Northeastern University researchers, in partnership with Consumer Reports, analyzed outbound internet traffic from 21 late-model vehicles and 30 companion mobile apps to map who receives in-car data. Using a Raspberry Pi Wi‑Fi access point to capture traffic during idle, driving, and while EVs were placed in a Faraday tent to block cellular, they found 19 of 21 vehicles contacted third-party domains - many tied to advertising and tracking. Seven companion apps transmitted sensitive identifiers such as VINs, emails, phone numbers, and precise locations, roughly doubling exposure to trackers. Tesla and General Motors models showed particularly high rates of third-party sharing, with recipients including Alphabet, Amazon, Meta, Microsoft, Pinterest, and Reddit.
Seventeen manufacturers were informed; most respondents blamed broad third‑party service contracts or urged consumers to opt out, while noting that declining data sharing can disable features like navigation or over‑the‑air updates. Honda was cited as a rare example of reducing precise geolocation sharing. Researchers call for stronger transparency and ecosystem visibility, warning that current disclosure and consent mechanisms allow unconsented data flows that enable profiling by insurers, lenders, retailers and others and create significant privacy and security risks.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.