Data obtained through automatic license plate readers (ALPR) operated by the Boston Transportation Department (BTD) has been exposed online, according to a report by DigBoston.
Automatic license plate readers have been deployed in many US cities, they are highly controversial due to the invasion of citizens' privacy and have been actively used by local authorities to issue illegal parking fines and to identify vehicles sought by the police.
In most cities, ALPRs are developed and managed by the transportation department, as is the case with the city of Boston.
And while the storage of users' personal and sensitive information on third-party servers has been prohibited, the city of Boston uses a server that belongs to Affiliated Computer Services (ACS) (ACS), a Xerox subsidiary, to store the data recorded by its ALPR systems.
The journalist of DigBoston, Mr. Kenneth Lipp, has revealed that this web server has inadequate security and has exposed the data obtained from the ALPRs since 2012.
The data includes details such as the license plate number, the location where the number was found, the make and model of the car.
Answering questions from Mr. Lipp on the subject, Affiliated Computer Services (ACS) isolated the specific server from public view within two hours.
But the scandal does not stop here. The problem is that this data is still being used by the Boston Police Department, even though in 2013 it announced, under pressure from various privacy advocacy groups, that it would stop using it.
Hundreds of emails containing license plate numbers are sent to the Boston Police Department on a daily basis, as this PDF report.
Even if the data is used only for locating stolen vehicles throughout the city, the problem of lack of transparency remains when it comes to public disclosures by law enforcement agencies, and their addiction to massive data collection practices.

