How I hacked modern vending machines
hackernoon.com
hackernoon.com
They installed readers into the soda machines, and they put a central panel in each laundry room with a reader and a keypad for you to indicate which washing machine you wanted to activate.
We found out that the vending machine hardware would query the card before selling you an item, but wouldn't debit your account until dispensing it, in case the vend failed. If you timed it just right and removed your card after it was interrogated but before the item dropped, you'd get it for free.
The smartcard project was only a 2-year evaluation and the university decided to move away from it, so the smartcard company came and took away all their hardware.
When they did this, they took the panel down out of the laundry rooms, but did not fully clean up the wiring coming out of the back of each washing machine. One of my roomates got curious and discovered shorting the leads of that wiring to a battery would mimic the signal the smartcard panel would use to tell the machine it's been "given" a quarter. Do that 3x and you got a 75 cent wash for free.
Instead of using Android, he used a freezer and a small hacksaw to section off coin-sized slugs from a frozen rod.
Have to give the points to Kilmer’s character because in addition to doing it first, his crime left almost no trail and didn’t come with felony exposure (most juries would not believe ice slugs are counterfeiting)
Making a daily habit of getting free hacked coffee could result in felony convictions and imprisonment in many countries for violating electronic data laws. I know FBI agents happy to bring charges for matters this trivial. This is where they’d rather spend their time instead of pursuing big league criminals.
Still a great article to read.
Just curious, what does one need to do in order to network with FBI agents and have them divulge what they're willing to charge people with?
The divulging comes in the form of an indictment, or, if you decide your integrity is not for sale and you turn down a plea offer, multiple days of hearings, trial, and sentencing.
Yep, I would add that the unknown programmer that wrote the app very likely thought that it was a very clever approach (and probably he/she has been paid good money to write the app).
Can you clarify?
It sounds like the responsability for having designed an insecure app is of the people that asked the programmer/sofware house to write it[1]?
[1] and as said very likely paid good money for it ...
>but I'd put this down to "bosses want this out by DATE? Alrighty..."
I've even been a part of some of those projects.
I'm guessing the reason they're doing a stored value system is because the per transaction part of the merchant fees is too high for vending machine coffee, getting a larger deposit as one transaction helps a lot with that (although, apparently not enough to hire people who know not to trust clients)
It's my impression that consumer payment systems operate on a good-enough principle. Being fraud-proof is not the goal, the goal is not to spend more on security than you are preventing in fraud.
The same principles often come into play with online games and cheating, yet constantly developers make the same mistakes.
And there you have it. Most people don’t understand security. The business can say they are MVP and “secure enough”.
You cannot rely on the data network, have to cope with all kinds of failure modes and mobile features support. Most companies decide that they will make some attempt to make things secure and live with the risk.
However, if you unplugged its ethernet connector and buy something, then somehow your would get your food/drinks and your transaction was stored into a buffer until the machine went online again.
That buffer being in volatile memory, unplugging the power cord of the machine was enough for it to forget you ever bought something.
The article has an old vibe of hacking articles published in the '90s/'00s (in a good way).
> obviously, it was password protected
Not obvious at all. Last time I checked, WhatsApp or Telegram didn't password protect their database (that was a while ago admittedly). And obviously, it doesn't actually provide that much protection if the key is on the phone, as the article demonstrates.
What?
Look at the second definition for the transitive verb.
https://en.wikipedia.org/wiki/FeliCa
I don't know for a fact that it works without a DB but I do know that they exist in places that don't seem to access to a DB and they work instantly (no long pause like credit cards).
It's worth stealing a $1 coffee to expose the extreme negligence behind the virtual clerk software. The software is essentially turning the vending machine into an honor box, and presumably the owner of the machine actually wanted proof of payment before vending anything, or they wouldn't have bought the machine. They could have put up a mains-powered samovar with a coin box bolted to it and a sign reading "1 euro per coffee. Call (+39) 355 5555555 to report problems."
It's not even clear to me who is being stolen from. How does Argenta determine how much they are to pay the machine owner? How do they determine how much to pay the machine servicer? If Argenta pays for the coffee, and the owners and servicers are unharmed, potential theft of coffee becomes an incentive to repair their software. Otherwise, you'd just be screwing some vending machine operator whose only failing was to trust Argenta over a dumb(er) coin and note validator.
This approach just makes the "hacker" look like a normal user to the casual observer.
Still, you would need to perform some "unusual" physical action on the physical machine and you might be noticed by people passing by or by a surveillance cam, this app hack is instead "clean".
And it makes you think about the reliability of any similar app based paying system, in this case is "their" money[1] that "you" can "steal" (by drinking and eating for free), but what if it was "your" money?
[1] so before or later the vending machine firm would notice
Pretty neat project to undertake. Kudos :D
Relax and have some fun. ;)
Further reading: http://time.com/4834112/millennials-gifs-emojis/
Although I grant you that plenty of baby boomers (and even older folks) do in fact use emojis, you can't seriously be arguing that they do so more than younger generations?
I would love to see some actual research on this. I have a completely untested theory, purely based on direct observation of my own friends and family, that the people who use emojis the most are those with the lowest writing skills. If that turns out to be true then emojis are in fact exacerbating the problem, because it doesn't much matter if my mother uses emojis instead of learning to spell, but I'd be very concerned if my daughter did.
The other point is that often times these machines that support an app get set up in companies for their employees, where you can be reasonably sure that everyone will play by the rules. We have a coffee machine at work that uses RFID tokens to handle credit with no security or encryption, and it works, even though we're all IT folks. A university with a CS department and its respective students is a different story though. :-)
That would absolutely not work in South America.
You can clearly see which tourists are from our part of the world in Europe where paying for transport is "optional"...
I find it disappointing so many cultures steal so easily if it's convenient.
He didn't hack the vending machine. He did hack the app. It was very cool and such, but not what I was expecting from the head line.
I bet you complain about build videos on YouTube too? "Come on, people have been building tables like this for millennia" not stopping to think that there are people without the skills to or that want to learn how to, or that can be shown a different way of thinking about an object via a well worded, easy-to-follow essay and guide on how they did their not-cutting-edge research?