Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This was (is?) also possible with Lyft. When I was interning in the US, my visa sponsor sent me a SIM card that they clearly reused several times a year. Opening the Lyft app with this SIM automatically logged me in to the attached account. I didn’t noticed this and took a 70$ trip from SF to SV. Next morning I realized it wasn’t my account and credit card details. Wrote to Lyft support but never heard back. It wasn’t even possible to log out of this account and create a new one.


Lyft probably decided it was cheaper to eat the $70 than admit this attack vector exists.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: