Build Sticker Decoder

DoctorDawg

Veteran Member
Joined
Aug 26, 2008
Location
Southeastern US
TDI
'09 Jetta Loyal Edition
Question for information security nuts....

DANGER, WILL ROBINSON!!!

For gosh sakes, please don't go typing your VIN number and build info into that web page!

My first thought is "heck, what's the big deal, any stranger can walk by my car parked in a parking lot, or even in my driveway, and copy down the VIN number," but internet bad-guys are getting so freakin clever these days I just want yuh tuh think this through before you go punching your info in. And I'm guessing that the OP is the guy running that web page.... (no offense, vagany; I'm just a suspicious old fart by nature, and yer a newbie with only a few posts, all at an ungodly hour of the (U.S.) morning and all on just one day).

Here, for example, is a fiendish conspiracy theory for ya (just by way of example): DoubleClick and many other internet advertising companies usually know your address (gained when you enter your address on a commercial web page operated by a company subscribing to their service), and can associate that address with a cookie set on your browser. So say I'm a really, really together high-volume car thief who has hacked into DoubleClick (or has purchased the DoubleClick data files from some other hacker); I know your address and can crack your DoubleClick cookie (this is a little tricky, but still do-able); I lure you and many others to my (Romanian?) web page, where you punch in your VIN and build info and I read your cookie. Voile! Almost overnight I have a really extensive database of where many of the (say, for instance) Campi white '09 TDIs in the U.S. and around the world are to be found at 3 AM local time. I can now offer my customers a real 'value-added' service...I can provide you overnight with exactly the 'used' car you want, right down to the exact color and equipped juuuust the way you like it, with ridiculously little effort on my part. When I get an 'order', I just go and reel in the nearest one found in the database. Or I sell zillions of copies of the database to other car thieves. Or both.

Addendum: a quick Google search of "bitnet.ro" reveals that these build decoders have been around on the web since at least 2004, appearing and disappearing, and most of them either Romanian or Russian. I have nothing whatsoever against Romanians or Russians...in fact, my own people are from over there...but in point of fact a very large percentage of the world's Internet scams are also from there, too.

How's THAT for paranoia? Huh? Huh? Remember: just because you're paranoid doesn't mean they're not out to get ya! In fact, now that I think about it, you couldn't pay me enough to punch my VIN and build info into that web page. A cool idea, perhaps, but very, very insecure.
 
Last edited:

vagany

Member
Joined
Sep 9, 2008
Location
Montrose
TDI
VW Jetta 2003 90 HP
I respect your opinion DoctorWag.

But what if it is just a honest hobby page?
And the data you punch in doesn't even get saved.

And you just ruined a poor guys work who was happy to share it with you.
 

DoctorDawg

Veteran Member
Joined
Aug 26, 2008
Location
Southeastern US
TDI
'09 Jetta Loyal Edition
vagany said:
But what if it is just a honest hobby page?
Its a good point, vagany (and by the way, welcome to TDIClub!). I did think about that before posting, but here's what I came up with:

Q: What if it is just an honest hobby page? A: Nothing really significant happens, but guy maybe needs to rethink the security implications of his hobby, maybe get a VeriSign certificate so this page can be traced to a known human being at a known location.

Q: What if it is not an honest hobby page? A: Many, many really bad things happen to lots of innocent people.

For me personally, its just not a very tough call....
 
Last edited:

vagany

Member
Joined
Sep 9, 2008
Location
Montrose
TDI
VW Jetta 2003 90 HP
In Germany there's a law which enforces every web publisher to identify itself. I think this should be made worldwide and also be applied to email. This is the only way to stop spammers.

But let's not get to far from the topic. The guy states on the main page:

If you are a professional or you don't trust this site, you should use official sources (manufacturer, dealership, etc.). This is a hobby site made by a VAG enthusiast as a freetime fun project and take it as it is.
That says it all.
 
Last edited:

twigless

Veteran Member
Joined
Jan 30, 2007
Location
Florida
TDI
2000 Golf GLS TDI 5-speed, 2002 Jetta GLS TDI auto (wife's)
Whoa, I'm sorry. I know you're supposed to search for an existing thread, but I figured no one would have posted anything like this!
http://forums.tdiclub.com/showthread.php?t=226690
I just posted a topic on it, just now. For what it's worth, I have the direct access to VW Hub, so Dr Dawg need not worry about info being shared or distributed.
Sorry for a redundant post!
 

DoctorDawg

Veteran Member
Joined
Aug 26, 2008
Location
Southeastern US
TDI
'09 Jetta Loyal Edition
twigless said:
For what it's worth, I have the direct access to VW Hub, so Dr Dawg need not worry about info being shared or distributed.
Sorry for a redundant post!
What's VW Hub? And why does that mean I needn't worry?
 

doonboggle

Veteran Member
Joined
Jul 2, 2007
Location
Elgin, Texas
TDI
2006 Jetta w/Taktonic 6sp. transmission, Silver; 1981 Rabbit pick-up
Agree with DD 1000 percent !!!! Never ever never voluntarily input personal data wherein you know nothing about the website !! NEVER EVER NEVER

On top of this, have not seen the 'ro' website extension before, but knowing the Russian one is 'ru', this alone scares me off as fast as I can exit.

FWIW
 

jvance

Veteran Member
Joined
May 22, 2008
Location
Private
TDI
Gave it back to VW
For the VIN, here's what I've puzzled out for the 09 Jetta TDIs:

3VWTL81K79M271485 - the VIN of the car I canceled at Chapman

3 - North America
V - Volkswagen
W - Passenger vehicle
T - Golf Variant (sportwagen) with Big Roof System. Other options are A - Jetta with no sunroof, C - Loyal Edition, P Golf Variant without Big Roof, R - Jetta with sunroof
L - 2.0L CR Diesel
8 - Side Rear airbags. 7 - no side rear airbags
1K - A5 platform
7 - no idea
9 - model year
M - factory - M is Puebla
last 6 digits - sequential manufacturing number.
 

twigless

Veteran Member
Joined
Jan 30, 2007
Location
Florida
TDI
2000 Golf GLS TDI 5-speed, 2002 Jetta GLS TDI auto (wife's)
jvance said:
For the VIN, here's what I've puzzled out for the 09 Jetta TDIs:

3VWTL81K79M271485 - the VIN of the car I canceled at Chapman

3 - North America
V - Volkswagen
W - Passenger vehicle
T - Golf Variant (sportwagen) with Big Roof System. Other options are A - Jetta with no sunroof, C - Loyal Edition, P Golf Variant without Big Roof, R - Jetta with sunroof
L - 2.0L CR Diesel
8 - Side Rear airbags. 7 - no side rear airbags
1K - A5 platform
7 - no idea
9 - model year
M - factory - M is Puebla
last 6 digits - sequential manufacturing number.
7 is the Check Digit (see Wiki on VIN). It's a number that double-checks to make sure you entered the VIN correctly. Very useful for computer entry, since you can program the values in. That way, if someone thought it was an "I" but was in fact a "1" (there are no "eyes" or "ohs" or "ques" in a VIN, just 1s and 0s), the computer would catch it with the check digit (the VIN wouldn't add up).
 

twigless

Veteran Member
Joined
Jan 30, 2007
Location
Florida
TDI
2000 Golf GLS TDI 5-speed, 2002 Jetta GLS TDI auto (wife's)
DoctorDawg said:
What's VW Hub? And why does that mean I needn't worry?
VW Hub is an internal site for VW dealer use. Within Hub is VIM (vehicle inventory management). This is where we view incoming inventory, search for available inventory (by area, state, region, or nationally), place an allocation order, RDR a new vehicle, etc etc etc.
Obviously it's password protected. I HAVE THE PASSWORD! muah muah ha!!!!!
but I use Hub for good, not evil. And I've found some little hidden features, like the Specific Vehicle info, as described above. Since it's a VW site, there's no risk involved, unlike some of these "ro" sites, or whatever it is.
 
Top