· via The Verge
Every connected car tested transmitted data to third-party trackers
A Northeastern University and Consumer Reports study found all 21 vehicles tested sent data to third parties, while seven brand apps leaked VINs, phone numbers and locations to ad networks.

Every car tested transmitted data
Modern vehicles quietly log where you drive, how hard you brake and how sharply you turn — and a new study suggests nearly all of them hand that information to companies outside the automaker. According to The Verge, researchers at Northeastern University, working with Consumer Reports, examined 21 late-model vehicles from 19 brands currently sold in the US, along with 30 companion mobile apps linked to actively used cars.
The findings were unambiguous: every one of the 21 vehicles transmitted data to at least one third-party domain over Wi-Fi, and more than half contacted domains specializing in advertising, tracking or analytics. Among the named recipients were Adobe, LexisNexis and Amplitude — companies that, as The Verge notes, may package vehicle and driving details for insurers or use them for ad targeting.
"I think the conclusion is that there's a lot to be worried about," project lead David Choffnes, former director of Northeastern's Cybersecurity and Privacy Institute, told The Verge.
How the researchers captured the traffic
To observe what cars actually send, the team had to get creative. Intercepting Wi-Fi was the straightforward part: researchers placed a Raspberry Pi inside each vehicle, connected it to the car's Wi-Fi and routed its internet through a mobile hotspot, allowing them to monitor outgoing traffic while the car was in motion.
Cellular traffic required more care. Rather than deploy an unauthorized base station that could interfere with public networks, the team built a car-sized Faraday tent that blocked all communication with cell towers, forcing each vehicle onto the controlled Wi-Fi connection.
The approach had limits. Researchers could identify destination domains, including those belonging to tracking companies, but could not decrypt the encrypted payloads without hacking the vehicles — meaning the actual contents of the transmissions may be broader than the domain data alone shows.
Google's infotainment platform tops the list
Not all cars leaked equally. Vehicles equipped with advanced infotainment systems — particularly those running Google's Android Automotive OS with Google Automotive Services — contacted the highest number of third-party domains. Choffnes told The Verge that an automaker's choice of software platform directly affects how much data reaches outsiders, since Google's platform includes built-in routines for communicating with both Google's own services and external entities.
Much of the tracking also flows through apps preinstalled in the car itself, Choffnes noted, with vehicles "essentially turning into the global smartphones."
Companion apps expose the most sensitive details
If the in-car telemetry is broad, the companion apps are worse. Seven of them — HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick and myGMC — transmitted sensitive information including vehicle identification numbers, phone numbers and precise locations directly to advertising networks. More than 70 percent of the tested apps contacted at least five unique advertising, tracking or analytics domains.
The pairing of a VIN with personally identifiable data particularly alarmed the researchers, because it allows data brokers to assemble detailed dossiers on individual drivers. As Choffnes put it, these are companies "that probably most consumers don't have a relationship with or have never heard of."
Automakers offered mixed responses
Industry reactions varied, The Verge reports. Some manufacturers defended their practices as legally compliant, while others acknowledged the vulnerabilities and shipped software fixes. Honda, for example, asked its analytics provider Amplitude to delete all collected location data and updated the HondaLink app to stop transmitting geolocation after being presented with the findings.
Why it matters
The study is the first systematic look at a practice regulators had previously flagged only piecemeal. The year before the study, the Federal Trade Commission penalized General Motors for collecting and selling precise location and driving behavior data without informed consent, and both Ford and Honda were fined smaller amounts for making it overly difficult to opt out. Until now, nobody had measured how widespread the behavior actually is across the market.
The answer matters because consumers have almost no practical visibility or control. As Choffnes observes, nobody sits in a dealership parking lot reading dense privacy policies on a tiny dashboard screen before tapping agree. His prescription is that automakers rebuild trust through transparency and explicit opt-in consent rather than opt-out defaults. Until that happens, one of the most expensive purchases a household makes doubles as a tracking device feeding companies most buyers never knew existed.
- #privacy
- #connected-cars
- #data-brokers
- #telematics
- #consumer-reports