Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wouldn't be terribly surprised if you could create a barcode that caused a barcode reader to send <windows key>+r and run some arbitrary command. So perhaps it wasn't a vector for an ATM, but maybe some other barcode reader where workers scan in arbitrary things they are handed...TSA maybe?


As far as I remember that's roughly how that exploit against an ATM worked:

https://xlab.tencent.com/badbarcode/

Also, perhaps folks working in data centers can and confirm/deny, but from what I know it's usually strictly forbidden to bring any USB devices into a data center area.


We use USB drives as installers and, in some cases, as boot volumes. (And of course keyboards and mice on crash carts and USB serial ports for laptops.)

We’re not a cloud provider, but I’ve been in lots of DCs and seen plenty of USB devices.


I'd love to have a crash cart. I'd spend all day crashing it into other carts.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: