Article may be outdated

This article is 15 days old. Some details may have changed since publication.

Hacker News·5 min read·hard

Remotely Unlocking Electric Scooters

H
henriemategui
Remotely Unlocking Electric Scooters
AI Summary

A security researcher details their process for identifying vulnerabilities in an electric scooter company's backend infrastructure. By enumerating subdomains and analyzing JavaScript bundles, the researcher discovered exposed API endpoints and administrative panels.

Why it matters

This highlights the security risks associated with rapidly deployed IoT fleets and the importance of securing backend APIs.

Dive DeeperCreate a free account to unlock

Note: to protect the company, I swapped out anything that could point back to it for fake examples. The domain electricscootercompany.com.br , the app package, and the user details (slug, name, and email) are all made up. None of it matches the real company.

It started with a news article. A company had just dropped a bunch of electric scooters in my city. Most people saw a new way to get around town. I saw a fleet of internet-connected devices running on a backend nobody had poked at yet.

First I needed two things: which company this was, and how the service worked for a normal user. The name was right there in the article, and a quick Google got me to their site, which laid out the flow:

That's the happy path for any user. I wanted to see what was going on behind it.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologystartups

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in