Open-source license plate reader
arstechnica.com
arstechnica.com
What's good for the goose ...
I suspect a much better job could be done now, with a combination of better cameras in phones, more cpu available to do the processing on newer phones, and I suspect a multicopter brushless camera gimbal to stabilise/aim the camera.
(I was very space-limited, since I was testing this on a motorcycle, a car with a better-than-phone-grade machine in it would make the job simpler.)
Random people can see my license plate but they don't know who I am. Today only people who know my license plate AND happen to see it randomly know I'm there at this moment, which is a reasonable expectation of privacy for me.
Now if there was a website where you can query a partially complete trip history of any license plate completely void that privacy. Think about such a tool in the hands of a paparazzi for instance...
Though I guess a smarter RFID plate could use latency to decide if a reader was "close enough", but that would make reliable reads harder since it would require several round trips.
The guy reckons 2 miles is theoretically possible with HAM radio-operator-legal transmit power (1.5kW) and the right antennas.
I'm not criticizing you; just clarifying. These are tough questions.
I tend to think that if you're in the clear to document something (ie, it's in public), then you are in the clear to publish it.
Otherwise, we have a mess of free speech boundaries.
the real issue is "a person who knows me well enough to know my license plate number can know my location at one point in time if they happen to be in the immediate area" vs. "all people who can find my license plate number can know my location at all points in time".
the dichotomy is "everyone in the checkout line can see what i'm buying" vs. "all people who know my first and last name can view my entire credit card transaction history".
Unless you want to draw a line between information which is directly observed by people and information which is collected by machine, this seems like a difference of degree, not of kind.
Nobody cares about any one particular data point being published; it's the collection of all of them that's revealing. See the "metadata" debate that's been going on for a year or two now.
I suspect that most folks would be willing to self-publish their checking account balance on one random day. But every day for a year, or their whole lives? Probably not. You have to marry me if you want to have that kind of information.
To find out where I am, you'd currently need to have me tailed. The cost involved gives me a reasonable degree of privacy in my estimation. You'd need to have some kind of reasonable cause, and assets, and need to think there was something in monitoring my movements worth spending for.
If it costs you $5 to pull up a complete driving history, you can surveil 1,000 people for the same cost, and go for a fishing trip. See if anyone moderately wealthy has been in a bad part of town, etc
Do you see a distinction between me taking a photo of you by being out in public being my right and me using a special camera to pick up photons emitted by your body and not blocked by your clothing and creating an image from these?
Do you see a distinction between me being able to look into your window from the public sidewalk and me using infrared technology to map out everything you do in the house?
What if I invent a camera that can take a photo of a letter and reveal all the contents inside in easily readable detail, without needing to touch the letter. By you grabbing a letter out of your mailbox, you are letting me see the outside of it, so if this camera can capture the content is there any significant difference?
BUT, technology allows me to capture far more than the visible spectrum. Give your clothes probably don't consist of lead plates, part of the photos I can detect are from your body and not your clothes. So using this information, and some recoloring algorithms, I can likely create a decent image of your underlying body.
Applying technology allows for more information to be withdrawn from situations where previously that information wasn't available. But due to the need for advanced technology to pick up on the information, most people do not even realize they are leaking it. (Take private conversation being recorded at a distance by viewing vibrations in objects near where the conversation is happening.)
Our technology has outpaced our moral/philosophical reasoning and the gap keeps growing.
If you see my license plate in the street today, I wouldn't care at all. I wouldn't be fine if you published that information in a "where is everybody right now" wiki. From that wiki a stalker would have it really easy to ruin my life; a burglar could break in at the good moment; an employer could know I visited their concurrent, probably for an interview; I go to this church/mosque/synagogue/... : now you know my religion;the neighborhood association could see I have 'too many' (for their standard) friends (or AirBnB customers?) visiting; marketers could see I go often to store X,Y, on vacation to Z, that I'm more of a Fast food Mc lover than a BK, ...
Also: So taking a photo of (or making a memory of having seen) doesn't violate your privacy . For many Europeans countries it does violate the privacy, if that photo has no public information purpose. For instance: http://uk.practicallaw.com/7-573-6346
In fact I've just done that with my car and it works. Has my name and address. The only gate is a captcha.
You can actually look up random people's numbers, because all the plates are two letters for the Canton, plus a number starting at 1. So for instance "ZG 888" is a valid plate, as is "ZH 12345"
Why should I not get the same level of privacy?
http://www.nytimes.com/2010/02/28/automobiles/28REPO.html?_r... http://www.nbcnews.com/news/other/license-plate-data-not-jus... http://www.thenewspaper.com/news/43/4338.asp
^ Link to the actual software from last week and some associated discussion.
It could lead to restrictions on what the government is permitted to do with the data.
So we'll have to deal with them somehow, and I'd prefer that the government not have a monopoly on the data -- frankly, I think that the data that the government collects in public should be made public, rather immediately, so that we can see what is being collected.
But there are other things to be mindful of...when publicizing how easy it is to be surveilled/attacked, how easy is it to for a mischievous person to make use of that information versus how long would it take to fix? I'd have mixed feelings about anyone publishing a user-friendly one-button-SWATter, even if it would most certainly spur some kind of movement to strengthen our emergency response systems (eventually).
But something that is basically an object detector plus OCR? No doubt that if many people run this software, and then feed into a system that makes it as easy (and ubiquitous) as Google to look up any license plate and see instantly all locations where it has been photographed, we would have a situation that would make most people a bit unhappy...but without those network effects, the personal use of this software would seem to be relatively benign, while at the same time educating people how easy it is to be tracked.
Then anybody could see stolen vehicles and report them. That would discourage theft.
Most likely the first thing thieves do is switch their plate with the plate of a similar car (same make, same color), then drive to another country where they'll be resold.
A professional car thief who steals cars in order to resell them may very well work that way. But I suspect those people are a small minority in comparison to the opportunists who probably don't have appropriate spare plates on hand, or the desperate criminals trying to pick up a getaway car, or the joyriders, etc.
In another car that I'd just purchased a cop pulled up next to me at a light and asked about my lack of plate. Said I bought it a couple days ago, he said I have X days in this state to get tagged and drove off.
Sometimes VIP type people get deputized or have their vehicles somehow associated with a police agency.
The flips side of that, though, is that this power exists and is being used by rich, powerful entities anyway. If I was a law-abiding member of a mosque or political group, I'd love to know that undercover law enforcement officers are trying to stir up trouble, for example. If they can track me, why shouldn't I be able to track them? Or, less melodramatically, the highest rate of road fatalities in my country involve logging trucks. There are persistent claims that companies keep them on the road for more hours than their drivers are legally allowed to work, but they're politically shielded from official investigations. It would be nice for citizen groups to have the tools to investigate those claims.
If we should be able to go about free of day-to-day surveillance (absent good, court-approved cause), which I certainly agree with, then we should be modifying laws and institutions to reflect that. Since what we've got is a situation where the powerful (government agencies, large companies) use the absence of regulation and powerful tools to watch us the second-best option is for us to have the tools to watch them.
Curious the downvotes on that comment, it's totally feasible.
(I suppose technically the TPMS requirement applies to the manufacturer as opposed to the owner, though.)
I'm guessing that you got downvoted because the logic is ridiculous: LPRs are to be feared because bombs can be attached to them. That is true of every technology. Also, if somebody has your plate number and knows your driving patterns well enough to leave a VBIED there - they could find a much more certain and easily executed method of assassination.
I have a friend who likes to make and print his own 3d models. He built his own 3d printer. I connected the camera he got to his raspberry pi and installed and configured octopi for him because he wasn't confident he could figure it out in a timely manner.
Nope, there were a small number of bomb makers who provided the bombs to a distribution network - this network then assigned the bombs to emplacement teams. There was also state level assistance coming from Iran. A few bomb makers and a lot of emplacement teams blew themselves up - so it isn't as easy as Hollywood has portrayed.
If you need more than around 200feet of range, a coathanger as an antenna at each end could probably triple that range, a couple of coathangers fashioned into a pair of 310MHz yagis could likely get you several miles range.
All for less than a Raspberry Pi camera.
Even if you, as a "smart guy" were also a bad guy, would you _really_ consider doing things "the hard way"?
The "bad guys" already know reliable ways of long-distance remotely triggering IEDs: https://www.google.com.au/search?q=IED+trigger&num=100&tbm=i...
They're using those cell phone we all threw out 10 years ago. (I think I see a dozen or more of my old Nokia 8210 there...)
In what way is acquiring the skills required to download/compile/configure this software, then integrate it with an electrically detonated bomb - more likely to be undertaken by "the bad guys" than hooking the detonator up to the backlight of a burner phone and standing a block away and texting it? (Just like every reported IED from the latest war-torn country being bombed into democracy and freedom.)
It makes me mad when intelligent people think up "bad things" that might be done with extremely high barriers to entry, when way simpler and easier to achieve methods for the same "bad stuff" are obvious.
Case in point - one of my local councils has just blanket banned "drones" (without even bothering to define what a "drone" is) on the pretext that "there is a concern about people taking unauthorised photos of children in public areas" - See more at: http://www.ausleisure.com.au/news/safety-fears-see-leichhard....
Watch this video of a $600 point-n-shoot camera (at least past the 37 sec mark) and tell me you're more at risk from someone with a drone invading your privacy: https://www.youtube.com/watch?v=Csp6asxf00o
If people want to take your (or your families) picture, they will. Probably with their cell phone without anyone noticing, or with a $600 camera on a tripod so far away you can't even see them. They _won't_ buy a $1,200+ drone and learn to pilot it, then fly it up close where you can see it. (And they _certainly_ won't be learning to assemble and tune their own quadcopter for a few hundred dollars of Chinese sourced parts. Not just to be a creep with.)
Same if they want to blow something up - they're not going to clone some open source code from github, learn how to use it's python bindings, and build a RaspberryPi powered auto-detonator to trigger off your numberplate. There are _way_ lower barrier-to-entry methods to achieve that goal (which are also way more reliable).
Do you think that's an appropriate response? Especially since it seems to be almost universally true that every time the TSA is tested, weapons still get through the checkpoints with startling regularity.
Sorry, but I still see this as kneejerk reactions to spectacularly unlikely scenarios of "bad things happening" being proposed and regulated by people who don't care about reducing other people's freedom because it won't affect them personally.
I'm still unsure what you're suggesting "shouldn't be allowed" here? Open sourcing computer vision projects? Publishing on github? SHould all hobbyists leave face detection algorithms to Facebook and Apple and Google, because someone else might misuse the results (worse that Zuckerberg already does)? It's all extremely reminiscent of the "crypto wars" and Homeland Security's new "House Un-American Mathematics Committee": https://twitter.com/puellavulnerata/status/67290345222221824...
Me? I'm 100% for publishing this(and similar) projects - because the tech is already out there and being used. Pretty much every towtruck and repo man has had this tech running for 5+ years, and almost nobody knows. Why is it a problem now that sufficiently motivated geeks can roll their own for ~$100 and a weekend's futzing around? Same with using promiscuous wifi adapters or TV-tuner SDRs to sniff MAC addresses or TMSIs - shopping malls and law enforcement are routinely using that tech to track you, I reckon more art projects showing how simple and creepy it is would be a good thing.
There's another movie-plot bomb detonator for you - an UberTooth One (or $5 Chinese counterfeit wifi adaptor in promiscuous mode) listening for the MAC address of your phone/smartwatch/tablet. What're we going to have to ban in response to that idea?
(I know, lets ban _ideas!_... (Sorry, that's way snarkier than intended...))
No because it is not going to make much difference.
> Sorry, but I still see this as kneejerk reactions to spectacularly unlikely scenarios of "bad things happening" being proposed and regulated by people who don't care about reducing other people's freedom because it won't affect them personally.
Fully agreed on that one.
> I'm still unsure what you're suggesting "shouldn't be allowed" here?
This software has a ton of bad use possibilities, I just threw out the first one that I could think of, there are a whole raft of others.
> Open sourcing computer vision projects? Publishing on github?
No, it's inevitable. But there is currently no framework on how to deal with these things. Just because you can doesn't always mean that you should. There are a ton of things I could do that are legal but that does not mean that all those things have a net-positive effect on the society we live in and I think that the ability to build these systems comes with some responsibility.
> Me? I'm 100% for publishing this(and similar) projects - because the tech is already out there and being used. Pretty much every towtruck and repo man has had this tech running for 5+ years, and almost nobody knows.
Yes, but they are limited in quantity and enough of a quantitative change is a qualitative change.
> (I know, lets ban _ideas!_... (Sorry, that's way snarkier than intended...))
I think I beat you to that:
* note: the definition of "good people" and "bad people" is not the point here
You may be able to get a list of law enforcement license plates through a FOIA request and then use this plus a network of many highway cameras to show a map of where law enforcement was last seen.
This may provide more clarity: http://stackoverflow.com/questions/1960802/can-i-use-librari...
Essentially - if you have modified openalpr then you are probably violating, if you haven't you probably aren't.
Unless you are a small company with a business model tied tightly around using a modified openalpr to generate revenue then there is plenty of scope for complying with the license without damaging the business. If you are then the company is stealing and I would advise leaving.
Either way you are under a moral, and potentially legal, obligation to bring the company towards compliance. Advice for you is not to massively rock the boat - do not use it as a means to hurt your employer (even after leaving) do not focus too much on it.
IANAL; The way I would approach this:
- forward the this news article (not the hacker news post) and the openalpr license page http://www.openalpr.com/license.html to your legal contact (and manager?). Attach a simple and professional message along the lines of "Saw an article about some software we use and I am concerned we may be accidentally violating the license"
- Do not act like you really care. You were just exercising due diligence in your job and forwarding on to people that deal with it. Don't rock the boat, don't defend yourself, don't threaten.
- Do care. If your company does not respond to you within a few weeks, threatens you in any way (interrogation), or says they are deliberately ignoring the license then you need to work on getting a new job. This is because your employers act exploitatively and without respect to the work of others (such as yourself). When you come into legal dispute (which happens more often with these kinds) they are not the ones you want to be fighting. So find another job (take your time) and leave, do not cite the license as a reason. Once you are safe notify the developers.
If you are careful, not disruptive, and don't use it to create gossip or push other agendas most employers will engage legal advice and work towards resolution thanking you in the process (its way better than being sued!) and you need not suddenly leave your job over an honest mistake.
That got me thinking about LPRs. Lease some land or the roof of a few buildings, and you'll build a dossier of regular I-95 travelers. People often go on vacation at the same time.
Figure out how to buy license plate data from the DMV, and you can market all sorts of stuff.
I knew that DOT's buy that data for traffic analysis. Never realized that folks can figure out the comparative average incomes for an average hotel guest based on that data. (you could see it in one of the screenshots.)
Unbelievable.
1. Govt will get to spend less on licence plate reading cameras
2. Govt will now be able to get more systems for the same spend