Is it even possible to "hack" an API that has no authorisation for any of its methods?
AI agent hacks gym to get its user a spot in pilates class
11–20 of 75 posts
Re: AI agent hacks gym to get its user a spot in pilates class
#12Is it even possible to "hack" an API that has no authorisation for any of its methods?
Re: AI agent hacks gym to get its user a spot in pilates class
#13Is it even possible to "hack" an API that has no authorisation for any of its methods?
Re: AI agent hacks gym to get its user a spot in pilates class
#14Is it even possible to "hack" an API that has no authorisation for any of its methods?
Re: AI agent hacks gym to get its user a spot in pilates class
#15Re: AI agent hacks gym to get its user a spot in pilates class
#16Re: AI agent hacks gym to get its user a spot in pilates class
#17Is it even possible to "hack" an API that has no authorisation for any of its methods?
If you leave your front door open I don’t think you’d classifying someone walking in and taking your laptop as ‘not stealing’.
Re: AI agent hacks gym to get its user a spot in pilates class
#18Re: AI agent hacks gym to get its user a spot in pilates class
#19Is it even possible to "hack" an API that has no authorisation for any of its methods?
If you ask a software developer: no If you ask a judge: probably yes
Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner and which are not intended for them and have been specially secured to prevent their access shall be liable to a custodial sentence not exceeding five years or to a monetary penalty.
Re: AI agent hacks gym to get its user a spot in pilates class
#20Is it even possible to "hack" an API that has no authorisation for any of its methods?
Practically speaking, discovering that fact and taking advantage of it, is already "hacking".
But say that the underlying api exposes some endpoint discoverability capabilities (eg. Exposing an openAPI spec), then arguably the action was invited: the actions was documented along with the auth model.