and exploitation of owners.

Anyone buying into this is clearly not thinking clearly. There’s nothing positive to report about the Tesla Semi. Boasts about it being reliable and efficient not only seem flagrantly untrue, the breakdowns end up being tied to a Stanford-like diabolical profit model that taxes owners just to keep their unstable rig on the road.

A badly broken Tesla concept vehicle and it’s operator wait on artificially constrained repairs. Source: Tesla Department of Public Contempt

Update March 31: Tesla just three months after pushing its years late product to market has issued a recall for its Semi because the brakes fail. Specifically the brake in park doesn’t activate, so the NHTSA warns a Semi can roll away.

Tesla recalls lately have been for the steering wheel, seatbelts and brakes. Just the little things.