Security Bug Found in Commercial Connected Laundry Machines

Laundry Machines Security Bug Featured

It can’t be said enough: if an object can be connected, it carries a security risk. Even commercial connected laundry machines have been found to be carrying a major security bug that allowed anyone to send commands remotely to the machines.

Tip: want to keep your PC protected? Try these Windows settings for free PC protection.

Two Students Find Security Bug in Laundry Machines

This issue was first found by two Califiornia college students, Alexander Sherbrooke and Iakov Taranenko. The former was sitting in the basement laundry room in January while on his laptop, trying to build an app to track the status of the laundry machines. He started to think about it, then ran some code instructions to one of the laundry machines to start a cycle, even though he had no balance in his laundry account. The machine started up and showed the message “Push Start.”

Laundry Machines Security Bug Man Waiting
Image source: Unsplash

He and his friend tried adding a fake balance of 13 million dollars into a laundry account. It was detected in the machine’s mobile app as though he’d really deposited it. These vulnerabilities could lead to many things, but they could certainly allow students, or anyone, for that matter – to do their laundry for free.

FYI: learn what the Windows Security button is and how to use it.

Laundry Machines Security Bug Reported

Students Sherbrooke and Taranenko reported their findings to CSC ServiceWorks, a laundry service company that operates the machines. The company manages a network of more than a million of these machines that are found in hotels, universities, and residences in the United States, Canada, and Europe.

They couldn’t find a dedicated security page to report such things, so they sent several messages to an online contact form but never heard back from the company. It was also reported to the CERT Coordination Center at Carnegie Mellon University. CERT helps disclose security flaws.

Laundry Machines Security Bug Commercial Connected Machines
Image source: Unsplash

It was noticed that commands could be sent to the machines’ servers, as security checks are on the user’s device in the app. CSC’s servers trust them with no questions asked. Once they looked at the network traffic, the two students found that they could get around the security checks and send the commands to the service. Email addresses used to create an account with the app also aren’t verified.

After the customary three months of waiting for the CSC to do something before going public with it, Sherbrooke and Taranenko are revealing more. They believe the vulnerability is in the API for the mobile app. CSC hasn’t done anything to fix the app, but they did wipe out the larger fake bank balance. However, smaller amounts of $50 to $100 remain in the account.

It needs to be noted that this security issue is on the entire network of devices – not just the ones at that particular college campus. That’s where it’s worrisome. If laundry machines have that security bug, think of how many other connected objects, that would otherwise be innocuous, have a security vulnerability. Read on to learn how to protect your privacy and security on Android.

Image credit: Unsplash

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.
When survivors near Lake Nyos woke on the morning of 22 August 1986, the cattle were dead in the fields, the birds had fallen out of the trees, and 1,746 of their neighbours were lying where they had stood the night before, with no fire, no flood, and no wound to explain it.
In October 2002, a Russian scientist named Dimitri Malashenkov stood up at a space conference in Houston and quietly explained that the dog Laika, whom the Soviet Union had publicly mourned as a heroic week-long orbiter in 1957, had actually died of heat and panic within about five hours of launch.