Post

Automatic Transmission: a data-privacy study of connected vehicles

A Northeastern/Consumer Reports study tested 21 U.S.-market vehicles and 30 companion apps. Researchers observed 19 vehicles contacting third parties over Wi-Fi; seven apps sent sensitive identifiers such as VINs, email addresses, phone numbers, or precise location to third parties associated with advertising and tracking. Pairing an app increased tracker exposure in the study. Vehicle traffic was encrypted, so researchers could see destinations but not packet contents; the app tests used instrumented iPhones to inspect traffic. These are measurements of this sample, not proof of what recipients later did with the data.

The authors say the research is peer reviewed and will appear at IMC ’26. In the 177-comment HN discussion, drivers described difficulty opting out or disabling telemetry, while others argued that physically disconnecting a modem may be possible on some models. Commenters also emphasized that the study cannot establish downstream sale or use of observed data, and some criticized the presentation of the project site.