mrkeyoor.com_
Fri 02 Oct 15:00 UTC
Tech7 min read

19 of 21 Connected Cars Contacted Third Parties in Privacy Study

A 21-car study found broad third-party contact and seven companion apps sending identifiers. Its warning lies partly in what encrypted vehicle traffic still hid.

A fleet worth more than $1.2 million still left researchers looking through a keyhole. They could see that 19 of 21 connected cars reached at least one third party over Wi-Fi, but encryption usually hid the payload. The companion apps were easier to inspect: seven of 30 sent personal identifiers to companies associated with advertising, tracking or analytics, according to a new Northeastern University and Consumer Reports study.

That split is the useful warning for anyone trying to judge a connected car by its settings screen or privacy policy. The car, its infotainment software, the manufacturer's servers and the phone app form one data system. Testing any one piece can miss traffic in the others. The researchers describe their observations as a lower bound, which makes the unseen traffic as important as the flows they documented.

The peer-reviewed 18-page paper, scheduled for the 2026 ACM Internet Measurement Conference, covers 21 vehicles from 19 brands and 30 companion apps. Tests ran between October 2024 and August 2025 on vehicles sold in the United States. The sample included model years 2022 through 2025, ranging from a Ford F-150 Lightning and Toyota Corolla Cross to a Tesla Cybertruck.

A $1.2 million view of where cars connect

Consumer Reports supplied its purchased test fleet. That solved a basic research problem: buying the same vehicles would have cost more than $1.2 million. The team then routed each car's Wi-Fi through a Raspberry Pi access point and used tcpdump to record the destinations it contacted. Tests covered an idle car, active use of its controls and infotainment system, and driving on private roads at 5 to 45 mph.

TLS encryption kept the contents of most vehicle traffic closed. The team could identify destination domains and communication patterns, yet it could not read the data inside those connections. That distinction matters. A request to a mapping or audio service is different from a transfer of location or identity, even when both go to an outside company. The paper classifies outside domains as support services, integrated services, advertising/tracking/analytics services, or other third parties rather than treating every external connection as equivalent.

Across the 21 cars, 19 contacted at least one third party over Wi-Fi. Eleven reached at least one domain that specialized in advertising, tracking or analytics. Thirteen contacted Google-associated domains in that category, including advertising services such as DoubleClick and Google Syndication. Cars with fuller infotainment systems tended to reach more outside domains, while models with limited infotainment functions contacted fewer. Even related brands behaved differently.

The researchers also drove 11 electric vehicles into a Faraday tent that reduced outside radio signals by about 93 decibels. Blocking cellular service caused some cars to move traffic onto the observable Wi-Fi connection, exposing destinations that had previously stayed out of view. It was an inventive workaround with a hard limit: only the Tesla Model 3 offered a user-accessible SIM that let the team capture cellular traffic directly. The authors could not establish that every blocked cellular flow reappeared on Wi-Fi.

The phone app opened a wider window

A phone allowed closer inspection. The team installed manufacturer apps one at a time on three test iPhones, added custom root certificates and sent traffic through mitmproxy. Testers accepted every requested permission, signed in with Consumer Reports accounts tied to the cars, and exercised available functions such as locating a vehicle, checking tire pressure and remotely opening a trunk. This setup exposed many app payloads, although certificate pinning still protected some first-party traffic.

Seventy percent of the apps contacted more than five advertising, tracking or analytics domains. Only 29 percent of the vehicles crossed that threshold in the Wi-Fi observations. For most vehicles in the sample, adding the companion app at least doubled the number of companies in that category. The apps for a few cars added more than 20 companies that the researchers had not observed in the vehicle traffic.

To find personal data, the team built a reference set from the test accounts and cars. It searched decrypted traffic for names, phone numbers, email addresses, locations, Wi-Fi credentials, license plates and vehicle identification numbers. The search also covered uppercase and lowercase versions plus MD5, SHA-1 and SHA-256 hashes of those strings. This caught identifiers that would have been easy to miss in a visual review of network logs.

Seven apps sent personal information to outside analytics or tracking companies: HondaLink, Lincoln, MyNISSAN, myBuick, myCadillac, myChevrolet and myGMC. VINs were the most common identifier. Six of those apps sent a VIN alongside at least one other type of personal data. The four GM-branded apps sent VINs to a group that included Adobe, Google, Meta, Microsoft and Yahoo. The exact recipients and fields varied by app.

A VIN can tie the car back to its owner

A VIN is visible through a windshield, but visibility is only part of the privacy question. It is a permanent identifier that follows the vehicle and cannot be reset like a mobile advertising ID. Pairing it with an email address, phone number or precise location lets an analytics company connect a particular car to activity elsewhere, the researchers argue in their PII analysis.

The paper found HondaLink sending a VIN and precise location to Amplitude, an event analytics service. After the researchers disclosed the finding, Honda said it asked Amplitude to delete the location data it had received and updated HondaLink so it would stop sending geolocation to the service. That response shows why payload visibility changes the conversation. A list of contacted domains can prompt questions, while a decrypted field can identify the practice that needs to change.

This research arrives after connected-car data has already produced consequences outside the lab. In January 2026, the US Federal Trade Commission finalized an order involving GM and OnStar. The agency alleged that the companies collected and sold precise location and driving behavior data from millions of vehicles without adequate notice or affirmative consent. The order bars some sharing with consumer reporting agencies and requires clearer choices. That case concerns a different data flow from the ones measured here, but it shows how vehicle telemetry can reach decisions about insurance and other services.

The disclosure replies exposed an ownership problem

The researchers contacted 17 of the 18 manufacturers represented in the study, excluding the bankrupt Fisker. Fourteen replied. Every respondent said the observed flows complied with contracts restricting service providers to uses described in privacy policies. Five attributed some tracking to webpages opened inside embedded browsers. Seven said owners were responsible for accepting terms attached to preinstalled apps or services. These explanations overlapped.

Recorded testing did not always show the cookie prompt that three manufacturers said embedded pages should display. The larger consent problem sat outside any single prompt. Manufacturer policies cited in the paper warned that declining data agreements could disable navigation, driver assistance, remote features or over-the-air updates. A buyer may technically have a choice while losing functions that were part of the purchase.

The policies for all seven apps that transmitted personal information disclosed that data might be shared with third parties. They did not consistently name the recipients or explain the purpose of each flow. A broad disclosure therefore could not tell an owner that one app would send a VIN to a particular analytics company, or that another would combine that VIN with an email address.

The limits keep the headline narrow

This study does not prove that 19 cars sent personal data to every third party they contacted. For vehicle traffic, it mostly proves that connections occurred. The stronger content claims come from decrypted app traffic, where the researchers could match transmitted fields to known test data. Keeping those findings separate avoids turning metadata into a claim about payloads.

The sample is also a US snapshot, not a ranking of every brand or current model. App versions, server behavior and vehicle software can change after an update. Testers accepted all requested permissions and exercised every available feature, so the sessions describe a fully permitted setup rather than every owner's daily use. Server-to-server transfers after data reached a manufacturer were outside the team's view.

Those constraints cut both ways. They prevent broad claims about the whole market, while the blocked cellular links, pinned app connections and invisible server-side transfers leave room for more recipients than the team observed. Better measurement will require repeat tests after software updates, direct access to more cellular interfaces and disclosures that name recipients instead of grouping them under a general third-party clause.

The next result to watch is concrete: whether manufacturers other than Honda alter a measured data flow, and whether an owner can see that change before pairing a phone. Until then, a connected-car privacy choice is hard to evaluate because the most useful question still lacks a simple answer: which outside company receives the VIN or location, and which paid-for feature stops working if the driver says no?

We reviewed this

  1. analytics — our honest review
  2. paper — our honest review
  3. fleet — our honest review

Sources

  1. Automatic Transmission: a data-privacy study of connected vehicles
  2. Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem
  3. FTC finalizes GM and OnStar connected-vehicle data order