Your car’s data privacy problems are worse than you think
You hear it all the time: Modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects vast amounts of data — tracking where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much more.
The legality of this data harvesting remains hotly debated. Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without informed consent. Other automakers, like Ford and Honda, have faced minor fines for making it overly difficult for customers to opt out. While industry observers long suspected that other carmakers were doing the same, the practice hadn’t been systematically investigated — until now.
This week, researchers from Northeastern University, in collaboration with Consumer Reports, published an in-depth examination of connected vehicle privacy behaviors. Utilizing nearly two dozen vehicles from CR’s test fleet, the team sought to answer critical questions: Which cars transmit data? Who receives it? Does it cross international borders? And what personally identifiable information is actually being exposed?
David Choffnes, project lead and former director of Northeastern’s Cybersecurity and Privacy Institute, said the goal was to reveal the sheer scale of modern vehicle data tracking and highlight how little visibility or control owners truly have over it.
“I think the conclusion is that there’s a lot to be worried about,” Choffnes said in an interview.
To get a complete picture, researchers analyzed 21 late-model vehicles from 19 brands currently sold in the US, along with 30 companion mobile apps linked to active vehicles.
“I think the conclusion is that there’s a lot to be worried about.”
— David Choffnes
For traffic sent directly from the cars, the team identified the destination domains — including various third-party tracking companies — though they could not decrypt the encrypted payload data without hacking the vehicles.
Intercepting Wi-Fi traffic proved relatively straightforward. Researchers placed a Raspberry Pi inside each car, connecting it to the vehicle’s Wi-Fi while routing its internet through a mobile hotspot. This setup let them monitor outgoing Wi-Fi traffic while the car was in motion.
Capturing cellular traffic required a more creative approach. To avoid deploying an unauthorized cellular base station that could interfere with public networks, the team built a car-sized Faraday tent. The tent blocked all signal transmissions between the vehicle and external cell towers, forcing the car to fall back on the controlled Wi-Fi connection.
The results were stark: Every single one of the 21 vehicles transmitted data to at least one third-party domain over Wi-Fi. Over half contacted domains specializing in advertising, tracking, or analytics (ATA). These companies, like Adobe, LexisNexis, and Amplitude, gather details about your vehicle or driving behavior to sell to insurance companies or target you with ads.
Vehicles equipped with advanced infotainment systems — particularly those running Google’s Android Automotive OS with Google Automotive Services — contacted the highest number of third-party domains. Choffnes noted that an automaker’s choice of software platform directly impacts how much data reaches third parties. Google’s platform, for instance, includes built-in routines to communicate both with Google’s own services and external entities.
“A lot of the tracking we also see through the apps that are built into the car,” Choffnes said. “So now, cars are essentially turning into the global smartphones.”
Mobile apps present an equally insecure vector. The team discovered that seven companion apps — HondaLink, Lincoln, MyNissan, myCadillac, myChevrolet, myBuick, and myGMC — transmitted sensitive details like vehicle identification numbers (VINs), phone numbers, and precise locations directly to advertising networks. Over 70 percent of the tested companion apps contacted at least five unique ATA domains.
Researchers were particularly alarmed by the pairing of a vehicle’s VIN with identifiable personal data, which allows data brokers to build detailed dossiers on individual drivers.
“We sort of think, ‘Oh, well, if your online companies can track what you’re doing online, but you’re in your car, are they tracking what car you have?’” Choffnes said. “And so we’re seeing they actually can. And these are going to companies that probably most consumers don’t have a relationship with or have never heard of.”
Automakers offered mixed reactions to the findings. Some defended their practices as legally compliant, while others acknowledged the vulnerabilities and issued software fixes. Honda, for example, requested that its analytics provider Amplitude delete all collected location data and updated the HondaLink app to cease transmitting geolocation after being presented with the Northeastern team’s findings.
Choffnes believes the deeper issue is that consumers rarely understand what they agree to when buying a connected car or setting up its app. Most drivers will not sit in a dealership parking lot reading dense privacy policies on a tiny dashboard screen before agreeing to the terms.
“I don’t think there’s a lot of trust as a result of this,” Choffnes said. “I think automakers would do well to earn that trust back. And one way to do that is through better transparency and helping consumers to not have data collected about them after they’ve made a really expensive purchase without having more explicit opt-in as opposed to opt-out.”


