John's avatar
John
truthinlogicbtc@nostrplebs.com
npub19zzz...z0pm
Conquer your ontological shock... Learn digital privacy - @npub1fvdyln3fhscsmlkzd2h3dchhlpvqkejmy83j2utxsvwq8m6nhkzsg4xydp
John's avatar
John 4 days ago
Adversarial thinking is seeping into the collective consciousness... this is very healthy. πŸ’ͺ The heroes will be slain, until we realize we do not need them.
John's avatar
John 1 week ago
Many are starting realize that newer cars are rolling surveillance devices... there is much attention on 2027, but it is ALREADY HERE. This is a Claude analysis I did for a friend. Beauty in simplicity, and beauty in analog. _____________ # Privacy & Telemetry Analysis β€” 2025 Cadillac XT6 *Working draft β€” v0.2. Built from GM's own privacy statements, FTC/state legal filings, GM service documentation, and owner-community teardown reports. Flag anything you want expanded, verified, or cut.* --- ## 1. Executive Summary The 2025 XT6 ships with an always-on cellular telematics module (OnStar) that is separate from any paired phone and active whenever the 12V battery has charge β€” not just when the engine is running. GM has been under sustained regulatory and legal pressure since 2024 for collecting precise geolocation and driving-behavior data and selling it to data brokers (LexisNexis, Verisk), who resold it to insurers. That specific sale pipeline has been shut down (GM ended it in April 2024; the FTC and California's DOJ have since banned it for 5 years), but the underlying collection infrastructure is still in the vehicle, and GM still collects data under its own privacy statement for many other stated purposes. There is no passive "government kill switch" built into this vehicle today. There **is** a subscriber-and-police-authorized remote slowdown/ignition-block feature (OnStar Stolen Vehicle Assistance). The more interesting question β€” addressed in Section 7 β€” is whether the *technical* pathway for that feature could be used outside its intended authorization process, or extended beyond what it does today. Short answer on both counts: the barrier is mostly software/procedural, not physical. There's documented precedent for GM's remote-command systems being compromised by outside researchers (Section 7b), and separately, the vehicle already has essentially all the hardware needed to go from "blocks the next engine start" to "reduces power or stops a moving vehicle on remote command" β€” because the harder version of that (safely slowing a moving vehicle while preserving steering/braking) already ships today as Stolen Vehicle Slowdown, and GM already pushes OTA software updates to the engine/transmission control module for unrelated reasons (Section 7c). Extending it further would very plausibly be a software and authorization change on hardware already in the field, not a new part. Physically disabling the module is possible but more involved on this platform than on many older vehicles, because GM's current electrical architecture ties the telematics module into a shared gateway with other modules (airbag system, driver-monitoring camera, ADAS map module). Details in Sections 4 and 10. --- ## 2. Connectivity Hardware & What It's Called | Component | What it does | Notes | |---|---|---| | **Telematics module ("VCIM" / "Communications Integration Module," CIM)** | The OnStar telematics unit: embedded 4G LTE cellular modem, GPS receiver, Bluetooth radio, Wi-Fi hotspot controller, microphone for voice/crash calls | Current GM service literature calls this the CIM; older documentation and forums use VCIM or "Telematic Communication Interface Control Module." Same part, different eras of naming. It is VIN-locked from the factory and listed under GM's option code UE1 ("OnStar equipped"). | | **Cellular carrier** | 4G LTE data connection | GM's OnStar system moved to 4G LTE connectivity starting in 2014, running on a commercial cellular carrier network rather than the owner's personal phone plan. | | **GPS** | Location fix | Shares the telematics module on most current GM vehicles; infotainment "privacy settings" on some model years allow disabling location services somewhat separately from disabling OnStar entirely. | | **Driver Attention System camera** | Infrared camera on the steering column, used by Super Cruise | Tracks head and eye movement to alert the driver if it detects inattention, and prompts the driver to steer manually if needed. **Trim-dependent:** Super Cruise (and this camera) is offered as part of the Platinum Package option on Premium Luxury and Sport trims β€” it is not standard across the whole XT6 lineup. On the fuse chart this is wired as its own "Driver Monitoring System Module" circuit (2022–2025 model years). | | **Super Cruise / ADAS stack** | Radar, cameras, LiDAR-sourced precision maps, GPS | Combines cameras, radar, GPS, and pre-scanned LiDAR highway map data to manage steering, braking, and acceleration on compatible roads; requires an active data connection for real-time positioning and periodic map updates. Also trim-dependent (see above). Note: the automatic/on-demand lane-change feature offered on some other Super Cruise vehicles is explicitly excluded on the 2022–2025 XT6, so even where equipped, it's the more basic version of the system. | | **myCadillac app / Vehicle Mobile App** | Remote start, lock/unlock, vehicle health reports, location | Runs through the same OnStar/GM cloud backend. | Core OnStar connectivity now comes bundled for a long default period on new Cadillacs: core OnStar features are included on all 2025-and-newer Cadillacs for 8 years, plus 3 years of OnStar One and Super Cruise (where equipped). That's a long window before an owner would hit a paywall that might otherwise force an active decision either way. --- ## 3. What Data Categories Are Collected Pulled from GM's U.S. Consumer Privacy Statement / Connected Services Privacy Statement and the FTC's complaint against GM: - **Precise geolocation** β€” GM increased what it collected through OnStar over time to include precise geolocation, gathered as often as every three seconds for some enrolled users during the Smart Driver program's operation. This is the single most contested data category. - **Driving behavior** β€” trip dates, start/end times, vehicle speed, distance driven, hard braking, rapid acceleration, late-night driving, and speeding events. - **Seatbelt / occupant data** β€” seatbelt-use status was explicitly part of the (now discontinued) Smart Driver scoring. - **Vehicle diagnostics & service history** β€” service history, mileage, and diagnostic information disclosed when the vehicle is serviced. - **Voice/microphone data** β€” used for voice commands and hands-free calling through the telematics module. - **Driver attention / gaze data** β€” collected locally by the Super Cruise camera to generate alerts, on equipped trims. GM's public materials describe this as functional (not sold), but it's technically biometric-adjacent data captured in-cabin, and it flows through the same connected-services stack. - **App & infotainment usage, cookies/device identifiers** β€” GM's products use cookies, web beacons, pixels, and other tracking technologies that can identify a user across devices, including via IP address or VIN. - **Account/contact/demographic data** β€” collected at purchase, service visits, the My GM Rewards loyalty program, and OnStar enrollment. - **Radio listening data** β€” GM states it no longer collects this but retains previously collected data under its stated retention schedule. --- ## 4. How the Data Is Transmitted - The telematics module has its own embedded LTE modem and antenna β€” it does not depend on a phone being paired or present. - It's powered by the vehicle's main 12V system plus a small internal backup battery, so it can remain reachable and report certain events even briefly after main vehicle power is interrupted. - Under normal operation, data streams to GM/OnStar servers continuously or in short intervals whenever the vehicle has power β€” historically as frequently as every 3 seconds for geolocation during active Smart Driver enrollment; baseline OnStar connectivity (crash notification, remote commands, vehicle health reports) checks in on its own schedule regardless of that program's status. - Super Cruise (where equipped) additionally pulls down map data over the same connection and reports vehicle position for lane-precision purposes. --- ## 5. Who Has Access | Party | Basis for access | |---|---| | **GM / OnStar internally** | Product improvement, R&D, "future technologies like electric vehicles and autonomous driving," warranty administration, marketing/analytics β€” per GM's own stated purposes. | | **Emergency services / law enforcement (routine)** | GM's privacy statement lists sharing with emergency service providers β€” law enforcement, roadside assistance, ambulance providers β€” as a standard disclosure category, plus the Stolen Vehicle Assistance program described in Section 7. | | **Law enforcement (compelled)** | Separate from the above: GM can be legally compelled via warrant, subpoena, or court order to hand over stored location/vehicle data regardless of a customer's own privacy settings. Consumer-facing opt-outs are not a shield against compelled legal process β€” worth treating these as two different access paths, not one. | | **LexisNexis Risk Solutions & Verisk** | **Discontinued as of April 2024.** These brokers previously received driving-behavior and geolocation data and resold "driving scores" to insurers. GM is now barred from this specific sharing for 5 years under the FTC order (through roughly 2031) and has been separately ordered to ask both brokers to delete GM-sourced data under a 2026 California settlement. | | **Insurance companies** | Indirectly, via the brokers above (now curtailed for the stated term). | | **Research/academic partners** | GM says it sometimes shares de-identified, anonymized data with select partners β€” e.g., the University of Michigan β€” for urban planning and road-safety research. | | **Dealers, financing partners, service providers** | Standard business-purpose sharing described in the privacy statement. | | **Third-party in-vehicle apps (Google Maps, SiriusXM, etc.)** | Governed by those third parties' own privacy policies once in use, not GM's. | --- ## 6. Legal & Regulatory Status (why this matters right now) This isn't a hypothetical concern β€” it's actively being litigated and enforced: - **January 2025, finalized January 2026:** the FTC brought its first-ever connected-vehicle-data action against GM and OnStar, alleging they collected and sold drivers' precise geolocation and driving-behavior data from millions of vehicles without adequate notice or consent. The final order requires GM to obtain affirmative consent before collecting connected-vehicle data, let consumers access and delete their data, allow disabling of precise geolocation where technically possible, and provide an opt-out β€” for 20 years, with a 5-year ban on selling this specific data category to consumer reporting agencies. - **State lawsuits:** Texas, Arkansas, and Nebraska filed suit earlier; Iowa's Attorney General filed in February 2026, alleging GM secretly collected and sold driving data from hundreds of thousands of residents without their knowledge, with dealership staff allegedly enrolling buyers during vehicle handoff without clear consent. - **California, May 2026:** GM agreed to a record $12.75M CCPA settlement β€” must delete retained driving data within 180 days absent express consent, ask LexisNexis/Verisk to delete GM-sourced data, and submit ongoing privacy assessments to regulators. - **GM's own posture:** GM says it has already consolidated many of its U.S. privacy statements into a single, simpler statement and expanded its privacy program to let customers access and delete personal information, framing the FTC terms as "measures that go above and beyond existing law." **Takeaway:** the worst publicly documented practice (silently selling driving/location data to insurers) was stopped by regulators, not proactively by GM. Everything else in GM's privacy statement β€” internal use, R&D, anonymized sharing, law-enforcement/emergency sharing, marketing β€” is still live, governed by consent captured at the dealership and tied to the vehicle's VIN. --- ## 7. Remote Vehicle Control / "Kill Switch" Capability β€” Policy vs. Technical Reality This is worth separating into two different questions: *what GM's stated process allows*, and *what the hardware and software are actually capable of*. ### 7a. The stated process OnStar's Stolen Vehicle Assistance requires, in order: (1) an active paid subscription, (2) the owner reporting the vehicle stolen to police, and (3) law enforcement confirming the theft and requesting OnStar's help. Only then can an OnStar Advisor send: - **Remote Ignition Block** β€” prevents the engine from starting on the next attempt; does not shut down a running engine. - **Stolen Vehicle Slowdown** β€” gradually reduces engine power to bring the vehicle to idle while preserving steering and braking, so it can be pulled over safely; can be re-enabled afterward at law enforcement's request. This is not a government mandate. It's a manufacturer-sold, opt-in service gated per-incident by police authorization β€” distinct from the separate, federally directed "advanced impaired-driving prevention technology" that Congress asked NHTSA to study, which as of 2026 still has no production implementation in any vehicle from any automaker. ### 7b. The technical reality underneath that process The important nuance: the thing gating Remote Ignition Block and Stolen Vehicle Slowdown is GM's **server-side authorization logic** β€” subscription status, billing, and a human confirming a police report β€” not a hardware fuse that only exists once those boxes are checked. The vehicle has to be *physically capable* of receiving and acting on an engine-power-reduction command at all times the module is powered and connected, because the feature has to work the instant law enforcement asks for it, on whatever car is stolen that day. That capability lives in the vehicle continuously; what's switched on or off is GM's willingness (and paperwork trail) to send the command, not the vehicle's ability to receive it. That distinction matters because of two documented precedents, neither of which is hypothetical: - **OnStar's own remote-command channel has been compromised before.** In 2015, researcher Samy Kamkar demonstrated "OwnStar," a device that intercepted communications between a driver's phone running the OnStar RemoteLink app and OnStar's cloud service, harvesting credentials and using them to remotely locate, unlock, and start the target's GM vehicle β€” without owner authorization. GM patched the specific server-side certificate-validation flaw involved, and by his own account the researcher couldn't drive the car away without a physical key. But it's a concrete example of an unauthorized party gaining functional remote command over a GM vehicle by attacking the authentication layer around a legitimate feature, not by defeating any hardware barrier. - **The Jeep Cherokee case (2015, a different automaker, same era) shows the more severe version of the risk.** Researchers Charlie Miller and Chris Valasek remotely compromised a Jeep's cellular-connected infotainment system and pivoted from there onto the vehicle's internal CAN bus, from which they could issue commands to steering, brakes, transmission, and more β€” while a journalist was driving the vehicle at highway speed, 16 km away from the researchers. That single demonstration triggered a 1.4-million-vehicle recall and reshaped how the whole industry designs vehicle networks, GM included: current GM electrical architecture (the "VIP" platform used across recent Cadillac/GM models) includes a dedicated gateway module specifically built to isolate safety-critical CAN networks from the infotainment/telematics side, precisely so a compromised telematics unit can't freely pivot into steering or brakes the way the Jeep's could. **Net assessment:** a modern GM vehicle's architecture is meaningfully hardened against the *Jeep*-style attack (telematics compromise cascading into full drivetrain/steering control) compared to 2015. But the *OnStar*-style attack β€” compromising the authentication around a legitimate, intentionally engineered remote-command feature (unlock/start, and by extension the ignition-block/slowdown channel) β€” is a different, narrower attack surface that has already been successfully demonstrated once against this same manufacturer's system, and there's no public evidence that category of risk has been eliminated, only that the specific 2015 vulnerability was patched. Whether today's authentication is adequate is essentially a question of how well GM's backend security holds up β€” which is a lower bar of trust than "physically impossible," and the same company whose data-handling promises were found by regulators to not match its practices for a decade. ### 7c. Could a Software Update Alone Turn "Won't Restart" Into "Shuts Down While Driving"? This deserves a straight technical answer, separated from speculation about GM's intentions: **the hardware prerequisites for that broader capability already appear to be present in this vehicle's architecture.** Whether it ever gets *turned on* is a policy/business decision, not an engineering one that would require new parts. Three concrete, sourced facts support that: 1. **GM already pushes OTA updates directly to the Powertrain Control Module, not just infotainment.** GM's electrical architecture (the Vehicle Intelligence Platform, layered with GM's "Ultifi" software platform) is explicitly built to deliver over-the-air updates to nearly every control module in the vehicle. This isn't theoretical β€” a real 2026-model-year GM service bulletin (Update 654.11, covering Buick/Chevrolet/GMC vehicles on the same general architecture family) documents an OTA release that changed Powertrain Control Module behavior in cars already in owners' driveways: transmission-protection logic, no-start diagnostics, check-engine-light triggers. The remote channel to change how the engine and transmission behave already exists and is already used routinely, for reasons that have nothing to do with theft recovery. 2. **The core actuation hardware for "the computer decides when the engine runs or doesn't" already exists and is routinely exercised β€” this is not exotic.** GM was an early adopter of electronic throttle control ("drive-by-wire"): the accelerator pedal doesn't mechanically connect to the engine at all; it sends a signal to the Powertrain Control Module, which commands a motor to open or close the throttle. The same PCM already has full authority to cut fuel, adjust throttle, and stop the engine on its own initiative today β€” that's exactly what Auto Stop-Start does at every red light on millions of GM vehicles, no remote command needed. Remotely triggering the same, already-existing engine-stop logic is a software/authorization question layered on top of hardware that's already there β€” not a new capability requiring new parts. 3. **The harder problem β€” doing this safely on a *moving* vehicle β€” is already solved and shipping, just gated to one use case.** Stolen Vehicle Slowdown isn't a future concept; it's a fielded feature that reduces engine power to bring a moving vehicle to idle on remote command, while preserving steering and braking. That's the genuinely difficult engineering problem (don't strand the driver without steering/brake assist mid-maneuver), and GM has already validated and shipped a solution to it β€” it's just currently authorized only for confirmed stolen vehicles at police request. Put together: the "next start only" limit on Remote Ignition Block looks less like a hard technical ceiling and more like a deliberate, conservative product choice β€” restart-blocking is lower-risk than intervening on a car already in motion, so GM shipped the cautious version for the everyday theft-recovery feature and the riskier "reduce power while moving" version only under tighter authorization (Slowdown). That's a reasonable design decision, but it also means the technical distance from where the car is today to "can be commanded to stop while running" is small β€” arguably already closed, under a different feature name and a narrower authorization gate. **Where this connects to actual law, not just hypotheticals:** Section 24220 of the 2021 Infrastructure Investment and Jobs Act is current, binding federal law (a January 2026 effort to defund it in the House failed) directing NHTSA to eventually require new vehicles to carry passive impairment-detection technology that can "prevent or limit vehicle operation if impairment is detected." NHTSA's and NTSB's own reporting on this explicitly frames "intervening once a vehicle is already in motion" as part of what the mandate contemplates β€” not merely blocking ignition at startup. As of 2026, NHTSA has repeatedly delayed the actual rule, and its stated reason every time is the same: passive, accurate impairment or blood-alcohol sensing isn't reliable enough yet. Nowhere in that public reporting is the vehicle-side control/actuation capability cited as the blocker. That's a meaningful asymmetry worth sitting with: the *detection* side of this kind of mandate is publicly, verifiably not ready; the *actuation* side, on a connected, drive-by-wire, OTA-updatable vehicle like this one, largely already is. **What this does and doesn't establish.** This is a structural observation about how software-defined connected vehicles are built generally β€” GM's included, but not unique to GM; most current "software-defined vehicle" platforms across the industry work the same way. It is not evidence that GM has secretly built or intends to activate a dormant "stop the engine on command" feature beyond what's already shipping as Stolen Vehicle Slowdown. But the underlying concern is legitimate and worth stating plainly: if a future law required the broader capability, the hard engineering work for a vehicle built like this one would likely already be done, and rollout could plausibly happen via a software update to hardware already in the field rather than a new part or a recall. The "plausible deniability" framing is really just describing normal engineering incentive β€” safety-critical systems get reused rather than rebuilt β€” but the practical result for an owner is the same regardless of motive: the capability doesn't require a different car, only different authorization logic on GM's servers. --- ## 8. Super Cruise: Does It Take Control From the Driver? Short answer: it's driver-assist, not autonomy, and it hands control back rather than seizing it β€” with a safety-fallback exception. - Trim-dependent (see Section 2): only relevant if the vehicle in question has the Platinum Package. - It's opt-in per drive (steering-wheel button); disengages instantly on brake tap or a second button press. - It requires the same OnStar/Cadillac Connected Services data connection for real-time positioning; vehicles include a bundled connectivity period, after which a paid plan is required to keep the feature functioning. - If the driver-attention camera detects prolonged inattention, the system escalates through visual, audible, and haptic warnings and will eventually bring the car to a stop at the roadside if the driver still doesn't respond β€” a safety fallback rather than the system "taking over" a normal drive. - As noted above, this XT6 generation is explicitly excluded from the automatic/on-demand lane-change feature offered on some other Super Cruise-equipped GM vehicles. --- ## 9. Does GM Rely on "Just a Privacy Policy" for Consent? Historically yes, and that's precisely what regulators objected to. Going forward, per the settlements: - Consent is now supposed to be captured at the dealership at time of purchase β€” OnStar gets linked to the vehicle's VIN and the buyer is asked to affirmatively agree or decline data collection at that point, rather than consent being buried in a clickthrough or an opt-out-by-default toggle discovered later. - Prior lawsuits specifically criticized language buried in a collapsed drop-down within OnStar's privacy statement β€” hidden by default β€” as inadequate disclosure for third-party data sharing. That's the exact practice the FTC and California settlements are meant to fix. - Practically: expect the substantive terms to still live in the privacy statement and connected-services statement, with the dealership moment functioning as a yes/no gate rather than a fully informed read-through. Worth checking actual sale paperwork for what was specifically signed, since dealership practices have historically varied (and were part of what several state AG suits allege). --- ## 10. Options to Reduce or Stop Data Collection, From Softest to Hardest | Level | Action | What's kept | What's lost | Confidence it actually stops transmission | |---|---|---|---|---| | **1. Software opt-out** | Log into the myCadillac app or a GM account β†’ Data & Privacy β†’ adjust geolocation/data-sharing settings; or call 1-866-MYPRIVACY (1-866-697-7482) or OnStar directly | Whatever isn't toggled off | Convenience features tied to whatever is disabled | Low–medium. Multiple GM owners across models report being told everything was "disabled" while the module's active-status light stayed lit and location data continued to update β€” treat app/phone opt-outs as a request sent to GM, not a guaranteed technical cutoff. GM's own statement also notes it may still collect geolocation in specific cases (e.g., emergency button press, high-voltage battery overheating) even after opt-out. | | **2. Formal data request** | Submit an access/deletion/opt-out request via GM's Consumer Privacy Request portal (gm.com/consumer-privacy) or 1-866-MYPRIVACY | Everything | Nothing directly | Addresses data already on file; doesn't by itself stop future collection | | **3. Cancel OnStar subscription entirely** | Call OnStar, cancel/unenroll | Basic vehicle functions unaffected | Crash notification, remote lock/start, Wi-Fi hotspot, Super Cruise (needs active connectivity), some app features | Medium β€” GM's statement notes it may still collect geolocation/vehicle info post-unenrollment in specific triggering events. | | **4. Pull the telematics fuse** | On 2020–2025 XT6 owner-sourced fuse charts, **F26 "Communications Integration Module (CIM)"** in the passenger-compartment fuse box (under the glove box) is the likely telematics circuit; **F11 "Driver Monitoring System Module"** (2022–2025) is the separate Super Cruise camera circuit | Most of the car | OnStar entirely, Wi-Fi, some voice features, possibly some Bluetooth microphone function, possibly the compass, and potentially fault-code warnings on shared circuits | Medium. Owner reports across GM models are inconsistent: some report a clean cutoff, others report the module's internal backup battery keeping some telematics function alive briefly after the fuse is pulled, and at least one owner reported the location indicator staying active after the fuse pull. **Confirm the exact fuse number against the specific vehicle's own fuse-box legend before pulling anything β€” GM's labeling has shifted across XT6 model years, and pulling the wrong fuse on a shared circuit can trip other systems (airbag-adjacent circuits on some GM platforms share fuses with telematics).** | | **5. Disconnect the module's antenna leads rather than pulling power** | Requires opening the dash/glovebox area and unplugging the antenna connectors from the module itself, leaving the module otherwise powered | Avoids some fault codes a full power-cut can trigger, since the module still boots normally β€” it just can't reach a tower | Cellular/data connectivity, Wi-Fi, remote features; GPS may persist if wired to a separate antenna | Higher confidence of killing the *transmission* specifically, at the cost of more disassembly | | **6. Full module removal** | Physically remove the telematics module and its internal backup battery | β€” | Everything above, until reinstalled | Highest, but the module is VIN-locked and part of GM's restricted-parts program, and improper removal/reprogramming can throw persistent fault codes on the shared CAN bus; likely affects lease/warranty terms | **Practical framing:** starting at Level 1–2 is cheap, reversible, and addresses the "what have they already got on file" question. Level 3 is the natural next step if the connected features aren't wanted at all β€” but note it doesn't fully sever the vehicle's ability to be reached, only GM's willingness to act on what it receives (see Section 7b). Level 4+ is only worth it if the analysis above concludes the residual technical exposure isn't acceptable even after canceling service β€” and even then, physical removal doesn't guarantee zero transmission if the backup battery or antenna paths aren't also addressed. --- ## 11. Why This Isn't a Simple Fuse-Pull Older telematics modules on some other vehicles were relatively isolated add-on circuits, so removing power to them had few side effects elsewhere. GM's current electrical architecture on this XT6 generation integrates the telematics module more tightly with: - the **Network/Serial Gateway Module**, which arbitrates CAN-bus traffic for many other modules and is also the piece specifically hardened post-2015 (Section 7b) to isolate safety-critical networks from the telematics/infotainment side, - the **Driver Monitoring System** for Super Cruise, on its own fuse but data-linked to the same infotainment/OnStar stack for map and connectivity data, and - the **Advanced Driving Integration Module (ADIM)** in the luggage-compartment fuse box, which supports the ADAS map subscription. That means an isolated fuse pull is more likely to throw diagnostic trouble codes elsewhere in the vehicle, and the cleanest disconnect (antenna-only, leaving the module logically "alive" but unreachable) takes more disassembly than a single fuse pull. This is a genuine platform difference from simpler, more modular telematics designs β€” not GM being arbitrarily more restrictive on paper. --- ## 12. Open Questions to Resolve as We Refine This - Which trim/options package is in question (Luxury / Premium Luxury / Sport / Platinum), since Super Cruise and Night Vision are optional and change what's actually wired into the vehicle. - Whether the goal is to keep Super Cruise and crash-notification (which require live connectivity) or to accept losing them entirely. - Whether to prioritize the formal GM data-deletion request (addresses what they already have on file) before doing anything physical. - Whether to pull the exact fuse-panel legend for a specific VIN's build before touching anything, since fuse assignments shifted between the 2020–2021 and 2022–2025 XT6 model years. - Whether to go deeper on the server-side/authentication side of Section 7b β€” e.g., what authentication GM currently uses for OnStar command channels, and whether any post-2015 audits or advisories are public. - Whether to dig further into Section 7c β€” e.g., GM's OTA update opt-out/consent mechanism (can an owner decline PCM-level updates specifically?), and whether GM's published Ultifi/OTA documentation says anything about update categories that require dealer/in-person action versus fully remote push. - Whether to track NHTSA's rulemaking docket on Section 24220 going forward, since a finalized rule would be the trigger point for any of this moving from "structurally possible" to "actually mandated." --- ## Sources - GM U.S. Consumer Privacy Statement β€” gm.com/privacy-statement - GM Connected Services Privacy Statement (PDF) β€” gm.com - FTC press releases, January 2025 and January 2026 β€” ftc.gov - TechCrunch, "The FTC's data-sharing order against GM is finally settled," January 2026 - CalMatters, "GM just paid a record penalty for breaking California privacy law," May 2026 - CX Today, "$12.75MN GM Customer Data Privacy Settlement Sets Record," May 2026 - GM Authority, "Iowa Attorney General Files Lawsuit Against GM Over OnStar Data Collection," February 2026 - Carscoops, "GM Faces New Lawsuit For Secretly Selling Your Driving Data," July 2025 - Insurance Journal, Arkansas lawsuit coverage, February 2025 - Cadillac.com β€” OnStar and Super Cruise product pages - OnStar.com β€” Stolen Vehicle Assistance pages - fuse-box.info β€” Cadillac XT6 (2020–2025) fuse assignment chart - GM TechLink / Vehicle Intelligence Platform documentation β€” on the Network/Serial Gateway Module's post-2015 security role - Engadget, Digital Trends, Dark Reading, Computerworld, Detroit News β€” 2015 "OwnStar" OnStar RemoteLink vulnerability coverage - Wired, Brookings, Kaspersky, Dark Reading β€” 2015 Jeep Cherokee Uconnect remote-hack coverage (Miller & Valasek) - Telematics Wire, Electrek, autoevolution β€” GM Vehicle Intelligence Platform (VIP) and "Ultifi" OTA software platform, including OTA reach into powertrain/body control modules - dot.report β€” GM Update 654.11 service bulletin (2026 Buick Enclave/Chevrolet Traverse/GMC Acadia), documenting a real OTA release modifying Powertrain Control Module behavior - Ricks Free Auto Repair Advice, CarParts.com β€” GM electronic throttle control ("drive-by-wire") fundamentals - Federal Register; NHTSA and NTSB reports to Congress on Advanced Impaired Driving Prevention Technology (Infrastructure Investment and Jobs Act, Section 24220); Kelley Blue Book and Dallas Express coverage of the rule's 2026 status - Various owner-forum threads (GM-Trucks.com, Chevy Bolt/Trax/Colorado forums, GM Volt Forum) on physical telematics-module disable procedures β€” anecdotal, not authoritative; verify against the actual vehicle before acting - Consumer Reports, "Stop Your Car From Collecting and Sharing Your Driving Data," 2025 *Note: fuse numbers and physical disassembly details from owner forums are anecdotal and vary by model year/build β€” verify against the actual vehicle's fuse panel legend before pulling anything.*
John's avatar
John 3 weeks ago
We are in the age of information warfare. On any given issue you will find noise pointing all directions, meant to distract and confuse. The only option is to be calm, and take your time to trace information back to verifiable fundamentals, no matter how much time or work that takes. Until then, be ok not knowing. Don't believe, don't "I feel like"... Know or don't know, either is ok. Then keep working towards knowing through the verification of fundamentals.
John's avatar
John 3 weeks ago
Are companies like Strike really Bitcoin companies, or are they just surveillance companies for Bitcoiners? Here is a Claude analysis from the latest Strike Privacy Policy https://strike.me/legal/privacy/ and Terms of Service https://strike.me/legal/tos/ : ⚑ Strike (strike.me) Privacy & ToS Breakdown β€” What You're Actually Agreeing To Before you use Strike, here's what the fine print actually says: πŸ“‹ Data They Collect Full legal name, DOB, address, email, phone, SSN/gov ID, bank account & routing numbers Photos of your government ID + facial geometry scans (biometric data) via their KYC partner (Persona) Your IP address, device identifiers, MAC address, location (inferred from IP), and full behavioral usage data Transaction history pulled from your linked bank account via third-party financial data providers Advertising partner data about your interests and behavior across other websites πŸ”— Where Your Data Goes Persona (KYC/biometric partner) β€” scans your face, stores it up to 3 years Checkout.com β€” processes card transactions under their own privacy policy Advertising networks β€” Strike explicitly shares your data for targeted ads across other platforms. You can opt out, but only for mobile, and only via a separate form Financial institution partners β€” vary by region, not named Business partners, professional advisors, analytics providers, and marketing companies Any acquirer in a merger or asset sale πŸ› Government & Law Enforcement Access Strike is a regulated Money Services Business (MSB) licensed with the NY DFS and registered with FinCEN. This means: They file Suspicious Activity Reports (SARs) with FinCEN, shared with the FBI, DEA, IRS, and ICE β€” and are legally prohibited from telling you this happened They comply with subpoenas, court orders, and government requests and will hand over your data The Travel Rule applies: if you send bitcoin to another exchange (especially in EU/UK), your name, address, and ID details go to the receiving institution OFAC sanctions screening of every user They explicitly reserve the right to "disclose any information necessary to satisfy any applicable law, regulation, Sanctions programs, legal process, governmental request, or law enforcement request" ⚠ Key Rights You're Giving Up No class action. The international TOS routes disputes to English courts (or El Salvador arbitration for El Salvador customers) β€” no US class action recourse for international users $100 liability cap. If Strike causes you losses of any amount, their maximum liability to you is $100 No consequential damages. Lost profits, trading losses, lost funds β€” all waived All transactions are final and irreversible β€” wrong address, lost funds, Strike bears zero responsibility They can freeze or terminate your account at any time, for any reason, including at a third party's request (e.g., a subpoena), and your funds may remain frozen indefinitely during an investigation They can change the TOS at any time β€” continued use = acceptance, even without direct notice to you You grant Strike a perpetual, irrevocable, worldwide license to use any content you upload to improve and market their services They can block you by IP or device ID at their sole discretion πŸͺ Tracking Uses cookies, web beacons, and pixel tags Does not honor Do Not Track (DNT) signals Shares data with advertisers for targeted advertising β€” you must opt out manually πŸ’‘ Bottom Line Strike is a legitimate, licensed fintech. But it is a fully KYC'd, AML-compliant, data-sharing, ad-supported, regulated financial surveillance platform. It collects biometric data, shares your info with advertisers and law enforcement, can freeze your funds without notice, caps its own liability at $100, and collects behavioral data across the web. That is not a criticism β€” it is what regulated financial services look like. But it is the opposite of financial privacy. If privacy is your priority, self-custody your bitcoin. ⚑🟠 image
John's avatar
John 0 months ago
This is an excellent podcast to start understanding the "Law Merchant" and the Lawful vs Legal paradigm we find ourselves in.
↑