You hear it all the time: modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects massive amounts of data: It tracks where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much more.
The legality of this data collection remains the subject of heated debate. Last year, the Federal Trade Commission sanctioned General Motors for illegally collecting and selling precise data on location and driving behavior without informed consent. Other automakers, such as Ford and Honda, have faced minor fines for making it too difficult for customers to opt out. While industry observers have long suspected that other automakers were doing the same thing, the practice had not been systematically investigated…until now.
This week, researchers at Northeastern University, in collaboration with Consumer Reportspublished an in-depth examination of the privacy behaviors of connected vehicles. Using almost two dozen vehicles C.R.In the test fleet, the team sought to answer critical questions: Which cars transmit data? Who receives it? Does it cross international borders? And what personally identifiable information is actually exposed?
David Choffnes, the project leader and former director of Northeastern’s Cybersecurity and Privacy Institute, said the goal was to reveal the magnitude of modern vehicle data tracking and highlight how little visibility or control owners actually have over them.
“I think the bottom line is there’s a lot to worry about,” Choffnes said in an interview.
To get a complete picture, researchers analyzed 21 late-model vehicles from 19 brands currently sold in the U.S., along with 30 companion mobile apps linked to active vehicles.
“I think the bottom line is there’s a lot to worry about.”
—David Choffnes
For traffic sent directly from the cars, the team identified destination domains, including several third-party tracking companies, although they were unable to decrypt the encrypted payload data without hacking into the vehicles.
Intercepting Wi-Fi traffic was relatively easy. The researchers placed a Raspberry Pi inside each car, connecting it to the vehicle’s Wi-Fi while routing its Internet through a mobile hotspot. This setup allowed them to monitor outgoing Wi-Fi traffic while the car was moving.
Capturing cellular traffic required a more creative approach. To prevent the deployment of an unauthorized cellular base station that could interfere with public networks, the team built a car-sized Faraday tent. The store blocked all signal transmissions between the vehicle and outside cell towers, forcing the car to fall back on controlled Wi-Fi.
The results were clear: each of the 21 vehicles transmitted data to at least one third-party domain over Wi-Fi. More than half contacted domains specialized in advertising, tracking or analysis (ATA). These companies, such as Adobe, LexisNexis, and Amplitude, collect details about your vehicle or driving behavior to sell to insurance companies or target you with ads.
Vehicles equipped with advanced infotainment systems, particularly those running Google’s Android Automotive operating system with Google Automotive Services, contacted the largest number of third-party domains. Choffnes noted that an automaker’s choice of software platform directly affects the amount of data that reaches third parties. Google’s platform, for example, includes built-in routines to communicate both with Google’s own services and with external entities.
“A lot of the tracking we also see through in-car apps,” Choffnes said. “So now cars are essentially becoming the global smartphones.”
Mobile applications present an equally insecure vector. The team discovered that seven companion apps (HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC) transmitted sensitive details such as vehicle identification numbers (VINs), phone numbers, and precise locations directly to ad networks. More than 70 percent of the companion apps tested contacted at least five unique ATA domains.
Investigators were particularly alarmed by the combination of a vehicle’s VIN with personally identifiable data, allowing data brokers to create detailed records on individual drivers.
“We thought, ‘Oh, well, if your online businesses can track what you’re doing online, but you’re in your car, are they tracking what car you have?’” Choffnes said. “And we’re seeing that they can actually do that. And these are going to companies that probably most consumers don’t have a relationship with or have never heard of.”
Automakers offered mixed reactions to the findings. Some defended their practices as compliant with the law, while others acknowledged the vulnerabilities and released software fixes. Honda, for example, requested that its analytics provider Amplitude delete all collected location data and updated the HondaLink app to stop transmitting geolocation after being presented with the Northeastern team’s findings.
Choffnes believes the deeper problem is that consumers rarely understand what they’re agreeing to when they buy a connected car or set up its app. Most drivers won’t sit in a dealership parking lot reading dense privacy policies on a small dashboard screen before agreeing to the terms.
“I don’t think there will be a lot of confidence as a result of this,” Choffnes said. “I think automakers would do well to rebuild that trust. And one way to do that is through greater transparency and helping consumers not have data collected about them after they’ve made a really expensive purchase without having a more explicit opt-in option instead of an opt-out option.”