We investigated 21 vehicles from the U.S. market in a controlled
environment along with 30 companion mobile apps instrumented
with on-site vehicles between October 2024 and August 2025. Below is a description of the experiments we ran and our setup.
Vehicle Testing
Photo is not loading images/rpi.png
Wi-Fi Testing Setup
To collect Wi-Fi traffic from vehicles,
we configured a custom access point (AP) on a Raspberry Pi and
used tcpdump to log all packets that were sent or received via this
AP.
This allowed us to see all the destinations the vehicles were sending data to but not the information within the packets as it was encrypted.
Photo is not loading images/test-facility.jpg
Stationary Tests
Idle Baseline vehicle on — no activity
Active Test perform all possible actions
Driving Test
drive 5–45 mph with acceleration & hard braking
Isolating Cellular Traffic
Photo is not loading images/faraday-tent.jpg
One hypothesis we tested was whether
blocking a vehicle’s ability to communicate over its cellular network
would force more Wi-Fi communication. To block external cellular
signals, we drove 11 EVs in the sample into a car-sized Faraday tent providing ≈93 dB of attenuation, blocking their
cellular connection entirely. Stationary Idle and Active tests were repeated inside the tent to see whether
traffic that normally goes out over cellular rerouted to Wi-Fi instead.
App Testing
In total, we experimented with 30 connected vehicle
companion apps that were paired with the vehicles at
Consumer Reports’s testing facility.
Device Setup
01We used a combination of test phones and iOS versions for our
experiments: an iPhone 8/iOS 16.6, an iPhone X/iOS 16.7.11, and an
iPhone 13/iOS 18.5.
02To minimize background traffic, we deleted all
non-essential apps on the test phones and tested apps one-by-one,
including deleting each vehicle app and restarting the phone before
downloading the next app.
03We used the iOS native screen recording
feature to record our interactions with each app for later review.
04To capture and decrypt network traffic from
the companion mobile apps, we used iPhones with custom root certificates connected
to mitmproxy.
Process for Testing Each App
01During app installation and login we accepted all permission requests (e.g., tracking,
location, calendar access, Bluetooth, notifications) that the application requested
02We had a Consumer Reports employee log into the app using
their existing credentials associated with a vehicle on the lot.
03Once we were logged-in, we manually exercised
all available functionality, such as looking for nearby charging staions, geolocating the vehicle, viewing vehicle data and service
history (e.g., tire pressure), viewing notifications (e.g., “doors are
unlocked”), and viewing in-app privacy policies.
04Some apps allowed
us to perform physical interactions on the vehicle, such as remotely
opening the trunk. We performed all such actions and verified that
the vehicle completed each request.