NULL license plate not such a bright idea
knrs.iheart.com
knrs.iheart.com
References: http://www.mekabay.com/overviews/risks/risks03_1986_06-04-19...
There was also a meme about a person that wrote on her ID application "note the hat on the 'e'" and of course her name was Sarah Note The Hat On The E on the issued ID.
EDIT: Yes her name was not Sarah and there is no 'e' in Sarah.
It seemed like it might work like humor in the TSA line.
Fine as long as you have extra time on your hands.
I wonder if it has even been towed/impounded?
And of course, in programmer humour, this translates to "while you're not busy with anything else, issue a fine." :)
https://www.nbcwashington.com/investigations/The-20000-Ticke...
Each day there was a 10-20% chance I would get a ticket on my windshield. I would collect them and take them to the uni security office once a fortnite to have them cancelled in bulk. I actually got pretty friendly with some of the staff there.
At least 4 of them were legitimate tickets because I parked overtime, over a line, etc, but the staff cancelled them anyway (:
NULL, NV, XXX, MISSING, NO PLATE
It was about a week before the router dropped its connection and needed to re-authenticate - and that's when I was called in to investigate the loss of connectivity - which Windows 10 very unhelpfully reported as the network cable disconnected and was resetting or power-saving on the NIC so the "link active" LED on the switch was going out for about 2 secs every 10 sec. Cue a round of cable and switch swapping to no benefit. The LEDs for all other devices on the switch (running Linux and mostly internal servers) were behaving normally.
I finally backtraced to the router and a useful error message. We put two-and-two together and my colleague called up the auto-saved details in their password manager; it was long, and ALL non-alpha numeric characters - starting with a backtick, which the router would not accept. I tethered my phone to my laptop and tried to login to the Web account portal - which would NOT accept the passphrase. I tried it without the backtick "just in case" - nope.
We had to do a "lost password" reset on the portal..and wait for the email with link.
Lessons learned:
The ISP's password change page did not seem to validate input, but the login page did.
Avoid backticks in passwords.
Fun fact: it's actually really easy to submit a string with a space on the end when entered via a PS4 controller.
I still can't believe a major bank got away with that for so long, apparently unharmed.
If you have time/patience it might be worth exploring.
Is there even a reason to include special characters in passwords? They add 10% more security[1] but cause all sorts of issues with systems. Just use an alphanumeric password that's 10% longer, and if special characters are mandatory, use a safe character at the end like _ or -.
[1] 6.55 bits per character (all printable ascii characters) rather than 5.95 (only alphanumeric)
Salted hashes have made rainbow tables less effective. Password managers have made single-use passwords more tenable.
Not knowing how a system will store my password, I still prefer to include special characters where available. Anecdotally, I tend to see the systems that are most averse to special characters are also strict about character limits, so simply increasing password length is not possible.
That's not how this works. By your logic having a password consisting of 1,2,3,4 is only twice as secure as having just 1,2.
Is that right?
I don’t... but i’ve seen it
calculations here: https://news.ycombinator.com/item?id=20678529
number of characters required for 128 bit entropy password using alphanumerics: 21.49[1]. round off to 22
number of characters required for 128 bit entropy password using all printable characters: 19.5[2]. round off to 20.
22/20 = 110%
[1] https://www.wolframalpha.com/input/?i=solve+log_2(62%5Ex)%3D... (under "real solution", click on "approximate form")
[2] https://www.wolframalpha.com/input/?i=solve+log_2(94%5Ex)%3D...
I logged in and then attempted to change my password to my new standard of 20+ character upper/lower/symbol. The problem was, they'd upgraded their forum software, and there was a bug that added password strength validation to the "old" password field.
So I was putting in:
Old: abc123 New: sZp10VzIoZI9g143
And was getting the error message "error: your password must be 8+ characters long". After about 10 minutes of frustration and realising they had both client and server validation I went down a similar route as you and used forgot-password even though I knew the password.
At one point GitHub even changed reduced their max password input to a sane amount, and I couldn't log in anymore with my existing insane password length a few years ago.
In most cases they fix the case when I report it, but my bank is terrible.
I figured out that they only did validation on SSIDs client-side, so managed to get around that to put emoji's in my SSID.
Which then proceeded to soft-brick the entire thing on config push. I'd have to log in to the web portal via another connection, change the SSID there, and then reset the hardware with the reset button to get internet working again.
I learned that lesson a different way: When I had a Windows phone my email password had a backtick, and the only way to enter it on the phone was to long-press the apostrophe, pick backtick from the three or four apostrophe variants that appeared, and pray I didn't fat-finger it and enter the wrong character. In general, there are just some second class citizen characters you should always avoid, because you never know how hard they're going to be to enter when you're on a phone or a kiosk or whatever. (Tilde, I'm looking at you, too.)
So, the password change page will accept any length password, will silently truncate it if longer & save it. Now on login page you have to guess the password length or reset.
I had the exact same issues with some passwords which were accepted when creating them, then not accepted anymore when used to log in.
This plus emails such as a@example.com or hjghgfggv@example.someweirdtld show how much sites are broken because of some philosophical ideas of developers.
Naturally I removed the badges from my car and put on different badges from another manufacturer. After a while they started to cite me as “other” and the trick no longer worked.
P.S. If the driver must be recognized does it mean that motorcyclists are exempt from photoradar fines?
Two MPs have actually been caught out by this law, convicted of perverting the course of justice and sent to prison:
https://www.dailymail.co.uk/news/article-1081607/Speeding-pu...
Quite brazen, and frankly a bit of an asshole thing to do.
My own unpaid ticket from weeks ago should become an asset. protect my car from violations with cast Invisibility.
I put the decoy on windshield, under the wiper blade, and wandered off for a bit.
But this upset the coin gods. When I went to my car an hour later, neatly tucked above my original ticket was a fresh new one. Balls.
Maybe using 2 old tickets will work. :)
I have a similar problem with my own identity. I was born in Canada's smallest province, PEI, and now live in its largest, Ontario. Some Ontario government software seems to have problems recognizing the relatively low numbers on PEI birth certificates.
Many developers have wondered why, when they stuck country-specific configurations in a YAML file, that things suddenly stopped working when they expanded support for Norway.
HCL, the hierarchical data storage language used by Terraform, is the closest thing I’ve seen to a happy medium between JSON and Yaml.
Another option, if the string values are not multi-line, is CommentJSON (use the Python module or write 10 lines of code that strips out comments from JSON if using another language).
{"comment": "JSON supports comments just fine. :-)"}https://yaml.org/type/bool.html
This should be used in schools as an example to illustrate how not to do things.
Afterwards I just try to avoid yaml if I can. While it looks cleaner than json, I don’t find it especially easy to read and there is unnecessary ambiguity due to unquoted strings. And it seems to have a thing against Norway ;)
But not only the value representation keeps the types ambiguous, also there is no off-channel place to disambiguate the types, and no value-independent rules for deciding on the types. If any of those was different, there wouldn't be a problem.
That said, I find these stories a little hard to credit, since you'd expect police officers in the EU to be fairly familiar with the standard EU driver's license layout.
The common design for all the EEA countries was supposed to be implemented by the members by the start of 2013 according to Wikipedia.
Until 2033 there will be valid licenses that were issued before the common license, so there's still a lot of different designs out there.
Very little faith left.
He refuses to change it because he did nothing wrong...sure, but you are also the only one being hurt by it. Is this really the hill to die on?
As I see it, this person is performing a public service by not budging on this. It's nowhere near on the same level as Rosa Parks not going to the back of the bus, but sometimes we need people to not simply go with the flow because it's the easiest thing to do.
This guy is really just wasting his own time for no actual benefit to anyone. If he genuinely enjoys it, then sure, I guess each to their own, but if not...
And frankly, why would it? Different government agencies likely have zero reason to cooperate on it. Especially if, say, the DMV is responsible for the error, but the courts are the ones dealing with the cost.
So unless this guy has a reason to think it will get fixed because of him... he's just wasting his time, no?
His family name was Nissan, and he registered the domain when Nissan still called itself "Datsun" in the U.S.A.
But how - he can challenge the fines in a court of law. Since it's a vanity plate, adding an extra notoriety won't hurt.
If he sees spending time and effort expunging his record every few weeks as worth the trade-off for the 'extra notoriety', then power to him. I wouldn't do that.
You're paying for it with a lawyer or with your own time
Sure, it would be nice if the systems where patched. But maybe he should just get a job at the DMVs IT department instead :)
In the end I would probably rather pay the fines than fix this bug, it's probably a lot of horrible systems barely held together..
Ew.
Haven't caught anyone else's tickets so far. SunPass won't accept 'N0 TAG' being associated with my transponder tho (have not tried 'N0NE' yet).
I did get pulled over on my very first ride with 'N0 TAG' and the first words out of the cop's mouth were 'Is that tag legit?' That may or may not have been a factor in catching a warning instead of a ticket that I absolutely earned.
When the German license plates were redesigned in the mid 1990-ies, also a different font was incorporated, which was engineered explicitly to thwart similar-shape attacks: https://en.wikipedia.org/wiki/FE-Schrift
This was a Python project and the product owner apparently already had learned 'None' equals NULL.
I dug into the file which we used to import the users from and discovered the user's lastname actually was 'None'.
x'; DROP TABLE drivers; --
on a plate, and driving up and down the highway past automated license-plate readers. ' or 1=1; drop table sys.systable; -- Computer Services
I had a lot of fun at Bank of America when I signed up for my business bank account shortly after registering the name. Not quite a license plate but similarly themedI will assume that we are all aware of the Exploits of a Mom, but just in case we have anyone reading this that doesn't already appreciate XKCD: https://www.xkcd.com/327/
Another picture (which I can't seem to find now) purportedly showed how one of the screens over the highway was displaying just an error message after triggering this exploit.
What this usually is is the result of systems that talk to systems that talk to systems that talk to systems, all in different legacy formats never written to be interchange formats. One system has true SQL NULLs, the next system down the chain only accepts strings for that field, NULL gets written as the most sensible string, and then from that point on all downstream systems can't tell the difference between the original system having had an SQL NULL or having had the string NULL.
I was amused.
Even without sql doing odd things certain strings will just cause problems.
https://www.telegraph.co.uk/news/worldnews/europe/ireland/47...
I was honestly kind of impressed.
PS: Reminds me, I should get one of those LPR T-shirts with license plates all over it.
I have a custom plate that is two common words, on a California 60s vintage plate (black plate with yellow lettering) and most parking garages that check and print your plate on the ticket always butcher it. Instead of (replaced for privacy) "FOO BAR" it will say "8A2M31W" or some garbage.
- 1Iil
- B8
- 0Oo
Examples:
- i1lIil1I
- 8BBil8I1
So wait, after he knew this was the outcome from using this plate he just decided 'nope, the DMV will definitely rectify this error'? Maybe he has a much higher tolerance for dealing with the DMV than I do, but surely there are far more productive ways to spend your time than constantly battling against invalid tickets. Additionally, I would be concerned about not being able to waive some of these tickets at some point and actually having to pay them,6k isn't exactly an insignificant amount and could also really impact insurance rates.
You're right that when faced with a choice between acting on principle vs acting pragmatically/for one's own benefit/convenience/need, people often don't have the luxury of (or patience for) choosing the former. But it's nice to see when someone does.
That's arguable, actually. The article states, but doesn't provide evidence, that Droogie "hoped it might confuse automatic license plate readers or the DMV's ticketing system".
If this was done in an attempt to evade enforcement of existing laws, then sorry: that's a crime, folks. You aren't allowed to pen test live systems!
Seems to be a clever technique here too, ending the article with what seems like a non-ending, so the user will keep scrolling.
If I remembered where the original content was I’d post it, or had a desktop/laptop browser to search with right now, I’d post a link, but I don’t. I just remember having read a much better article about this in the past.
My buddy Stan registered for null@verizon.com back in the early 2000s so you could link sms to email delivery. Wound up with so. many. text messages. Reminders to take medicine, personal convos, sports results, everything.
Was great fun to read while waiting for class.
But someone still owns test.com, and I can't imagine what that mail server goes through.
It would be cool if you could do punctuation so you cloud get "'; drop table;" alas little Bobby Droptables will likely never get that plate. :-)
I did see a plate "I<heart>0X45" which was a cute nerd joke, I expect that would be more difficult to get these days.
I find websites that won't accept it because they think it's an invalid address all the time. I have no idea what logic they're using, would love to find out.
>Things started to go awry when he first registered the tags. He tried typing in his license plate but the DMV website wouldn't accept it.
Let's talk about the fact that the DMV website wouldn't accept it. Do you think this is all right behavior on the part of the DMV website?
It's really interesting because if you're coding up the DMV web site, it makes sense to disallow NULL just as a preventative measure, like not allowing '-- in a query (to prevent SQL injection attacks.)
I would generally think that on the whole you should accept -- as a substring in a password. But is it wrong programming if you don't allow that substring?
Disallowing it could cause someone's chosen password to fail, so they have to change it for you to accept the password they want, but if you know for sure that you use sql as part of processing passwords you might well decide that it is acceptable to make people have to try a new password before you'll accept theirs, in case you are not confident that you are escaping everything correctly.
So from my end it seems okay to do something like disallow NULL.
If you consider the choice of the programmer on DMV's web site, what do you think about their choice to reject this input, even though in fact it turned out to be legitimate? Is it acceptable programming practice?
Blocking -- in a string does not prevent SQL injection attacks. Using proper parameterised queries does. This might sound mildly hostile but "you are not confident that you are escaping everything correctly" - when this is a well defined and solved problem - means you should not be building this application as you're too incompetent to. For the millions of taxpayer money wasted on this kind of thing, it is absurd.
Blacklisting keywords used in XSS is also completely futile, pointless, useless, and does nothing but piss off users that can no longer use anything containing the word log or window or whatever.
Even if NULL then does have this address attached, why does it take the branch where it looks for the data?
I suppose it would be in a relational DB, perhaps there's a join that drops missing entries, but if they aren't missing they show up?
The problem is that the employees with access to the system are required to enter a 'valid' value. But in some cases there is no value. So the 'valid' value they've come up with is the string "NULL" - they can't use "~~NULL~~" because ~ isn't allowed on a license plate. So because A) anyone can request a valid value on a plate, and B) nonce values must also be "valid" within the system, the tax payer is capable of ordering a nonce value on a plate.
Almost certainly because of software constraints, like the form not allowing the plate number field to be blank.
https://www.google.com/search?client=firefox-b-d&q=danny+whi...
In Spain, people normally have two surnames, one from the mother and one from the father (no, it doesn't exponentially grow with generations :D). He had issues enrolling in uni, as the system required two surnames so he ended up with "Andres Schmidt Schmidt". He had issues down the road as well, having to explain himself every time he needed to register for something. I think the student id was also a hash which included the name and he hadn't been consistent with his "full" name in all systems.
At least his story brings to light the poor quality of software the DMV is using.
I'm curious about the other, unintended consequences of naming things null in other web applications; maybe its time to explore ...
Was funny in 1995, not so much now.
So he went to the DMV and asked them to change it, and they wanted to charge him to do that.
He’s like, no, i’m not paying.
Eventually he writes a letter to his politician saying “please revoke my license plate” and eventually he gets a letter saying they got a complaint (ie: his) and the DMV wants to revoke his plate.
But he had to wait 30 days For the appeal clock to run out, just in case he wanted to appeal his own complaint.
Kinda funny, but kinda sad that someone paid $400k+ per year by the government wasted thousands more because he didn’t want to pay the $100 plate change fee.
* some details/numbers estimated from memory.
Ref: http://www.thesmokinggun.com/documents/crime/end-road-gotmil...
I think they should have been allowed to keep it, frankly.
plate VARCHAR(8) NOT NULL DEFAULT "NULL"
Or rather the type is actually Option<String>: plate VARCHAR(8) NULL DEFAULT NULL
In which case, how is it the software can't tell the difference between Some("NULL") and None()?The only thing I can think of is the software (or it's database driver) handles everything in strings; so None() and Some("NULL") both get converted to "NULL"?
JOHN,DOE,NULL,08-12-1983
JANE,DOE,FX9-80Z,01-23-1960This article is garbage and a lot of the discussion here revolves around the spin and emphasis on facetious scenarios I mentioned in the presentation
Cool the DMV fixed it. Just try that with so called "identity theft"
The name is my 6 letter last name.
I've received thousands of emails from random people. There are so many letter.name or number.name similar addresses that I'm constantly getting very personal emails of other people (deaths, marriages, invoices, business reports, etc)
The delivery man called to tell me my address was incorrect. When I asked him what was wrong, he told me it said 'Null Null Null Null'.
A couple of cars in my city have plates like "0O00OO" or "BB88B8B"
One guy that I've seen driving near my place has two cars both with variations of "11ll11l" Both the same make and model and color.
I really dont think this will help him much.
I'm thinking of types such as Maybe/Option or Either.
I hate it for example when a C/C++ function has to return a -1 in case of failure.
If they had to use a string (and I doubt they had to), they could at least have used the empty string.
>used the word NULL
Oh god, I feel faint.
BTW, California has a problem with issuing both plates with 0 (zero) and O (letter) in them. They both look the same.
> Apparently, when they didn't have the right data for a vehicle, a privately operated citation processing center used the word NULL in the license plate field for many tickets.
These bugs and categories of errors should simply not be possible in sane languages or frameworks.
> Apparently, when they didn't have the right data for a vehicle, a privately operated citation processing center used the word NULL in the license plate field for many tickets. Since that just happens to be Droogie's license plate, he got all of them.
So it's 'confusing' the string NULL used incorrectly (kind of, it's fine under the assumption that no one will have the license plate NULL but that assumption is wrong) with the string NULL.
DROP DATABASE;
There's photo evidence in the much better article at https://mashable.com/article/dmv-vanity-license-plate-def-co... from the DEFCON talk.
First of all they are accidentally committing fraud (libel?) against this guy. But more importantly, why is there a private processing center? Don't the officers type this in as they fill out the ticket? or even just scan the plates? If there aren't plates on the vehicle it should be towed or booted. What is the point of recording tickets with no plates? Is the processing center paid per ticket recorded?
I would take that with a grain of salt. The linked article on a talk-radio site, and was likely intended as a wacky news bite that the hosts breeze through and then make jokes about. I figured the exact technical details of what is causing the problem was lost in translation. More likely that they were leaving the plate blank, and then the backend software was confusing null database fields with the string "NULL".
I assume the government entry system doesn't have an explicit way to set the data as missing, so they work around it like this.
I'm not sure if that's still happening.
As surprising as it may be, bad code is often written by bad programmers. It doesn't matter what language you use if you write bad code.
What happened in this case was that people used the literal value "NULL" to mean "I don't know". They could have used the word "LOLCAT" and the effect would have been the same. Overuse of in-band signalling is a general design flaw not specific to any programming language. (Remember when people would whistle a 2600Hz tone to make free phone calls? Same thing as this.)
null
Which makes for a bit of funny because NULL is not defined