A large-scale measurement study examined how connected vehicles and their companion mobile apps share data with manufacturers and third parties. Working with Consumer Reports, researchers tested 21 late-model vehicles (19 brands) and 30 companion apps between October 2024 and August 2025. Vehicle network traffic was captured via a custom Raspberry Pi Wi‑Fi access point and tcpdump, and cellular behavior was probed by driving vehicles into a Faraday tent (~93 dB attenuation). Companion apps were exercised on test iPhones with custom root certificates and mitmproxy to decrypt traffic; testers accepted requested permissions and exercised all app features to observe real-world data flows.
The study found extensive third-party contact and transmission of sensitive identifiers: 19 of 21 vehicles contacted at least one third party over Wi‑Fi, seven of 30 apps sent PII (VINs, emails, phone numbers, precise location) to tracking/advertising firms, and five apps sent VINs plus other PII. Pairing an app roughly doubled exposure to trackers and in some cases added 20+ new ones. Manufacturer responses largely shifted responsibility to consumers; only Honda enacted a change to stop sending precise geolocation to a tracker. The results reveal a large gap between disclosures and actual data sharing, significant variability across models, and an urgent need for greater transparency and consumer control.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.