You hear it all the time: Modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects vast amounts of data — tracking where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much more.
Your car’s data privacy problems are worse than you think
The legality of this data harvesting remains hotly debated. Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without informed consent. Other automakers, like Ford and Honda, have faced minor fines for making it overly difficult for customers to opt out. While industry observers long suspected that other carmakers were doing the same, the practice hadn’t been systematically investigated — until now.
This week, researchers from Northeastern University, in collaboration with Consumer Reports, published an in-depth examination of connected vehicle privacy behaviors. Utilizing nearly two dozen vehicles from CR’s test fleet, the team sought to answer critical questions: Which cars transmit data? Who receives it? Does it cross international borders? And what personally identifiable information is actually being exposed?
David Choffnes, project lead and former director of Northeastern’s Cybersecurity and Privacy Institute, said the goal was to reveal the sheer scale of modern vehicle data tracking and highlight how little visibility or control owners truly have over it.
“I think the conclusion is that there’s a lot to be worried about,” Choffnes said in an interview.
To get a complete picture, researchers analyzed 21 late-model vehicles from 19 brands currently sold in the US, along with 30 companion mobile apps linked to active vehicles.
“I think the conclusion is that there’s a lot to be worried about.”
— David Choffnes
For traffic sent directly from the cars, the team identified the destination domains — including various third-party tracking companies — though they could not decrypt the encrypted payload data without hacking the vehicles.
Intercepting Wi-Fi traffic proved relatively straightforward. Researchers placed a Raspberry Pi inside each car, connecting it to the vehicle’s Wi-Fi while routing its internet through a mobile hotspot. This setup let them monitor outgoing Wi-Fi traffic while the car was in motion.
Capturing cellular traffic required a more creative approach. To avoid deploying an unauthorized cellular base station that could interfere with public networks, the team built a car-sized Faraday tent. The tent blocked all signal transmissions between the vehicle and external cell towers, forcing the car to fall back on the controlled Wi-Fi connection.
The results were stark: Every single one of the 21 vehicles transmitted data to at least one third-party domain over Wi-Fi. Over half contacted domains specializing in advertising, tracking, or analytics (ATA). These companies, like Adobe, LexisNexis, and Amplitude, gather details about your vehicle or driving behavior to sell to insurance companies or target you with ads.
Vehicles equipped with advanced infotainment systems — particularly those running Google’s Android Automotive OS with Google Automotive Services — contacted the highest number of third-party domains. Choffnes noted that an automaker’s choice of software platform directly impacts how much data reaches third parties. Google’s platform, for instance, includes built-in routines to communicate both with Google’s own services and external entities.
“A lot of the tracking we also see through the apps that are built into the car,” Choffnes said. “So now, cars are essentially turning into the global smartphones.”
Mobile apps present an equally insecure vector. The team discovered that seven companion apps — HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC — transmitted sensitive details like vehicle identification numbers (VINs), phone numbers, and precise locations directly to advertising networks. Over 70 percent of the tested companion apps contacted at least five unique ATA domains.
Researchers were particularly alarmed by the pairing of a vehicle’s VIN with identifiable personal data, which allows data brokers to build detailed dossiers on individual drivers.
“We sort of think, ‘Oh, well, if your online companies can track what you’re doing online, but you’re in your car, are they tracking what car you have?’” Choffnes said. “And so we’re seeing they actually can. And these are going to companies that probably most consumers don’t have a relationship with or have never heard of.”
Automakers offered mixed reactions to the findings. Some defended their practices as legally compliant, while others acknowledged the vulnerabilities and issued software fixes. Honda, for example, requested that its analytics provider Amplitude delete all collected location data and updated the HondaLink app to cease transmitting geolocation after being presented with the Northeastern team’s findings.
Choffnes believes the deeper issue is that consumers rarely understand what they agree to when buying a connected car or setting up its app. Most drivers will not sit in a dealership parking lot reading dense privacy policies on a tiny dashboard screen before agreeing to the terms.
“I don’t think there’s a lot of trust as a result of this,” Choffnes said. “I think automakers would do well to earn that trust back. And one way to do that is through better transparency and helping consumers to not have data collected about them after they’ve made a really expensive purchase without having more explicit opt-in as opposed to opt-out.”
- Andrew J. Hawkins
You hear it all the time: Modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects vast amounts of data — tracking where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much…
Recent Posts
- Samsung gives its two-year-old Galaxy Tab S Plus an overhaul
- The new Samsung Galaxy Tab S12 Ultra is here — and we’ve used it
- Apple’s ‘HomePad’ will reportedly launch on October 13th
- The Best Gaming Routers (2026): Tested By a Family of Gamers
- Where to draw the line on AI: Lessons from digital forensics
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023