• technocrit@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    2
    ·
    16 hours ago

    “The API has zero authorisations checks on cancelling other people’s reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you’ve moved from #4 to #3 already,” it messaged back.

    Is this a “hack” or just a completely insecure API?

    I’ll you one thing for certain: It’s not “AI”. Doesn’t exist.

    • luciferofastora@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      35 minutes ago

      It’s exploiting a vulnerability (unsecured API) without permission of the gym running the software, to the detriment of whoever arrives and finds their reservation cancelled and probably also of the gym who now (unjustly) has to deal with the (justly) upset customer.

      The gym’s software should be secured better, but that doesn’t make it less of a hack.

    • mal3oon@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      10 hours ago

      I think for non-tech users, this is definitely a hack. It’s like script kiddies level damage, except using AI.