Live data from Hacker News

How I hacked modern vending machines

hackernoon.com

31–40 of 90 posts

Re: How I hacked modern vending machines

#31
post #2

How I hacked a totally insecure android vending machine wallet app would be more to the point, but nice anyway.

How dare someone share what they learned!

I bet you complain about build videos on YouTube too? "Come on, people have been building tables like this for millennia" not stopping to think that there are people without the skills to or that want to learn how to, or that can be shown a different way of thinking about an object via a well worded, easy-to-follow essay and guide on how they did their not-cutting-edge research?

Re: How I hacked modern vending machines

#34
Almost felt like security through obscurity. Because this modify the app hack was huge for cheating in some games on jail broken iPhone years back. I would increase my coins and keep playing. I was under the belief developers stopped it years ago by making purchases done server side. So to see that this app it is done locally on the device was a big surprise to me and I would have not guessed it possible(in the sense that it would be crazy to ever build a payment app that way as this abuse has been done with games for years)."

Re: How I hacked modern vending machines

#35

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

But the benchmark this system was compared to was already a trust-the-client system : coin payments! I'm sure you can defraud coin-op machines, it's just not easy or common enough to worry too much about.

It's my impression that consumer payment systems operate on a good-enough principle. Being fraud-proof is not the goal, the goal is not to spend more on security than you are preventing in fraud.

Re: How I hacked modern vending machines

#36

Earlier quoted context omitted.

"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

If they want it out by $DATE I'd argue it'd be simpler to add support for Apple Pay / Google Wallet.

I'd bet they didn't want to provide SIMs and data contracts for every vending machine.

Re: How I hacked modern vending machines

#37
post #29
post #21

Earlier quoted context omitted.

This is why I so love the millenials' habit of communicating via hieroglyphs when we have perfectly good words.

What do millenials have to do with it? You think baby boomers don't use emoji too? Relax and have some fun. ;)

Speaking as a millennial, millennials as an age group have a lot to do with it. Have you actually communicated in writing with people of varying age groups? It's blatantly obvious to anyone with "millennial" / "Gen Y" (loosely: born after 1985) family or friends that emoji use is heavily driven by younger users.

Further reading: http://time.com/4834112/millennials-gifs-emojis/

Re: How I hacked modern vending machines

#38

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."

To be fair, I'm sure the amount of money lost to people hacking vending machines by reverse engineering APKs is far smaller than the cost of getting every machine a network connection to a central server

Re: How I hacked modern vending machines

#39

I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.

I actually came to complain about the silly filler content I had to scroll past that felt like ads were inserted? I just closed the page after I lost the article in the memes.

Re: How I hacked modern vending machines

#40

"One day I decided to interrupt seasoning myself in the bat-cave and direct to my hometown to get some sunlight..." What?

I was laughing at that myself. Guessing this is something that sounds way better in the author's native language.

Yeah seasoning in italian never means “adding spice to some food” but only “keeping it in a cold/dry place and wait for it to be ready“ (usually months, sometimes years).
Post reply on HN