Your car’s data privacy problems are worse than you think

A team of researchers tested 21 vehicles and found that all of them transmitted data to a third-party domain. And over half were pinging advertising companies.


You hear it all the time: Modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects vast amounts of data — tracking where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much more.
The legality of this data harvesting remains hotly debated. Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without informed consent. Other automakers, like Ford and Honda , have faced minor fines for making it overly difficult for customers to opt out. While industry observers long suspected that other carmakers were doing the same, the practice hadn’t been systematically investigated — until now.
This week, researchers from Northeastern University, in collaboration with Consumer Reports , published an in-depth examination of connected vehicle privacy behaviors. Utilizing nearly two dozen vehicles from CR ’s test fleet, the team sought to answer critical questions: Which cars transmit data? Who receives it? Does it cross international borders? And what personally identifiable information is actually being exposed?
David Choffnes, project lead and former director of Northeastern’s Cybersecurity and Privacy Institute, said the goal was to reveal the sheer scale of modern vehicle data tracking and highlight how little visibility or control owners truly have over it.
“I think the conclusion is that there’s a lot to be worried about,” Choffnes said in an interview.
To get a complete picture, researchers analyzed 21 late-model vehicles from 19 brands currently sold in the US, along with 30 companion mobile apps linked to active vehicles.
“I think the conclusion is that there’s a lot to be worried about.”
For traffic sent directly from the cars, the team identified the destination domains — including various third-party tracking companies — though they could not decrypt the encrypted payload data without hacking the vehicles.
Intercepting Wi-Fi traffic proved relatively straightforward. Researchers placed a Raspberry Pi inside each car, connecting it to the vehicle’s Wi-Fi while routing its internet through a mobile hotspot. This setup let them monitor outgoing Wi-Fi traffic while the car was in motion.
Verified source · The Verge
Reported by The Verge. Open the original for full media and formatting.
More in More
All news
MoreAmerica.gov gets really weird when you ask it about Minecraft, but it’s not a glitch
For the sake of national security, it's a relief to learn that America.gov is not hallucinating to the point that it's penning lengthy poetry.
Read at TechCrunch
MoreBMW’s revamped i3 boasts up to 468 miles of range
When BMW first announced it was reimagining the i3 as an all-electric four-door sedan built on its Neue Klasse platform, it left out a lot of important details, like battery capacity, range, and price. Today, the German automaker is finally starting to fill in the blanks on the…
Read at The Verge
MoreWill Amend IT Rules To Bar Under-18s From Social Media: Centre To SC
The Centre has informed SC that it plans to amend the IT Rules to prevent children under the age of 18 from opening social media accounts.
Read at Inc42
MoreRazer’s low-latency wireless gaming keyboard is almost half off
Woot has the Razer DeathStalker V2 Pro TKL on sale for $130, a significant discount from its usual $219.99 price point. This keyboard is built for competitive gaming, with a low latency 2.4GHz wireless connection, and low-profile linear optical switches for faster activations th…
Read at The Verge