BlackVue dashcam shows anyone everywhere you are in real time and where you have been in the past

An app that is supposed to be a fun activity for dashcam users to broadcast their camera feeds and drives is actually allowing people to scrape and store the real-time location of drivers across the world.

BlackVue is a dashcam company with its own social network. With a small, internet-connected dashcam installed inside their vehicle, BlackVue users can receive alerts when their camera detects an unusual event such as someone colliding with their parked car. Customers can also allow others to tune into their camera’s feed, letting others “vicariously experience the excitement and pleasure of driving all over the world,” a message displayed inside the app reads.

Users are invited to upload footage of their BlackVue camera spotting people crashing into their cars or other mishaps with the #CaughtOnBlackVue hashtag. It’s kind of like Amazon’s Ring cameras, but for cars. BlackVue exhibited at CES earlier this month, and was previously featured on Innovations with Ed Begley Jr. on the History Channel.

But what BlackVue’s app doesn’t make clear is that it is possible to pull and store users’ GPS locations in real-time over days or even weeks. Motherboard was able to track the movements of some of BlackVue’s customers in the United States.

The news highlights privacy issues that some BlackVue customers or other dashcam users may not be aware of, and more generally the potential dangers of adding an internet and GPS enabled device into your vehicle. It also shows how developers may have one use case for an app, while people can discover others: although BlackVue wanted to create an entertaining app where users could tap into each others’ feeds, they may not have realized that it would be trivially easy to track its customers’ movements in granular detail, at scale, and over time.

BlackVue acts as another example of how surveillance products that are nominally intended to protect a user have been designed in such a way that can end up in a user being spied on, too.

“I don’t think people understand the risk,” Lee Heath, an information security professional and BlackVue user told Motherboard. “I knew about some of the cloud features which I wanted. You can have it automatically connect and upload when events happen. But I had no idea about the sharing” before receiving the device as a gift, he added.

Ordinarily, BlackVue lets anyone create an account and then view a map of cameras that are broadcasting their location and live feed. This broadcasting is not enabled by default, and users have to select the option to do so when setting up or configuring their own camera. Motherboard tuned into live feeds from users in Hong Kong, China, Russia, the U.K, Germany, and elsewhere. BlackVue spokesperson Jeremie Sinic told Motherboard in an email that the users on the map only represent a tiny fraction of BlackVue’s overall customers.

But the actual GPS data that drives the map is available and publicly accessible.

1579127170434-blackvue-user-gps
A screenshot of the location data of one BlackVue user that Motherboard tracked throughout New York. Motherboard has heavily obfuscated the data to protect the individual’s privacy. Image: Motherboard

By reverse engineering the iOS version of the BlackVue app, Motherboard was able to write scripts that pull the GPS location of BlackVue users over a week long period and store the coordinates and other information like the user’s unique identifier. One script could collect the location data of every BlackVue user who had mapping enabled on the eastern half of the United States every two minutes. Motherboard collected data on dozens of customers.

With that data, we were able to build a picture of several BlackVue users’ daily routines: one drove around Manhattan during the day, perhaps as a rideshare driver, before then leaving for Queens in the evening. Another BlackVue user regularly drove around Brooklyn, before parking on a specific block in Queens overnight. The user did this for several different nights, suggesting this may be where the owner lives or stores their vehicle. A third showed someone driving a truck all over South Carolina.

Some customers may use BlackVue as part of a fleet of vehicles; an employer wanting to keep tabs on their delivery trucks as they drive around, for instance. But BlackVue also markets its products to ordinary consumers who want to protect their cars.

1579127955288-blackvue-live-feed
A screenshot of Motherboard accessing someone’s public live feed as the user is driving in public away from their apparent home. Motherboard has redacted the user information to protect individual privacy. Image: Motherboard

BlackVue’s Sinic said that collecting GPS coordinates of multiple users over an extended period of time is not supposed to be possible.

“Our developers have updated the security measures following your report from yesterday that I forwarded,” Sinic said. After this, several of Motherboard’s web requests that previously provided user data stopped working.

In 2018 the company did make some privacy-related changes to its app, meaning users were not broadcasting their camera feeds by default.

“I think BlackVue has decent ideas as far as leaving off by default but allows people to put themselves at risk without understanding,” Heath, the BlackVue user, said.

Motherboard has deleted all of the data collected to preserve individuals’ privacy.

Source: This App Lets Us See Everywhere People Drive – VICE

PopSockets CEO calls out Amazon’s ‘bullying with a smile’ tactics, shows how monopolies are bad for competition

Amazon has a “bullying” problem.

So insisted PopSockets CEO and inventor David Barnett today while describing his company’s relationship with the e-commerce and logistics giant. Barnett was addressing members of the House Subcommittee on Antitrust, Commercial, and Administrative Law and, over the course of the hearing, laid out how the Jeff Bezos-helmed corporate behemoth had pressured his smartphone accessory company in a manner best described as incredibly shady.

Barnett was joined by executives from Sonos, Basecamp, and Tile, who all took turns airing a list of grievances against major tech players such as Amazon, Apple, Facebook and Google. They all recounted, in manners specific to their respective companies, how the major tech players have used their market dominance to squeeze smaller competitors in allegedly anticompetitive ways.

The CEO of PopSockets, however, appeared to have a personal beef with Jeff Bezos (which he pronounced “Bey-zoo”).

“Multiple times we discovered that Amazon itself had sourced counterfeit product and was selling it alongside our own product,” he noted.

Barnett, under oath, told the gathered members of the House that Amazon initially played nice only to drop the hammer when it believed no one was watching. After agreeing to a written contract stipulating a price at which PopSockets would be sold on Amazon, the e-commerce giant would then allegedly unilaterally lower the price and demand that PopSockets make up the difference.

Colorado Congressman Ed Perlmutter asked Barnett how Amazon could “ignore the contract that [PopSockets] entered into and just say, ‘Sorry, that was our contract, but you got to lower your price.'”

Barnett didn’t mince words.

“With coercive tactics, basically,” he replied. “And these are tactics that are mainly executed by phone. It’s one of the strangest relationships I’ve ever had with a retailer.”

Barnett emphasized that, on paper, the contract “appears to be negotiated in good faith.”

However, he claimed, this is followed by “… frequent phone calls. And on the phone calls we get what I might call bullying with a smile. Very friendly people that we deal with who say, ‘By the way, we dropped the price of X product last week. We need you to pay for it.'”

Barnett said he would push back and that’s when “the threats come.”

He asserted that Amazon representatives would tell him over the phone: “If we don’t get it, then we’re going to source product from the gray market.”

In other words, as with so many things Amazon, it’s either play ball or get bent according to Barnett.

An Amazon spokesperson reached for comment, unsurprisingly, framed the issue differently.

“We sought to continue working with PopSockets as a vendor to ensure that we could provide competitive prices, availability, broad selection and fast delivery for those products to our customers,” read the statement in part. “Like any brand, however, PopSockets is free to choose which retailers it supplies and chose to stop selling directly through Amazon.”

Essentially, in Amazon’s view, PopSockets chose to get bent. We should all be so lucky to be offered such a choice.

Source: PopSockets CEO calls out Amazon’s ‘bullying with a smile’ tactics