How two American students manage to run washing machines completely for free


Mathilde Rochefort

May 21, 2024 at 3:27 p.m.

2

Washing machines are also prone to vulnerabilities.  © engin akyurt / Unsplash

Washing machines are also prone to vulnerabilities. © engin akyurt / Unsplash

Two American students discovered a security flaw allowing anyone to avoid paying for laundry detergent provided by more than a million washing machines connected to the Internet. The company that operates them does not deign to respond to them.

CSC ServiceWorks describes itself as the leading provider of commercial laundry services and airline distribution solutions in the United States, Canada and Europe. Its washing machines equip residences, hotels and universities around the world, but clearly the security of its devices is not a priority.

In January, two University of California students, Alexander Sherbrooke and Iakov Taranenko, managed to activate a machine by running a code script, despite the fact that their linked account was dry. They later added a multimillion-dollar virtual balance to one of their laundry accounts, allowing them to access it through the CSC Go app.

Best antivirus, comparison in May 2024
To discover
Best antivirus, comparison in May 2024

Apr 30, 2024 at 3:05 p.m.

Service comparisons

An API story

According to the students, the vulnerability is in the API used by the mobile application, which offers the ability to top up your account, pay and start laundry on a nearby machine. The company’s servers can indeed be tricked into accepting commands that change the account balance, because security checks are carried out by the application through the user’s device and then are automatically approved by the servers.

Sherbrooke and Taranenko were able to bypass the app’s security controls and send commands directly to the CSC’s servers, which are not available through the app itself. Technically, anyone can activate a company machine without paying or creating a fake account at CSC Go, as the servers also do not check whether new users own their email address.

The students wanted to alert the company through messages and phone calls. If their requests have remained unanswered until today, the firm took care to withdraw the balance of several million dollars from their account. They decided to reveal their discovery to the media to get management to react.

  Activating a washing machine for free and remotely is the discovery of two students © Shutterstock

Activating a washing machine for free and remotely is the discovery of two students © Shutterstock

Potential hazards

The ability to activate a machine for free seems harmless, but the vulnerability of such devices still presents dangers. For example, sending commands through the API is likely to bypass safety restrictions that washing machines are equipped with to prevent overheating and fires.

I don’t understand how such a large company can make these kinds of mistakes and have no way to contact them », Regrets Taranenko.

This case highlights the need to provide sufficient security controls for connected objects. It has already happened that hackers have managed to activate cameras from abroad or even gain access to smart sockets.

What are the best washing machines?  Comparison 2024
To discover
What are the best washing machines? Comparison 2024

Apr 18, 2024 at 09:50

Comparative

Source : TechCrunch

Mathilde Rochefort

Mathilde Rochefort

After my journalism studies, I decided to focus on areas that fascinate me: new technologies, video games, or even astronomy. I love sharing around these topics but my...

Read other articles

After my journalism studies, I decided to focus on areas that fascinate me: new technologies, video games, or even astronomy. I love sharing around these subjects but my curiosity leads me to discuss many other subjects through my articles.

Read other articles



Source link -99