The car and the app are two transmitters.
Northeastern University researchers and Consumer Reports tested 21 late-model vehicles and 30 companion apps. The vehicle tests used a custom Wi-Fi access point. The app tests used instrumented iPhones and a custom root certificate so the researchers could inspect app traffic.[1]
The study reports that 19 of the 21 vehicles contacted at least one third party over Wi-Fi. Seven of the 30 apps sent sensitive identifiers to companies associated with advertising and tracking. Five apps paired a vehicle identification number with other personal information.[1]
The product boundary is larger than the dashboard. The phone app is another data route.
A destination is not a decoded payload.
The vehicle capture exposed network destinations, but encryption kept the payload hidden. The app setup allowed the researchers to decrypt app traffic. Those observations support different claims. A contacted domain proves a connection. It does not, by itself, prove which fields crossed it or how the recipient used them.
The researchers classified first parties, service providers, and advertising, tracking, or analytics companies. That recipient work matters. A list of hostnames without company ownership and business role leaves the route half identified.[1]
The blind spot belongs on the diagram.
The study blocked cellular signals for a subset of electric vehicles with a Faraday tent, then repeated its Wi-Fi tests. It did not inspect general cellular payloads from every vehicle. The authors also limit their result to the tested U.S. vehicles, apps, software versions, and observation period from October 2024 through August 2025.[1]
That limit does not weaken the measured result. It prevents a Wi-Fi result from pretending to describe every route. The same rule applies to coding agents, smart devices, and desktop extensions. Put unobserved traffic on the map instead of deleting it from the story.
Pairing can change the exposure.
The research page says pairing a companion app roughly doubled exposure to advertising and tracking companies on average. Consumer Reports describes apps that sent vehicle identification numbers with an email address or location data. It also reports that app links and embedded third-party code were part of some manufacturer explanations.[2]
This is a composition problem. The car, account, phone, embedded web page, analytics kit, and remote service can each add a route. Review the assembled product. A clean result from one component cannot clear the rest.
User control needs a tested effect.
The Federal Trade Commission finalized an order with General Motors and OnStar in January 2026. The order requires affirmative express consent for covered connected-vehicle data, a copy and deletion route, an option to disable precise geolocation collection on capable vehicles, and a way to opt out of some geolocation and driving-behavior collection.[3]
That order applies to the named companies. It is not a general feature list for every car. For any connected product, test the control against observed traffic. Record what stops, what continues for safety or service operation, and whether account deletion reaches the device, app, and downstream records.
Build the telemetry record before the verdict.
Keep five fields together: observation point, destination, payload visibility, recipient role, and user control. Add the product revision and test action. If a field is unknown, write unknown. Do not convert a missing capture into a clean bill of health.
The Hacker News item was the discovery route. Its title and comments are not research evidence.[4] The loom below turns the study method into a reusable inspection sheet for any product with more than one network route.