A new study from Northeastern University and Consumer Reports measured real network traffic from 21 connected cars across 19 brands. The results confirm that privacy concerns about connected cars are not just theoretical: most vehicles contacted third-party advertising, tracking, and analytics domains, with Tesla's Model 3 contacting 34 such domains plus 37 from integrated apps. Alphabet domains were the most frequently contacted, including advertising services like doubleclick.net.

The study also tested 30 companion apps and found that using them can multiply exposure, with General Motors, Toyota, and Nissan among the worst offenders. Some electric vehicles, when cut off from cellular signals in a Faraday tent, redirected traffic to Wi-Fi, revealing additional data flows. The researchers could not decrypt the actual data packets, but DNS and TLS metadata were enough to map the connections.

When the researchers contacted 14 automakers, most said third-party data sharing was covered by contracts prohibiting use of personally identifiable information outside privacy agreements. Several also said it was up to consumers to read and accept terms, even though declining can mean losing features. One positive note: Honda changed its practices after being contacted and no longer shares precise location data with at least one tracking company.