字号 ·· | 护眼
arstechnica

这项研究考察联网汽车如何共享你的数据,以及与谁共享This study looks at how and with whom connected cars share your data

点「原文对照」整页切到原文,或双击某段只看那段的原文。

在几乎不会令人感到惊讶的新闻中,联网汽车仍然是彻头彻尾的隐私噩梦。不过,多亏了东北大学和《消费者报告》研究人员团队开展的一项研究,我们现在对这些汽车泄露了哪些数据以及泄露给谁有了更清晰的认识。对19个不同品牌的21辆汽车进行测试后,研究人员发现了流向广告商和追踪器的流量模式,以及与微软、Adobe等大型科技公司共享的数据。测试还发现,使用汽车配套应用可能会让问题更加严重。

In news that should surprise very few, connected cars remain a complete privacy nightmare. But now we have a better idea of what data those cars are giving away, and to whom, thanks to a study conducted by a team of researchers at Northeastern University and Consumer Reports. Testing 21 cars from 19 different brands revealed patterns of traffic to advertisers and trackers, as well as data shared with Big Tech firms like Microsoft and Adobe. And using a car’s companion app can multiply the problem, their testing found.

2023年,莫zilla基金会发布了一份引发广泛关注的报告,审视了二十多家汽车制造商的隐私政策。报告令他们深感震惊,并写道:“就隐私而言,汽车是我们审查过的所有产品类别中最糟糕的。”但那次分析只是通过阅读各品牌的各项隐私政策来完成;今天这项研究则是在多种场景下测量真实汽车产生的网络流量,包括汽车怠速和行驶时的场景。研究人员甚至将11辆汽车——仅限电动汽车——停放进法拉第帐篷,以观察蜂窝信号中断后,相关流量是否会转而通过汽车的无线网络连接传输。

In 2023, the Mozilla Foundation published a widely covered report looking at the privacy policies of more than two dozen automakers. They were appalled, writing that “cars are the worst product category we have ever reviewed for privacy.”But that analysis was conducted by sitting down and reading all the various privacy policies of each brand; today’s study involved measuring traffic from actual cars under a number of scenarios, including idling and being driven. The researchers even parked 11 cars—just the electric ones—in a Faraday tent to see if the loss of a cellular signal would push that traffic to the car’s Wi-Fi connection instead.

研究人员发现,使用经过修改的证书来实际查看数据包内容的尝试均告失败。但“网络流量追踪仍提供了有价值的信息,包括通过DNS流量访问的域名、TLS握手中的服务器名称指示(SNI)、数据传输量及其时间规律,以及不同实验场景下的行为差异”。

Attempts to actually see what was in the data packets using modified certificates failed in every case. But “the network traces still yielded valuable information, including the domains contacted via DNS traffic, Server Name Indication (SNI) in TLS handshakes, the volume and timing of transmissions, and differences in behavior across experimental scenarios,” they found.