Back to Blog
Privacy & Mobile Security

Connected Cars as a Surveillance Platform: What the Northeastern Study Shows

A Northeastern University study with Consumer Reports traces data moving between vehicles, their companion apps and third parties. For security teams, the car is now a data-exposure surface as well as a safety-critical system.

PyramidLedger Research3 min read
Share

Key Takeaways

  • Researchers at Northeastern University, working with Consumer Reports, mapped data flowing among vehicles, the apps that ship with them and third-party companies.
  • Nearly every automaker sends data to outside entities, including insurers, lenders, data brokers, infotainment and WiFi hotspot vendors, and government agencies.
  • Roughly a quarter of the vehicle apps studied transmitted personally identifiable information, including owner names, VINs and precise location.
  • Treat the vehicle app and the telematics back end as a mobile and API attack and privacy surface, not just a consumer-privacy issue.

What the research found

Bruce Schneier summarises a new study from Northeastern University, carried out with Consumer Reports. In his account, it shows for the first time the data flowing among the vehicles, the apps you download when you buy a car, and third-party companies. It documents which kinds of data are taken from vehicles and which companies receive them.

The headline finding is breadth. Nearly every automaker sends data to external entities. The recipients named in the summary are:

  • car insurers and lenders taking part in telematics data exchanges;
  • thousands of data brokers that build personalised risk scores;
  • infotainment and WiFi hotspot product vendors;
  • local and state government agencies working on planning, traffic and safety.

Why the app layer matters

About a quarter of the vehicle apps transmitted personally identifiable information. That included the owner's name, the VIN and precise geographic location. Those three fields are enough to link a specific person to a specific vehicle and to where it travels. According to the summary, brokers and marketers use that linkage to build profiles. Those profiles are then sold to financial institutions, insurers, pharmaceutical firms, lenders and retailers, who use them to set loan terms and filter service offers.

For a security practitioner, this reframes the vehicle. The companion app, the telematics back end and the SDKs inside them are ordinary mobile and API attack surface. They also sit on a data-sharing chain the end user rarely sees. A VIN plus a precise location is a durable identifier. Unlike a password, it cannot be rotated.

What security and privacy teams should take from it

  • Include automotive and mobility apps in mobile testing scope. Check what each one sends, to whom, and whether the traffic matches the privacy notice.
  • Map third-party SDK and partner flows. Data leaving through an SDK or a partner API is still your data-protection exposure.
  • Minimise identifiers. If you build connected-vehicle or fleet products, ask whether name, VIN and precise location need to travel together at all.
  • Fleet owners should review contracts and consents. Telematics sharing with insurers and brokers can happen under terms nobody read.

Limits of what we can say

The primary study is not linked in the summary we reviewed. The figures above come from that summary. We have not independently verified per-manufacturer results or how the sample of apps was chosen. Read the full Northeastern and Consumer Reports material before citing specific brands.

Frequently Asked Questions

What data do connected cars share with third parties?

According to the Northeastern University and Consumer Reports study as summarised by Schneier, nearly every automaker sends data externally. About a quarter of the vehicle apps transmitted personally identifiable information such as names, VINs and precise location.

Who receives connected-car data?

Recipients include insurers and lenders in telematics data exchanges, thousands of data brokers, infotainment and WiFi hotspot vendors, and local and state government agencies.

Why is this a security issue and not only a privacy issue?

The vehicle apps and back-end services that move this data are mobile and API surfaces. Identifiers such as the VIN and precise location are hard to change once exposed. Both can be tested for over-collection and leakage like any other application.

Sources

  1. 1Connected Cars Are a Surveillance Platform — Schneier on Security
Share

Read next