These students discovered a security bug that could let millions of us do laundry for free


Two students found a way to do their laundry for free, after discovering a bug in the app that accompanies the laundry machines at their college campus.
Since they were honest people, they reported their findings in good faith. However, it seems that the company making the app didn’t really bother to reply to their messages or, even worse, address the issue for months.
Reporting on the findings, TechCrunch says the bug is still present and that free laundry is still possible.
Bugged API
Apparently, more than three months ago, UC Santa Cruz students Alexander Sherbrooke and Iakov Taranenko discovered that the app for internet-connected laundry machines built by CSC ServiceWorks came with numerous flaws. The app, among other things, allows users to top up their accounts and use the funds to purchase laundry washing.
First, anyone could register an account with any fake email address – the app didn’t bother checking if the owner of the account also owned the associated email address (which is standard practice these days).
Then, they found that the API used by the CSC Go mobile app was flawed in a way that allowed the users to trick CSC servers into accepting commands that change the account balance. One of the users topped up their account by more than a million dollars, to prove their point.
After discovering the flaws, the two students allegedly tried reaching out to the company in different ways, but failed to ultimately share their findings with anyone. After that, they contacted the media.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“I just don’t get how a company that large makes those types of mistakes, then has no way of contacting them,” Taranenko said. “Worst-case scenario, people can easily load up their wallets and the company loses a ton of money. Why not spend a bare minimum of having a single monitored security email inbox for this type of situation?”
The company did wipe the students’ balance, but apparently the bug can still be abused.
More from TechRadar Pro
Two students found a way to do their laundry for free, after discovering a bug in the app that accompanies the laundry machines at their college campus. Since they were honest people, they reported their findings in good faith. However, it seems that the company making the app didn’t really…
Recent Posts
- Die in the Dungeon will keep you busy until Slay the Spire 2
- Sana Grain Mill Review: Makes Specialty Flours a Piece of Cake
- I tested an ultra-cheap Dolby Atmos soundbar against a premium alternative, here’s why it’s worth spending the extra cash
- ‘Revolutionary’ Wi-Fi router which can send data up to 10 miles away goes on sale for less than $100 – just make sure you’re happy with the 32Mbps speed
- The Humane Ai Pin Will Become E-Waste Next Week
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010