And lo, as the prophecy foretold, California's digital license plates are totally hackable, giving away GPS location and user info:

https://jalopnik.com/researchers-hacked-californias-digital-license-plates-1849966295

Researchers Hacked California's Digital License Plates, Gaining Access to GPS Location and User Info (Update)

Just months after release, cybersecurity researchers have hacked Reviver Rplates and gained access to GPS location and sensitive user data.

Jalopnik
@evacide no one could have predicted this. no one.

@evacide Fix't, _and_, if they did it once, they'll probably do it again... that's my estimated profit-cy...

Besides. Custom plates make one too damn _identifiable_ (to somebody other than the steenking badges).

@evacide Sounds like Stasi and a new market for stolen plates…
@evacide Really not sure what's wrong with stamped steel. It's bad enough that one lightbulb in my bathroom wants to be connected to the internet and get a firmware update; all teh bullshit gizmos needing a internet connection is completely dystopian, imho.
@ninavizz
yay, and like the rumbas vacuums, they take pictures and video unawares by the people that bought them.

@evacide 100% predictable.

And how do these plates work when the vendor declares chapter 11 in a few years?

@evacide seems like they didn’t pen test or hire external design analysis.
@evacide why is this even a thing 🤨

@evacide

Notably the original system hack and privilege escalation known as "Reviver" continues unabated.

@evacide digital license plates? Whyyyyyy?
@evacide But we must have them! We must! There's simply no other way to put a number on the back of a car.

@evacide Why, Why, WHY do those things have GPS?

So far I've found that a rectangular strip of aluminum stamped with letters and numbers is pretty unhackable. Maybe we should give that a try.

@evacide who could have predicted?

well, everybody. But other than that, who, who could have predicted?

@evacide Why… I swear I am just going to get it tattooed on my forehead: “Technology is not a panacea!”
@evacide I think the worst part of this is that there was a user-side mechanism for changing the account type. Pretty sure my first JavaScript tutorial emphasized that…
@evacide Can anyone explain why anyone would want these in the first place?
@jeffjarvis @evacide Everything "high tech" must be good, right? Or if it ain't broke, fix it to break it? :P
@jeffjarvis @evacide Exactly MY question, too! Why in the world would you put one of these on your car? What benefit is there to having a "digital" license plate versus the tried-and-true piece of metal we all have now?

@jeffjarvis @evacide

Surveillance capitalism.

Is it just me, but are tech venture capitalists all wannabe voyeurs or big fans of "1984" style government?

@jeffjarvis @evacide Because otherwise you have to receive a sticker in the mail or from the DMV office, open the envelope, go out to your car, maybe clean off the license plate a little bit, and put the new sticker on over the old one. And you have to do this every. single. year. With a digital license plate you are saving minutes, maybe even multiple hours, over the course of your lifetime.
@evacide and nobody was shocked
@evacide I wasn’t aware of these digital plates before. Why would anyone want to get one? What service are they providing?

@evacide

My dumb, metal license plate doesn't have GPS or other personal data in it, why does this one?

This feels like every time I go to buy a new TV and all that's available are smart TVs: we just need a display, not all the other fancy shit (that increase an IoT's attack surface).

@evacide I'm very much not surprised
@evacide I totally didn't see that coming and also the other guy would say that you should take the path to the right.
@evacide Digital license plates are a solution in search of a problem.
@evacide What is the supposed benefit to a consumer for a “digital license plate”? Crazy idea! It’s our digitize-everything and make a buck biz culture. Our only defense is “say, no, don’t be a sucker.”
@evacide Well, you could knock me down with a feather...
@evacide "key is under the welcome mat" level security, as usual.
@evacide "Why do we even have this lever?"
@evacide Rediculos! Why would anybody want to hack a digital license plate, except serial abusers, con men, the INS and the annoying busybody next door?

@evacide I still don't understand the argument for them in the first place. It's not like registrations on cars change all that frequently…

(If we were to instead implement a Japan-like permanently-attached license plate that would be something else. But that's not even planned).

@evacide I'll leave CA before I let the state add a GPS tracker to me - might just finally be the final impetus I need to take my tax dollars elsewhere. There's precisely zero chance... unless I can run Doom on it? ;)
@ladyparabellum It’s crazy. It’s something STASI would do. Mass surveillance is the antitheses to freedom and democracy.
@breadbin it's "boiling the frog" here - it slowly gets worse and worse and no one seems to notice.
@ladyparabellum I fear those that notice doesn’t have the pull to make any changes. Especially with two major parties where neither wants to move the needle on this. :(
@breadbin I've found that, with each small additional invasion that I object to, the popular opinion is: "it's a little thing, don't be unreasonable! "
Taking the long view, as The State does, they're all "little invasions" that ultimately equate to everything. That's why I have zero tolerance.
@ladyparabellum Privacy (liberty if you will) and human rights aren’t something you meet in the middle with, they are lines in the sand that will never move.
@breadbin I wish society in-whole agreed with you [us] - they don't. [Everyone] wants to dictate everyone else's life, just to a greater or lesser degree.

@evacide

Digital license plates. What could possibly go wrong?

@evacide "hope Californians have a software patching window scheduled for their license plate" is a very boring, stupid, and cruel dystopian reality quote we can now say unironically.
@evacide @glennf who could have foreseen such a thing?
@evacide why does your license plate need a gps???
@evacide Aaaaand Elon suspends California.
@evacide Modern autos have dozens of threat vectors. It hasn’t happened yet, but the day will come when someone takes remote control of car with malevolent intent. There also dozens of ways to remotely identify individual cars and get GPS localization on vehicles. There will also always be threat actors 🤷🏼‍♂️— part of life.The interesting part (to me) is detecting whether someone is hacking your system *at this moment*, and what do you do (technically) to protect your control options, e.g., ensure graceful degradation of systems as opposed to a possible catastrophe.
@evacide Also, people are still gambling in Casablanca.