A recent study by researchers from Northeastern University, in collaboration with Consumer Reports, examined the data privacy behaviors of connected vehicles. The team tested 21 late-model vehicles from 19 brands currently sold in the US, along with 30 companion mobile apps linked to active vehicles.
The investigation revealed that every one of the 21 vehicles tested transmitted data to a third-party domain. Furthermore, more than half of these vehicles were found to be sending data to advertising companies. This indicates a broad practice of data collection and sharing within the automotive industry.
David Choffnes, project lead and former director of Northeastern’s Cybersecurity and Privacy Institute, stated that the goal of the research was to expose the extent of modern vehicle data tracking and to emphasize the limited visibility and control car owners have over their data. Previous instances, such as the Federal Trade Commission penalizing General Motors for illegally collecting and selling location data, underscore the ongoing concerns regarding vehicle data privacy.
Researchers analyzed traffic sent directly from the cars to identify destination domains, including various third-party tracking companies. While they could identify these destinations, they were unable to decrypt the encrypted payload data without compromising the vehicles. The study also involved intercepting Wi-Fi traffic, which proved to be a more straightforward process.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new report by Northeastern University and Consumer Reports found that 19 of 21 major automakers routinely collect and share personally identifiable connected-car data with advertisers, data brokers, and tech companies like Google, Amazon, and Meta. This practice exposes consumers to extensive data dissemination within the advertising ecosystem, raising significant privacy concerns regarding vehicle data. The findings detail how data moves from cars to companion apps and then to third parties, often including sensitive information like names, email addresses, and precise geolocations.
A new study by Northeastern University and Consumer Reports found that 19 out of 21 tested connected vehicles and 7 out of 30 companion apps share sensitive user data, including VINs and precise location, with third-party tech companies like Google and Meta. This data sharing allows for the creation of detailed consumer profiles, which are then sold to various companies, raising significant privacy concerns for vehicle owners.
A new study by Northeastern University and Consumer Reports found that connected cars transmit data to advertisers, trackers, and companies like Microsoft and Adobe. The research involved testing 21 cars from 19 brands, observing data traffic patterns during various scenarios, and highlighted that companion apps can increase data sharing. This provides concrete evidence of data transmission beyond what privacy policies indicate.
Researchers from Northeastern University and Consumer Reports found that all 21 modern vehicles they tested transmit data to third-party domains, with over half sending data to advertising companies. This study systematically investigates data collection practices in connected vehicles, highlighting a lack of transparency and control for car owners.