Analyzing automated license plate reader vulnerabilities, demo and code, livestream!
The short version: WLTechBlog builds on Matt Brown's ALPR hacking research, live-coding a binary parser that turns exposed camera data streams into real-time vehicle tracking dashboards.
Our Take
This one stings because it's not theoretical. WLTechBlog picks up where Matt Brown's original teardown left off and shows, step by step, how carelessly deployed license plate readers can leak raw traffic data to anyone who knows where to look. Writing a parser for a binary stream isn't exotic hacker wizardry — it's the kind of thing a bored grad student could do over a weekend. That's exactly the problem: the barrier between 'law enforcement surveillance tool' and 'anyone's real-time vehicle tracker' turns out to be embarrassingly thin.
What makes this footage matter isn't just the vulnerability itself, it's what the data reveals once you can actually read it — timestamps, plate numbers, and enough context to reconstruct someone's daily movements. These systems were sold to cities as a narrow tool for catching stolen cars and wanted suspects. Instead we get devices sitting exposed on the open internet, capable of being queried by plate, with none of the access controls you'd expect from a system that logs where every car in town goes. When the security is this sloppy, 'trust us, only cops can see it' stops being a credible argument.
Check our camera map to see what's been spotted running near you, and if you want to push back on this kind of deployment in your own city, our take-action page has concrete next steps. Credit to WLTechBlog and Matt Brown for doing the unglamorous work of actually proving these risks instead of just speculating about them.
This is DeFlock The USA’s original commentary. The video above is the work of WLTechBlog, published on YouTube — full credit to the creator.