HNHacker News
TopNewBestAskShowJobs

theappanalyst

66 karma · joined February 7, 2019

submissionscomments
theappanalyst··on Tell HN: Somebody implemented something I wrote a blog about
I enjoyed when a french hacker used information from my blog to set off all the alarms of Bird scooters in Lyon France for an evening.

I had written about (what I considered as) a vulnerability that allowed remote triggering of Bird Scooter alarms (Bird disagreed of course) on my blog [1]. I then saw this github repo linked in the comments for setting off alarms of Bird scooters [2] and reached out to the author.

The author let me know that they had used the info in my blog to script a tool for setting off Bird Scooters en masse. They then targeted the script at all the scooters in Lyon and subsequently fell asleep. When they woke up the noticed the end point was disabled... Bird had taken the action to disable the API endpoint in response of course.

Probably would've been easier to fix before someone scripted it out but it made for a fun story.

[1] https://theappanalyst.com/bird.html [2] https://github.com/pcouy/bird-whisperer

theappanalyst··on App Analysis: Air Canada
Haha very true, I was never expecting this to get much traction... will update with the proper pki asap, thanks :)
theappanalyst··on App Analysis: Air Canada
Exactly! Glad someone is catching my point, the issue is is that people go to the end of the earth to protect databases of credit card information, I doubt the same can be said for a database of screenshots containing equivalent info.

Another big issue I see is I may trust company X with my data but I as a consumer wouldn’t know I’m actually sharing my data with company Y and I think that is something users should be aware of.

theappanalyst··on App Analysis: Air Canada
Thanks I try not to be overly sensationalist about my topics and just display the facts. Thanks for giving it a read :)
theappanalyst··on App Analysis: Air Canada
Author here, these are not mockups and if you watch the video linked you can see me replay the session I captured using a https proxy. Hope that clears things up, thanks for your interest!