Millions at risk due to severe security flaw in license plate readers

Cars on the road with blue overlay indicating what data may be contained about the drivers within
(Image credit: Shutterstock)

A curious security researcher who bought a Motorola automated license plate reader was able to discover a concerning security flaw that affects hundreds of live ALPR cameras across the country. Matt Brown, who runs Brown Fine Security, purchased a Motorola ReaperHD ALPR license plate reader surveillance camera off eBay and quickly found that many of the same, live cameras are misconfigured to stream color, infrared black-and-white and car data including license plate numbers to the open internet where they can be accessed by anyone in real time without a username or password.

Brown, who made a series of YouTube videos demonstrating his proof-of-concept tool that exposes these vulnerabilities, initially only reverse engineered his own camera to extract the device’s firmware when he found video streams on the device. He then set out to see if any of the real world devices were available online, and was able to use text from a 404 error page to find the IP addresses of the exposed devices on the public internet. More than 150 devices appear when using a publicly available internet scanning tool.

ALPR cameras are often placed along roads, on the dashboard of police vehicles or even inside of trucks in order to automatically take pictures when they detect a car passing by. The system uses machine learning to extract text from the license plate, which is stored alongside details such as where the image was taken, as well as the time, and the make, model and color of the vehicle. The videos and databases of collected data are then frequently used by police to search for suspects.

Motorola has responded by confirming the exposures and a spokesperson has told media outlets it is working with affected customers to close the open access. A spokesperson explains: “The ReaperHD camera is a legacy device, the sales of which were discontinued in June 2022. Findings in the recent YouTube videos do not pose a risk to customers using their devices in accordance with our recommended configurations. Some customer-modified network configuration potentially exposed certain IP addresses. We are working directly with these customers to restore their system configurations consistent with our recommendations and industry best practices. Our next firmware update will introduce additional security hardening.”

However, this isn't the first instance of this kind of breach: A community called DeFlock, which is an open-source map of ALPRs in the United States, has also found roughly 170 unencrypted ALPRs. The founder of that community even built a script that can take the data, decode it, add timestamped information and dump it onto a spreadsheet in order track a specific car's movements.

In 2015 the Electronic Frontier Foundation and University of Arizona researchers found hundreds of exposed ALPR streams, and in 2019 a hack of an ALPR vendor at the Department of Homeland Security resulted in the license plates of images of travelers being put up for sale on the dark web.

Brown, the security researcher, says that while not all Motorola ALPRs are leaking data or streaming to the open internet, the security flaw is still concerning and not something that is going to be fixed overnight. "You still have a super vulnerable device that if you gain access to their network you can see the data. When you deploy the technology into the field, attacks always get easier, they don't get harder."

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

Read more
A digital license plate on a grey car
Digital license plates can be hacked to avoid tolls, fines and tickets
Green skull on smartphone screen.
Only 3 of the top 150 Android apps can detect reverse engineering tool Frida — here's why that's bad
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
A Wi-Fi router next to a phone with a lock symbol on the screen
Massive MikroTik router botnet has been spreading malware – here’s how to stay safe
Graphic of fibre optic cables attacking code
An estimated 46,000 VPN servers are vulnerable to being hijacked
Latest in Online Security
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
An Android bot next to an Android TV remote
Millions of Android TVs hijacked in massive botnet — how to see if yours is at risk
Poster of Elon Musk saying "I am stealing from you"
Elon Musk's DOGE blocked from accessing your data – and 3 in 4 Americans agree
A fake text message on a smartphone being held by both hands.
Toll road scams are worse than ever — what to look for and how to stay safe
A phone with Google Search open on screen
Google just made it easier to remove your personal info from search results — here's how to do it
Eight Sleep Pod 4 Ultra with head raised in beige bedroom
Eight Sleep smart beds reportedly have a secret backdoor that can be accessed remotely — everything you need to know
Latest in News
Charlie Cox as Matt Murdock / Daredevil in "Daredevil: Born Again"
I just watched ‘Daredevil: Born Again’ and it has one serious problem
Google search on a phone
Google Search's AI Overviews just got a major Gemini 2.0 upgrade — here's what's new
Press
Hulu top 10 shows — here's the 3 worth watching right now
Emily Blunt in Sicario
'Sicario’ just hit Netflix’s top 10 movies — stream this crime thriller rated 92% on Rotten Tomatoes
Helix ErgoAlign mattress topper on top of black mattress on wooden bedframe in bedroom with plant, gold bedside lamps and grey rug
Helix launch two new mattress toppers for advanced cooling and back pain relief
Mac Studio M4 Max
Apple announces Mac Studio with M4 Max and M3 Ultra — here's what's new