Back Arstechnica This study looks at how and with whom connected cars share your data
In news that should surprise very few, connected cars remain a complete privacy nightmare. But now we have a better idea of what data those cars are giving away, and to whom, thanks to a study conducted by a team of researchers at Northeastern University and Consumer Reports . Testing 21 cars from 19 different brands revealed patterns of traffic to advertisers and trackers, as well as data shared with Big Tech firms like Microsoft and Adobe. And using a car’s companion app can multiply the problem, their testing found.
In 2023, the Mozilla Foundation published a widely covered report looking at the privacy policies of more than two dozen automakers. They were appalled, writing that “cars are the worst product category we have ever reviewed for privacy.” But that analysis was conducted by sitting down and reading all the various privacy policies of each brand; today’s study involved measuring traffic from actual cars under a number of scenarios, including idling and being driven. The researchers even parked 11 cars—just the electric ones—in a Faraday tent to see if the loss of a cellular signal would push that traffic to the car’s Wi-Fi connection instead.
Attempts to actually see what was in the data packets using modified certificates failed in every case. But “the network traces still yielded valuable information, including the domains contacted via DNS traffic, Server Name Indication (SNI) in TLS handshakes, the volume and timing of transmissions, and differences in behavior across experimental scenarios,” they found.
All of the cars contacted a first-party domain (i.e., the OEM)—after all, all the cars tested were connected cars and that means connecting to something. And a few left it there—the Buick Envista and Mercedes-Benz EQS didn’t appear to reach out to anywhere else, for example. Others were far more promiscuous, with Tesla topping the chart: The Model 3 contacted 34 advertising, tracking, and analytic domains, as well as 37 domains from apps integrated into the infotainment system.
Alphabet’s domains were the most frequently contacted—again not enormously surprising given the penetration of its Android Automotive OS into the sector. “But many of the [second-level domains] we observed were not necessary for core services (e.g., doubleclick.net and googlesyndication.com, which are used for advertising purposes),” the authors wrote. Media streaming—Spotify, Sirius XM, and so on—is well represented, as are mapping companies like HERE, TomTom, and Mapbox.
Using a car’s infotainment system resulted in it contacting the most domains, versus just sitting idle or driving for all the cars tested—apart from the Tesla Cybertruck, that is, which instead contacts 26 more third-party domains while driving than stationary.
Because of exhaust fumes, it was only safe to test electric vehicles in the Faraday tent. Cut off from a cellular signal, some of the EVs—including the Cadillac Lyriq, Chevrolet Blazer, Honda Prologue, and Rivian R1S—simply stop using those connected subsystems. But some of the cars tested redirected their traffic to Wi-Fi, allowing the researchers to see traffic flows that were previously unobservable.
, they tested 30 different connected car apps, which in some cases exposed users to more than 20 new advertising, tracking, and analytics companies—General Motors, Toyota, and Nissan were the worst offenders.
The authors reached out to 17 of the automakers ( Fisker had already gone under ) and heard back from 14. The replies are not entirely encouraging. All the OEMs told the researchers that the data-sharing with third parties was covered by contracts prohibiting the use of PII outside the scope of their privacy agreements—the same privacy agreements that horrified the Mozilla Foundation in 2023.
Some of the automakers also deflected blame onto the embedded browser running inside the infotainment system and said it was up to users to select the right prompt when asked to accept or reject a cookie. And seven said that it’s the consumer’s responsibility to read and accept all of the terms and conditions for all the connected services, even though in many cases the software is already installed on the car. And as the authors note, declining a data-sharing agreement can result in a loss of services and functionality—not a great solution if it means losing useful features you expected to work when you bought the car.
However, there was at least one positive outcome: after being contacted, Honda changed its data practices and no longer shares precise location data with at least one tracking company.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
