How can Westfield secure this? Whichever method they choose, they have to ship the key with the app, won't they? And then someone can just reverse engineer it out, and we're back at the same place. Or is there a nice way to do this?
Well, to start with they could lock the API down correctly so you had to supply a number plate to get 2-3 likely matches. And fuzz the photos they send a bit more so it is legible enough to identify your car, but not to read the license plate itself. And remove superfluous data from the IP results, like time of entry. As compared to the current system where you can immediately get a list of every car in the carpark,…
The app is essentially designed to let people look up car locations by license plate numbers, and as long as it does that it seems to me there will be some level of privacy issue.