Live data from Hacker News

9M logs of Brits' road journeys spill from number-plate camera dashboard

theregister.co.uk

51–53 of 53 posts

Re: 9M logs of Brits' road journeys spill from number-plate camera dashboard

#51

There seems to be an assumption that this would come under GDPR, but that's not obvious to me (excluding the potential images of people). Putting aside ethical concerns , would there be any legal ramifications for capturing the presence of a car at a certain location and sharing it? The licence plate identifies the car, not the driver. (Similar schemes are in place for boats and airplanes of course)

The driver of a private motor vehicle is almost invariably the registered keeper. In most of the case where it is not then it is a family member. Are you implying that the slightest doubt about the identity of the driver means that it is perfectly alright to collect the data? because if so that surely also applies to many other GDPR situations, where families share a single computer for instance.

I'm actually saying I don't know; where is the line? Licence plates seem like an interesting test case, given many registered keepers are companies (either company cars, work vehicles or hire cars).

Re: 9M logs of Brits' road journeys spill from number-plate camera dashboard

#52
post #19

Earlier quoted context omitted.

It's difficult question in the interpretation of the CMA; if you're not asked for a password do you know that you're unauthorized? https://www.cps.gov.uk/legal-guidance/computer-misuse-act

> if you're not asked for a password do you know that you're unauthorized? I imagine that depends. If your bank allows you access to another person's account by manipulating the URL, that presumably counts as a crime. (Incidentally, this exact vulnerability has happened in the real world. https://news.ycombinator.com/item?id=2656837 , https://www.theregister.co.uk/2011/06/14/citigroup_website_h... )

> ... manipulating the URL, that presumably counts as a crime.

"Manipulating the URL" -- "?id=1", "?id=2", "?id=3", in effect -- was enough to get Andrew Auernheimer (a.k.a. "weev") convicted and sentenced to ~3.5 years in prison [0].

Yes, his conviction was later vacated -- albeit due to a "technicality" ("improper venue"). Regardless, he still spent more than two years locked up for what really does seem like some completely exaggerated bullshit!

> "... [the Third Circuit judges] were skeptical of the original conviction, noting that no circumvention of passwords had occurred and that only publicly accessible information was obtained."

---

(Note: I've never met the guy, nor would I ever want to. Everything I've heard and read indicates that he's a pretty shitty human being -- and I suspect that didn't help him very much at trial. He almost certainly was deserving of some "bad karma" but that's not for the "justice system" to dish out.)

TL;DR: If you're in the U.S., you might want to think long and hard before taking that chance!

---

[0]: https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

Post reply on HN