Gas pumps happen to be about as insecure as your typical router
myfox8.com
myfox8.com
[0] https://apma4u.org/wp-content/uploads/2012/06/Crompco-Update...
The gate locked up and started screeching its "i scanned a card" chime on loop.
It was hilarious... and i guess a matter of poorly sanitized inputs.
See: https://en.wikipedia.org/wiki/EICAR_test_file
and this video https://www.youtube.com/watch?v=cIcbAMO6sxo where all the gates at a parking garage are rendered inoperable because someone scanned a QR code that encoded EICAR
Given that 747s (IIRC) are still using floppy disks (https://google.com/search?q=747+floppy+disks) the chances are the billing was probably done by some equally byzantine process.
Yes, I'm saying that, despite the fact that
"capture calling card number for later using on-plane PBX, establish satellite call directly to dialed number"
and
"establish satellite call directly to on-ground PBX, which asks for calling card number and forwards call"
both ultimately return TRUE for "but users can trigger our satellite uplink to initiate connections just by picking up the phone!!1"... but the latter approach actually blocks illegitimate use and is thus measurably better, and skips the need for an on-plane PBX too.
I can't help but wonder if there was some sort of "capture the number first before initiating the call" initiative early on (which totally makes sense), only for the calling-card billing integration to fall through at some point rendering the whole approach moot.
Naturally I'm making a lot of assumptions here, the biggest being that the plane isn't just making a direct-to-ground connection the moment you pick up the phone, with an on-ground system accepting then forgetting the calling card number. That would be even more stupefying but I do doubt that's what was happening.
https://www.theverge.com/2017/10/24/16505912/floppy-disk-3d-...
I have a credit card that bluescreens (some) PoS terminals. I theorize the upstream server is returning a rare error code when it's used in contactless mode, because that account's never been approved for contactless. In that case I'm going with lack of sanitizing inputs.
Q: This barcode scanner has a million options, how do we configure them?
A: By showing configuration barcodes to it!
https://downloads.dell.com/manuals/all-products/esuprt_tab_m...
[1] https://cdn.sparkfun.com/assets/b/5/0/e/e/DY_Scan_Setting_Ma...
... but yeah, it should require pressing a recessed button with a pin or something. not allow it all the time.
That's rare though, and sometimes the installer disables it for convenience while they're debugging the system and never re-enables it. So the vast majority of scanners in the wild will happily accept an enter-config-mode at any time.
Aren't they just USB HID (previously: serial) devices that literally just output key codes for the numbers detected?
I also used a 2D scanner and it worked the same way.
Keyboard-wedge is only one of a dozen ways a barcode scanner can send data. Most also have legacy serial interfaces for use with old POS systems, so you have scantags that enable and disable those, and configure the baud rate, start bits, stop bits, parity bits, flow control (like a dozen different types), minimum idle time between subsequent codes, etc. And some of the old stuff isn't exactly ASCII, like there are systems that operate in MSI/Plessey mode which is all sorts of martian. It has its own whole config tree. I don't even remember how Nixdorf mode works, I never had to deal with it.
And even within USB, sometimes you emulate a HID keyboard and send scancodes, sometimes you enumerate as an actual USB HID barcode scanner (that's a dedicated device class), sometimes you emulate a USB CDC serial device and inherit all the serial config from above minus the baud rate. Oh, and sometimes you can configure the USB polling interval for performance.
Do you start with a special key/character to signal that a barcode is coming, or just begin vomiting digits into wherever the cursor happens to be? Pad shorter codes with leading zeroes? Do you send CR or LF at the end, perhaps both? Or some other key/character like tab?
Oh and keep in mind that some barcodes can do alpha characters too. Which keyboard layout are you emulating, because the whole world isn't US-English? Convert to upper or lower case? Filter characters? Send a different start-character to indicate that an alpha code is coming?
And then you've got the symbology selection. There are hundreds of different types of barcodes, and they're used for different things. Have you ever scanned a box and the scanner picked up a barcode from the shipping label rather than the UPC? That's because whoever set up the POS didn't disable the other symbologies. They should have. So there are config variables for all that. Even just the UPC/EAN/JAN family has a dozen subvariants, and some POS systems want a prefix to indicate which variant is coming down the wire.
Then there's scan tuning. How many times does the laser/imager need to read the code before it considers it good? Crank this up to increase confidence, crank it down to favor speed. How much "dead time" should the reader take after scanning one code before it can scan another code? How much should it have before it can scan the SAME code again? Picture the way a clerk whips products across the scan window and try to tune it so you can easily scan multiples of an identical product, without scanning the very same item twice if it remains within the window too long.
Newer scanners also have tunables for recognizing barcodes displayed on LCDs since customers now sometimes present coupons on their phone screens. That's its own whole can of worms and largely newer than my time in the industry so I don't know the specifics, but again it's a performance tradeoff depending on the situation.
There's also minimum and maximum distance and apparent line width, which can help in certain handheld situations (think of the handheld style used at convenience store counters) where it otherwise might pick up distant products on the counter by mistake. But sometimes you might want to be able to scan things from a few feet away, so that's configurable.
Then you've got UX variables. Beep after a good read? Configure pitch, duration, and volume. Different beep/tone for error? All of the above again. Turn the feedback LED(s) green/red for those statuses? Or does green mean "ready for scan", like at self-checkouts? Scanner always active, or only when activated by button push (handheld) or proximity sensor (pedestal) or scale (checklane)? Or active only when DTR line high (serial)? Timeout after activation if no valid read? There's so much more, this only scratches the surface.
Finally, all these config variables can be stored, recalled, defaulted, protected, and unprotected.
The fancier scanners have well over a thousand config variables you can set, for example: https://www.zebra.com/content/dam/zebra_new_ia/en-us/manuals...
It's interesting how can we make this easier to secure, as embedded developer perhaps there should be an security by default, making it harder to circumvent that and making installs like this.
Can watch plenty of episodes in the time saved not having to go out of the way / stop at a gas station at least once a week.
But that’s actually kind of a fun idea, watch a show or movie in bursts. Thanks! Maybe you look forward to the next charging stop, to find out what happens after the cliffhanger!
Here you just select if you want to pay by card at the pump or at the desk and away you go.
- should I be depressed at how shoddy our infrastructure is
- elated that despite the low hanging fruit of these vulnerabilities, they aren't exploited nearly as often or as devastatingly as they could be
alternatively you can phish a credit card without leaving your house and get a way better return for lower exposure
The gas is already paid for by the gas stations at X price. Arbitrarily lowering it to $0.01/gal does not do anything but hurt the local gas station owner or piss off minimum wage worker(s) dealing with the fallout.
You could set up payments via anonymous cryptocurrency.
From article: “At the time of the study, Kaspersky said around 29% of gas stations in India, and 27% in the US were connected to the Internet.”.
That had the potential for a lot more than $1000 before getting fixed, although you would want your opsec to be pretty good.
Gas and dash isn’t a new idea.
https://en.wikipedia.org/wiki/Critical_infrastructure
You could end up with a felony conviction.
The point is, if they want someone poking around these systems, they'll contract with them to do that. You should not tamper with them just out of curiosity. Convicted felons have a hard time finding jobs.
Once a customer of the penal system, always a customer. They've worked hard to get their retention / repeat business numbers up this high. Why take that away from them?
If there are more jobs than people, felons will be hired.
To pick a boring example, see the multitude of companies complaining about labor shortages and also the number of felons who are struggling to find jobs.
You can argue whether a punitive system that effectively provides a deterrent is right or wrong, but a punitive system that isn't effective as a deterrent cannot make the same argument.
You plebs have no business poking around and find out what people in power are doing or find out if they've done their job properly. If they wanted someone holding them to account, they'd contract them to do thay'
Okay, I call bullshit. That which can be claimed without evidence can also be refuted without evidence.
That said, if you’re feeling like finding out do heed caution because I’m sure the Man will love to make an example of the first person we figures out how to pump their gas at $0.01 per gallon.
Aside from the extreme rudeness, what evidence are you looking for? Do you want GP to attach sensitive or classified pen tests results here in public forum?
GP's claim is so obviously true that I don't see why they would need to provide "evidence," but you can find a mountain of it yourself with a single duck: https://duckduckgo.com/?q=us+government+penetration+tests&at...
Pen tests are a requirement for any vendor doing business with the gov. Check out NIST 800-53 and the FedRAMP security process. It's much more intensive than SOC2 which is the standard in the commercial world. I think your information is about 10 to 20 years out of date.
Not every claim is an argument requiring evidence.
I work in the industry, you are 100% wrong, due to NDAs I offer no proof of your wrongness.
Go find it yourself if so inclined.
I am claiming relevant experience as my insider knowledge. What experience or proof do you have to back your refutation?
That’s how this works. When somebody gives you a peek behind the curtain while chatting, you don’t go and demand proof. You can ask for it nicely of course. That is the socially acceptable thing to do.
Your behavior is out of line given the casual and pleasant discourse before you showed up.
It is up to you as a communicator to establish your credebility so that people can trust your words and take your seriously. It's not a favour to the audience.
As far as I can tell, this gentleman has categorised you as a random dude at the bar making things up.
What do you do?
Nothing. Because you are not in a position to know better. It’s your unsubstantiated guess against a possible lie.
If you are coming to the conversation in good faith, you don’t start with an accusation of lying. You share your doubts and ask politely for more information.
Not caring if you offend someone? That’s also quite rude!
Not every single thing spoken requires a double blind study.
The person “calling bullshit” was wrong. I work in the industry, and no I’m offering no evidence due to NDAs.
Yes, agree 100%. When you're busting balls with your friends it's perfectly fine, but when it's a stranger online who doesn't know you at all and is likely from a very different culture, it's not a good idea to respond that way, unless you want to offend.
> Pen tests are a requirement for any vendor doing business with the gov.
What does this prove? Solar Winds, Colonial Pipeline (maybe more relevant here), etc.
Your search link doesn’t include anything about extensive penetration tests ensuring the security of these devices. That’s the claim. Where is the evidence?
Also calling someone’s knowledge “out of date” is a, dare I say rude assumption. But judging by your assuring in the security of government contractors I’d say your opinions are quite naive :)
Sadly, this is an is/ought problem. I don't want to live in a world with poverty and war either, but that doesn't make it fact.
> What does this prove? Solar Winds, Colonial Pipeline (maybe more relevant here), etc.
The point of pen tests is not to guarantee perfection. There are also ways to sweep things under the rug if those in charge are so inclined. But the existence of those things doesn't mean pen tests aren't done, or that nobody cares about security.
> Your search link doesn’t include anything about extensive penetration tests ensuring the security of these devices. That’s the claim. Where is the evidence?
Did you look at either of the first two hits? The first four indeed are evidence that the government does pen tests. The first hit is a government department that solely exists to do penetration tests[1]. The second one called "PENETRATION TEST GUIDANCE" is all the rules regarding how penetration tests must be done[2].
1: https://www.doi.gov/ocio/customers/penetration-testing
2: https://www.fedramp.gov/assets/resources/documents/CSP_Penet...
Ok your turn for evidence. What evidence do you have that all of those things are fake? Or that none of the compliance officers actually check it?
> Also calling someone’s knowledge “out of date” is a, dare I say rude assumption.
You're right, I apologize for doing that. I actually thought that was more charitable than the other possibilities, but it doesn't add anything to the discussion so should have been left out.
Lol, exactly
> But the existence of those things doesn't mean pen tests aren't done, or that nobody cares about security.
No one said that. Are you okay?
>What evidence do you have that all of those things are fake? Or that none of the compliance officers actually check it?
I know for a fact that they do and that those documents are not fake :)
"I call bullshit" is a colloquialism that derives from the "Bullshit Game"[0].
Learn you some language for a great good.
Like public facing websites that advertise they are meant to have users are pretty safe, but after that, explicit authorization is a good idea vs deciding for yourself whether it might be critical infrastructure.
Despite Putin’s bluster about nuclear weapons, cyberattacks are the easiest way for Russia to inflict pain on the US and Western Europe in response to economic sanctions and our support for Ukrain militarily. And those could do a lot of damage, both in terms of our economies and even civilian American/European lives.
Then find out you can control the cost/litre at the pumps via some awful soap api.. That's talking over the internet anyway..
I mean. So I've heard... (Looking at you, TOTAL)
I don't think the kind of people who are robbing gas really care about weather this is a bad idea. That's why sometimes the right answer is to focus on preventing the crime because...
> You could end up with a felony conviction.
The crooks really don't care. It's all about not getting caught.
Most of the people who did financial crimes: Got away with it multiple times and just assumed they wouldn't get caught.
The rest: totally irrational and fueled by mental health problems. Addictions, depression, relationship problems...
I wish we were as good at helping people as we are at isolating and punishing. If punishment was a good deterrent, we wouldn't have roughly .7% of the adult population in jail.
Never go to a gas station again.
The majority of the charging you do will be at your home, where you already pay for electricity. Unlike gas stations, which you go to every few weeks, you'll "fill up" away from home only infrequently, only when traveling multiple hundreds of miles away.
When you are away from home, it's sometimes possible to charge anonymously like you describe. RV campgrounds/RV parking often has a dumb electric outlet (which you'll need an adapter for) that can charge you quicker than a regular household outlet. Any place that has regular electric outlets can "trickle charge" you.
That said, you're right that EV charging when you're on a trip is more tech heavy and less anonymous than filling up at a gas station.
If your threat model doesn't allow for certain private companies to know your rough whereabouts when you're on road trips, then yeah, don't get an EV, don't use credit cards, don't use a phone, etc etc. Most people's threat models are perfectly fine with this though.
I'm worried someone will stumble upon the 50 meters of charging cable I have to hang from the third floor, along the pedestrian way, towards the car - in case I'm lucky to get a parking space just in front of the condo.
Like others have said, most of the "gas station" is at your residence and is probably via a dumb charger.
I'm already at >30min on waiting for gas pumping on my ICE for 2022. I'm still at 0 minutes on my EV.
If I go on a road trip and spend an hour waiting to charge, I will still have spent less time waiting on refueling on my EV than my ICE.
Oh yea, its also almost 1/10th the energy cost driving the EV than the ICE.
/s
And the cherry on top: loud video ads that you must stand there and watch while enduring all of this. THOSE have good screens and seem capable of playing back video well enough. If only they could dedicate a fraction of that compute power to making the purchase process less awful.
100% not surprised that these were programmed probably by a junior right out of college back in the 80s then never updated.
Foreigner can pay inside directly to the attendant, or sometimes pumps accept 99999 as the ZIP code in those cases.
When it's freezing cold outside, 1) no, I don't want a fucking car wash and 2) I really resent having to spend the couple extra seconds out in the cold to answer that question.
Also, FWIW its not that crazy about asking about a car wash when its freezing outside especially if you're in an area where they salt the roads a lot. From what I understand a lot of people will do a lot of undercarriage washes when things get salty. I don't live in those areas so I'm not the best to offer advice in that, but I do know briny water and metal aren't good for things you want to not have rust to nothing in a few years.
I agree, it's important to wash the undercarriage when there's salt on the road. However, I would never get a car wash at any old gas station, the risk of swirling or scratching my paint is too high. On top of that, who knows if these bottom-barrel gas station washes even clean the undercarriage effectively, or even at all.
Oh and of course there's the risk of accidentally pressing the wrong button, being charged for the car wash, and having to waste more time getting refunded.
[0]https://www.asus.com/us/Networking-IoT-Servers/WiFi-Routers/...
That phrasing seems to imply to readers that awareness of a serious/expensive security vulnerability would result in it being fixed.
It's really an industry problem, everyone who works in the c-store side of things is old as dirt and doesn't understand or care about security.
That should be considered gross negligence. Criminal negligence for anything shipped with default credentials since ransomware became a thing.
Still there is a lot more there than a VPN router. Lots of software and likely plenty of bugs.
/s
If that doesn't work, you should be able to find a factory reset button. Look for a hole you can stick a paper clip in, and power cycle with the button depressed.
Once you do that, call your ISP and ask for the default password.
/s
Luckily, every other hop you traverse across the internet is untrustworthy too, so having a bad router shouldn’t worry you. Treat your home wifi like you treat Starbucks wifi.
The term "CPE" seems to be more about device ownership than technical function.
Not ownership, location. CPE can be owned by the network provider or by the customer.
But it indeed doesn't have a clearly defined technical function. CPE can be just a modem, a consumer all-in-one device, or a "proper" enterprise-y router from Cisco/Juniper/...
The term "transparent routing" is used throughout the document to
identify the routing functionality that a NAT device provides. This
is different from the routing functionality provided by a traditional
router device in that a traditional router routes packets within a
single address realm.
Transparent routing refers to routing a datagram between disparate
address realms, by modifying address contents in the IP header to be
valid in the address realm into which the datagram is routed.
Section 3.2 has a detailed description of transparent routing.
Section 2.2 https://datatracker.ietf.org/doc/html/rfc2663NAT is still routing, even if it is different than "traditional" routing.
(And the reason it's a informational RFC is that IETF didn't want to encourage NAT)
ctrl +f “NAT router”