Car is a smartphone on wheels. Here's who's listening
Car is a smartphone on wheels. Here’s who’s listening
汽车就是装了轮子的智能手机,看看谁在监听
Connected Vehicle Ecosystem
互联汽车生态系统
This diagram shows the data flows to and from a vehicle and its companion mobile app. Both devices send data, including private consumer data, to different 1st and 3rd party servers using Wi-Fi and cellular service. Solid arrows represent flows that were intercepted through our experiments. 该图展示了车辆及其配套移动应用程序之间的数据流向。这两个设备都通过 Wi-Fi 和蜂窝网络将包括消费者隐私数据在内的信息发送到不同的第一方和第三方服务器。实线箭头代表我们在实验中拦截到的数据流。
The Problem
问题所在
Once the data gets sent to these servers, it is up to the companies that receive the consumer information to make decisions on what they do with it. Unfortunately, in many cases, this includes sharing or selling consumer data to other undisclosed 3rd parties. Consumers have no control over their data once it has left their device. 一旦数据被发送到这些服务器,接收消费者信息的公司就有权决定如何处理这些数据。不幸的是,在许多情况下,这包括将消费者数据共享或出售给其他未披露的第三方。一旦数据离开设备,消费者就无法再对其进行控制。
In this paper, we take the first steps to address the limited visibility into the privacy implications of the connected vehicle ecosystem. We identify two vantage points in the ecosystem where we can gain insight into the data that connected vehicles are sharing with both manufacturers and third parties: the vehicles themselves and the mobile apps provided by manufacturers. 在本文中,我们迈出了第一步,旨在解决互联汽车生态系统隐私影响透明度不足的问题。我们在该生态系统中确定了两个可以洞察互联汽车与制造商及第三方共享数据的切入点:车辆本身以及制造商提供的移动应用程序。
We ask the following guiding questions: 我们提出了以下指导性问题:
01 What personal consumer data do connected vehicles and their companion mobile apps transmit? 01 互联汽车及其配套移动应用程序传输了哪些个人消费者数据?
02 Who receives that personal consumer data? 02 谁接收了这些个人消费者数据?
03 What is the manufacturer response to these findings? 03 制造商对这些发现有何回应?
Methods
研究方法
We investigated 21 vehicles from the U.S. market in a controlled environment along with 30 companion mobile apps instrumented with on-site vehicles between October 2024 and August 2025. Below is a description of the experiments we ran and our setup. 在 2024 年 10 月至 2025 年 8 月期间,我们在受控环境中调查了美国市场的 21 款车辆,以及 30 款与现场车辆配套的移动应用程序。以下是我们进行的实验及其设置的说明。
Vehicle Testing: Wi-Fi Testing Setup
车辆测试:Wi-Fi 测试设置
To collect Wi-Fi traffic from vehicles, we configured a custom access point (AP) on a Raspberry Pi and used tcpdump to log all packets that were sent or received via this AP. This allowed us to see all the destinations the vehicles were sending data to but not the information within the packets as it was encrypted. 为了收集车辆的 Wi-Fi 流量,我们在树莓派(Raspberry Pi)上配置了一个自定义接入点(AP),并使用 tcpdump 记录了通过该接入点发送或接收的所有数据包。这使我们能够看到车辆发送数据的所有目的地,但由于数据包已加密,我们无法查看其中的具体信息。
Isolating Cellular Traffic
隔离蜂窝流量
One hypothesis we tested was whether blocking a vehicle’s ability to communicate over its cellular network would force more Wi-Fi communication. To block external cellular signals, we drove 11 EVs in the sample into a car-sized Faraday tent providing ≈93 dB of attenuation, blocking their cellular connection entirely. Stationary Idle and Active tests were repeated inside the tent to see whether traffic that normally goes out over cellular rerouted to Wi-Fi instead. 我们测试的一个假设是:阻断车辆通过蜂窝网络通信的能力是否会迫使其进行更多的 Wi-Fi 通信。为了阻断外部蜂窝信号,我们将样本中的 11 辆电动汽车开进了一个汽车大小的法拉第帐篷,该帐篷提供了约 93 分贝的衰减,完全阻断了它们的蜂窝连接。我们在帐篷内重复了静态空闲和主动测试,以观察通常通过蜂窝网络传输的流量是否会改道至 Wi-Fi。
App Testing
应用程序测试
In total, we experimented with 30 connected vehicle companion apps that were paired with the vehicles at Consumer Reports’s testing facility. 我们总共测试了 30 款互联汽车配套应用程序,这些应用程序均在《消费者报告》(Consumer Reports)的测试设施中与车辆进行了配对。
Process for Testing Each App: 每款应用程序的测试流程:
01 During app installation and login we accepted all permission requests (e.g., tracking, location, calendar access, Bluetooth, notifications) that the application requested. 01 在应用程序安装和登录过程中,我们接受了应用程序请求的所有权限(例如:跟踪、位置、日历访问、蓝牙、通知)。
02 We had a Consumer Reports employee log into the app using their existing credentials associated with a vehicle on the lot. 02 我们让一名《消费者报告》的员工使用与现场车辆关联的现有凭据登录应用程序。
03 Once we were logged-in, we manually exercised all available functionality, such as looking for nearby charging stations, geolocating the vehicle, viewing vehicle data and service history (e.g., tire pressure), viewing notifications (e.g., “doors are unlocked”), and viewing in-app privacy policies. 03 登录后,我们手动操作了所有可用功能,例如查找附近的充电站、定位车辆、查看车辆数据和服务历史(如胎压)、查看通知(如“车门已解锁”)以及查看应用内隐私政策。
04 Some apps allowed us to perform physical interactions on the vehicle, such as remotely opening the trunk. We performed all such actions and verified that the vehicle completed each request. 04 一些应用程序允许我们对车辆进行物理交互,例如远程打开后备箱。我们执行了所有此类操作,并验证了车辆是否完成了每项请求。
Findings
研究发现
- 19 of 21 vehicles contacted at least one third party over Wi-Fi, including known advertising and tracking domains. 21 辆车中有 19 辆通过 Wi-Fi 联系了至少一个第三方,其中包括已知的广告和跟踪域名。
- 7 of 30 companion apps transmitted sensitive identifiers (VINs, emails, phone numbers, precise location) to third parties associated with advertising and tracking. 30 款配套应用程序中有 7 款将敏感标识符(车辆识别码 VIN、电子邮件、电话号码、精确位置)传输给了与广告和跟踪相关的第三方。
- Transmitting multiple forms of PII (Personally Identifiable Information) to the same third party allows advertisers to build in-depth profiles on consumers. 将多种形式的个人身份信息(PII)传输给同一个第三方,使广告商能够建立深入的消费者画像。