Live data from Hacker News

How I hacked modern vending machines

hackernoon.com

1–10 of 90 posts

Re: How I hacked modern vending machines

#3
Much simpler hardware hacking: slightly bend the control panel and/or the door with a small lever (a coin might be sufficient). On some models, opening the door starts the "admin mode" where you can control each spire, do tests, change prices etc. The sensor for door opening can be fooled by the slight bend, hence allowing you to take whatever you want.

Re: How I hacked modern vending machines

#4
post #3

Much simpler hardware hacking: slightly bend the control panel and/or the door with a small lever (a coin might be sufficient). On some models, opening the door starts the "admin mode" where you can control each spire, do tests, change prices etc. The sensor for door opening can be fooled by the slight bend, hence allowing you to take whatever you want.

Perhaps if the vending machine isn't in a public space / covered by CCTV etc.

This approach just makes the "hacker" look like a normal user to the casual observer.

Re: How I hacked modern vending machines

#6
post #3

Much simpler hardware hacking: slightly bend the control panel and/or the door with a small lever (a coin might be sufficient). On some models, opening the door starts the "admin mode" where you can control each spire, do tests, change prices etc. The sensor for door opening can be fooled by the slight bend, hence allowing you to take whatever you want.

Sure, also lockpicking the door open would work, and if you had the possibility to bring the vending machine at home and disassemble/study it you would probably also find another three different ways, what gives?

Still, you would need to perform some "unusual" physical action on the physical machine and you might be noticed by people passing by or by a surveillance cam, this app hack is instead "clean".

And it makes you think about the reliability of any similar app based paying system, in this case is "their" money[1] that "you" can "steal" (by drinking and eating for free), but what if it was "your" money?

[1] so before or later the vending machine firm would notice

Re: How I hacked modern vending machines

#8

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

>I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

Yep, I would add that the unknown programmer that wrote the app very likely thought that it was a very clever approach (and probably he/she has been paid good money to write the app).

Re: How I hacked modern vending machines

#9

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

Re: How I hacked modern vending machines

#10

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

>"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

Can you clarify?

It sounds like the responsability for having designed an insecure app is of the people that asked the programmer/sofware house to write it[1]?

[1] and as said very likely paid good money for it ...

Post reply on HN