Last year, California made digital license plates available to drivers in the state. Instead of rusty planks of metal hanging from the front of a car, residents have the option of switching to a plate-sized screen displaying a license plate number, customizable with personalized banners.
However, just a few months after the option was introduced, it seems a security researcher has managed to compromise the license plates’ cybersecurity protections. In a recent blog post, web application expert Sam Curry said he successfully hacked into California’s plates.
More specifically, he and a bunch of friends were able to attain “full super administrative access” to all of the user accounts, and their details, linked to Reviver—the company tasked with selling the state’s tech-savvy license plates.
In the horrifying discovery, Curry found that a malicious hacker would’ve been able to track the physical GPS locations of all customers, update any vehicle’s status to “stolen,” and access all personal records, including one’s address, phone number, and more.
Furthermore, attackers could choose to change or delete the text displayed on any of the digital plates, and even use a “fleet management” function to locate and manage all of the vehicles in a company’s entire fleet.
The cybersecurity flaw had far-reaching consequences beyond just Reviver’s database, as the team noted they could “additionally access any dealer and update the default image used by the dealer when the newly purchased vehicle still had dealer tags.”
When Motherboard reached out to Reviver, the company did own up to the software vulnerabilities, though it said that it had patched the leaks up “in under 24 hours,” along with taking “further measures” to ensure such intrusions were not possible again.
Thankfully, if you’ve got a digital license plate, an internal investigation from the firm confirmed that the vulnerability had not been misused by hackers, and there was no evidence of any risks to customers.
While it’s good news that no one’s information got stolen, this incident no doubt brings back the question regarding the proliferation of the Internet of Things: does everything really need to be digitized?
Sure, while connecting appliances, cars, and even apparel to the internet could make certain features more convenient, could we be opening ourselves up to more and more security vulnerabilities?
In the age of rising cybersecurity concerns, such as with popular social media platforms like TikTok, perhaps more thought has to go into making a digital version of a product that may not need one. After all, if it ain’t broke, don’t fix it, right?