Your car and its mobile app are probably handing over all kinds of data to tech companies
Your car and its mobile app are probably handing over all kinds of data to tech companies
你的汽车及其配套移动应用可能正在向科技公司泄露各种数据
Modern-day vehicles built with connected car technology such as WiFi and GPS collect reams of data about its owners. And that data is not staying private, according to a new study conducted by researchers at Northeastern University. 现代汽车内置了 WiFi 和 GPS 等联网技术,会收集大量关于车主的数据。根据东北大学研究人员的一项最新研究,这些数据并未得到妥善保护。
That conclusion isn’t new — there have been numerous investigations and lawsuits exposing how driving data is collected and shared with third parties, including insurance companies. What the study reveals is just how vast the problem is and how hard it is for consumers to avoid, short of not using the vehicle or its convenient features like remote start and unlock. 这一结论并不新鲜——此前已有大量调查和诉讼揭露了驾驶数据是如何被收集并与保险公司等第三方共享的。这项研究揭示的是该问题的严重程度,以及消费者在不放弃使用车辆或远程启动、解锁等便捷功能的情况下,想要规避这一问题有多么困难。
Researchers in partnership with Consumer Reports tested 21 late-model vehicles from 17 automakers, including GM brands Cadillac and Chevrolet as well as Ford, Lucid, Rivian, Tesla, Toyota, and more. They also examined 30 companion mobile apps to “understand the privacy implications of the connected vehicle ecosystem.” The peer-reviewed study will be published this week. 研究人员与《消费者报告》(Consumer Reports)合作,测试了来自 17 家汽车制造商的 21 款近期车型,包括通用汽车旗下的凯迪拉克和雪佛兰,以及福特、Lucid、Rivian、特斯拉、丰田等。他们还检查了 30 款配套移动应用,旨在“了解联网汽车生态系统的隐私影响”。这项经过同行评审的研究将于本周发布。
The implications aren’t great for consumers, whose data is being shared with tech companies including Adobe, ContentSquare, Google, Microsoft, Meta, Snap, and Yahoo. Nineteen of the 21 vehicles tested sent traffic to at least one third party and seven of the 30 apps gave sensitive data such as the vehicle identification number (VIN), emails, phone numbers, and precise location to third-party companies associated with tracking and advertising. 这对消费者来说并不是好消息,因为他们的数据正被共享给 Adobe、ContentSquare、谷歌、微软、Meta、Snap 和雅虎等科技公司。在测试的 21 款车型中,有 19 款会将流量发送给至少一个第三方;在 30 款应用中,有 7 款将车辆识别码 (VIN)、电子邮件、电话号码和精确位置等敏感数据提供给了与追踪和广告相关的第三方公司。
This often went a step further with multiple forms of information being sent to the same third party, a scheme that allows advertisers and data brokers to build in-depth profiles of consumers, according to the findings. These profiles can be particularly hard for consumers to shake because they’re sold to a variety of companies including insurers and banks. 研究结果显示,这种情况往往更进一步,即多种形式的信息被发送给同一个第三方,这种机制使得广告商和数据经纪人能够构建消费者的深度画像。这些画像对消费者来说尤其难以摆脱,因为它们会被出售给包括保险公司和银行在内的各类企业。
When researchers paired the companion app to the vehicle it roughly doubled the exposure to advertising and tracking companies. The findings were shared with the different manufacturers and all of them, with the exception of Honda, shifted blame elsewhere and often to consumers, the researchers said. (Honda did respond by improving its data collection practices after learning about the findings and ordered its vendor Amplitude to delete all geolocation data it had received.) 当研究人员将配套应用与车辆配对时,其暴露给广告和追踪公司的风险大约增加了一倍。研究人员表示,他们与各汽车制造商分享了这些发现,除本田外,所有制造商都将责任推卸给其他方,甚至推卸给消费者。(本田在获悉研究结果后,通过改进其数据收集实践做出了回应,并要求其供应商 Amplitude 删除其已接收的所有地理位置数据。)
Consumer Reports was told by several automakers that some links in their companion apps opened outside webpages, which might include cookies that collect customer data. Regardless of how this data was collected, drivers weren’t informed. 几家汽车制造商告诉《消费者报告》,其配套应用中的一些链接会跳转到外部网页,这些网页可能包含收集客户数据的 Cookie。无论这些数据是如何被收集的,驾驶员都未被告知。