Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I would like to see some legal and regulatory steps. When we purchased our Ioniq, there was no agreement for data sharing, etc. - we have basically a cash register receipt, nothing more.

Whenever there is a major update, an insanely long T&A appears on the screen. No one is going to read it. The only options are "accept" or clicking it away. If you click it away, it comes back the next day. It cannot possibly be legal for them to basically force T&A - a one-sided contract change - on customers.



We need judges to start growing a backbone and declaring these one-sided "agreements" unconscionable. The company has outsized power over the purchaser, the terms tend to be one-sided, and there is no meaningful choice to the purchaser. These things should be clear cut cases of unconscionability, and judges should be throwing them out left and right and penalizing the companies who try to push them.


It's arguably a violation of the CFAA.


It wouldn't be a very solid argument. Telematics are universally disclaimed in owners manuals. A good chunk of modern owners manuals are legally-required disclaimers of various sorts which are all deemed valid for those reasons.

And a ruling that it doesn't matter because "nobody reads that" wouldn't be a good thing either -- basically that would make most SaaS engineer into criminals.


So I can put a disclaimer in remote shell malware I distribute on the internet and get out of a CFAA violation? I don't think that's quite right. A lot of this software is very clearly malware, that it's shipped by the manufacturer and includes documentation doesn't change that IMO.


Yes, a lot of software has remote access capability and it is legal when intended. The CFAA doesn’t care about how it works or why. It entirely hinges on whether the access was authorized. Your opinion about whether the software is good or bad is legally irrelevant.


Good to know, I guess I'll write an .ssh/id_rsa harvesting worm and chuck it in a pip package tonight with a license that includes a clause requiring surrender of any machine its installed on.


The intent and the totality of what you are doing matters. And worms, by definition, run on computers without authorization.


Further:

Safer roads and more convenient travel comport with public policy; and,

No one in 2025 has a reasonable expectation they are not being surveilled by their new car.

(FWIW, I’m against surveillance transport but there is no reasonable way to say these contracts of adhesion are unconscionable under US law).


> No one in 2025 has a reasonable expectation they are not being surveilled by their new car.

This is not even slightly true. People are barely aware of the fact their car has any connectivity in the first place, let alone that it tracks everything you do in a way that's tied to your real life identity.

You're probably, talking mostly to us "techies". Anyone else probably wouldn't be too surprised if you told them, but they definitely wouldn't expect it to be like that.


They don’t have a reasonable expectation of buying a surveillance-safe new car because one does not exist.

Other than that I hear you. You’re talking about the reasonable expectation in someone’s head but I’m talking about the possibility even existing in the marketplace. I guess you could argue maybe the reality of the market is trumped by the opinion of a person as to the reality of the market. I’m not sure that makes sense (or that ut doesn’t).

I guess you’re saying “they do have that expectation” while I’m saying “regardless of anyone’s expectation, car manufacturers have all addressed the market in a way that makes the expectation false and therefore unreasonable.”


> You’re talking about the reasonable expectation in someone’s head

The legal concept of a person's "reasonable expectation" is literally this. But it doesn't really matter legally, because these systems are explicitly disclosed in the documentation that automakers provide.


That’s not correct: both the objective and subjective reasonable expectation are implicated. If the objective standard was not relevant, why would it matter if the manufacturer made the disclosure you mentioned?


> If the objective standard was not relevant, why would it matter if the manufacturer made the disclosure you mentioned?

We’re talking about it because you brought it up, but it generally does not apply to data privacy in the US.

Courts recognize that peeping toms can’t look into your window, but ad tech absolutely can track data about you, in your car, or even your home.


The status quo is, as long as clickthroughs don't hurt the consumer then and there, they are valid. Can you imagine if this status quo were upended? Chaos. The end result would be a uniform agreement, kind of like the GDPR, but more expansive, and guess what: the scope of what clickthroughs will permit would be expanded, not constrained.

This thing about judges... if you brought a complaint to court that doesn't show any harm, you'll get the opposite result that you want: judges will expand the legality of clickthroughs. This is what happens, without a doubt.

Privacy advocates have numerous strategic failures. One is failure to show meaningful harm of specifically the data gathering permissions in these clickthroughs, in any legal venue, anywhere. The harms have always been of other issues, like a data breach, and even then, the harms amount to ones of dollars per person, in places where judges have approved data breach settlements. Another failure is of leadership/education: they cannot communicate the very simple idea to the public that there is privacy in the sense of limiting government overreaching versus privacy in the sense of limiting dissemination of embarrassing personal information. There are so many steps in this privacy mission before the judges.


Absent something like a component of the GDPR, I'd highly doubt the judiciary in any country is going to originate a major civil right.

The correct place ELA / T&A consent should be defined is in something like the GDPR -- along with strict requirements as to what standard of consumer free choice is required for it to be enforceable.


I would prefer to take it broader and codify it in law that:

1. The terms and conditions of a product, service, etc. "primarily" aimed at a consumer have simple, human readable terms. Like a food label or similar to the broadband label.

2. The terms are presented and acknowledged PRIOR to purchasing (not after opening the package, driving off the lot, putting the DVD into the player). The company needs to find a way to deliver the T&C's before purchase. If you need me to agree to 50 pages things before I can use your product, I didn't really purchase it, I am receiving a license to use it....

3. If these terms and conditions will be changed retroactively (for existing customers) that must be optional, opt-in and not required to continue to use the product.

I think this would stop a lot of the shenanigans companies pull on end users, that they DON'T pull in B2B environments.


This still puts the company too much in the driver's seat. An actual "contract" or "agreement" is supposed to be a meeting of the minds between two parties. It's not simply one-sided terms dictated by one party without opportunity for the other party to negotiate. And each party should have negotiating power and choice beyond "take it or leave it".

And, before you dismiss this idea with "Ha ha imagine if every cell phone provider had a custom, bespoke, negotiated contract with each customer! It can't be done!"

If providing real negotiating power and choice to your customer is too much of an overhead burden, then maybe the company should not be allowed to make the "agreement" a condition for buying/using the product.


> And, before you dismiss this idea with "Ha ha imagine if every cell phone provider had a custom, bespoke, negotiated contract with each customer! It can't be done!"

This actually already happens to some extend. Nor a different contract for every individual user but my mobile phone plan is not one you can currently purchase from the provider but just available to existing customers who have been upgraded (more data for the same price as the original contract).


It's not the judges job to bring a case before the court.

What we actually need is a Consumer Protection Alliance that is made by and funded by people who want protection from this and are willing to pay for the lawyers needed to run all of the cases and bring these cases before a judge over and over and over again until they win.

This would mean people like you and me and a million others of us paying $20-$50/month out of pocket to hire people to sue companies that do this shit.


Nullifying the agreement isn't enough because companies will still try to trick people into believing they are bound to it. There need to be actual consequences for even trying such bs - essentially this needs to be recognized as a type of fraud.


This is the kinda of thing that was preventing me from seriously considering Tesla. I accept that there is a lot more tech involved so some updates are necessary, but turning cars into cells on wheels made everyone way too eager to not ship finished product.


>> but turning cars into cells on wheels made everyone way too eager to not ship finished product.

I knew a former manager of OTA (over the air updates) at one manufacturer. I said that needed to be used for emergency updates only and not so people could be late with features or QA. She totally agreed and said it was becoming a battle with all the software teams thinking it meant they could be late and it'd be OK. They think it makes the deadline fuzzy or non-existant.


I looked at a company that did this stuff with a box that could remotely power up/down and unlock / lock a vehicle. They never even thought to check whether the vehicle was in motion or not, that's how confident they were that they'd never ever make a mistake.


If there's one device/product in my life that I do not want to have reliant on CI/CD, that I want delivered to me in a fully finished and ready to go condition where I can trust that absent material breakdown will stay exactly the same, it's my car.

Update your apps all you want. Change the layout. Betray your users and sell their data to AI, whatever, the consequences are on you.

Update my car, change its performance or range or the layouts of the buttons in the infotainment system so that I might be distracted or expecting an outcome that is suddenly no longer possible and I or the people I injure in the accident have to live with the consequences for the rest of our lives.


I would love for there to be a robust jailbreak community for tesla cars.

I've also heard that the defunct fisker cars might have this sort of hacking community - you might be able to get the source code for the car.


I've been told T&A after you bought a product is actually not legal in the EU. The popups still appear, and everyone clicks thorugh. It can't be legal. Whatever they want me to agree with, they have to force me at checkout time. Everything beyond that is plain ransomeware.


It kind of depends; there's a difference between Europe and the EU, for one. But there are also things you can hide away in the T&C and privacy statements, while other stuff (usually involving PII) needs explicit consent and opt-outs.

The EU mandates the presence of an emergency cellular radio on board of new vehicles in case of crashes. It took some convincing, but that radio is now supposed to be off by default.

You can demand a refund for Windows keys that came along with your computer if you disagree with the ToS (which has been tested by a French court IIRC), and that ability is actually included in the Windows EULA these days, but getting that kind of thing enforced will be draining. Repeated calls and repeated emails at the very least, filing complaints and threatening legal action if the vendor doesn't want to comply.


I recently had a similarly unfriendly experience in my inlaws' new Lexus, which has an accompanying mobile app for vehicle management and some advanced setup features. How did we learn about this almost completely required app & mobile setup process? If you start driving with Google Maps via Android Auto it will terminate the AA interface after a few minute and replace it with a nag screen about setting up the Lexus mobile software. There is no alternative but to comply.


> There is no alternative but to comply.

Maybe not within the confines of the head unit but you can still stick your phone onto the dash like I do in my (dumb) cars.


I bought a 2020 car recently. It comes with Android Auto, whereas previously I'd just mount my phone to the dashboard. But with Android Auto, every time the voice gives out a navigation instruction, music playing from the infotainment is paused; in my previous car the voice would play from my phone, on top of the music coming out of the car's sound system.

So I've ordered a mount so I can mount my phone to the car again...


Android auto also prevents you from typing in a new destination while driving. Because no one ever has a passenger that can do that for you, right?


The story is still infuriating. You can't use what you paid for, unless you comply with what the manufacturer wants.


Oh, I agree that it's infuriating, frustrating and disappointing. My US-based stance is that, while there have been some encouraging developments on the right-to-repair front, more generally the rollback/demonization of regulations, de-fanging of CFPB et al all project a future where this sort of behavior is the norm for an ever increasing number of "critical" devices and we have no recourse. So, I think we have to be ready to vote with our dollars and reject these options, bend these devices to our will when it's possible and work around them when it's not.


Is there truly no way to disable the nag screen for those that don’t care about the advanced features?


Thanks for the heads-up ... I've been drooling over an ioniq 5 (ideally N) for quite some time as an excellent alternative to the Douche-la.

But this kind of thing really puts me off ...

I've been maintaining a 2005 Toyota and a 1969 Vw Beetle ... no worries about fucking T&C's or T&A's ... looks like I'll continue the maintenance regime, which I kind of enjoy anyway.


Nissan Leafs are I think the most DIY friendly EVs, certainly 1st generation, and also 2nd, but 3rd generation that is coming soon … not so much. Anyway 1st and 2nd can definitely be completely offline and there are significant online communities of tinkerers and even open source tools to interact with them.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: