Privacy professionals
fromTheregister
1 day agoSticky-note security turned gym into hall of '80s horrors
Leaving default security credentials exposed can lead to unauthorized access and potential security risks.
A closer look at the Android app and Bluetooth traffic showed that locking, unlocking, and basic status checks all occur locally over Bluetooth, with the cloud mostly along for the ride. Before accepting commands, the scooter runs a simple authentication check: it sends a short challenge, the app replies with a cryptographic response, and access is granted. It's designed to stop random passers-by from hopping on and riding off. In theory, at least.