Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It looks like someone has figured out how to empty the card, in 2 minutes: https://twitter.com/#!/jonathanscard/status/1003474991889776...


I heard that! Looks like Jonathan's social experiment is clashing w/ eBay's "people are good" philosophy... either that or there are a LOT of thirsty people all at the same time.

Regardless, I'm glad we tried it; anyone have any theories of how it's being hacked?


I guess a way of doing it is to brute force the 8 digit CSC on the website and then transfer funds away from the card.


I hope Starbucks has some mechanism to prevent brute-forcing like this.


I think someone could have bought a SBux card with it. Looks like it has happened at least a few times now all within less than a minute or two of the balance being there. An employee or someone camping a store, perhaps... Is it possible to use the number to buy a card off their website online?


I'll be willing to put another $100 on the card on behalf of @Socialize's SDK Speed Challenge ( http://go.GetSocialize.com/SDK-Challenge) if someone can come up with a way to track who's hacking it. Any ideas?


I wonder what data you could get from reading the actual barcode? Would the CSC be in there?

Edit: I just checked with an online barcode reader and this isnt the case. It resolves to 6061006913522430


How is this post not spam?


is there a way to figure out what store the purchases are coming from?


Someone is DEFINITELY messing with it -- nobody buys exactly $45 in Starbucks: http://twitter.com/#!/jonathanscard/status/10035604975584460...


you never know -- multiple purchases could've added up to $45.00 exactly I guess


I'm inclined to go with Occam's Razor on this one and I am usually Devil's Advocate arguing that highly improbably events don't by themselves prove "guilt". However, multiple such? Even I think this looks very suspicious (and have become somewhat appalled at the amount of money people are willing to throw away to test if this has been hacked or not).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: