episode.ascii — live render
● episode

Hotline Hacked Vol. 10

TL;DRHotline Hacked Vol. 10 features listener calls: a hardware designer pranked his boss Bob with an Arduino that toggled caps lock, causing Bob to buy a MacBook Pro; a college group crashed campus internet trying to Google-bomb a friend's…

Double Digits! Featuring caller stories of sarcastic keyboard pranks, failed SEO birthday gifts, vending machine hijinks and more.

Transcript

Machine-generated transcript; may contain errors.

Speaker 1: Thank you for calling Hotline Hacked. Share your strange tale of technology, true hack, or computer confession. After the beep.

Speaker 2: Hi, guys. I love the show. Even though I'm not a programmer or a hacker, I'm a hardware designer that occasionally do some low level c in Python. I also love a good prank. One day I saw a Reddit post about a guy creating a sarcasm keyboard. Basically, a device that took the input from the keyboard and toggled shift for every character. I thought it was the coolest thing ever. I just had to make one. Then I realized that this could also be a fantastic prank and my target would be Bob, my boss. I couldn't modify his keyboard or plug something between the keyboard and the computer because of it being wireless. So I went to our box of development boards and found an Arduino Micro. This device features a microcontroller that has native USB that can act like a HID device. I programmed it to delay for five minutes when it powers up so that he could log in as usual. And then when he's in the zone to bash out his passive aggressive emails, caps lock would start toggling every one hundred milliseconds, shooting random caps into his text. I tested the device a couple of times and after Bob left for the day, I plugged the device into his docking station and hid it out of his sight. The next morning, I came to the office a little bit early to make sure I would be there before Bob. He came in, sat down and started his morning routine, but he didn't show up at the coffee machine as usual at nine like we normally do. I went to his office with my coffee in my hand like that character Bill Lumbergh in Office Space and went, hi Bob, what's happening? He said, I have an issue. I've tried several keyboards but the caps lock is going crazy. I've googled it and everything points to faulty laptop. So I just ordered a MacBook Pro. I've thought about switching for a while and I've been putting it off too long. I wish I didn't but I had to tell him about the prank. His only response was, you fucking nerd. He did have laugh though and thought it was the funniest and most cunning prank he'd ever witnessed. I still remain employed to this day and Bob is very happy with his MacBook. Thanks for listening. Have an awesome day.

Speaker 3: You nerd. You fucking nerd.

Speaker 4: Welcome to Hotline Hacked. It's the call in show where you

Speaker 5: can share your strange tale of technology,

Speaker 4: true hack, or computer confession. If you wanna share your technology, true hack, or computer confession. If you wanna share

Speaker 5: your story, go to

Speaker 4: hotlinehacked.com. And, you should know, Hotline Hacked is brought to you by Push Security. They help companies stop identity attacks before they happen, and they do it all right where it starts in the browser. You're gonna hear more about it later in the episode.

Speaker 3: I hear that phrase all the time from my wife.

Speaker 4: You fucking nerd.

Speaker 3: That that one lands for me because it's personal. The, You felt that one a little deeper than

Speaker 5: Yeah.

Speaker 3: A little deeper. I I love that this guy just stumbled on and made himself a USB rubber ducky. Like, he's just like, wouldn't it be cool if I created a USB hardware device that, like, just injected keystrokes? And it's like, yeah. That's that's a thing.

Speaker 4: Yeah. So I found the thing that he's talking about, which is a a little box that someone named Ben s developed, and it just it's the exact same thing that you built. It uses a Raspberry Pi Pico, but it's the exact same basic idea. Just sits in between a keyboard and the computer and randomly, caps locks to get the so there's a thing called irony punctuation, which is an idea of, like, there could be a character to denote sarcasm or irony in text on the Internet, which is notoriously hard to do. There's even a rule about this. It's called Poe's Law, which just talks about, the the the difficulty of parsing sarcasm when it comes to extreme views on the Internet when intent is so difficult to parse. Probably the most successful version of this, of trying to denote sarcasm, didn't come from any, like, intentionally designed symbol. It came from a meme, I think, of, Spongebob Squarepants. Most people would be familiar with this. And it's just the idea that if you're yelling sarcastically or loudly, just make the the the characters go up caps lock, not caps lock, caps lock, not caps lock. And that for some reason seems to just read as mockery.

Speaker 3: I think I need to implement that rule in my personal life because I troll quite a bit in group chats, and I think a lot of people take face value. Yeah. So especially with all the political stuff going on in Canada, I have some very opinionated friends, and it's fun just to devil's advocate troll them. And I think they might think I'm a terrible person now.

Speaker 4: Yeah. I I maybe on that one would definitely crack open the, irony punctuation so no one gets confused. It is useful. It's a pretty useful way to tell someone, yeah, the mocking Spongebob meme. That's what I was looking for. It comes from the episode Little Yellow Book. And it is. It's an image of him acting like a chicken, and he looks very, very silly. And it's a great way to to make maybe, I guess, your boss Bob feel like he's a little bit silly at work.

Speaker 3: I I love that he poor Bob got pranked, but then out of it came his

Speaker 5: Yeah.

Speaker 3: Love affair with MacBook Pros and, you know, the Apple OS system, macOS system. The one thing that I did like about this technically is that because he was using a wireless keyboard, he couldn't put something in the USB line. Like, he couldn't put an interface between the keyboard itself. So what he actually did was added a second keyboard, So he couldn't hold shift, like, he couldn't send a shift a or a shift s command in. So he just would throw caps locks and on and off randomly to get the same output. The, I don't know. A little bit of, like, a hack to get around the fact that he wasn't on a cabled keyboard. But, yeah, custom built himself an Arduino micro USB rubber ducky. And fun thing, fun prank, he's still gainfully employed, and I understand why. Like, if if I employed somebody who's, like, use their fun spare time to do things like this, I'd be like, yeah. Cool. You're, like, technically competent and capable. Good prank.

Speaker 4: Also gave the boss an excuse to get a new MacBook Pro. There's shades of that there.

Speaker 6: Totally.

Speaker 4: Where it's like, well, maybe you played a little prank on me. Maybe I rushed out the door to buy a new MacBook Pro a little bit quicker than I might have otherwise due to our company's acquisitions policy, or like new gear policy. So maybe we all just, pretend like this didn't happen.

Speaker 3: I'm, this is a total tangent, but I feel like I'm good for those on the show is, I have my old MacBook Pro sitting beside me. Oh. And I am installing Linux on it because it is a last generation Intel MacBook Pro, which is the worst of all of the generations of MacBook Pro, as you know, because you had one too.

Speaker 4: I recall that was like a sweet spot where that computer that had just rocked for a decade and has rocked for, like, five years since just very briefly sucked.

Speaker 3: Yeah. Yeah. Like, I it's, essentially a $6,000 paperweight at this point. So I am trying to breathe some life back into it by turning it into, like, a UNIX, laptop that I'm gonna use for programming and stuff. But the one thing I will say is more tangents is more annoying than I thought it would be because the teaching of MacBook Pros need custom Linux kernels to let the keyboard, mouse, Bluetooth, and Wi Fi work, which are most of the things you need on a functioning computer.

Speaker 4: You use mice on keyboards, bro? That Fucking nerd.

Speaker 5: So the

Speaker 3: worst thing is is, like, I have some some, like, mechanical keyboards and stuff, but I don't have, like, mice and keyboards sitting around because I have to use, like, hard lined external devices to do this. And it's just been more of a headache than I anticipated. So I spent wasted more time last night doing that exact thing than I would have liked to have.

Speaker 4: So here's here's my question. Hit me. When you install macOS on what is traditionally a Linux or Windows PC, it's called a Hackintosh. Mhmm. It's getting tougher to do, but that we have a whole name for that. There's a whole culture behind it. Is there a name for installing Linux on a busted old Mac?

Speaker 3: Not that I know of. Could you be at the moment where you get to name something? You might be

Speaker 4: trying to think. Like, what's a what's a good punny name? Because Hackintosh, great, self self explanatory. You're hacking together a Macintosh. What would Linux?

Speaker 3: I don't think there is a commonly used and associated name with this. So name away, Jordan. You've created this naming incident in in the world, Posintosh, like putting POSIX, like a Unix operating system on a Macintosh. Is POSIX a a Linux? Mac MacInix. MacInix.

Speaker 4: I wanted to have the fraud hack element to it. We're gonna come back to this later. I'm gonna stew on this a little bit maybe during some of the sub subsequent calls.

Speaker 5: K.

Speaker 4: Yeah. Yeah. Figure this out.

Speaker 3: You can drill this with your favorite AI chatbot to come up with a catchy name, and we'll get back to that later.

Speaker 4: I want this to be human. I want this to be from my mind.

Speaker 3: Don't you know that Grok and ChatGPT and Cloud are just extensions of your mind at this point?

Speaker 4: What am I if not merely a vehicle that types things into Claude?

Speaker 3: Half of the YouTube viewers actually think we're just AIs chatting about things. So

Speaker 4: I sometimes I wonder the same question.

Speaker 3: Alright. Next story.

Speaker 4: Next story.

Speaker 7: This is Roe, and I've got two short stories that I'm hoping you can help me bring full circle. The first is about some sketchy web traffic, and the second is a physical infrastructure prank. So for the first one, I went to a really tiny college, and all of us knew each other pretty well, and most of us were pretty close. So when one of us was out of the country on her birthday, the idea was floated that we should try to Google her name so much that it showed up as one of Google's top results for that day as a little unconventional birthday gift. So we set to work manually searching, just like grandma used to do since none of us knew how to write any code at that point or script. So after a few hours of going after this, we lost Internet to the entire campus. Our ISP shut it down because they thought we were up to something, and they were kinda right. So that that shut down class for the afternoon on that day. So I am sorry, Caroline, that we did not get your name as one of the Google's top results, but maybe I just got you on a podcast. Happy birthday.

Speaker 3: Happy birthday, Caroline.

Speaker 4: Happy birthday, Caroline. I wanna know, when did you go to university that it was possible to get someone's name to the top of Google search rankings?

Speaker 3: That's exactly what I was doing there. I was like, the amount of times you would need to Google something to compensate for the 7,000,000,000 people in the world constantly Googling.

Speaker 4: Like, I went to university in the eighteen hundreds, surprisingly, during which Google was available briefly.

Speaker 3: Like, you would you would need, like, a botnet that wasn't doing, like, any kind of DDoS ing or anything, but the botnet was just flooding Google's algorithm with Caroline.

Speaker 4: Or Caroline's last name is so iconic, so singular

Speaker 5: Yes.

Speaker 4: That it somehow that what like, a dozen people googling something a bunch during the day was gonna I have follow-up questions, but let's continue. The, the second one came when

Speaker 7: I was working as a telecom designer at an engineering firm. We had these big l shaped desks that were stand up, sit down desks with some memories, and they were pretty cool. There was a little controller. And as I was cleaning my desk one day, I realized that these have r j 45 jacks on them, which intrigued me. I knew it wouldn't be Ethernet, but it wasn't clear at all what the protocols were. I did some digging online and found next to nothing on whether it was just simple voltage. Was there some kind of signal? No idea. And I didn't even have a multimeter that day, like, no equipment to even take a guess.

Speaker 3: I just need to jump in here because I have one of these desks and it has r j 40 fives on it. And there are massive stickers around it being like, this is not a network connection. And I'm sure I'm sure it's bad to plug things into this that you shouldn't.

Speaker 4: So So r g 45 I I'm not gonna couch it for anyone that doesn't know. I don't know. I'm googling it. That looks like a phone jack or like a cable

Speaker 3: jack or something. It's a an Ethernet jack.

Speaker 8: Oh, okay. Got it. Got it.

Speaker 3: Got it. So phone jacks were r j twelves 12, I think. Yeah. Digging through memory. And then Understood. Ethernet, cat five e, cat five, cat six, cat seven are all r j 45 size jacks. Copper cable, ability to transmit voltage. Let's see where the story goes.

Speaker 7: Yeah. So I felt a little defeated at first, but then I realized if I unhooked everything from the switch and we just went with the passive stuff, it might work. I wasn't sure about cables and all of that, but we were gonna try it. So I got the, got the key from Anthony in IT. Shout out, Anthony. You rule. And Lot of

Speaker 3: shout outs in this, guys.

Speaker 5: Lot of shout outs. I appreciate it.

Speaker 7: Anthony. Big ups. Patched my controller through our telecom infrastructure in the building to my neighbor's desk and hit it, and it worked. So it worked just as well as if it was plugged right in. I was afraid of voltage drop, but no factor. So we now had a working zero day and needed a worthy target. So, naturally, we picked the intern in a different department who worked on the opposite end of the building. And he was a mutual friend, so this was we picked you because we love you. Love you, Cherian.

Speaker 3: There we go. One more.

Speaker 4: I really feel like I feel like Cherian? Cherian, I feel like this dude, and I appreciate this a lot, is gonna share this episode now with a couple of different people. Call that free marketing.

Speaker 7: So when he was away, I fixed the original patch and patched it into his desk. And since he was so far away, I couldn't actually see him from my desk. So we had a third party act as a relay partly because it was funnier and partly because it would help obfuscate what we were up to. So we're just using hand signals. At first, we would do little bumps up and down just to see how he would react. And it scared him at first, of course, when your whole desk goes up. Before long, we just went for the sky fully straight up all the way, and stuff has fallen off his desk and cables are straining. And, he took it like a champ. He was really cool about it. So we naturally bust out in laughter, and the jig was up. So we helped him clean up his desk and make it all right and explain what we had just done and how it worked. So the part where I'm hoping you can help me bring this full circle is I recently included this story in a cover letter for a job application. So if you run a pen testing firm and this story sounds familiar, I would very, very much like to hear from you.

Speaker 9: Oh, ho ho.

Speaker 7: We'll talk. Thank you, guys.

Speaker 3: Keep up

Speaker 7: the great work. Thanks, guys. See you.

Speaker 3: Man, this guy really, like, saw the hotline hacked opportunity as a marketing platform.

Speaker 4: I have some messages to get out. My dear friend, Caroline, happy birthday. New intern at old company. Gotta reveal some stuff. And if you are looking to hire, I am your man.

Speaker 3: He's working with the way he's got. The, Our podcast. Calling jacking your, stand up desk controller into somebody else's stand up desk's receiver. An Ode might be a stretch. The, the other thing I wanna say

Speaker 4: done it before.

Speaker 3: That's true. I never even

Speaker 4: It might it might reach the technical definition of it.

Speaker 5: I don't know if you're gonna be reading

Speaker 4: about it in the news, but

Speaker 3: Shows creative thinking.

Speaker 4: It sure does.

Speaker 3: Give them that.

Speaker 5: The the

Speaker 3: one thing I will say is, like, after last episode where, like, somebody brought receipts, it's like I feel like you could've strengthened this with receipts. Like, I want video footage of this guy's desk going crazy and him losing it. Like that's Yeah. Like, let's raise the bar here on hotline hack. Let's push it up a notch. Like, if you're gonna do a crazy prank like this

Speaker 4: of your crimes. I we want proof.

Speaker 3: Like hand signals, schman signals. It's like I want three angles of video. I wanna be able to see this person losing it.

Speaker 4: I want that TikTok. Okay. So the the standing desks have these r j 45 jacks with with which are just like Ethernet ports essentially. And he figures out, is it as simple as just the output on one sent into the input on the other? It's just that now I'm controlling your desk kind of thing.

Speaker 3: It it sounds like they set up he bypassed all the switching gear, which would have caused it to, like, look for real network, you know, protocols and things. And he just created a coupled line between his desk and the intern's desk. So just connecting Ethernet cables and then plug that into the the desk brain. So his controller talked to that desk's brain.

Speaker 4: Okay. And then starts toggling it up and down first.

Speaker 3: Yeah. Little little ticks.

Speaker 4: Little ticks here and there. You you kinda notice it moving subtly until he I I did really like this. Went for the sky, which I appreciate that the motors in these desks, I don't want someone producing one of these desks with a motor that could literally send it to the sky. But when he said that, I did picture like a desk, an l desk shaped hole in the ceiling with, like, a startled guy standing behind it as birds fly overhead like a shot off the top kind of thing, which Ferry didn't do that.

Speaker 3: But the one thing I will say is being the the owner of one of these desks and the user of one of these desks Mhmm. Is I I have a cable nightmare because I have one, two, three, four, five monitors, multiple audio interfaces, two computers. Like, my desk is chaos. Mhmm. And I never take it full stand, like, all the way up because I just know, like, the amount of power bars mounted to the bottom of my desk. Like, this thing is is a is a house of cards of cables. And if I put it straight to the sky, I'm sure it would like ripping power bars off the bottom, disconnecting, like, my, like, light controllers. Sure. And it would just be nuts out. Like, at least they helped him put his desk back together because I'd be pissed about that.

Speaker 4: One of these days, I have a sense of your setup, and I feel like one of these days I'm gonna have to, like, call in, one of those big avalanche dogs to come rescue

Speaker 3: Yeah. He's penguin Tash. There we go. Nice. Yeah.

Speaker 4: I found it. Took me a minute.

Speaker 3: Penguin Tosh will be the, the third, computer on this desk.

Speaker 4: Yeah. And then I just wanna briefly go back. I was curious. So there might be some ambiguity here about what the caller meant in their first call regarding Caroline's birthday and name on Google.

Speaker 3: True. True. Multiple stories here. Can't forget them all.

Speaker 4: There's there's multiple stories. I appreciate it. I like the density.

Speaker 3: I will say I just wanna jump in and interrupt you rudely and

Speaker 4: say Sure. Painlessly.

Speaker 3: Let's not turn hotline hacked and the fact that we often don't listen to these stories before we record into a way to market things because that will make us have to listen to them all in advance.

Speaker 4: Yeah. There's something we try and listen to the first chunk of the call to get a sense of whether it's a good fit and how it's gonna flow, but not to listen to the entire thing because the element of surprise often contributes to the vibes. May maybe don't. I appreciate that there was no and find me on LinkedIn at the end of that. It was subtle, but walking the razor's edge. As a small business, you should plan to spend at least 10,000 a month on Google Ads in most cases, but a 10 x that ad spend up to 10 k is what you'd need to really move need to move the needle on short term search engine rankings. So bad news about Googling a name a bunch, you're about 5 figures short on the ad spend of getting that to rank, but I appreciate the spirit of it. And it is making me want a stand up desk. I'm in this tricky spot where I have a a desk I love very, very much. It's like a it's a little bit precious to me. It was made with a family member, but the legs are structural to it. It's like the leg is the point. It's like a cool found object desk. So if I, I, I'm kind of just stuck, stuck sitting, unfortunately,

Speaker 3: stuck with sentimentality,

Speaker 4: stuck with sentimentality,

Speaker 3: burdened by sentimentality. Once again,

Speaker 4: by a deep emotional attachment

Speaker 5: to

Speaker 4: a piece of furniture made by a loved

Speaker 3: one. In another digression. Mhmm. A callback digression. What did you call it again? Penguin Tosh?

Speaker 4: Penguin Tosh.

Speaker 3: Yeah. So the Linux penguin has a name. Oh. And that name is Tux.

Speaker 4: Tux Toc.

Speaker 3: Which well, it brings me to Mac and Tux.

Speaker 4: Oh. See, we don't we don't need cloud.

Speaker 3: We don't need Gipity. No Gipity. No no Gipity here.

Speaker 4: No Gipity here.

Speaker 3: We got Mac and Tuxes.

Speaker 4: We got we got Mac and Tuxes. We got Tux Toches. Yeah. It's good. I like it. Meanwhile, there's an LLM kicking up 30,000 better options per minute. Anyway, before we keep it going, why don't we just tell everybody about who this who this show is brought to them by? Yeah. Well, hacked podcast

Speaker 3: Mhmm. Brought to them by push security. You know, one of the fun things about hosting this podcast, Jordan, other than weird stories and subtle marketing promotions that come in as stories, we get to see a lot of tools, companies, meet a lot of people, get to know the community really well. And, I mean, we talk to a lot of them off the air, and some of them are really cool ideas and other ones are solutions just looking for problems.

Speaker 4: And then something comes along and we just have that moment of like, well, gosh darn it. Why didn't we think of that, Scott?

Speaker 3: Like, gosh darn it.

Speaker 4: It's really obvious in hindsight. Someone was gonna build it.

Speaker 3: Yeah. And Push Security built it. Like, identity, attacks, phishing, credential stuffing, account hijack or session hijacking, account takeovers, massive causes of the breaches right now. And their approach, you know, it's super interesting, and I totally had that moment. Like, to their CEO's face was like, shit. Why didn't I think

Speaker 5: it happened?

Speaker 3: You said shit. Rude. It was I I

Speaker 4: mean, we had just met him, but it worked. It worked out in the end. There's they're they're presenting sponsored They're presenting sponsored

Speaker 3: presenting on that dashboard.

Speaker 4: Yeah. What else can you ask for? Instead of trying to lock down everything at the infrastructure level, they start where people actually work, which is in the browser. It's where we're talking right now. They built a browser extension that observes corporate identities created by employees and logs into their work apps, which when you think about it, makes a heap of sense.

Speaker 3: Yeah. Because they've got visibility from the browser into all the SaaS applications, seeing how they exactly the identities are being used. Are credentials being stolen? Are they reusing passwords? Are have people figured out ways to get around multifactor authentication? Are they using local accounts when they should be using the single sign on identity provision accounts?

Speaker 4: And the kicker, if they do find those vulnerabilities, they can automatically enforce controls to fix them all right there, all right in the browser.

Speaker 3: But it's not just about protecting identities. Push is monitoring them too in real time for attacks using adversary in the middle toolkits, cloned login pages, stolen credentials, stolen session tokens, phish kits, all kinds of things. All these attack trajectories and attack surfaces that expose themselves in the browser, Push is there monitoring them.

Speaker 4: It's like endpoint detection response, but all right in the browser. Very, very cool stuff.

Speaker 3: And as you might have heard in the last episode

Speaker 5: Mhmm.

Speaker 3: Adam, CEO came on. The team is super sharp, killer researchers, big in the red team world. They recently put up this thing on cross IDP impersonation where attackers bypass multifactor authentication and single sign on by just registering their own identity provider.

Speaker 4: It's really cool stuff. You guys can demo it. Check it out. Push Security. It's a super smart approach. It's a really solid team. It's very interesting research. Check them out at pushsecurity.com.

Speaker 3: That's pushsecurity.com.

Speaker 6: Hey. How's it going, guys? Did not listen to your show for a while now. Just listen to the first part of your most recent of online, Jack. About that guy who's at a college and he was tapping his credit card on doors, to see if he could get get in for fun.

Speaker 3: Yeah. The building buyer. Yeah.

Speaker 4: The guy buying buildings by tapping his credit card on the, security. Yep.

Speaker 3: Mhmm. Remember remember the episode. Remember the story.

Speaker 6: I'm actually a security specialist, so he's, in my wheelhouse. Well, I'll tell you whoever for, more too many details about exactly what I'd use. But I give you a little bit of insight of what probably was going on there. Most likely, probably that electronic hardware on that door had failed for whatever reason. I don't know what type of electronic hardware is on that door, but it was probably unlocked essentially. But in software, on their access control system, it talks probably on the schedule. And when he opened the door, a door position sensor back ended contact, showed that it was forced open, which triggered an alert to their security team, in this sense by he was allegedly surrounded by cops or security security guards, which is which is good. It means that that that I team actively monitor their system, which I always tell my customers and and actually, they also know these good as your as your human response. You can have the most advanced system out there in the world, but if nobody's actually monitoring it, it's it's a slipper. However, there is some creative tapping random credentials at cards. There are some systems out there that, I would say are particularly great systems, that if they fall off network, they don't actually store any in it or not very many, credentials locally on the door controller. So they have the ability to failover so that if any credential that the system can read, I e card format, so it would have to be a, at least a card that the system's designed to be open for you would open the door. Sounds absolutely ridiculous. I I I think it is ridiculous. It is a feature that exists out there.

Speaker 3: This does sound ridiculous that thank you for calling in. Thank you for giving us a best take of what probably happened. Funny enough, I've been installing a new access control system in our office, and I'm oddly more familiar with this stuff than I was two weeks ago. The fact that a system will, in a fail state, just allow any kind of RFID handshake to open the door seems like the worst physical access security policy you could have.

Speaker 4: For a security device. I can think of certain pieces of hardware where storing certain pieces of information on the hardware, it's kind of trivial. There's microphones, USB microphones that will store certain sound profiles on the device, others that require a secondary piece of software to do it. It costs a $50 difference. It's a little nice to have you plug your mic in your friend's computer and you get the profile. Letting me get into a building I shouldn't has slightly higher stakes and I'm not sure that you should be selling that first version of that product.

Speaker 3: The one thing that I've been finding interesting, and here I'm gonna go on another tangent and digression here is, like, electronic locks that these access control systems control all run on, like, 12 volt DC, like very, like, minimal amounts of power. It's nothing crazy. And lots of these locks, if you can sever that power connection open. So it's like I could see Jordan's face right now. You won't be able to, but it's really good.

Speaker 4: It should be everyone's listening. Like, there's a lock.

Speaker 5: If you

Speaker 4: can cut the power, you break in. I'm like, that's the easiest heist movie ever. Like, just cut the power to the building and then walk

Speaker 3: in. There's some that fail safe and some that fail secure so you can set them because the other problem is is, like, if they don't open in case of emergencies, like, clearing the building will be very impossible because a lot of them have electronic relays to reopen them from the inside. So, like, if you're in a secured facility, you have to push a button for the door to open to get out. So then you have to set fail safe, fail secure, and it becomes, like, this interesting thing. But, like, even aside from cutting the power to the building, like like, you know, those big magnet locks that you see on, like, glass doors? Like, they only stay locked because they're getting a constant feed of 12 volt power. And if you just interrupt that power relay, those doors just wide open.

Speaker 4: Yeah. Sure. I guess it depends on the type of building if you want to fail secure versus fail open. I definitely appreciate like there's enough horror stories of weird stuff happening where a building was burning and a door got locked and a bunch of people die in a supermarket in South America. It's like those stories suck. That shouldn't you don't want to design a system that works that way. I'm surprised there isn't sort of like a healthy intermediary where it's like, the door just has like a fail close in one direction, where it's like, there's a there's a door handle that will open it even if there's no power and there's another door handle that won't open it if there's no power and you just put one of those facing outside of the building. There could still be vulnerabilities where a person could get a thing through now and maybe open it up like coat hanger style. But I would still take that over the alternative of we must either entomb them or open the doors to everybody.

Speaker 3: Well, the the beauty is is that the best the best cross for that is is like we I can we have a power lock, like a power strike on our new on our office door, and it is fail secure, I think, is the right one. So that with the power goes out, it stays locked. But then on the inside of that door, there's one of those push rails that physically opens the tumbler. Yeah. Opens the door. So you can still get out in in an emergency, but the lock stays safe if it's like the middle of the night, somebody cuts the power to the building and tries to break in. But anyway, I just find it I found this fascinating just because I've recently gone down this rabbit hole of, like, looking at these access systems. And it's like you have these really comp plex identity control verification encrypted back ends for the access systems. And then the lock is literally like the red and the black power cables. It's like there's none. There's no cryptid Yeah. There's no there's no brain in the lock. Yeah. But the lock is controlled by a brain, and it's like all you have to do is kind of, like, get in between that and boom it it opens.

Speaker 4: Starting something new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button that's used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts sort of getting abandoned in the parking lot and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.

Speaker 9: Study And play. Come together on a Windows 11 PC. And for a limited time, college students get The best

Speaker 3: of both worlds.

Speaker 9: Get the Unreal College Seal, everything you need to study and play with select Windows 11 PCs. Eligible students get a year of Microsoft three sixty five premium and a year of Xbox Game Pass Ultimate with a custom color Xbox wireless controller. Learn more at windows.com/studentoffer. While supplies last, ends June 30, terms at a k a dot m s slash college p c.

Speaker 10: When you need to build up your team to handle the growing chaos at work, use Indeed sponsored jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications, and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit at indeed.com/podcast. That's indeed.com/podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed sponsored jobs.

Speaker 11: Sierra has all the best active and outdoor brands you need. From athletic stuff, like a full court pickup game, swish, to athletic stuff, like a half mile stroll. Get those steps in. And for morning hikes up the mountain trail, good pace to nighttime ghost stories from the camping chair. What a twist. Whatever level of active, Sierra loves it all. Head to Sierra or sierra.com for the brands you want at the prices that let you do it all. From athletic to athletic ish, Sierra's got it.

Speaker 12: Hey there. My name is Wolf. I really like your podcast and the idea of the hacked hotline series, so I thought I would share a story of mine. It's not overly technical or crazy, but I think it fits. About five years ago, I was working as an aircraft mechanic at an airport. The company had vending machines that were supplied by a vendor. Each of us had a small blue key fob that we could use to pay at these vending machines. To add money to the key fob, we would hold it against the reader on the machine and insert coins. I had always wanted to work in IT and had a hacker mindset. I loved breaking things to understand how they worked behind the scenes. One cold winter morning, I stood in front of a vending machine to buy a coffee. Then a thought crossed my mind, what would happen if I removed the key fob at just the right moment while adding money to it. I decided to try it. I held the key fob against the reader, inserted a coin, waited one second, and removed it. Nothing happened. I tried again but waited a bit longer. Normally, when the charging process is successful, there is a distinct beep sound, and a small LED lights up green. This time, however, the beep was distorted, and the LED lit up yellow instead of green. I checked the balance displayed on the vending machine, it showed the amount of the coin I had inserted. Then, to make sure I wasn't imagining things, I checked the balance on my key fob at a different vending machine. To my surprise, the money had been added to my key fob as well. Curious, I pressed the return button on the vending machine, and it spit out the coin I had inserted. I had effectively duplicated the coin's value. Since the highest value coin in my country is worth 5, I realized I could easily generate a lot of money by repeating the process. I tested it a few more times to confirm that it worked. But I didn't want to get into trouble or exploit the bug. Instead, I went straight to security and reported my discovery. The security officer looked baffled and unsure of what to do. He asked me to show him what I had found, so I did. He told me he would investigate and that I might be contacted about it. He also instructed me not to tell anyone other than security. A week passed, and then one day, the security officer approached my work area, this time accompanied by three men in suits. My mind started racing. Had I done something wrong? Was I about to lose my job? One of the men introduced himself and explained that they were from the vending machine vendor. They wanted to know more about the issue and asked me to demonstrate it. I explained everything and showed them how it worked. They took notes, asked questions, and thanked me before leaving. The whole thing felt like a crime scene investigation. The next day, nearly all vending machines in our hangars were shut down, with signs saying, out of service. This did not go over well. Mechanics are serious coffee addicts. Another week later, the same men in suits returned. They told me I had discovered a bug that affected nearly all of their machines and thanked me for reporting it instead of abusing it. Before they left, one of them handed me a small box. Inside was a red key fob with my name engraved on it. They explained that I could use this key fob to buy items from their vending machines, up to $5 per day, without ever needing to charge it. It acted like a special credit card for their machines, even at train stations where their vending machines only accepted coins or credit cards. This experience fueled my passion for IT. I started learning Python and JavaScript, staying up late to work on projects. One of those projects was a chatbot, which eventually became quite popular. I continued working as a mechanic for two more years, and not a single day passed without me using that red key fob. I was the king around my workmates and friends. Eventually, I decided to leave the company to pursue an apprenticeship in IT. One day, after making my decision, I ran into the IT help desk manager in the cafeteria. He knew my father, who worked at the company a few years ago, and struck up a conversation with me over lunch. I mentioned my plans to leave and my chatbot project. Then he asked, wait, aren't you the guy who found the vending machine bug? Yeah, that was me, I replied. He told me that the company was urgently looking for an IT apprentice and that, since I had already demonstrated an interest in IT and gained some knowledge, he would be happy to recommend me for the position. I eagerly agreed. After completing a few test days in the IT department, they offered me the apprenticeship on the spot. Now, I'm about halfway through my apprenticeship, and I love it. That's my story of how I transitioned into the IT sector. Hope you enjoyed it, and have a great day.

Speaker 3: I love it. Great story. I feel like the when they started, I was interested to hear where it went because it sounds like he figured out a way to lose his money. He was like, I'm putting coins in the machine, but I'm not getting

Speaker 4: Bingo.

Speaker 3: And I was like but then he's like, oh, I hit the refund button and the coin came back.

Speaker 4: Coin came back out. I was like, you found the opposite of an infinite money glitch. And then it partway through, I was like, no. There it is. It's an infinite money glitch. Got it. Got it. Got it.

Speaker 3: I have a sneaking suspicion that this person's from Japan.

Speaker 9: Mhmm.

Speaker 3: Because, the vending machine culture in Japan's outrageous. They're everywhere. And the fact that they're like, a lot of the indications that he said, like, the largest coin is $5. Like, 500 yen is the largest coin. And so I was like, okay. So this person's in Japan. There's vending machines everywhere, and he now has, like, the gold key to buy something at any vending machine in Japan, apparently, which is also probably why the company took it so, like, was so worried about it. It's not just the hangers of people, but there's probably, like, 50,000 of these vending machines across the country.

Speaker 4: Yeah. That's that's a really good take because my big question had to do with the apparent, like, squad of men in black type characters that show up because you got the best of a vending machine. I've without digging into too much detail, I've had family that worked in airlines. I have some very early memories of hanging out in, like, weird parts of airports when I was a little kid before the security was what it is today and having some very bad airport vending machine coffee. And I can tell you, there was a guy coming and picking up a bag of quarters every couple of weeks. There were no, like, suited people touching down from the private jet to come figure out who hacked the system.

Speaker 3: See. But then again That

Speaker 4: makes make more sense.

Speaker 3: More leading indicators that is Japan. Bunch of salary men,

Speaker 4: black shirts.

Speaker 3: Like, it's just it's it's it fits the vibe. I like it. The the I I'm I like the story. I like that they use it as a pivot, showed some some interest. I I thought it was gonna go in the darker way, like the, pharmacy credits where it's like, yeah. I figured out how to do this, and then it became my life just like stealing points.

Speaker 4: Right. Yeah. Sure. There's a there's a version of this where they get enraptured with it. They acknowledge the infinite money glitch they've discovered and their whole world just becomes juicing, you know, 500 yen at a time out of a out of a coffee machine. This is much more interesting. I am regularly on this show confronted with, like, pretty real questions about how I would behave morally in different situations. There's certain stories where I see the the kind of good path, and I know very confidently I would have taken that. There's other ones where I'm like, oh, maybe I just be free coffee baby for the rest of my life and just I'm the guy that knows how to get free coffee out of these things. I'm not so sure I would have done the right thing in this case.

Speaker 3: Well, in my if my hypothesis is correct, and this is Japan, it's not just coffee. Like, you can buy anything. Food. Yeah. Food, booze, like, you name it. Cool.

Speaker 4: I would love to have that culture here. The vending machine. And then I would love to be the god of the vending machines with the sacred key fob that opens all of them.

Speaker 3: Yeah. I do. And, like, the the honorary red key fob engraved with their name. Like, also Swaggy. Yeah. Totally swaggy. So so if if if you'd submitted this story, please drop us a note. I'd love to know if I'm correct that this is in Japan. But thank you for calling in. Great story. I'm hoping you're enjoying your IT days. If you're learning Python, Python's one of my favorite languages and also one of the languages that the AI bots are best at writing. So if you just need a bunch of it Python code written, talk to Jipity.

Speaker 4: Here's my question. With that magic red key fob, I'm I'm holding the the magic red key fob from this call in my mind. And the security expert that called in about the buying a building with a credit card call from previous Could you What could you buy with that fob? It's $5 a day, but, like, you go up to the the main headquarters of this vending machine consortium, starts tapping it on shit.

Speaker 3: Well, if the previous caller that had called in was right, you know, all you need is a malfunctioning access system, and you can buy whatever you want.

Speaker 4: That that's still pretty shocking to me, and does make certain, like, heist movies make sense. There there's often a, like, we gotta shut down the power time moment. It's a good there might be something to that. $5 a day. Yeah. Wow. Lots to unpack in this one.

Speaker 3: Well, here here's the thing, and this is just straight hypothetical. Like, we're just BSing at the end of the episode now.

Speaker 6: Sure.

Speaker 3: But, like, a lot of buildings, like, call them commercial towers. They're not like Oh,

Speaker 4: there's a third rail here where we're gonna the way I would prop a building, I guess,

Speaker 3: is what I'm saying. Well, Well, no. But you think about it, like, from a security perspective, it's like a lot of these controlled infrastructure pieces are inside of, like, large commercial buildings. And it's like cutting the power to a lock or bypassing the control unit directly sending the power into these locks would be really difficult for the outside of a building because the outside of a building is clad with stones and marble and all this stuff. But when you're inside of a The inside. Yeah. But if you're, like, on the 36th Floor of a corporate tower, and there's a half inch piece of drywall between you and the red and black cables, it takes an exacto knife and a battery, and you've bypassed, you know, a $100,000 access control system.

Speaker 4: Pretty.

Speaker 3: So it's like, how secure are we, Jordan?

Speaker 4: I have a friend. She she was in town. She was crash crashing with us, and she she's a a lawyer. And she she was asking about work, and she was asking about the podcast. And she had that kind of polite moment that people do where they're like and it's like a tech show. Right? Yeah. Totally. It's a tech technology show about, like, security and hacking. And she's like, oh, what do you mean hacking? We talked about it, and she's like, got it. So you're telling people how to do that stuff. I felt like the it felt like the restaurant went quiet in that moment. I was

Speaker 9: like, no. No. No. No. No. No.

Speaker 4: No. We're not telling people how to do this stuff. We're just talking about people who did it and then telling people how to do this

Speaker 3: stuff. I I don't agree with that. We never do that.

Speaker 4: No. We never do that. For liability's sake, we never tell anybody. For liability's sake, we never do that. That was me doing a gag. That's I just I love it. I love it so much. I I haven't done the, like, tapping my credit card on a building thing since we made jokes about it in the last episode, but I have, like, no word of a lie thought about it every single time I walk past a building where I can see the key fob thing up front, which is most buildings. I think about it all of the time now. So I was really excited to see that follow-up call. I like the follow-up call thing. I think we're gonna do more of that.

Speaker 5: Yeah.

Speaker 4: If you wanna share your strange tale of technology, your computer confession, your true hack, go on over to hotlandhacked.com. There's a phone number you can call. There's an email you can submit to. You can send us text. You can send us an AI voice. We just wanna hear from you.

Speaker 3: And if you would like your voice obfuscated

Speaker 5: Mhmm.

Speaker 3: Just let us know. Yep. Either send us in text and we'll use, an AI bot to convert it into audio, or if you send us in a phone call or any of those things, we will convert them into we can obfuscate them. No problems. This show, again, brought to you by Push Security, pushsecurity.com.

Speaker 4: They help companies stop identity attacks before they happen. They do it all right inside the browser. Reverend's already working anyway. If you wanna find out more, check them out at pushsecurity.com. I think that's another one in the bucket.

Speaker 3: I think so.

Speaker 4: I think so. Get at us with your story. We wanna hear it. And until until then, catch you in the next one.

Speaker 5: If you're a lineman in charge of keeping the lights on, Grainger understands that you go to great lengths and sometimes heights to ensure the power is always flowing, which is why you can count on Grainger for professional grade products and next day delivery so you have everything you need to get the job done. Call 1800, click grainger.com, or just stop by. Grainger, for the ones who get it done.

Speaker 13: Why is every drop of Two Hearted IPA put through a vigorous 100 quality control process in order to make its way out of the brewery? Because, fact, a vigorous 99 quality control process doesn't sound nearly as impressive. Two hearted IPA, never half hearted, Two hearted. Bell's Brewery, Comstock, Michigan. Please drink responsibly.

Speaker 8: Ryan Reynolds here for Mint Mobile. I don't know if you knew this, but anyone can get the same premium wireless for $15 a month plan that I've been enjoying. It's not just for celebrities. So do like I did and have one of your assistant's assistants switch you to Mint Mobile today. I'm told it's super easy to do at mintmobile.com/switch.

Speaker 14: Upfront front payment of $45 for three month plan, equivalent to $15 per month required. Intro rate first three months only, then full price plan options available. Taxes and fees extra. Fee full terms

Speaker 5: at mintmobile.com.