Date: May 20, 2024
Two students from the University of California found a bug in the IoT-enabled laundry service that could give away millions of laundry for free.
How stringent is the security in the IoT industry that witnessed a sudden bloom, thanks to AI? Automation, remote accessibility, and the Internet of Things are the three recent innovations that have entered both personal and commercial spaces. However, the security layers in these technologies often lack safety fundamentals. Two students from the University of California have proved this point with a risk that could have cost a company millions of dollars.
According to the reports, Alexander Sherbrooke and Iakov Taranenko exploited the APIs of CSC Service Works’ laundry machines. The students used a loophole in the IOT-powered connectivity of the machines with the company’s software and remotely commanded it to do their laundry without making any payment. They also updated a laundry account to show that it had a million dollars in its wallet.
The company that runs these machines has over a million laundry and vending machines serving in colleges, multi-housing communities, laundromats, and other public places in the USA, Canada, and Europe. The students who found out about the bug immediately reported it to the company with all the required details, which are attached to this email. After getting no response from the company, they even called it up to explain the drastic nature of the situation. The company, however, remained silent in their response.
When the students mentioned a bug that filled an account with millions of dollars in its wallet, the company simply removed the wallet money. It is unclear whether the company has corrected its security layers, but IoT devices usually have more than tolerable vulnerabilities. The company has a published list of commands that enable connection with all CSC network-connected laundry machines.
Hackers from around the world look for such vulnerabilities to earn quick and explosive income that usually bankrupts the company. CSC’s lack of response reflects its inadequate commitment to security or insufficient awareness of the direness of the situation. IoT devices have multiple vulnerabilities, as people who make them usually benefit from enabling maximum connectivity, which exposes them to potentially dangerous third-party APIs.
Often, security researchers find these loopholes and report them to the designated authorities to prevent fraudulent activities in exchange for a nominal fee or reward. Google is the mastermind that has built one of the strongest bug-testing independent networks of talented individuals like Alexander Sherbrooke and Iakov Taranenko. It not only responds promptly, but also gets into action swiftly, while rewarding the bug finders and fixers with hefty money.
By Arpit Dubey
Arpit is a dreamer, wanderer, and tech nerd who loves to jot down tech musings and updates. Armed with a Bachelor's in Business Administration and a knack for crafting compelling narratives and a sharp specialization in everything from Predictive Analytics to FinTech—and let’s not forget SaaS, healthcare, and more. Arpit crafts content that’s as strategic as it is compelling. With a Logician mind, he is always chasing sunrises and tech advancements while secretly preparing for the robot uprising.
Reddit Unveils AI-Powered Search Tool for Smarter Results
Reddit launched Reddit Answers, an AI-powered search tool that curates and summarizes discussions to enhance user experience and reduce reliance on Google.
OpenAI Scraps o3 Model, Pushes for Unified GPT-5 in a Major AI Overhaul
OpenAI is canceling its o3 AI model and merging it into GPT-5 for a simpler, more powerful system. A big move to stay ahead in the AI race.
Virtual Reality in Healthcare: Revolutionizing Patient Care
Experience the power of virtual reality in healthcare as it transforms medical training, patient care, and treatment methods with immersive technology for better accuracy, efficiency, and improved outcomes.
Google I/O 2025: Dates Announced for the Tech Giant’s Biggest Event of the Year
Google I/O 2025 is set for May 20-21! Expect big AI reveals, Android 16 updates, and more. Registrations are open for keynotes, demos, and game-changing tech innovations!