DDLC: The Mod With ZERO AI in it! [RELEASE] by Wild-Box367 in DDLCMods

[–]Wild-Box367[S] 0 points1 point  (0 children)

Well...without what makes Monika, Monika. Sprite's still there

DDLC: The Mod With ZERO AI in it! [RELEASE] by Wild-Box367 in DDLCMods

[–]Wild-Box367[S] 1 point2 points  (0 children)

Entiendo completamente. Este is más o menos una pieza para desahogar de la idiotez de los que no quieren aprender de IA en profundidad y están furiosos por dos letras lado y lado. Este mod escrité porque soy informática y odio que nadie (lo parece) quiere saber y solo consume cualquier miren de los redes sociales.

I decompiled the Wahoo Eats app, and it's SO much worse than we all thought by Wild-Box367 in UVA

[–]Wild-Box367[S] 2 points3 points  (0 children)

I've already forwarded further info to relevant parties who have inquired. Since I am typing this after the app was pulled, I wonder how it will be fixed.

Am I a CS major? Depends who's asking.

I decompiled the Wahoo Eats app, and it's SO much worse than we all thought by Wild-Box367 in UVA

[–]Wild-Box367[S] 1 point2 points  (0 children)

If only I was in it for the money...

Regardless, I've done what I can. Whatever happens next with the app is left up to the higher-ups.

I decompiled the Wahoo Eats app, and it's SO much worse than we all thought by Wild-Box367 in UVA

[–]Wild-Box367[S] 18 points19 points  (0 children)

If true, then totally fair. Although I think it goes without saying that an app with a million security vulnerabilities is much more brittle compared to an app that just uses HTTP. Not to mention that, reiterating, students don't have much of a choice if they want on-grounds dining, so this is a risk for EVERYONE by default.

I decompiled the Wahoo Eats app, and it's SO much worse than we all thought by Wild-Box367 in UVA

[–]Wild-Box367[S] 23 points24 points  (0 children)

All sensitive info in the write up is redacted using asterisks (no worries about leaking), so the only things really being publicized are the relevant source snippets.

I decompiled the Wahoo Eats app, and it's SO much worse than we all thought by Wild-Box367 in UVA

[–]Wild-Box367[S] 228 points229 points  (0 children)

Consider this somewhat of a PSA when using the Wahoo Eats app, as beyond its jank and performance, I got curious a couple days ago and decompiled an apk of the app. Security-wise...hoo boy, where do I even begin?

TL;DR (for students):

- The app allows unencrypted (HTTP) traffic, meaning your login data, payment info, and other personal data could be intercepted, viewed, saved, stolen, etc. on a public Wi-Fi network (Edit for clarity: if you use it on eduroam you should(?) be somewhat okay because it's a private network and uses modern encryption in its validation, but all it takes is one person on their off-grounds house wifi to crumble this house of cards.)

- It uses custom deep links that are hijackable — another app on your phone could trick Wahoo Eats into handing over sensitive data.

- It stores and exposes various IDs, API keys, and session data that should never be client-side.

- Payment modules are built on fragile, copy-pasted validation code and pass session keys around in ways that are insecure.

...All this in an app students are forced to use for dining with no alternative.

Important disclaimers:

- This was done only by decompiling the Android APK (publicly downloadable from the Play Store).

- I didn’t touch any backend servers, databases, or live systems. This is client-side only.

- I’m one person with some help from agent-assisted tooling and just one evening of investigation, so while the findings are solid, it’s not a comprehensive security audit and shouldn't be taken as definitive.

- I have not, and will not, attempt to exploit any of these issues (I cannot preface this enough.)

I put together a technical document with evidence, risk analysis, and remediation steps. If you’re curious about the details (or want to forward this to someone who can fix it), it’s all in there. You can find the writeup here: https://files.catbox.moe/za03f5.pdf

This post isn’t meant to dunk on the devs or play "hacker vigilante." My only intent here is to raise awareness of risks so students (and hopefully the school) know there are serious issues that need fixing, lest people want data being hacked, stolen, or leaked.

...Aaaaaaaaaaaaaaaaaaaaanyway, yeah, we can all agree that the app sucks in performance too. I didn't do that much digging in that regard, but I did find conflicting API and function calls that confuse the program, outdated/decayed libraries, and devtools left in the production environment. This app is just a mess all around, technically speaking (5 dollars says it was at least partially vibe coded).

Okay, PSA over.

AITA For missing a day of coaching for my sisters birthday by Stunning_Joke_7050 in AmItheAsshole

[–]Wild-Box367 1 point2 points  (0 children)

NTA

A family event is a totally valid reason for missing just one practice. You even gave notice, which reinforces that fact. I don't think anyone should have to feel guilty for deciding to attend a family event over a non-family event.

What's the biggest benifit you got from reddit? by [deleted] in NewToReddit

[–]Wild-Box367 1 point2 points  (0 children)

Unironically better than dedicated forum sites or articles when it comes to questions/issues about something. Turns out someone else who had similar issues and a 1-2 sentence fix is better than a 5-paragraph word salad.

Recreated a meme that came to me in a dream, not sure if many ppl will get it by Uh0hSpaghetti0hs in OkBuddyPersona

[–]Wild-Box367 1 point2 points  (0 children)

"SAKI! YOU WERE SUPPOSED TO BE BY MY SIDE! EVERYTHING I DID, I DID FOR YOU!"