The study, conducted by a team from Northeastern University and Consumer Reports, measured actual network traffic from connected cars under various conditions—idling, being driven, and for 11 electric models, even parked in a Faraday tent to observe what happens when cellular signals are lost and data shifts to Wi-Fi.
While the researchers were unable to decrypt the actual data packets—modified certificate attempts failed—the network traces still revealed valuable patterns. By analysing DNS traffic, Server Name Indication in TLS handshakes, and the volume and timing of transmissions, they could identify which domains the cars contacted and how behavior changed across scenarios.
The results showed that data is being sent to advertisers, trackers, and companies like Microsoft and Adobe. Using a car's companion app magnified the data-sharing, the study found.
This is not the first time connected cars have been flagged for poor privacy practices. In 2023, the Mozilla Foundation reviewed the privacy policies of more than two dozen automakers and concluded that "cars are the worst product category we have ever reviewed for privacy." That analysis, however, was based on reading privacy policies; the new study provides empirical evidence of the data flows in action.