Key facts
- Connected cars continue to exhibit poor data privacy practices, according to a new study.
- Researchers measured network traffic from 21 cars across 19 brands.
- Data was shared with advertisers, trackers, and major tech firms like Microsoft and Adobe.
- Tesla's Model 3 was found to contact 34 advertising, tracking, and analytic domains.
- Alphabet's domains were the most frequently contacted by the tested vehicles.
Connected cars present a significant privacy challenge, with a recent study by researchers at Northeastern University and Consumer Reports revealing extensive data sharing with advertisers, trackers, and major technology firms. The study tested 21 vehicles from 19 different brands, measuring network traffic under various conditions, including when cars were idling and being driven. This research builds upon previous findings, such as a 2023 report by the Mozilla Foundation that labeled cars as the worst product category for privacy.
While the researchers could not inspect the content of data packets, they analyzed network traces including DNS traffic and TLS handshakes. All tested vehicles connected to their original equipment manufacturer's (OEM) domains. Some, like the Buick Envista and Mercedes-Benz EQS, appeared to limit their external connections. However, Tesla's Model 3 was found to be significantly more expansive, contacting 34 advertising, tracking, and analytic domains, in addition to 37 domains associated with integrated infotainment apps.
Alphabet's domains were the most frequently contacted across the tested vehicles, a finding not entirely unexpected given the prevalence of its Android Automotive OS. The study noted that many of these contacted domains, such as doubleclick.net and googlesyndication.com, are used for advertising purposes. Media streaming services like Spotify and Sirius XM, as well as mapping companies such as HERE, TomTom, and Mapbox, were also represented in the data traffic.
