By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Study Reveals Connected Cars Share Data With Advertisers, Big Tech

Connected cars continue to present significant privacy concerns, with a recent study by researchers at Northeastern University and Consumer Reports providing detailed insights into the types of data shared and the recipients. The investigation tested 21 vehicles across 19 distinct brands, uncovering patterns of data transmission directed towards advertising networks and tracking entities, as well as major technology firms including Microsoft and Adobe. The use of a car's companion mobile application was found to exacerbate these privacy issues, according to the study's findings. This research builds upon previous work, such as a 2023 report by the Mozilla Foundation, which characterized automakers' privacy policies as the "worst product category" reviewed for privacy. However, while Mozilla's analysis relied on reviewing written privacy policies, the Northeastern University and Consumer Reports study employed a more empirical approach by measuring actual network traffic generated by vehicles under various operational conditions, including when idling and when being driven. To further isolate data sharing mechanisms, researchers specifically parked 11 electric vehicles within a Faraday tent to determine if a loss of cellular signal would reroute data transmissions through the car's Wi-Fi connection. Although the researchers were unable to inspect the contents of the data packets directly, even with modified certificates, the network traffic analysis proved highly informative. The study successfully identified the domains contacted through DNS queries, the Server Name Indication (SNI) data exchanged during TLS handshakes, and quantified the volume and timing of data transmissions. Crucially, the researchers observed distinct behavioral differences in data sharing across the various experimental scenarios, highlighting the dynamic nature of connected car data privacy. The study's methodology involved capturing network traffic from the vehicles, analyzing DNS requests, and examining TLS handshake data to infer the destinations and nature of the data being shared. This comprehensive approach allowed for a granular understanding of how connected car ecosystems interact with external services, often without explicit user awareness of the full extent of data dissemination. The findings underscore the need for greater transparency and user control over the data generated and transmitted by modern vehicles.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.