Your car's data privacy problems are worse than you think
Researchers from Northeastern University and Consumer Reports tested 21 connected vehicles, finding that all transmitted data to third parties.

Stock photo for illustration only, not from the actual event
- Researchers tested 21 vehicles from 19 brands and found every single one transmitted data.
- Over half of the tested cars pinged advertising, tracking, and analytics companies.
- Infotainment platforms like Google Automotive OS contacted the highest number of third-party domains.
- Vehicle owners currently have very little visibility or control over this data tracking.
Modern cars are frequently described as smartphones on wheels, collecting vast amounts of data regarding driving locations, acceleration, braking severity, and steering habits. The legality surrounding this harvesting remains intensely contested, following last year's penalty issued by the Federal Trade Commission against General Motors for collecting and selling precise location data without informed consent, alongside minor fines given to automakers like Ford and Honda.
To investigate whether this practice extended industry-wide, researchers from Northeastern University, in collaboration with Consumer Reports, published an in-depth examination using nearly two dozen vehicles from CR's test fleet to track destination domains, cross-border transmissions, and exposed personally identifiable information.

Stock photo for illustration only, not from the actual event
David Choffnes, project lead and former director of Northeastern's Cybersecurity and Privacy Institute, explained that the primary goal was exposing the immense scale of vehicle data tracking and demonstrating how little control owners possess.
The team analyzed 21 late-model vehicles from 19 brands sold in the US, alongside 30 companion mobile apps. By placing a Raspberry Pi inside each vehicle and building a car-sized Faraday tent to block external cellular signals, researchers successfully monitored outgoing traffic during transit.
"I think the conclusion is that there's a lot to be worried about."
David Choffnes
The widespread transmission of telemetry data from modern automobiles to third-party data brokers highlights a growing regulatory blind spot in connected transportation. As vehicles increasingly integrate complex infotainment software and continuous cloud connectivity, consumer driving habits are routinely monetized by analytics firms and insurance providers without transparent opt-out mechanisms.
The findings revealed that all 21 vehicles transmitted data to at least one third-party domain over Wi-Fi, with over half contacting advertising and tracking entities such as Adobe, LexisNexis, and Amplitude. Furthermore, vehicles equipped with Google Automotive OS contacted the highest number of external domains due to built-in system routines communicating with external entities.
Source: The Verge
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment