Car App Data Leaks: How Big Tech Exploits Driver Privacy

www.news4hackers.com-car-app-data-leaks-how-big-tech-exploits-driver-privacy-car-app-data-leaks-how-big-tech-exploits-driver-privacy

Some car apps are transmitting vehicle owner data to major technology firms, raising significant privacy concerns.

Key Findings of the Study

A research initiative examining 21 vehicles and 30 automotive applications revealed that certain systems share sensitive information including vehicle identification numbers (VINs), residential addresses, mobile phone numbers, and location details with advertising, tracking, and analytics entities.

Data Transmission Practices

The study, conducted in collaboration with Consumer Reports, involved testing vehicles acquired for evaluation purposes. The sample included 19 distinct automotive brands. Researchers highlighted that while enforcement actions like the FTC’s against General Motors have drawn attention, the broader privacy risks within connected vehicle networks remain underexplored.

Testing Methodology

The investigation employed a Raspberry Pi-based access point to monitor Wi-Fi traffic from vehicles, conducting tests in three scenarios: 30 minutes of inactivity while parked, 30 minutes of interaction with vehicle controls, and 15 minutes of operation on a private test track. All tested vehicles rejected modified digital certificates designed to decrypt traffic, indicating robust certificate validation protocols.

Privacy Implications

Researchers documented domain connections, traffic patterns, and data transmission volumes. Cellular network data sharing remained inaccessible for most vehicles due to encryption. To assess Wi-Fi-based data flows, 11 electric vehicles were placed in a Faraday tent to block cellular signals.

Third-Party Connections

Nineteen of 21 vehicles connected to at least one third-party domain via Wi-Fi, with 11 encountering advertising or analytics-related domains. Thirteen vehicles interacted with Google-associated domains, including doubleclick.net and googlesyndication.com, which the researchers noted were not essential for core vehicle functions.

Tracking Domains and App Integration

The Tesla Model 3 engaged with 34 unique tracking domains, the Cybertruck 23, and the Cadillac Lyriq 10. Companion applications significantly increased tracking exposure, with 70% of apps contacting over five advertising or analytics domains compared to 29% of vehicles. Researchers observed that app integration often doubled cumulative tracking activity.

Data Sharing by Manufacturers

Seven of 30 applications transmitted personal data to third parties, including VINs, license plate numbers, owner names, phone numbers, addresses, location data, and Wi-Fi credentials. VINs were the most frequently shared identifier, with GM’s myCadillac, myChevrolet, myBuick, and myGMC apps transmitting them to Adobe, Acxiom, ContentSquare, FullStory, Google, Meta, Microsoft, Snap, and Yahoo.

Manufacturer Responses

Automotive manufacturers often deflect responsibility to consumers, with privacy policies disclosing potential third-party data sharing without specifying entities or purposes. GM, Lincoln, and Nissan acknowledged VIN sharing, with Nissan claiming it was more privacy-preserving than other identifiers. Tesla warned users that declining data sharing could lead to reduced functionality or vehicle inoperability.

Conclusion and Recommendations

The study concluded that significant discrepancies exist between public disclosures and actual data sharing practices in connected vehicles, urging greater transparency to address privacy risks. Researchers emphasized the need for improved visibility into vehicular data ecosystems to mitigate potential harms.

According to the study, “the broader privacy risks within connected vehicle networks remain underexplored.”



About Author

en_USEnglish