Daily MaverickUNFIT FOR SERVICE?: Malema’s JSC future hangs in balance despite belated apologyESPN DeportesChiefs toma la cima y Seahawks cae dramáticamenteESPNFollow live: Ozzie Albies' RBI triple in the 6th gives Atlanta lead in Game 1RTP DesportoLíder da Liga Portuguesa prevê regresso das bebidas alcoólicas aos estádiosThe Jerusalem PostSource to 'Post': Israel on high alert, but no concrete intel. warning for attack before electionsColliderKiefer Sutherland Officially Confirms 'Young Guns 3': “The Script Is Amazing” [Exclusive]Football ItaliaItaly’s Raspadori sent back to Atalanta and will miss France and Turkiye games through injuryDigital SpyCoronation Street's Kevin and Ronnie to fear gun link after shock Jodie incidentBusiness AMNa gedwongen uitzetting van 87-jarige kondigt Spanje maatregelen tegen woningcrisis aanThe Hollywood ReporterGuy Raz Acquires Ownership of ‘How I Built This’ Podcast, Partners With Vox Media (Exclusive)RMF24Straż miejska będzie mogła więcej? Nowy bat na kierowców łamiących przepisySRF NewsKrieg im Nahen Osten – USA verhängen Sanktionen gegen Waffenbeschaffer für Iran
The Daily Newsstand · Free, Always
Tuesday, September 29, 2026

This study looks at how and with whom connected cars share your data

Translate

In news that should surprise very few, connected cars remain a complete privacy nightmare. But now we have a better idea of what data those cars are giving away, and to whom, thanks to a study conducted by a team of researchers at Northeastern University and Consumer Reports. Testing 21 cars from 19 different brands revealed patterns of traffic to advertisers and trackers, as well as data shared with Big Tech firms like Microsoft and Adobe. And using a car’s companion app can multiply the problem, their testing found.

In 2023, the Mozilla Foundation published a widely covered report looking at the privacy policies of more than two dozen automakers. They were appalled, writing that “cars are the worst product category we have ever reviewed for privacy.” But that analysis was conducted by sitting down and reading all the various privacy policies of each brand; today’s study involved measuring traffic from actual cars under a number of scenarios, including idling and being driven. The researchers even parked 11 cars—just the electric ones—in a Faraday tent to see if the loss of a cellular signal would push that traffic to the car’s Wi-Fi connection instead.

Attempts to actually see what was in the data packets using modified certificates failed in every case. But “the network traces still yielded valuable information, including the domains contacted via DNS traffic, Server Name Indication (SNI) in TLS handshakes, the volume and timing of transmissions, and differences in behavior across experimental scenarios,” they found.

All of the cars contacted a first-party domain (i.e., the OEM)—after all, all the cars tested were connected cars and that means connecting to something. And a few left it there—the Buick Envista and Mercedes-Benz EQS didn’t appear to reach out to anywhere else, for example. Others were far more promiscuous, with Tesla topping the chart: The Model 3 contacted 34 advertising, tracking, and analytic domains, as well as 37 domains from apps integrated into the infotainment system.

Alphabet’s domains were the most frequently contacted—again not enormously surprising given the penetration of its Android Automotive OS into the sector. “But many of the [second-level domains] we observed were not necessary for core services (e.g., doubleclick.net and googlesyndication.com, which are used for advertising purposes),” the authors wrote. Media streaming—Spotify, Sirius XM, and so on—is well represented, as are mapping companies like HERE, TomTom, and Mapbox.

View the original on Ars Technica →

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.