• Possibly linux@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      That’s how it works in security. It is unethical to not give the company time to react before public disclosure.

  • evatronic@lemm.ee
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 months ago

    Fun.

    From the article, the linked Swagger docs : https://web.archive.org/web/20240120071238/https://mycscgo.com/api/v1/docs/static/index.html#/

    And a little more detailed account : https://timesofindia.indiatimes.com/technology/tech-news/how-this-security-bug-in-washing-machines-can-help-college-students-in-the-us-do-free-laundry/articleshow/110277923.cms

    It looks like these laundry machines are controlled by a mobile app, and requests are routed through The Internet™. The flaw appears to be the web service presumes a user is only able to gain access to their API endpoints via the mobile app, which only exposes certain functions to a user.

    Once authorized, though, there’s no further checks like oauth scopes or even user roles, to prevent someone from doing a little bit of lateral movement to admin-style endpoints.

    Lazy. The machine makers should be ashamed.

    • anakin78z@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 months ago

      I once took over an app that worked like this. Access to one thing? Access to everything! And they had a hard coded admin password in the server code. 🤦 The client wasn’t happy when I proposed a complete rewrite. Eventually my manager begged me to stop working with them, so we did.

  • ATDA@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 months ago

    His hat is only white because he got to test this a bunch before exposing the vulnerability.

  • ChickenLadyLovesLife@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 months ago

    I (white boy) visited India in the early '90s and brought back a bunch of rolls of half-Rupee coins as souvenirs. Turns out they were the exact same weight and diameter as US quarters (even down to the number of ridges, which makes me suspect India bought a bunch of used US minting machines to make them), so I started using them at laundromats. The exchange rate at the time was 35 Rs to the dollar, so a load in the US that normally cost $1 was costing me less than 6 cents. I do feel bad for the harassment that actual Indian customers probably ended up receiving, although possibly the owners never noticed or cared.

    • PrettyFlyForAFatGuy@feddit.uk
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      6 months ago

      When i used to go to france for my family holiday every year (i live in southeast england so not far) i used to take as many 2p coins as i could because they were close enough to the €2 coin to work in those insert and twist sweet/small toy machines

      • ChickenLadyLovesLife@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 months ago

        British coins really seem absurdly overly-beefy for the monetary value they represent. I think it’s a way of saving up metal for the next time the Germans need sorting out.

  • PM_Your_Nudes_Please@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    6 months ago

    Here’s a reminder that most washing machines use a universal key, which you can buy online for like $5. You can just pop it open and hit the little “coin inserted” switch to make it think you paid.

    • Snot Flickerman@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      6 months ago

      Not the same company, but I live in apartments with washer/dryers like this. Coin op entirely removed.

      You have to have a device that is bluetooth capable to use them.

      Anyway pretty sure someone in this apartment has figured out something similar because the machines keep magically becoming unpaid machines after they get serviced. After each service, they will be asking for money to be able to be used for like a day or so, but then soon enough, I’ll go back to the laundry room and all the machines will be free and not asking for money. Just ready to go, no device required.

      Originally, I thought it was the company disabling them due to like a data breach or something and was trying to find out if there was an undisclosed data leak and/or a class action lawsuit brewing. Since neither of those are the case, I’m pretty sure it’s a Notorious Do-Gooder.

      So, thanks, Notorious Do-Gooder, for all the free washes and drys.

      (Especially since this same idea crossed my mind over a year ago but I’ve just been too lazy to view the bluetooth data traffic myself)