ParkMobile Breach Exposes License Plate Data, Mobile Numbers of 21M Users
krebsonsecurity.com
krebsonsecurity.com
I prefer parkmobile over waiting in line at kiosk, especially since they're broken or barely functional (try seeing their screens in the Florida sun).
Most every app you are using has a mobile-reactive webapp that'll invade your security + privacy less.
Microsoft has adopted this heavily. Outlook, for example, is now a cross platform PWA.
“It’s also curious that ParkMobile hasn’t asked or forced its users to change their passwords as a precautionary measure. I used the ParkMobile app to reset my password, but there was no messaging in the app that suggested this was a timely thing to do.”
Really the only improvement (besides not getting hacked) would be not storing the license plate numbers/vales. They could be hashed just like passwords using bcrypt.
What's interesting is they say the salt values were not stored which is odd as typically password hashes use per input unique salts that have to be stored. Not sure if that means they used an additional salt or if they reused the same salt.
The app could let you "lookup" an existing entry from the license plate since it would then just be checking if the entered plate value matches one of the existing hash values.
I guess the part that would be weird is if your license plate # changed but you kept the same vehicle. e.g kid driver their 'parents' car but one year registers it under their own name.
Some people don't seem to like the idea, but I think it adds an easy additional layer of protection. At least in the past many of the password leaks seemed to be due SQL injections and only leaking the database content. Pepper stored in the code would have protected the passwords.
If they are using it for their marketing: I was never notified of that.
1) You may have been given a fine erroneously that the data would prove you shouldn't have been given.
2) Financial records have to be kept for several years in most countries. Details of the transaction would form part of this.
3) The terms and conditions say they'll do it.
Why are details of such “secretive forms” excluded? Where is this forum? Can I read it for myself?
MD5 is still common for password hashes? That can't seriously be true anymore.
On the other hand, I’ve gotten free parking multiple times because their UI is terrible, and I didn’t successfully start the parking session. No tickets yet. I’d definitely contest if I got one though.
In the US, governments have been doing that for quite a while, of course.
Edit: I guess that kind of tracking is already possible if car dealerships and mechanics sell that information.
https://www.autoblog.com/2019/09/17/license-plate-scan-drn-p...
For $20, a Digital Recognition Network (DRN) customer can look up any license plate in the United States. If there is a match, the program will show the last time one of the company's cameras captured the plate, including a photo and information about when and where the photo was taken. The company sells the data to businesses, such as auto lenders, insurance carriers, repossession agents, and private investigators, but it can also be accessed by law enforcement. With more than 9 billion license plate scans in its database, it's a vast tracking tool that holds a massive amount of power. Vice recently looked deeper into the company and detailed how it works.