Inti De Ceukelaire Profile picture
Sep 26 12 tweets 6 min read
🔥PRIVACY SCOOP: How ANYONE can track your car using only your license plate: a thread! 🧵👇
#osint #privacy (1/X)
Between June and Sept '22, I challenged 120 car owners to track their location using their license plate. Over 100 days, I was able to track down 29% using three different methods. The issues discovered are widespread and there’s no easy fix - so I made one! (2/X)
Method #1: registering the target's license plate in parking apps and enabling license plate recognition (ANPR). I could add as many plates as I wanted. Doesn't matter if they already used parking apps: I could claim their plate as if it were my own.(3/X) support.4411.io/hc/en-be/artic…
Method #1 (cont): the moment my targets entered one of the 100's ANPR-enabled parking lots in their area, I would get an instant notification of their location: hospitals, concert venues, office buildings, libraries, shopping malls, public transit stations and even the zoo. (4/X)
Method #1 (cont) Most sessions would cost the attacker a few €.But with an average cost of €8.56 per hit it's incredibly cheap. Since their targets are stationed for a while, attackers can go to the vehicle and await them. Victims of abuse, crime and war are most at risk.(5/X)
Method #2 is 100% free and works for free on-street parking (e.g. 30 mins, kiss & ride...). Once a target uses their slot, anyone else entering their plate will be refused a free slot that day. Attackers can use this error find out whether their victim parked there that day.(6/X)
Method #2 (cont) I developed a stalkerware tool 'platescan' that automates this and creates a free session for the target's license plates in all zones every night. If it detects the error, it sends a notification to the attacker with their location (7/X)
Method #3 is also free and requires no technical knowledge: some vendors allow you to request an overview of parking sessions & receipts by supplying the target's license plate and phone number. That's all you need. Automate this & get real-time updates on incoming sessions.(8/X)
The privacy disaster is widespread throughout Europe: I was able to track down targets near the Spanish border, 1.100km away from their home. We detected 1000's of affected locations already and more are being installed as we speak. Is anonymous parking a thing of the past? (9/X)
Not only parking is affected: ANPR-enabled toll roads are becoming the norm. The toll you pay: your privacy. Or are you willing to take a 100km detour? (10/X)
There is no opt-out to having your car tracked. So we created one. Today we're releasing notmyplate.com: a website built with the help of privacy lawyers allowing drivers to invoke their GDPR right to restrict data processing to all vendors at once. It's 100% free.(11/X)
We need to stop the unsafe rollout of these systems before it's too late. Inform your friends & call your legislators to spread awareness & drive change.
📝 Whitepaper: notmyplate.com/whitepaper
📰 Press: notmyplate.com/press
🐦 Twitter: @intidc (NL) and @securinti (EN)
(12/X)

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Inti De Ceukelaire

Inti De Ceukelaire Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(