
A collaborative study conducted by Northeastern University and Consumer Reports examined privacy practices across 21 late-model vehicles from 19 manufacturers currently sold in the United States, along with 30 associated mobile applications. The investigation sought to determine which vehicles collect and transmit data, identify the recipients of that information, assess whether it crosses international boundaries, and document what personally identifiable information is exposed during the process.
The research methodology involved innovative technical approaches to capture different types of data transmission. Researchers placed a Raspberry Pi device inside each vehicle to monitor Wi-Fi traffic while routing connections through a mobile hotspot. To analyze cellular transmissions without deploying unauthorized base stations, the team constructed a Faraday tent large enough to block signal transmissions and force vehicles to rely on controlled Wi-Fi connections for data transmission analysis.
Findings revealed that every vehicle in the study transmitted data to at least one third-party domain over Wi-Fi, with more than half contacting companies specializing in advertising, tracking, or analytics. Third-party recipients included firms such as Adobe, LexisNexis, and Amplitude. Vehicles equipped with advanced infotainment systems, particularly those utilizing Google’s Android Automotive OS with Google Automotive Services, contacted the highest number of third-party domains. The companion mobile applications presented additional security concerns, with seven apps including HondaLink, MyNissan, and various General Motors applications transmitting vehicle identification numbers, phone numbers, and precise location data directly to advertising networks. Researchers expressed particular concern about the pairing of vehicle identification numbers with personal identifiable information, which enables data brokers to compile comprehensive profiles on individual drivers.
Automaker responses to the research varied. Some manufacturers defended their practices as legally compliant with existing regulations, while others acknowledged vulnerabilities and released software updates. Honda specifically requested that its analytics provider delete collected location data and modified the HondaLink application to stop transmitting geolocation information following presentation of the study’s findings. Researchers emphasized that most consumers lack clear understanding of data collection practices when purchasing connected vehicles or configuring associated applications, noting that dense privacy policies presented on small dashboard screens during dealership transactions rarely receive careful review from buyers.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI