Two students find security bug that could let millions do laundry for free - eviltoast
  • Excrubulent@slrpnk.net
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 months ago

    Well that’s the thing, you don’t need a lot. You’re handing out these cards and people walk out the door with them, so you can’t trust they’re not going to mess with them. They don’t need to be walking around with a writer, you need one person to have access - either own one or have one at work or a university lab - and they can make as many cards as they want to give to their friends. Then they could use your business for years and get thousands of dollars of free service without you ever knowing.

    That’s the real threat here I think - a poor university student with a technical degree challenging themselves to cheat the system and help out their friends. I mean it’s probably not going to happen, but a business owner who’s aware of this attack vector could spend the time to get a basic encryption system going that’s practically unbreakable.

    • ridethisbike@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 months ago

      Might be unbreakable, but all the attacker has to do is put money on it once and then just duplicate the card. You don’t need to beat the encryption. You just need to make the machine think the card is legit