this post was submitted on 20 May 2024
379 points (98.0% liked)

Technology

55940 readers
4226 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] Excrubulent@slrpnk.net 12 points 1 month ago* (last edited 1 month ago) (14 children)

It could be simply obscure like you say, but the absence of a network doesn't guarantee it's that easy to hack.

They could use a checksum and your trick would invalidate the card until you figured out the correct algorithm, which would require a new visit to the laundromat for every new attempt, so basically impractical.

That or the card is just simply encrypted, which would make it impossible to interpret. It would be easy to implement too because the shared secret is between machines that are all physically controlled by the laundromat.

[–] Pacmanlives@lemmy.world 1 points 1 month ago (5 children)

I mean how many people are gonna be walking around with card rw

[–] Excrubulent@slrpnk.net 2 points 1 month ago (4 children)

Well that's the thing, you don't need a lot. You're handing out these cards and people walk out the door with them, so you can't trust they're not going to mess with them. They don't need to be walking around with a writer, you need one person to have access - either own one or have one at work or a university lab - and they can make as many cards as they want to give to their friends. Then they could use your business for years and get thousands of dollars of free service without you ever knowing.

That's the real threat here I think - a poor university student with a technical degree challenging themselves to cheat the system and help out their friends. I mean it's probably not going to happen, but a business owner who's aware of this attack vector could spend the time to get a basic encryption system going that's practically unbreakable.

[–] ridethisbike@lemmy.world 2 points 1 month ago (1 children)

Might be unbreakable, but all the attacker has to do is put money on it once and then just duplicate the card. You don't need to beat the encryption. You just need to make the machine think the card is legit

[–] Excrubulent@slrpnk.net 2 points 1 month ago* (last edited 1 month ago) (1 children)

Yup, I've realised that's what people are saying. That's not an easy one to guard against I'm afraid.

[–] ridethisbike@lemmy.world 2 points 1 month ago* (last edited 1 month ago) (1 children)

I just re-read the comment chain and saw it was mentioned before. Oops lol

[–] Excrubulent@slrpnk.net 1 points 1 month ago

No worries I've been in this thread a bunch and only just got it.

load more comments (2 replies)
load more comments (2 replies)
load more comments (10 replies)