Security News > 2021 > December > Pandemic-Influenced Car Shopping: Just Use the Manufacturer API

Pandemic-Influenced Car Shopping: Just Use the Manufacturer API
2021-12-03 20:09

Jason Kent, hacker-in-residence at Cequence, found a way to exploit a Toyota API to get around the hassle of car shopping in the age of supply-chain woes.

First, some background: Many outlets have widely reported that manufacturers are putting 99 percent of a vehicle together, parking it in a lot somewhere and assuming the missing parts, like computer chips, will be available soon and they'll be able to make the engines run so the vehicles can be sold.

Rather than tediously browsing dealer websites to view inaccurate information, I turned to pulling data from the manufacturer API that I had found, to see what is being built and where I can buy it.

The beginning of the VIN is the manufacturer and model, and the numeric part at the end is the serial number for the vehicle.

It's unrealistic to expect the average car buyer to start writing bots to figure out how to find their next vehicle.

For now, we will assume it is used to provide a preview of coming vehicles with the hope that Toyota will take steps to use what they have to improve shopping experience.


News URL

https://threatpost.com/pandemic-car-shopping-manufacturer-api/176740/