How I hacked a totally insecure android vending machine wallet app would be more to the point, but nice anyway.
How I hacked modern vending machines
41–50 of 90 posts
Re: How I hacked modern vending machines
#42Re: How I hacked modern vending machines
#43Re: How I hacked modern vending machines
#44I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.
"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."
And there you have it. Most people don’t understand security. The business can say they are MVP and “secure enough”.
Re: How I hacked modern vending machines
#45Earlier quoted context omitted.
I was laughing at that myself. Guessing this is something that sounds way better in the author's native language.
Yeah seasoning in italian never means “adding spice to some food” but only “keeping it in a cold/dry place and wait for it to be ready“ (usually months, sometimes years).
Re: How I hacked modern vending machines
#46Re: How I hacked modern vending machines
#47Earlier quoted context omitted.
This is why I so love the millenials' habit of communicating via hieroglyphs when we have perfectly good words.
What do millenials have to do with it? You think baby boomers don't use emoji too? Relax and have some fun. ;)
Although I grant you that plenty of baby boomers (and even older folks) do in fact use emojis, you can't seriously be arguing that they do so more than younger generations?
I would love to see some actual research on this. I have a completely untested theory, purely based on direct observation of my own friends and family, that the people who use emojis the most are those with the lowest writing skills. If that turns out to be true then emojis are in fact exacerbating the problem, because it doesn't much matter if my mother uses emojis instead of learning to spell, but I'd be very concerned if my daughter did.
Re: How I hacked modern vending machines
#48Earlier quoted context omitted.
"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."
Vending machines could be in buildings that blocking cell reception. I bet one of the requirements were that app should work offline. And there you have it. Most people don’t understand security. The business can say they are MVP and “secure enough”.
Re: How I hacked modern vending machines
#49Earlier quoted context omitted.
"Never trust the client" is a lesson every developer learns at some point. Incredible how an entire company missed that, but I'd put this down to "bosses want this out by DATE? Alrighty..."
But the benchmark this system was compared to was already a trust-the-client system : coin payments! I'm sure you can defraud coin-op machines, it's just not easy or common enough to worry too much about. It's my impression that consumer payment systems operate on a good-enough principle. Being fraud-proof is not the goal, the goal is not to spend more on security than you are preventing in fraud.
The same principles often come into play with online games and cheating, yet constantly developers make the same mistakes.
Re: How I hacked modern vending machines
#50I guess plenty of people are going to come in here to wave their e-peen and comment on how trivial and obvious this "hack" is, but that's kind of the point. Us developers could learn a lot from this - mainly how not to design any kind of payment app.
I actually came to complain about the silly filler content I had to scroll past that felt like ads were inserted? I just closed the page after I lost the article in the memes.