Misconfigured License Plate Readers Expose Real-Time Data and Video

In a concerning revelation, a security researcher has disclosed a significant flaw in the operation of automated license-plate-recognition (ALPR) systems, specifically those manufactured by Motorola. These systems, designed to assist law enforcement in monitoring vehicle activity, have been found to be leaking real-time data and video feeds, compromising the privacy and security of thousands of individuals. In Nashville, Tennessee, for example, an ALPR system managed to capture images and detailed information from almost 1,000 vehicles in just 20 minutes. This data, collected by one of Motorola’s ALPR systems, is theoretically intended for the exclusive use of law enforcement agencies. However, a discovered vulnerability has made it possible for unauthorized individuals to access live video feeds and extensive records of vehicles in motion, highlighting the vast surveillance capability of this expanding technology.

Over the past few months, more than 150 Motorola ALPR cameras have been responsible for exposing their video feeds, as well as leaking sensitive data. This incident was researched by Matt Brown, who publicized the findings after purchasing an ALPR camera on eBay and conducting a reverse engineering analysis. Shockingly, these systems broadcast live footage without requiring any form of authorization, such as usernames or passwords, thereby greatly expanding the potential for unauthorized access.

Motorola has confirmed these security lapses, as reported by WIRED. It stated that the company is actively collaborating with its customers to rectify these issues. ALPR cameras have increasingly populated urban and suburban areas throughout the United States over the past decade. Deployed by companies like Motorola and Flock Safety, these cameras automatically snap photos when vehicles come into view and populate databases that law enforcement uses to track suspect activities. Placement of these devices ranges from permanent installations along roadways to mobile platforms in police vehicles and even deployable units in trucks.

The data inadvertently exposed includes not only the make, model, and color of vehicles but also occasionally captures bumper stickers and other identifying markers, leading to a heightened concern over privacy implications. As per Matt Brown, who leads cybersecurity firm Brown Fine Security, every camera incident he identified was positioned over roadways with a singular focus on one lane of traffic. Additionally, some of the video streams reviewed included one in color and another in infrared, with atmospheric conditions visible, such as falling snow.

This unfolding situation highlights the critical need for comprehensive security measures and awareness in the deployment and management of surveillance technology.