February 26, 2014 at 7:26 a.m.

Washington Mall touchscreens hacked

IT guru proves point of ‘rampant lack of precautions in Bermuda’
Washington Mall touchscreens hacked
Washington Mall touchscreens hacked

By Sarah [email protected] | Comments: 0 | Leave a comment

Multimedia designer Karriem Sharrieff hacked into the public touchscreens at Washington Mall to help highlight what he has labelled a gross lack of digital security on the island.

He simply walked up to the touchscreen and used its available features to circumvent the mall directory application and uploaded his Twitter profile page. He pointed out that he could have chosen to upload any digital material he wished to and could also have disabled the software completely.

After the stunt, Mr Sharrieff reached out to the Washington Mall staff and informed them that their kiosks were susceptible to attack. The machines were reset, but not modified, so he performed the same exploit the following day on multiple kiosks simultaneously. On day three the operators responded, informing Mr Sharrieff that they had addressed the issue.

Mr Sharrieff, owner of Exist Media and co-founder of social media group Bermemes, told the Bermuda Sun: “I essentially used the system’s onboard capabilities against itself. Once the dedicated kiosk app was circumvented, it granted me full administrative access to the machine. 

“With that being the case, I could have controlled any component of the machine. I noticed that the system was set up for remote administration, but chose not to disable that software so that the owners were still able to utilize it. I could have locked them out of their own system and hijacked it completely for whatever purposes I saw fit. 

“I have been in Information Technology for over a decade and have always been fascinated with the rampant lack of precautions taken in Bermuda regarding digital security. It is one of the most digitally insecure and unregulated locales that I have ever been exposed to. I hacked the machine in order to raise public awareness about how simple it is to have your data and devices compromised in lieu of proper security.”

Bermudian law does not cover the particular style of breech that was employed due to its nondestructive and non-malicious nature.

When contacted, a Washington Mall spokesman said he wished to make no comment on the issue.

Mr Sharrieff added: “The operators of those kiosks are now afforded the benefit of having one less security hole to worry about. If this were elsewhere in the world I may have been offered a job or reward on the spot for pointing out the flaw, but I’m not exactly holding my breath for that.” 


Comments:

You must login to comment.

The Bermuda Sun bids farewell...

JUL 30, 2014: It marked the end of an era as our printers and collators produced the very last edition of the Bermuda Sun.

Events

October

SU
MO
TU
WE
TH
FR
SA
29
30
1
2
3
4
5
6
7
8
9
10
11
12
27
28
29
30
31
1
2
SUN
MON
TUE
WED
THU
FRI
SAT
SUN MON TUE WED THU FRI SAT
29 30 1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31 1 2

To Submit an Event Sign in first

Today's Events

No calendar events have been scheduled for today.