Car is a smartphone on wheels. Here's who's listening
- ID
- 31689
- Status
- summarized
- Published
- 04 Oct 2026, 11:43 PM
- Fetched
- 05 Oct 2026, 3:32 AM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://automatictransmission.khoury.northeastern.edu/
- Source URL
- https://hnrss.org/best
Summary
- Score
- 6.0
- Created
- 05 Oct 2026, 3:32 AM
- Tags
- Audience
- developersvibe_coderssaas_startup_founders
What happened
Researchers at Northeastern University, working with Consumer Reports, tested 21 late-model connected vehicles (19 brands) and 30 companion mobile apps, and found that 19 of 21 vehicles sent traffic to at least one third party over Wi-Fi. Seven of 30 apps transmitted sensitive identifiers to third-party companies, and 5 of 30 sent VIN plus other PII to trackers. The peer-reviewed paper is slated for IMC '26, and the fleet used (supplied by Consumer Reports) would have cost over $1.2M to assemble independently.
Why it matters
If you ship a mobile companion app — car-related or not — this is concrete evidence that third-party analytics and tracker SDKs leak identifiers like VIN and PII: 7 of 30 apps did it, and 5 leaked VIN specifically. Before your next release, intercept your app's outbound traffic (proxy or on-device capture) and check what your analytics/attribution SDKs actually send, because 'we only use standard SDKs' was true of these apps too. The text contains no Malaysia-specific finding, so treat any local insurer, telco, or connected-car angle as a downstream question, not a reported fact.
Discussion angle
Walk through how you'd audit your own app's third-party traffic in an afternoon — proxy interception, SDK inventory, and what you'd do if you found a tracker receiving a device or account identifier you never intended to share.