Study Finds Connected Cars And Apps Share Data With Third Parties
Researchers found widespread third-party connections from connected cars, while seven companion apps sent sensitive information to advertising and tracking companies.
Connected cars and their companion apps expose drivers to extensive third-party data collection, according to a study by Northeastern University researchers working with Consumer Reports. The team examined 21 late-model vehicles and 30 mobile apps, finding that third-party connections were common and that seven apps transmitted sensitive information, including vehicle identification numbers and precise locations.
Table of Contents
What the researchers found
The Verge reports that all 21 vehicles contacted at least one third-party domain over Wi-Fi, and more than half contacted domains associated with advertising, tracking or analytics. TechCrunch describes the vehicle finding differently, saying 19 of the 21 sent traffic to at least one third party. The outlets also give different descriptions of the sample: TechCrunch says the vehicles came from 17 automakers, while The Verge says they represented 19 brands sold in the US.
The researchers could identify where vehicle traffic was going, but could not decrypt the encrypted data itself without hacking the cars, according to The Verge. That distinction means a connection to a domain did not, on its own, show precisely what information a vehicle sent.
Companion apps exposed identifiable details
The app analysis provided a clearer view of sensitive information leaving drivers’ devices. Seven apps sent details such as vehicle identification numbers, phone numbers and precise locations to advertising networks, The Verge reports. They were HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick and myGMC. TechCrunch also lists email addresses among the types of sensitive data found in transmissions from the seven apps.
According to The Verge, more than 70 percent of the 30 apps contacted at least five distinct advertising, tracking or analytics domains. TechCrunch reports that pairing a companion app with a vehicle roughly doubled its exposure to advertising and tracking companies. The findings raise particular concern when a vehicle identifier and personal details reach the same recipient, potentially allowing information about a driver to be linked together.
How the companies responded
TechCrunch says the researchers shared their findings with automakers and that Honda was the exception to a broader pattern of manufacturers deflecting responsibility. The Verge characterizes the responses as mixed: some companies defended their practices, while others acknowledged problems and made software changes. Both outlets report that Honda changed its app’s handling of location data and asked its analytics provider, Amplitude, to delete geolocation data it had received.
Some automakers told Consumer Reports that links in their apps could open external webpages where cookies might collect data, according to TechCrunch. The outlet says drivers were not informed of that collection. The study’s findings show why the privacy implications of a connected vehicle may extend beyond the car itself to the app used to control it.
Sources
This story was compiled by AI from the reports below. Read the originals for the full details.