E90Post
 


Extreme Powerhouse
 
BMW 3-Series (E90 E92) Forum > BIMMERPOST Universal Forums > Off-Topic Discussions Board > Security Flaws in California's Digital License Plates (Reviver)



Reply
 
Thread Tools Search this Thread
      01-09-2023, 12:29 PM   #1
MunkyTool
First Lieutenant
MunkyTool's Avatar
United_States
575
Rep
372
Posts

Drives: 2023 G80 Comp X-Drive
Join Date: Nov 2011
Location: Los Angeles, CA

iTrader: (0)

Garage List
Security Flaws in California's Digital License Plates (Reviver)

Was always suspicious of these.

"A team of security researchers managed to gain “super administrative access” into Reviver, the company behind California’s new digital license plates which launched last year. That access allowed them to track the physical GPS location of all Reviver customers and change a section of text at the bottom of the license plate designed for personalized messages to whatever they wished, according to a blog post from the researchers."

https://www.vice.com/en/article/wxn9...e-gps-location
Appreciate 0
      01-09-2023, 01:30 PM   #2
jmack
First Lieutenant
jmack's Avatar
549
Rep
384
Posts

Drives: OG M2, E70 X5M
Join Date: Oct 2018
Location: TN

iTrader: (0)

It's a feature, not a flaw.
Appreciate 0
      01-09-2023, 02:02 PM   #3
detroitm2
Colonel
detroitm2's Avatar
United_States
2451
Rep
2,539
Posts

Drives: 2018 M2
Join Date: Aug 2018
Location: Michigan

iTrader: (2)

Garage List
2018 BMW M2  [10.00]
Just like any other piece of technology, theres bound to be flaws. This isn't really surprising. These were fixed well ahead of public release.
__________________
2018 M2 - Daily Driver/Track Car
Motorcity BMWCCA Member
Instagram | YouTube
Appreciate 0
      01-09-2023, 02:48 PM   #4
NYG
Brigadier General
NYG's Avatar
United_States
12075
Rep
4,237
Posts

Drives: Audi R8
Join Date: Feb 2017
Location: Brooklyn, NY

iTrader: (0)

Lol @ blindly trusting any new technology.

The amount of people who have Alexas, ring cameras and stuff is wild. Those things are such huge security breaches.

"it duznt mattur cuz evrythin traks u even ur fone" or "if u hav nuthin 2 hide then who cares" <- pick whichever terrible logic to justify bad decisions
Appreciate 4
jmack548.50
      01-09-2023, 03:10 PM   #5
Tyga11
Banned
3509
Rep
1,752
Posts

Drives: M3 Comp
Join Date: Jul 2019
Location: Arizona

iTrader: (0)

Quote:
Originally Posted by NYG View Post
Lol @ blindly trusting any new technology.

The amount of people who have Alexas, ring cameras and stuff is wild. Those things are such huge security breaches.

"it duznt mattur cuz evrythin traks u even ur fone" or "if u hav nuthin 2 hide then who cares" <- pick whichever terrible logic to justify bad decisions
I have ADT security cameras. Are you saying they are at risk of hacking from criminals or the government? Or both?

What is your solution? Not to have cameras?
Appreciate 0
      01-09-2023, 03:13 PM   #6
CarsAndGuitars
Lieutenant
2087
Rep
544
Posts

Drives: 2022 M240i
Join Date: Mar 2022
Location: South FL

iTrader: (0)

Quote:
Originally Posted by Tyga11 View Post
I have ADT security cameras. Are you saying they are at risk of hacking from criminals or the government? Or both?

What is your solution? Not to have cameras?
If I may stray back on topic, why does a license plate have GPS capability - regardless of it being government-issued?
__________________
2022 BMW M240i Portimao
Gone: 2020 Genesis G70 3.3T | 2018 Audi A5 SportBack | 2015 Challenger Scat Pack | 2011 Mustang V6 | numerous others..
Appreciate 3
BMWGUYinCO4335.00
jmack548.50
      01-09-2023, 03:49 PM   #7
NYG
Brigadier General
NYG's Avatar
United_States
12075
Rep
4,237
Posts

Drives: Audi R8
Join Date: Feb 2017
Location: Brooklyn, NY

iTrader: (0)

Quote:
Originally Posted by Tyga11 View Post
I have ADT security cameras. Are you saying they are at risk of hacking from criminals or the government? Or both?

What is your solution? Not to have cameras?
Dedicated server inside of your home.
Appreciate 4
      01-09-2023, 04:39 PM   #8
detroitm2
Colonel
detroitm2's Avatar
United_States
2451
Rep
2,539
Posts

Drives: 2018 M2
Join Date: Aug 2018
Location: Michigan

iTrader: (2)

Garage List
2018 BMW M2  [10.00]
Quote:
Originally Posted by CarsAndGuitars View Post
If I may stray back on topic, why does a license plate have GPS capability - regardless of it being government-issued?
Its not government issued, Its just authorized for use in US states.

The GPS is used to track the vehicle in the event that its stolen. (it also has LTE capabilities)
__________________
2018 M2 - Daily Driver/Track Car
Motorcity BMWCCA Member
Instagram | YouTube
Appreciate 0
      01-09-2023, 04:39 PM   #9
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by Tyga11 View Post
I have ADT security cameras. Are you saying they are at risk of hacking from criminals or the government? Or both?

What is your solution? Not to have cameras?
Your own cameras that are not cloud attached nor dependent on it. I have security cameras on my home but the system is totally autonomous not requiring any stupid cloud server. As an extra measure, I have the cameras isolated on a specific part of my network where the cameras don't have access to anything else on my network nor have Internet access. If I want to view the live feed from the cameras or recorded video remotely, I connect to an SSL VPN server I set up in my network.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 0
      01-09-2023, 04:40 PM   #10
G35POPPEDMYCHERRY
Banned
G35POPPEDMYCHERRY's Avatar
No_Country
5006
Rep
4,135
Posts

Drives: F80
Join Date: Dec 2015
Location: Philadelphia

iTrader: (1)

Quote:
Originally Posted by zx10guy View Post
Your own cameras that are not cloud attached nor dependent on it. I have security cameras on my home but the system is totally autonomous not requiring any stupid cloud server. As an extra measure, I have the cameras isolated on a specific part of my network where the cameras don't have access to anything else on my network nor have Internet access. If I want to view the live feed from the cameras or recorded video remotely, I connect to an SSL VPN server I set up in my network.
you must have something to hide
Appreciate 1
UncleWede18403.50
      01-09-2023, 04:41 PM   #11
detroitm2
Colonel
detroitm2's Avatar
United_States
2451
Rep
2,539
Posts

Drives: 2018 M2
Join Date: Aug 2018
Location: Michigan

iTrader: (2)

Garage List
2018 BMW M2  [10.00]
Quote:
Originally Posted by NYG View Post
Dedicated server inside of your home.
You'd still want/need offsite storage if you want any kind of redundancy. In-home storage wont do you any good if your house is burned down, or the storage device is stolen.

Your point is valid, but the idea that you can keep everything "in house" likely isnt realistic from a redundancy standpoint.
__________________
2018 M2 - Daily Driver/Track Car
Motorcity BMWCCA Member
Instagram | YouTube
Appreciate 1
NYG12075.00
      01-09-2023, 04:44 PM   #12
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by detroitm2 View Post
You'd still want/need offsite storage if you want any kind of redundancy. In-home storage wont do you any good if your house is burned down, or the storage device is stolen.

Your point is valid, but the idea that you can keep everything "in house" likely isnt realistic from a redundancy standpoint.
I'm in process of setting up a site to site VPN tunnel between my primary home and vacation home. I have a Dell VRTX blade server with two M630 blades. Once I get the network sorted between the homes, I'll stand up my Equallogic iSCSI SAN with 16TB of storage. I'll then replicate the video data to that storage array.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 0
      01-09-2023, 04:50 PM   #13
detroitm2
Colonel
detroitm2's Avatar
United_States
2451
Rep
2,539
Posts

Drives: 2018 M2
Join Date: Aug 2018
Location: Michigan

iTrader: (2)

Garage List
2018 BMW M2  [10.00]
Quote:
Originally Posted by zx10guy View Post
I'm in process of setting up a site to site VPN tunnel between my primary home and vacation home. I have a Dell VRTX blade server with two M630 blades. Once I get the network sorted between the homes, I'll stand up my Equallogic iSCSI SAN with 16TB of storage. I'll then replicate the video data to that storage array.
I don't see a ton of benefit of using a site-to-site VPN for this. Unless you're trying to encrypt a wide variety of traffic. Though it will likely make it a bit easier to implement the storage array replication.

I'd probably just do something simple over SSL/SSH to get the same level of encryption as your VPN.

Both methods will achieve what you're seeking though
__________________
2018 M2 - Daily Driver/Track Car
Motorcity BMWCCA Member
Instagram | YouTube
Appreciate 0
      01-09-2023, 05:16 PM   #14
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by detroitm2 View Post
I don't see a ton of benefit of using a site-to-site VPN for this. Unless you're trying to encrypt a wide variety of traffic. Though it will likely make it a bit easier to implement the storage array replication.

I'd probably just do something simple over SSL/SSH to get the same level of encryption as your VPN.

Both methods will achieve what you're seeking though
The reason I'm doing a site to site is because there are things I want to be able to access over there and vice versa depending on where I am physically located. One thing which will be nice is to get my IP phones at my vacation home running through the site to site to work with my call manager at my primary home. Currently, I'm using a unique layer 2 extension solution between locations. And yes, I'm planning on using Equallogic SAN replication across the tunnel as I have a PS6100 at my primary home and a PS4000 at my vacation home. I'm trying to get OSPF working between the two locations but I think I'm running into a SonicWall limitation on requiring a static public IP. So I'm going to try coding in static routes to get the routing working.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 0
      01-09-2023, 05:24 PM   #15
detroitm2
Colonel
detroitm2's Avatar
United_States
2451
Rep
2,539
Posts

Drives: 2018 M2
Join Date: Aug 2018
Location: Michigan

iTrader: (2)

Garage List
2018 BMW M2  [10.00]
Quote:
Originally Posted by zx10guy View Post
The reason I'm doing a site to site is because there are things I want to be able to access over there and vice versa depending on where I am physically located. One thing which will be nice is to get my IP phones at my vacation home running through the site to site to work with my call manager at my primary home. Currently, I'm using a unique layer 2 extension solution between locations. And yes, I'm planning on using Equallogic SAN replication across the tunnel as I have a PS6100 at my primary home and a PS4000 at my vacation home. I'm trying to get OSPF working between the two locations but I think I'm running into a SonicWall limitation on requiring a static public IP. So I'm going to try coding in static routes to get the routing working.
Ah, yeah. That would fall under the "I wanna do other things" option.

I've had good luck with Fortinet hardware in the past setting up site-to-site links. (Though I have a close friend who was a vendor, so I may be a bit bias)
__________________
2018 M2 - Daily Driver/Track Car
Motorcity BMWCCA Member
Instagram | YouTube
Appreciate 0
      01-09-2023, 05:30 PM   #16
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by detroitm2 View Post
Ah, yeah. That would fall under the "I wanna do other things" option.

I've had good luck with Fortinet hardware in the past setting up site-to-site links. (Though I have a close friend who was a vendor, so I may be a bit bias)
I do have a Fortinet firewall. But it's being used in my primary home as the gateway into my management network. Yeah, my "home" network is overkill, but it's how I design networks when I was building data centers. I installed a Palo virtual firewall but haven't gotten around to do anything with it yet.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 0
      01-09-2023, 05:58 PM   #17
Murf the Surf
Captain
Murf the Surf's Avatar
21225
Rep
623
Posts

Drives: Porsche 993
Join Date: Mar 2022
Location: Port Carling, Muskoka

iTrader: (0)

Quote:
Originally Posted by NYG View Post
Dedicated server inside of your home.
Yup, the problem is people want real time monitoring and then give up the privacy to get it.
Appreciate 2
NYG12075.00
      01-09-2023, 06:12 PM   #18
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by Murf the Surf View Post
Yup, the problem is people want real time monitoring and then give up the privacy to get it.
I think it's more of people's perception of value and also not understanding that easy comes at a cost. I get why these things are appealing. I helped set up a Ring doorbell camera for someone. It was stupid easy. But non cloud connected devices do require some level of technical expertise to implement. And for whatever reason, home IT is something that many people refuse to spend money on getting a company to set it up for them if they lack the skills. Hence this growing industry of the easy button network devices.

Another thing that people don't understand aside from the security issues, is that they really don't own the equipment. That device is only functional as long as that cloud server is up and running or supports their hardware. Once either goes away, you're stuck with buying new hardware regardless of if that hardware is working and satisfies your needs.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 2
      01-10-2023, 08:11 AM   #19
Murf the Surf
Captain
Murf the Surf's Avatar
21225
Rep
623
Posts

Drives: Porsche 993
Join Date: Mar 2022
Location: Port Carling, Muskoka

iTrader: (0)

Quote:
Originally Posted by zx10guy View Post
I think it's more of people's perception of value and also not understanding that easy comes at a cost. I get why these things are appealing. I helped set up a Ring doorbell camera for someone. It was stupid easy. But non cloud connected devices do require some level of technical expertise to implement. And for whatever reason, home IT is something that many people refuse to spend money on getting a company to set it up for them if they lack the skills. Hence this growing industry of the easy button network devices.

Another thing that people don't understand aside from the security issues, is that they really don't own the equipment. That device is only functional as long as that cloud server is up and running or supports their hardware. Once either goes away, you're stuck with buying new hardware regardless of if that hardware is working and satisfies your needs.

My sister has a couple of Nest cameras outside of her house. Kind of interesting that she gets a chime on her phone when ever anyone is at the front door, but she also gets a chime anytime the neighbours cat walks through her back yard.

I'm very reluctant to use any of the smart devices in my home. Our new furnace and heat pump came with a proprietary smart thermostat, and that's it for us at this point. I do like that I can monitor the house temp while were away from home. We are heading south for a couple of months so it does offer some piece of mind.
Appreciate 2
zx10guy5516.00
NYG12075.00
      01-10-2023, 09:22 AM   #20
zx10guy
Brigadier General
5516
Rep
3,322
Posts

Drives: 2013 135i
Join Date: Feb 2014
Location: DC

iTrader: (0)

Quote:
Originally Posted by Murf the Surf View Post
My sister has a couple of Nest cameras outside of her house. Kind of interesting that she gets a chime on her phone when ever anyone is at the front door, but she also gets a chime anytime the neighbours cat walks through her back yard.

I'm very reluctant to use any of the smart devices in my home. Our new furnace and heat pump came with a proprietary smart thermostat, and that's it for us at this point. I do like that I can monitor the house temp while were away from home. We are heading south for a couple of months so it does offer some piece of mind.
The behavior of your sister's Nest cameras shows that Nest has a weak human recognition software/algorithm. Blue Iris is known to have very good human recognition limiting false positives.

I agree on the smart/IoT devices. Won't use them if I can avoid them. I do have a smart thermostat too. It's at my vacation home. It allows me to precondition the house before I arrive and the same as you keep tabs on it temp wise. The thermostat is from Honeywell. Figure they wouldn't be as nefarious as the big players with snooping. The thermostat saved my butt when I was getting temperature alerts that my house was too cold. It was during the really cold winter season we had a few years ago. Thought the furnace was just catching up with heating the house. Temps kept falling based on the alerts I was receiving. This prompted me to make an immediate trip out where I found the furnace not working.
__________________
Quote:
Originally Posted by Lups View Post
We might not be in an agreement on Trump, but I'll be the first penis chaser here to say I'll rather take it up in the ass than to argue with you on this.
Appreciate 1
      01-11-2023, 01:23 AM   #21
W Cole
Major
145
Rep
1,130
Posts

Drives: 2009 M3
Join Date: Dec 2010
Location: Newport Coast, CA

iTrader: (5)

Quote:
Originally Posted by Tyga11 View Post
I have ADT security cameras. Are you saying they are at risk of hacking from criminals or the government? Or both?

What is your solution? Not to have cameras?
Closed circuit cameras is the solution
Appreciate 1
Reply

Bookmarks

Tags
california, gps, hack, license plate, location, research, reviver


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -5. The time now is 01:50 AM.




e90post
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.
1Addicts.com, BIMMERPOST.com, E90Post.com, F30Post.com, M3Post.com, ZPost.com, 5Post.com, 6Post.com, 7Post.com, XBimmers.com logo and trademark are properties of BIMMERPOST