01-09-2023, 12:29 PM | #1 |
First Lieutenant
577
Rep 372
Posts
Drives: 2023 G80 Comp X-Drive
Join Date: Nov 2011
Location: Los Angeles, CA
|
Security Flaws in California's Digital License Plates (Reviver)
Was always suspicious of these.
"A team of security researchers managed to gain “super administrative access” into Reviver, the company behind California’s new digital license plates which launched last year. That access allowed them to track the physical GPS location of all Reviver customers and change a section of text at the bottom of the license plate designed for personalized messages to whatever they wished, according to a blog post from the researchers." https://www.vice.com/en/article/wxn9...e-gps-location |
01-09-2023, 02:02 PM | #3 |
Colonel
2453
Rep 2,539
Posts |
Just like any other piece of technology, theres bound to be flaws. This isn't really surprising. These were fixed well ahead of public release.
|
Appreciate
0
|
01-09-2023, 02:48 PM | #4 |
Brigadier General
12461
Rep 4,327
Posts |
Lol @ blindly trusting any new technology.
The amount of people who have Alexas, ring cameras and stuff is wild. Those things are such huge security breaches. "it duznt mattur cuz evrythin traks u even ur fone" or "if u hav nuthin 2 hide then who cares" <- pick whichever terrible logic to justify bad decisions |
Appreciate
4
|
01-09-2023, 03:10 PM | #5 | |
Lieutenant Colonel
3527
Rep 1,755
Posts |
Quote:
What is your solution? Not to have cameras? |
|
Appreciate
0
|
01-09-2023, 03:13 PM | #6 |
Lieutenant
2089
Rep 544
Posts |
If I may stray back on topic, why does a license plate have GPS capability - regardless of it being government-issued?
__________________
2022 BMW M240i Portimao
Gone: 2020 Genesis G70 3.3T | 2018 Audi A5 SportBack | 2015 Challenger Scat Pack | 2011 Mustang V6 | numerous others.. |
Appreciate
3
|
01-09-2023, 03:49 PM | #7 |
Brigadier General
12461
Rep 4,327
Posts |
|
Appreciate
4
|
01-09-2023, 04:39 PM | #8 | |
Colonel
2453
Rep 2,539
Posts |
Quote:
The GPS is used to track the vehicle in the event that its stolen. (it also has LTE capabilities) |
|
Appreciate
0
|
01-09-2023, 04:39 PM | #9 |
Brigadier General
5545
Rep 3,344
Posts |
Your own cameras that are not cloud attached nor dependent on it. I have security cameras on my home but the system is totally autonomous not requiring any stupid cloud server. As an extra measure, I have the cameras isolated on a specific part of my network where the cameras don't have access to anything else on my network nor have Internet access. If I want to view the live feed from the cameras or recorded video remotely, I connect to an SSL VPN server I set up in my network.
|
Appreciate
0
|
01-09-2023, 04:40 PM | #10 | |
Banned
5007
Rep 4,135
Posts |
Quote:
|
|
Appreciate
1
UncleWede18487.00 |
01-09-2023, 04:41 PM | #11 |
Colonel
2453
Rep 2,539
Posts |
You'd still want/need offsite storage if you want any kind of redundancy. In-home storage wont do you any good if your house is burned down, or the storage device is stolen.
Your point is valid, but the idea that you can keep everything "in house" likely isnt realistic from a redundancy standpoint. |
Appreciate
1
NYG12461.00 |
01-09-2023, 04:44 PM | #12 | |
Brigadier General
5545
Rep 3,344
Posts |
Quote:
|
|
Appreciate
0
|
01-09-2023, 04:50 PM | #13 | |
Colonel
2453
Rep 2,539
Posts |
Quote:
I'd probably just do something simple over SSL/SSH to get the same level of encryption as your VPN. Both methods will achieve what you're seeking though |
|
Appreciate
0
|
01-09-2023, 05:16 PM | #14 | |
Brigadier General
5545
Rep 3,344
Posts |
Quote:
|
|
Appreciate
0
|
01-09-2023, 05:24 PM | #15 | |
Colonel
2453
Rep 2,539
Posts |
Quote:
I've had good luck with Fortinet hardware in the past setting up site-to-site links. (Though I have a close friend who was a vendor, so I may be a bit bias) |
|
Appreciate
0
|
01-09-2023, 05:30 PM | #16 |
Brigadier General
5545
Rep 3,344
Posts |
I do have a Fortinet firewall. But it's being used in my primary home as the gateway into my management network. Yeah, my "home" network is overkill, but it's how I design networks when I was building data centers. I installed a Palo virtual firewall but haven't gotten around to do anything with it yet.
|
Appreciate
0
|
01-09-2023, 05:58 PM | #17 |
Captain
21668
Rep 632
Posts |
|
Appreciate
2
CTinline-six6942.50 NYG12461.00 |
01-09-2023, 06:12 PM | #18 | |
Brigadier General
5545
Rep 3,344
Posts |
Quote:
Another thing that people don't understand aside from the security issues, is that they really don't own the equipment. That device is only functional as long as that cloud server is up and running or supports their hardware. Once either goes away, you're stuck with buying new hardware regardless of if that hardware is working and satisfies your needs. |
|
Appreciate
2
CTinline-six6942.50 Murf the Surf21667.50 |
01-10-2023, 08:11 AM | #19 | |
Captain
21668
Rep 632
Posts |
Quote:
My sister has a couple of Nest cameras outside of her house. Kind of interesting that she gets a chime on her phone when ever anyone is at the front door, but she also gets a chime anytime the neighbours cat walks through her back yard. I'm very reluctant to use any of the smart devices in my home. Our new furnace and heat pump came with a proprietary smart thermostat, and that's it for us at this point. I do like that I can monitor the house temp while were away from home. We are heading south for a couple of months so it does offer some piece of mind. |
|
01-10-2023, 09:22 AM | #20 | |
Brigadier General
5545
Rep 3,344
Posts |
Quote:
I agree on the smart/IoT devices. Won't use them if I can avoid them. I do have a smart thermostat too. It's at my vacation home. It allows me to precondition the house before I arrive and the same as you keep tabs on it temp wise. The thermostat is from Honeywell. Figure they wouldn't be as nefarious as the big players with snooping. The thermostat saved my butt when I was getting temperature alerts that my house was too cold. It was during the really cold winter season we had a few years ago. Thought the furnace was just catching up with heating the house. Temps kept falling based on the alerts I was receiving. This prompted me to make an immediate trip out where I found the furnace not working. |
|
Appreciate
1
Murf the Surf21667.50 |
01-11-2023, 01:23 AM | #21 |
Major
145
Rep 1,129
Posts |
|
Appreciate
1
Murf the Surf21667.50 |
Post Reply |
Bookmarks |
Tags |
california, gps, hack, license plate, location, research, reviver |
|
|