When tinkering becomes surveillance: the DOJ's car-app data grab and what it means for digital freedom

Posted on 15.05.2026

Somewhere between the spanner and the smartphone, the humble act of modifying your own car has become a data-privacy flashpoint. According to MacDailyNews, the U.S. Department of Justice has asked Apple and Google to identify more than 100,000 users of a popular car-tinkering app as part of an emissions crackdown. That's not a typo: a hundred thousand people, named via their app store accounts, in a single demand.

The case is American, the app is niche, and the legal hook is environmental. But the principle it tests — whether a government can compel the world's two biggest gatekeepers to unmask an entire user base in one go — should make every Australian who has ever installed a hobbyist app sit up.

What's actually being asked

Strip away the headline and the DOJ's request is striking for its scale. Investigators aren't naming a suspect and asking the platforms for their device details. They're going the other way: starting with an app, and asking Apple and Google to hand over the identities of everyone who downloaded it. The justification, per the reporting, is an investigation into devices and software that can be used to defeat vehicle emissions controls — so-called "delete" tunes that disable diesel particulate filters or alter engine maps.

That kind of tampering is illegal under the U.S. Clean Air Act. Selling the hardware is a clearer offence than installing it, and using a tuning app is something else again — plenty of users tinker on race-only vehicles, dyno cars, off-road utes, or simply read engine data without modifying anything. A blanket unmasking treats all 100,000 the same until proven otherwise.

The right-to-repair backdrop

For the past decade, a global "right to repair" movement has argued that owning a thing should mean being allowed to fix, modify and understand it. Tractors, iPhones, coffee machines and cars have all been battlegrounds. In Australia, the Productivity Commission's 2021 right-to-repair inquiry pushed for clearer consumer rights on motor-vehicle service information, and the Motor Vehicle Information Scheme now legally requires manufacturers to share service and repair data with independent mechanics.

Car-tuning apps sit in a messy corner of that movement. Some uses are squeaky-clean: reading fault codes, logging performance on a track day, recalibrating after a legal hardware change. Others — defeating emissions equipment on a road-registered vehicle — are not. The technology itself is dual-use, much like a VPN, a torrent client or a 3D printer.

That's exactly why the DOJ's approach matters. If the legal answer to "this tool can be misused" is "identify everyone who touched it," the chilling effect ripples far beyond diesel utes.

Why Apple and Google are the pressure point

The reason the DOJ went to Cupertino and Mountain View, rather than to the app developer, is structural. To install almost any app on an iPhone or a stock Android device, you go through the App Store or Google Play. Those storefronts know who you are: your Apple Account or Google account, your payment details, often your device identifiers and rough location.

Apple's leverage here is amplified by its market position. MacDailyNews reports that iPhone's share of U.S. smartphone sales has reached 75% at the country's three biggest carriers. Between Apple and Google, virtually every American mobile user — and the overwhelming majority of Australians — is reachable through one of two corporate ledgers.

That concentration is convenient for law enforcement and uncomfortable for everyone else. It means a single subpoena, served on two companies, can theoretically illuminate the private behaviour of a stadium's worth of people. There's no analogue equivalent. Imagine demanding a list of everyone who bought a Haynes manual for a Nissan Patrol.

The privacy precedent that should worry Australians

Australia has no First Amendment, and our anti-tampering and emissions rules are enforced through a patchwork of federal and state laws, including the Road Vehicle Standards Act and state EPA regulations. We do, however, have the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 — the so-called "anti-encryption" law — which already gives Australian agencies broad powers to compel technology companies to help with investigations.

What the U.S. case crystallises is the next logical step: not breaking encryption to read messages, but using app-store metadata to map communities of interest. The technique is well-suited to:

  • Protest and activism apps
  • Reproductive-health and LGBTQ+ apps
  • Cryptocurrency and privacy tools
  • Whistleblower or journalist-source apps
  • Hobbyist tools that brush up against regulation — drones, radio scanners, lockpicking guides, car tuners

None of those user bases are inherently criminal. All of them could be "unmasked" with the same legal instrument used here. Once the playbook exists, it tends to get reused.

Where platforms could push back

Apple, in particular, has built much of its brand on privacy: on-device processing, App Tracking Transparency, end-to-end iMessage. That posture is going to be tested as the company's hardware strategy diversifies — MacDailyNews has even reported the company is testing Intel for low-end and legacy chips, suggesting more SKUs, more markets and more regulatory entanglements ahead.

Platforms have three obvious levers when faced with a bulk demand:

1. Narrow the request

Push the government to specify suspects, regions or transaction patterns rather than handing over the full user list. Courts in the U.S. have previously trimmed overbroad "geofence" warrants on similar grounds.

2. Notify users

Where law permits, tell affected users their account information has been requested. Both Apple and Google publish transparency reports; the granularity of those reports is itself a privacy lever.

3. Collect less

The strongest defence against a subpoena is not having the data. App stores could, in principle, allow more anonymous installation flows for free apps, or shorten retention windows for download logs. That's a commercial decision dressed up as a technical one.

The bigger question for tinkerers

The romance of the home mechanic — the Saturday morning under the bonnet, the dyno graph, the OBD-II reader plugged into a daily driver — has always lived in tension with regulators. What's new is that the workbench is now digital, and the tools phone home.

It's reasonable for governments to enforce emissions law. Diesel "delete" kits do real harm: a 2020 EPA report estimated that tampered heavy-duty pickups in the U.S. would emit as much excess NOx over their lifetimes as adding millions of additional trucks to the road. Australians breathing the air over the Hume Highway have a stake in that too.

But enforcement choices have shapes. Going after manufacturers and sellers of illegal hardware targets the supply side. Auditing registered vehicles targets the actual offence. Demanding the identity of every person who installed an app targets a population, most of whom have done nothing wrong, in the hope of finding the few who have.

That's the line the DOJ's request crosses, and it's the line right-to-repair advocates have been warning about for years. The argument was never that tinkerers should be above the law. It was that the law shouldn't treat curiosity as probable cause.

What to watch next

Three things will tell us how seriously to take this case as precedent. First, whether Apple and Google comply, fight, or negotiate the scope. Second, whether U.S. courts treat bulk app-user disclosures the same way they've treated geofence warrants — with growing scepticism. Third, whether Australian agencies cite the American model when seeking similar information here.

For now, the practical takeaway is unglamorous but real: the apps on your phone are not anonymous. The storefront knows. And in 2024, "the storefront knows" increasingly means the government can know too, in batches of a hundred thousand.

Related on Bleen

Sources

Comments 0