Categories: Tech

Two students discover security bug that could allow millions of people to do laundry for free

A security breach could allow millions of students to do laundry for free, thanks to a single company. This is due to a vulnerability that two students at the University of California, Santa Cruz found in internet-connected washing machines used for commercial purposes in several countries, according to TechCrunch.

The two students, Alexander Sherbrooke and Iakov Taranenko, apparently leveraged an API for the machines to remotely command them to work without payment and update a laundry account to show it contained millions of dollars . The company that owns the machines, CSC ServiceWorks, says it has more than a million laundries and vending machines in operation at colleges, multi-housing communities, laundromats and more across the United States, Canada and Europe.

CSC never responded when Sherbrooke and Taranenko reported the vulnerability via email and phone call in January, TechCrunch writing. Despite this, the students told the outlet that the company “quietly erased” their fake millions after contacting them.

The lack of response led them to report their findings to others. This includes the fact that the company published a list of orders, which both declared. TechCrunch allows you to connect to all washing machines connected to the CSC network. CSC ServiceWorks did not immediately respond to The edge’s request for feedback.

The CSC vulnerability reminds us that the security situation with the Internet of Things is still not resolved. For the exploit discovered by the students, CSC may be assuming the risk, but in other cases, lax cybersecurity practices have allowed hackers or company contractors to view the footage of the security cameras from strangers or access to smart plugs.

Often, security researchers discover these security vulnerabilities and report them before they can be exploited in the wild. But it’s no use if the responsible company doesn’t respond.

News Source : www.theverge.com
Gn tech

Eleon

Recent Posts

Symptoms, spread, what to know – NBC Chicago

A new variant of COVID-19 is raising questions and capturing the attention of researchers as we approach fall and winter.…

14 mins ago

Kits Cubed: Oakland native and Stanford student creates nonprofit to help kids learn about science

OAKLAND, Calif. (KGO) -- A Stanford student is doing his part to build a better San Francisco Bay Area.He builds…

15 mins ago

House Speaker Mike Johnson calls for more ‘manpower’ to protect Trump after second assassination attempt

The Secret Service "acted so quickly and so decisively" to thwart an assassination attempt on former President Donald Trump at…

16 mins ago

Massachusetts man drives pickup truck onto college football field in Colorado

Crime Authorities say the man was involved in several accidents. A football game between UCLA and the University of Colorado…

17 mins ago

State’s experiment with grocery chain mergers sparks fight to stop Albertsons’ deal with Kroger

Washington state lawyers will have past grocery chain mergers — and their negative consequences — in mind when they go…

18 mins ago

Ben Affleck ‘couldn’t help but touch’ Jennifer Lopez at brunch

Ben Affleck "couldn't keep his hands off" Jennifer Lopez during their brunch on Saturday, a source exclusively tells Page Six.…

19 mins ago