9 ms·
How to earn money by hacking a “walking for money” app
- laurent123456 5y agoIt feels like the presence of the Google and Slack API keys should have been responsibly disclosed to the company before writing this article. Now that it hits the front page of HN there's a strong change someone's going to exploit that.
- deadf00d 5y agoThanks for the feedback ! All keys, secrets, credentials has been anonymized.
- laurent123456 5y agoWell, yes, but you didn't anonymize the name of the app, so it's easy to download it and extract the credentials.
- gunfighthacksaw 5y agoThat’s not their fault lol
- mousetree 5y agoIt's still available on the archive.org link
- deadf00d 5y agoNop, it was from the first publishing of the article.
- jonasdegendt 5y agoHackers News hug of death? :)
- bitwize 5y agoAllAdvantage, 2020s edition!
- deadf00d 5y agoYeah, these concepts are pretty annoying..
- hombre_fatal 5y ago"Web surfing for money" was pretty lame. But inspiring people to get off their ass and walk around with rewards seems nice whether it's financial rewards or to catch pokemon. A simple UI on my phone that tells me how many steps I have and a progress bar was enough to make me religious about getting my 10k steps each day, and it's been nothing but a good thing in my life. I even got my girlfriend addicted. We'll take a walk to the grocery store together to buy a pineapple, just for the steps.
- Nextgrid 5y ago"inspiring people to get off their ass and walk around" is nice. Conning them into believing the app is after their well-being while stalking them in the background and selling their personal data is scummy.
- hombre_fatal 5y agoWell, there's nothing that's truly after your well-being except you and your loved ones. Not even my local gym nor Youtube workout videos nor my $1 pedometer phone app is after my well-being. Our incentives simply align. I want to exercise more, they want to sell me something that I want to use. Everyone is free to do push-ups and run at their own leisure without giving money to anyone else. Unfortunately most of us have trouble with that. It seems too much to call something a "con" if it can compel someone to improve their health just because it's transactional. If someone can figure out how to make money from compelling people to exercise, I think it's a net positive. At least it's certainly better than all the money being made by compelling people to indulge in habits that are bad for them, which seems like just about everything.
- aj7 5y agoHave you checked what constitutes fraud in France? Just sayin’…
- withinboredom 5y agoWho the heck puts a slack webhook in a client? That's literally begging for disaster.
- deadf00d 5y agoYep, that's pretty bad.
- gigaflop 5y agoReading this made me confused. You have a 'hire me' link on a page where you talk about exploiting someone's app? If you're not writing this up like a white hat, isn't the article counterproductive to you? I can understand why you did all this (and hopefully, you reached out to the app provider to let them know about these holes), and it seems like you know enough about what you're doing. I'm just scratching my head at the end of all of this, and the article itself feels like it lacks structure.
- deadf00d 5y agoThe idea is to show my work. I tried to add a touch of humor, I think it's funny to try to earn money like this (actually you can't because they verify all transaction). If you think I can be seen as a black hat, I might modify some of it. Also, a lot of developer (and some of my colleague too) tends to think that "hacking" doesn't exist like in movies or even doesn't exist at all (because they use ORM, don't laugh, I really got this one). By taking a real world example, I think It's a cool way to get people back in reality. Anyway, people and my customers, hire me for my skills, and for what I did. Nobody care that you hacked an office, but if this office is the CIA, then it's cool. For the lack of structure, it probably is, if you can give me example that I could fix, It would be very kind of you. Thanks for your feedback.
- mr-wendel 5y agoI would like to highlight the parent post's comment about attempting to contact the people whose work you are exposing vulnerabilities in. I have to say that if this is "showing your work" then the most important thing you've shown is poor judgement in publishing their secrets in a submission to a very popular website. The fact that they have followed such shockingly bad security practices themselves is absolutely no excuse. The work I wish we saw was the valiant effort you made to contact the company and help them see their mistakes. That is an area where we can all use more good examples, even if only to show how difficult it is to get something so obviously problematic taken seriously. I'm certain you mean no ill will, but the lack of consideration here is concerning. [EDIT] As per the posters comments, the keys included weren't the real ones. I still think the point stands: they are trivial to obtain when you know they are included in the package so their exclusion only means so much.
- orf 5y agoArchive link: https://web.archive.org/web/20220228134714/https://www.deadf00d.com/post/how-to-earn-money-by-hacking-a-walking-for-money-app.html https://web.archive.org/web/20220228134714/https://www.deadf...
- dangerboysteve 5y agointeresting, all the urls in the source have have been prefixed with "https://web.archive.org/web/20220228134715/ https://web.archive.org/web/20220228134715/" by arvhive.org
- danpalmer 5y agoIt's a snapshot. If they didn't do that then all URLs would be resolved against the original page which could change or disappear.
- ale42 5y agoBut also URLs in the extracted/reverse engineered source code are prefixed, doesn't make sense. It's a bug from archive.org...
- hombre_fatal 5y agoThey rewrite the hrefs in the document so that you can easily click around inside the snapshot. The links just aren't necessarily archived as well, but sometimes they are.
- Liquid_Fire 5y agoWhat the parent commenters are saying is that URLs in the page which are _not links_ have also been rewritten, e.g. the ones in the source code snippets which are plain text. They are not clickable so it makes little sense to the user that they are rewritten. I imagine they probably have a pretty liberal regex working on the source code so that it can also rewrite URLs in JavaScript/CSS/etc.
- actually_a_dog 5y agoI've got a better hack: Step 1. Get a dog. Step 2. Walk your dog. That's it.
- vanous 5y agoI simplified it to just: - walk And it has been amazing.
- CraneWorm 5y agodoesn't load w/o js
- deleted 5y ago[deleted]
- deadf00d 5y agoMe: publish on HackerNews Strapi: - [2022-02-28T14:27:04.385Z] error KnexTimeoutError: Knex: Timeout acquiring a connection. The pool is probably full. Are you missing a .transacting(trx) call? - That's the best I can do.
- encryptluks2 5y agoAnother title for this could be, how to get prison time for committing fraud.
- deadf00d 5y agoFor which crime ?
- encryptluks2 5y agoHacking and abusing a walking for money app for profit.
- y42 5y agoIm Germany there is the term "instruction to the offence" - that is a crime itself. Just saying...but I'm not a lawyer, dunno how that's handled globally.
- asteroidp 5y agoNo one would ever see prison time for some thing like this.. ever
- deadf00d 5y agoBack online ! for the last time I hope :') Also strapi take soooo much ressources...
- PaulHoule 5y agoI can make most pedometers think I am walking by folding my arms so they cross my chest and then moving my lower arms in circles along the horizontal axis perpendicular to my body. I am not sure if getting 10,000 steps this way is easier or harder than walking but then again in the summer I like to get up at sunrise and got walk six miles, then walk another six miles before sunset.
- dncornholio 5y agoYou scored some internet points.. But posting this before the company could react, smells of bad taste, and won't score you much respect.
- gamblor956 5y agoIt's not just bad taste. Some of the described actions would legally be considered fraud (both in the U.S., and in France where the author and app are based).
- deadf00d 5y agoLike what ?
- encryptluks2 5y agoI mean in the US, you have the CFAA and in France a quick Google search indicates the illegalities of doing something like this. I wouldn't be surprised to see the company go after you and to be questioned by law enforcement. Don't say no one warned you.
- deadf00d 5y ago"illegalities of doing something like this" -> Like what ? Maybe you can provide sources ?
- dncornholio 5y agoTrying to do a crime is punishable. Your blogpost is one big confession on how your tried to hack a company out of money. No?
- gamblor956 5y agoFraudulently recording steps, and the other example of you gave making calls to the API. Legally, those API calls signify something in the real world. You are representing that the action/status signified by the API call happened in the real world. _It's one thing to accidentally or mistakenly call those APIs, but to do so deliberately if such action/status is not true is fraud. By itself, that the API calls are fraudulent wouldn't matter. But in your case, the purpose of the fraud is financial gain: each API call earns you money. In the U.S., this would be (felony) theft by fraud, among other crimes. French laws are more complicated, and as I'm not French nor do I speak French I won't attempt to go into any detail as to what the specific crimes would be, other than to say it appears that your actions, if performed, would appear to constitute several different crimes. [Note that in the U.S., intent matters, so fake API calls for purposes of QA testing, security testing, etc., isn't fraud...but could be a crime if performed without the website owner's permission.]
- gowld 5y agoAside from now doing the Google API work client side, how to build an app like this, securely? If the server does work based on client data, I can still do more "normal" work by modifying the client. That is, what is a non-hackable way to measure the physical environment of a consumer smartphone? Can the critical data be stored in a DRM module protected by OEM TPM module?
- deadf00d 5y agoIt's exacly my point in the "about phone data" section.
- Nextgrid 5y ago> to measure the physical environment of a consumer smartphone? At this point you need to be more precise about what you exactly intend to measure. Even if you build something perfectly unbreakable, nothing prevents an attacker from simulating the environment around it, whether movement (by building a robot to shake the device), visual (monitor in front of camera sensor), radio (GPS constellation simulators, etc). I've seen physical security companies enforce patrols by having their guards tap their phone on a physical device in the secured property (which does a challenge-response) to prove that they've indeed been there at a given time, but even that can be defeated by attaching a device with a microcontroller and some out-of-band channel (cellular, etc) to relay the signals over the internet and allow them to "check-in" at every location without physically being there. The system works because in most cases the cost & skill required for such an attack isn't worth it (if you have those skills you typically already have access to better-paying jobs). Health tracker apps typically don't have this problem because the incentives are aligned - the user has no incentive to lie to their health tracking app so no security is needed. It's a problem for this particular app because the true purpose of the app isn't to encourage healthy living, it's "growth and engagement" where advertisers can pay to get people to go to certain places and most likely buy their location data as well - in this case the relationship is adversarial and there's no bulletproof solution, it will always be a game of cat & mouse. The proper solution is to just find a better business model where incentives are aligned.
- MaxLeiter 5y agoNiantic tried to implement anti-cheat measures around Pokemon Go. They hashed a lot of data available to the client and the phone. With some math/ML it's easy to do outlier detection and find the hacked/spoofed clients based on their GPS/gyroscope/accelerator/... data. It took ~4 days for the community (some bot devs, mostly map / tool developers) to figure it out, although the scene has never been the same since.
- Jabbles 5y agoAre "walking for money" apps just scams? If not on the user, then on the advertisers who fund it?
- anticristi 5y agoI demonstrated browser automation to the sales/marketing team. The world is simply not ready to know.
- Traster 5y ago>No money has been stolen using this method, as every attempts to cashout has been denied by human verification. This makes it sound a lot like the only reason you didn't exploit this for profit is because you tried and failed.