Third-party automotive apps present both privacy and security risks

connected car apps could give hackers access to your vehicle

(Image credit: SergeyBitos/Shutterstock)

As cars have become more intelligent, more users are turning to third-party connected car apps to access a wider range of functions compared to first-party offerings. But new research warns they can put your privacy and the security of your vehicle at risk.

To compile its new report (opens in new tab) on automotive mobile apps, researchers at the cybersecurity firm Kaspersky analyzed 69 popular third-party apps designed to control connected cars to find that more than half (58%) of these applications use a vehicle owners’ credentials without first asking for their consent. Even worse, 14 percent of the apps tested had no contact information, which makes reporting a problem near impossible.

These third-party connected car apps cover almost all major vehicle brands, including Tesla, Nissan, Ford and Volkswagen. But Kaspersky’s researchers claim that they are often not entirely safe to use. Of the key privacy risks drivers might face while using these apps, over half don’t warn them regarding the risks of using the owner’s account from the original automaker’s service.

You may be wondering why some connected vehicle owners turn to third-party instead of first-party apps to control their cars. The reason for this is that they offer unique features that have not yet been introduced by the vehicle manufacturer like being able to see fuel/energy consumption charges depending on the route they take or allowing a user to manage several different car brands all from within one app.

Using authorization tokens instead of a username and password

Some of the developers of third-party connected car apps use an authorization token instead of a username and password in an attempt to appear more credible. However, if a token is compromised, an attacker could get access to your connected car in the same way they could do so with your credentials.

Using authorization tokens doesn’t ensure total safety according to Kaspersky and despite this, only 19 percent of developers mention that they use tokens instead of credentials and warn their users about the potential dangers.

Head of transportation security at Kaspersky, Sergey Zorin, provided further insight on the firm’s new report in a press release (opens in new tab) while warning users that using third-party connected car apps could put their private information at risk, saying:

“The benefits of a connected world are countless. However, it is important to note that this is still a developing industry, which carries certain risks. When downloading a third-party application to control your car remotely, users should be aware of possible threats. We entrust a lot of private information and personal data to connected technology.

Unfortunately, not all developers take a responsible approach when it comes to data storage and collection, which results in users exposing their personal information. This data may further be sold on the dark web and end up in untrustful hands. Moreover, cybercriminals might not only steal your data and personal credentials but also gain access to your vehicle – and that might lead to physical threats. For these reasons, we urge application developers to make user protection a priority and take precautionary measures to avoid compromising their customers and themselves.”

How to safely use third-party connected car apps

If you do want to use a third-party app with your connected car, Kaspersky has several recommendations to help you stay safe while doing so.

First off, you should only download apps from official stores like the Apple App Store or Google Play Store. While there could be dangerous apps on either store, at least they are checked by Apple and Google and there is an approval system in place.

Next up, you should check the permissions of the apps you use and carefully consider before giving them access to high-risk permissions like Accessibility Services. The less data an app can collect on you the better as it could be exposed online accidentally or disclosed following a data breach.

In terms of keeping your device secure, you should consider installing a mobile antivirus while keeping both your operating system and apps regularly updated.

When in doubt though, it’s always better to rely on first-party connected car apps from your vehicle’s manufacturer as opposed to trying to use third-party ones to add new features. If you want a feature added to a first-party app, you can always reach out to your vehicle maker or the app’s developer instead, though this may take some time.

MOTOR'S NEWS RELATED

Join Road & Track and Car and Driver on Our Annual Car of the Year Tests

Check out today's coolest new cars alongside editors at Performance Car of the Year, Lightning Lap, and 10Best Awards.

View more: Join Road & Track and Car and Driver on Our Annual Car of the Year Tests

Satisfying Subaru SUVs That People Love Driving and Owning

Satisfying Subaru SUVs that people love driving include the 2022 Crosstrek The 2022 Forester is another Satisfying Subaru SUV that people love Don’t overlook the 2022 Outback for a stress-free driving experience Subaru makes a reliable and safe sport utility vehicle, but that’s not all. These Satisfying Subaru SUVs ...

View more: Satisfying Subaru SUVs That People Love Driving and Owning

Holiday Rambler Eclipse RV Debuts With Theater Seats, Drop-Down Loft

It’s available with three different floor plans.

View more: Holiday Rambler Eclipse RV Debuts With Theater Seats, Drop-Down Loft

Genesis prices 2023 G80 electric car at $81,000, expands EVs to more states

Genesis on Thursday expanded the breadth and availability of its electric car lineup on its path to becoming a fully electric automaker by 2030. The luxury brand’s newest car, the 2023 Electrified Genesis G80, will cost $80,920 (including a $1,095 destination fee) when it goes on sale in September. The ...

View more: Genesis prices 2023 G80 electric car at $81,000, expands EVs to more states

This C5 Corvette Turned Off-Roader Could be Yours For Small Bucks

Photo: Caleb Hodshire/Facebook Fans of the Chevrolet Corvette and off-road vehicles now have a golden opportunity to combine their two passions for a small amount of money. A tuning enthusiast in Illinois, who specializes in Corvette conversions, is selling on Marketplace a fifth-generation (C5) 1999 Corvette built to venture ...

View more: This C5 Corvette Turned Off-Roader Could be Yours For Small Bucks

Audi heads to F1, 2025 Cadillac Celestiq, 2023 Electrified Genesis G80: Today's Car News

Audi confirmed it will enter F1 for the 2026 season. The automaker will team with a thus far unknown chassis partner to provide power units that will be built in Germany and run on synthetic fuel. Alfa Rome announced it will split with Sauber, and all points sign to Audi ...

View more: Audi heads to F1, 2025 Cadillac Celestiq, 2023 Electrified Genesis G80: Today's Car News

Genesis expands GV60, an electric SUV, availability to four more US states

Where is the Genesis GV60 available to buy Electrek’s Take Now might be your chance if you’ve been waiting to buy the Genesis GV60 EV SUV. The Korean luxury automaker announced Tuesday that its flagship electric SUV, the GV60, will be available in four more US states starting in ...

View more: Genesis expands GV60, an electric SUV, availability to four more US states

Our Long-Term 2022 Cadillac CT5-V Blackwing Is off to an Unforgettable Start

With our 668-hp, six-speed-manual sports sedan, the highs are high, and the lows are low.

View more: Our Long-Term 2022 Cadillac CT5-V Blackwing Is off to an Unforgettable Start

Dodge goes electric in style | Autoblog Podcast #744

Tested: Best Car Vacuums for 2022

China: Power to the people or to the carmakers?

Tesla premium connectivity through Starlink V2 confirmed

2022 Ford F-150 Lightning strapped to dyno despite challenges

1983 DeLorean DMC-12 with 5,397 miles for sale

Numbers of Koenigsegg CC850s increase to 70 due to high demand

Tech Deep Dive: What Makes the New Porsche GT3 RS the Most Extreme 911 Ever

4 Terrible 2022 Subcompact SUVs That Consumer Reports Predicts Owners Will Hate

Xiaomi in talks with BAIC to produce electric cars, says Bloomberg

Audi Has Decided to Enter Formula 1 in 2026 After Much Speculation

North Dakota Swing Ahead For WoO: What To Watch For

OTHER MOTO NEWS