back to article Nespresso smart cards hacked to provide infinite coffee after someone wasn't too perky about security

Some commercial Nespresso machines in Europe that incorporate a smart card payment system can be manipulated to add unlimited funds to purchase coffee, thanks to reliance on technology that's been known to be insecure for more than a decade. In a coordinated vulnerability disclosure published this week, Polle Vanhoof, a …

  1. Ken Moorhouse Silver badge

    Coffee and Mifare Classic

    Guaranteed to give sleepless nights.

    1. don't you hate it when you lose your account

      Re: Coffee and Mifare Classic

      Easy to spot the hacker, he's the one wide eyed hanging off the ceiling.

      1. Glen 1
        Joke

        Re: Coffee and Mifare Classic

        That's where the unsecured ethernet ports are...

  2. Evil Auditor Silver badge

    Absolutely appalling thinking that someone would do that: drinking coffee.

    1. Anonymous Coward
      Anonymous Coward

      Better drinking coffee than teabagging.

      1. chivo243 Silver badge
        Paris Hilton

        Depends if you are the bagger or the baggee? And I thought this teabagging required one man, and two women to connect the dots?

        1. Disgusted Of Tunbridge Wells Silver badge

          Tea bagging is a ritual performed on rugby team busses should a passenger mistakenly fall asleep.

    2. chivo243 Silver badge

      Believe it or not, I've only had one cup of coffee in my life! When I was a kid it was expen$ive and not a children's drink. I never cared for the smell of coffee, throw a few morning ciggies from the parents on top of that... I'm glad they smoked ciggies and drank coffee then, I do neither as an adult because of it. The parents have long stopped both coffee and ciggies!

      1. Blackjack Silver badge

        I usually prefer tea when I have time to relax but I go for coffee when I need to wake up fast, is less painful that an ice bag in my pants.

        1. CountCadaver Silver badge

          I just go for Pepsi, caffeine is enough to combat sleepiness and slow bowels (coffee being a stimulant for more than just your mind) Also tastes better than coffee (well to me anyway)

          1. This post has been deleted by its author

            1. Anonymous Coward
              Anonymous Coward

              When was the last time you saw someone keep soda in their mouth (continuously, no swallowing) for a full day?

              Seriously, though, this is pretty thoroughly debunked. For one, it takes more than a full day to do anything. For another, there are plenty of foods that are more acidic - like oranges - that are considered harmless to teeth.

              https://www.snopes.com/fact-check/coke-dissolves-teeth/

              https://www.popularmechanics.com/science/health/g1249/8-popular-tooth-myths-debunked/

            2. Dr_N

              Blackjack> Let's do an experiment, get a teeth, any teeth, it can be from a dead animal, and leave it in a glass of coke-cola for a day, then look at what happened to it

              Is the dead animal tooth specified because the "human tooth dissolves overnight in soft drink" is an urban myth? (Orange juice would yield similar results.)

        2. Evil Auditor Silver badge

          ice bag in my pants

          @Blackjack: please, elaborate!

          1. Blackjack Silver badge

            There is no faster way to wake up someone that putting ice in their private parts.

            1. jake Silver badge

              You've obviously never had children.

              1. Blackjack Silver badge

                You evidently never meet a heavy sleeper, I sleep through my house exploding for example. And people who live in apartment buildings either quickly learn to ignore crying children or gets ways to do so like noise canceling headphones, having music at a high volume using headphones and so on.

    3. jake Silver badge

      To be perfectly fair ...

      ,,, the bilge known as "Nespresso" is hardly coffee.

      1. seven of five

        Re: To be perfectly fair ...

        Dangerous ground (Ha!) for someone from the US...

        Yes, I know, just as with the beer - you can have decent in the States..

        1. jake Silver badge

          Re: To be perfectly fair ...

          At least here in the States we don't try to brew it like tea, with boiling water.

          Yes there is good beer here in the States. When I have friends over from Europe and the UK, instead of taking them wine tasting (everybody does that!), I take them on a tour of the breweries here in Northern California's supposed "wine country". First timers are always quite shocked at the quality and variety of real beer around here. And no, contrary to popular belief, it's not all overly hopped IPAs.

          1. Dave 126 Silver badge

            Re: To be perfectly fair ...

            In the States, the output of smaller, independant breweries used to be known as 'Regional Beers' before the Craft Beer tag was adopted to distinguish them from the big corporate players. Craft Beer is a legally defined term in the US, but has no meaning in the UK (though it often serves as a warning to the drinker). As jake notes, US craft beer isn't all overly hopped IPAs.

            1. Glen 1
              Windows

              Re: To be perfectly fair ...

              But I *like* overly hopped IPAs.

              1. Sgt_Oddball
                Windows

                Re: To be perfectly fair ...

                Overly hopped? No such thing....

                Now where's my dank, yellow triple IPA that's so thick a spoon would stand in it?

                Why, yiss offisshur, I have beeeen beerrrin' drink. * hic * How did you know?

            2. Anonymous Coward
              Anonymous Coward

              Re: To be perfectly fair ...

              US craft beer isn't all overly hopped IPAs.......

              .... but any country that can call Budweiser "beer" can't make proper beer. The American IPAs are uniformly dreadful - they all taste of grapefruit. The other American "craft" beers are anything but - they still haven't cracked the fairly simple process of making good beer. They also insist that most of their brews are <2% alcohol - they'd barely class as beers over here....

              1. jake Silver badge

                Re: To be perfectly fair ...

                You are not even wrong.

          2. Headley_Grange Silver badge

            Re: To be perfectly fair ...

            But the "real beer" in the US is still served under gas pressure and chilled isn't it? I've never been to a bar in the US that served hand-pulled ale at cellar temperature.

      2. Zarno
        Coat

        Re: To be perfectly fair ...

        I sense some involvement from Sirius Cybernetics.

        "He had found a Nespresso machine which had provided him with a plastic cup filled with a liquid that was almost, but not quite, entirely unlike coffee."

        My apologies for the parody.

        I need to hit the shops for some tea leaves soon, running low.

      3. Blackjack Silver badge

        Re: To be perfectly fair ...

        Agreed, is really overpriced crap, get me coffee beans from Brazil please.

    4. Flywheel
      FAIL

      Relax, Nespresso isn't coffee. Not really. Ask a real coffee drinker. I'm surprised Vanhoof admitted to this one.

      1. Anonymous Coward
        Anonymous Coward

        I'm a real coffee drinker, and Nespresso is definitely coffee, with some rather nice choices, too.

        It's fine to bitch about users not recycling the doses as they should, but the quality of the coffee itself is perfectly good.

        1. Roland6 Silver badge

          >but the quality of the coffee itself is perfectly good.

          Well it is an improvement to instant coffee and/or filter coffee that was ubiquitous before Starbucks; but a fresh cafetiere will give you the full on aroma plus all those esters that I don't see in a Nespresso cup.

          >It's fine to bitch about users not recycling the doses as they should

          Whilst the aluminium capsules are 'recycleable', it is at some energy cost...

          1. Anonymous Coward
            Anonymous Coward

            In the UK you can get Lyons ground coffee (paper) bags which are compostable. Individually sealed to maintain freshness - the external pouch is now rated as "industrial compostable". In an article they said that ground coffee loses much of its aroma after being exposed to air for 30 minutes.

            1. Roland6 Silver badge

              >In the UK you can get Lyons ground coffee (paper) bags which are compostable.

              My resident coffee aficionado has taken to these - for those occasions a cafetiere is too much hassle and only a kettle is to hand...

              >In an article they said that ground coffee loses much of its aroma after being exposed to air for 30 minutes.

              Hence the advice to keep your open bag of ground coffee sealed and in the coldest part of the fridge.

              1. Anonymous Coward
                Anonymous Coward

                I buy the Lyons coffee bags online in catering size boxes of 150 at a discount price. You have to buy several boxes to get the order free next-day delivery. Buying 10 boxes gets the maximum discount of 150 for £21.

                That's 14p a bag - compared to the retail boxes of 10 for £2.20 viz 22p a bag.

                Use by dates seem ok for me using at least a box a month viz minimum 5 cups a day.

                Any such investment is better than the interest on my savings account these days.

        2. low_resolution_foxxes

          Some Nespressos are decent enough (especially in hotels/B&B environments). I personally just don't like coffee pods for home use, mentally all I can think about is HP printers and encrypted inkjet cartridges selling for an insane amount (same pricing strategy!).

          Coffee beans cost ~ £10 for a 1kg bag, I use a cheap spice grinder and you can make ~ 100 cups of coffee. So that's ~ £0.10 of coffee per drink. Imagine the price when a large company buys it by the pallet!

          Nespresso pods are ~ 30-70p depending on quantity.

          So basically, when my wife buys Starbucks coffee for £3-4, I die a little inside.

    5. Brian Miller

      Absolutely appalling that someone would want an unlimited supply of bad coffee.

  3. Anonymous Coward
    Anonymous Coward

    Nespresso 'Smart Cards' - maybe not so smart then?

    Especially if they can be hacked by what I can only imagine to be the student masses (as in later life the general stress of making a living and having to deal with incompetent bosses day in and day out is usually enough to keep me wide awake at night).

    1. JimboSmith Silver badge

      I worked temporarily at a firm that had smartcard entry system and used the same card for lunch payments. The HR bloke who was doing my hello welcome to the firm told me it meant it was quicker for everyone in the canteen. I was give my freshly printed card and immediately tested it with my phone and discovered twas a Mifare classic. I mentioned this to the HR bloke who listened to my explanation that these had been hacked and cracked. He said they knew but this wasn't a problem for the firm. Adding money onto the card was done by debit card and the cash value stored on a central computer not the card. Therefore they'd dealt with the threat of somebody 'adding' money to the card. Further to that it had been signed off as perfectly safe to use by DORM (the department of risk management).

  4. A random security guy

    It is fair trade ...

    Mi Fare trade coffee

    1. Spiz

      Re: It is fair trade ...

      Good work! Are you a dad by any chance?

  5. Aristotles slow and dimwitted horse

    Nespresso...

    For coffee lovers that wouldn't know a decent coffee if it bit them in the arse.

    1. Dr_N

      Re: Nespresso...

      AKA "The English" with their high street coffee shops selling assorted tepid brews for eye-watering prices.

      Only in Italy, Turkey and to some extent France and Spain can you get consistently good coffee from a variety of outlets.

      1. jake Silver badge

        Re: Nespresso...

        Nah. They all ruin it with boiling water, just like the Brits.

        1. Tom 38

          Re: Nespresso...

          I don't know what you're smoking today jake, we make coffee the same way as the rest of Europe - ground coffee + steam, ie espresso. Occasionally at home you'd use a moka (still ground coffee + steam), but french press is rare these days - you'd never get french press if you buy a coffee.

          The abomination that is hours old filter coffee kept warm on a hotplate only exists in the US. Now that really isn't coffee.

          1. Anonymous Coward
            Anonymous Coward

            Re: Nespresso...

            There are a few cafes in my local town where french press is an option on the menu except (a) not right now because of The Covid, (b) they're referred to as a cafetiere (I've only really heard the term "french press" being used by our left-ponidan cousins)

          2. Dr_N
            Trollface

            Re: Nespresso...

            Tom 38> we make coffee the same way as the rest of Europe

            Gaslighting! We all know the majority in the UK drink Nescafé style instant coffee granules.

            1. Jellied Eel Silver badge

              Re: Nespresso...

              We all know the majority in the UK drink Nescafé style instant coffee granules.

              Yup. I once tried one of those canned coffees. But they were expensive, and I went back to the more traditional instant coffee experiences. Providing you have hot water, it's easier to just buy a jar of instant granules, add water, stick the lid back on, shake, and drink*.

              But technology's gorn mad..

              Vanhoof, in his post, advised Nespresso to upgrade its smart cards and to store monetary value on a remote server rather than on the smart card itself.

              Yeh, right. And end up with hordes of involuntarily decaffinated demanding to know why they can't get a fix because the Internet is down. Remote coffee was best implemented long ago by Cambridge Uni caffeine fiends. At least then if there were connectivity issues, it became a Schrödinger's Coffee experiment, not knowing if the pot was full or empty until you directly observed it..

              *then start shaking again. I did this once on a bet, but never again..

              1. Anonymous Coward
                Anonymous Coward

                I once tried one of those canned coffees

                Remember the short-lived Nescafe-in-a-can which heated itself?

                I bought one from a service station once. Never saw them again after that.

            2. Anonymous Coward
              Anonymous Coward

              Re: Nespresso...

              "We all know the majority in the UK drink Nescafé style instant coffee granules."

              My relatives always served up Bird's Mellow instant. I had to remember to take my own coffee on visits.

            3. keith_w

              Re: Nespresso...

              At my Aunt's house, made with boiled milk.

          3. TRT Silver badge

            Re: Nespresso...

            BUT... you must admit, the "brown Windsor soup" on the keep warm hotplate DID give birth to the webcam.

            1. Dr_N

              Re: Nespresso...

              TRT> "brown Windsor soup"

              Mmmmmmm. Nutty!

              1. TRT Silver badge

                Re: Nespresso...

                This coffee smells like shit!

          4. Kernel

            Re: Nespresso...

            "we make coffee the same way as the rest of Europe - ground coffee + steam,"

            If you're using steam then you're doing it wrong - coffee is made with water that is below boiling temperature, about 97 degrees. Steam is only involved if you're steaming milk to add to the coffee after it's been brewed.

        2. Hans Neeson-Bumpsadese Silver badge

          Re: Nespresso...

          The best system I've found for making coffee at home is the Mokka pot, which uses boiling water. Much superior to espresso style IMHO as the water is boiled but not superheated.

        3. EnviableOne

          Re: Nespresso...

          they never use boiling water now adays its ruined the tea....

      2. Anonymous Coward
        Anonymous Coward

        Re: Nespresso...

        > Only in Italy, Turkey and to some extent France

        France?

        Austria and nowadays the Czech Republic are right up there with Italy.

        Which in a way is not surprising, seeing as coffee was introduced to Europe via Austria during one of the traditional Ottoman invasions.

        1. Anonymous Coward
          Anonymous Coward

          Re: Nespresso...

          " the traditional Ottoman invasions."

          In which case most of the Middle East should make reasonable coffee.

          On the morning break in the fields on kibbutz in Israel a large flask would arrive with very black, very sweet coffee - plus vending size plastic cups.. Someone said it was Turkish-style coffee. The Arabs boil it up in a brass pot - and then decant it into tiny ceramic cups.

          1. Anonymous Coward
            Anonymous Coward

            Re: Nespresso...

            > In which case most of the Middle East should make reasonable coffee.

            And they do, actually. But of course it's made to a different taste.

            > On the morning break in the fields on kibbutz in Israel a large flask would arrive with very black, very sweet coffee

            Depends very much on the kibbutz and how long ago it was, but sounds like Russian style Turkish coffee (sic). Remember that kibbutzim started off as socialist work colonies.

            > The Arabs boil it up in a brass pot - and then decant it into tiny ceramic cups.

            "The Arabs" is a very large and diverse group, but in the Arabian Peninsula you can drink a type of very spicy, very rich coffee (pronounced something like gha'wa), which vaguely fits your description except that you never ever boil it, that'll ruin it. Instead it's "cooked" very gently. It brings such fond memories. :)

  6. Mr Dogshit

    Something something Java

  7. Headley_Grange Silver badge

    Binary Dump

    "He then made a coffee purchase to see where the binary data changed, reflecting a credit deduction."

    I did the same thing in about 1984 with Zork to stop the burning branch going out.

    1. Kevin McMurtrie Silver badge

      Re: Binary Dump

      That was easy in the 80s. The game gives you 4 lives? Parse through the binary and replace the first 10 non-instruction numbers 3 or 4 with 99. Repeat until you have more lives then narrow down the search. Now trace the code disable the counter update. Games were so small that this took only a few hours. It was not a boring task either, as the malfunctions induced in the game were often hilarious. Old computers never had any error handling. You could even patch the CPU's interrupt handlers to be no-ops so it was absolutely impossible for it to stop running code until the power was cut.

  8. Hans Neeson-Bumpsadese Silver badge
    Coat

    Security matters, people. Wake up and smell the coffee

    1. Mike 125

      >Security matters, people. Wake up and smell the coffee

      This one is McAfee's cup of tea.

      1. jdiebdhidbsusbvwbsidnsoskebid Silver badge

        Expect to see more coffee options on the Nespresso machines from now on. Espresso, flat white or white hat?

  9. Anonymous Coward
    Anonymous Coward

    Stored on a remote server, not on the card?

    Better hope the connection to that server is pretty damn secure. Facing a horde of angry and deprived coffee drinkers is not an activity I would enjoy when the network goes down...

  10. anthonyhegedus Silver badge

    Nothing wrong with nespresso. Yes, you can get a better espresso if you buy your own beans, grind them to just the right size powder, tamp it down to exactly right pressure and then use exactly the right pressure and temperature water to pull a perfect shot.

    First thing in the morning? No thanks!

    I want something by tired and bleary-eyed brain can get around so that I can get caffeine quickly into my bloodstream. Nespresso is better than the vast majority of coffee shops I've been to, even the ones purporting to be independent and 'coffee-loving'. It's not perfect, but it keeps me alive.

    1. Roland6 Silver badge

      >First thing in the morning? No thanks!

      ...

      I want something my tired and bleary-eyed brain can get around so that I can get caffeine quickly into my bloodstream. Nespresso is better than the vast majority of coffee shops I've been to

      Well, you ready do need to be a little more awake to visit a coffee shop and more appropriately attired...

  11. Anonymous Coward
    Anonymous Coward

    "We asked Nespresso to clarify which of its machines might still rely on Mifare Classic cards, but we've not heard back."

    What happened at the coffee shop:

    Employee: Hey boss, we got a email from The Register, an IT magazine that is doing a story on some of the cards we use. They're asking us what machines they can hack for free coffee, what should I tell them?

    Boss: Seriously? don't respond.

  12. Picky, but...

    Hacking for unlimited coffee...

    ... I don't know how they can sleep at night.

  13. Drew Scriver

    The coffee lady...

    Back in the day we had a coffee lady walking up and down the offices to serve us coffee (and tea) and cookies.

    Sadly, she's been replaced by Mi Fare Lady Nespresso machines :-(

    1. adam 40 Silver badge

      Re: The tea lady...

      Back in the day we had a tea lady walking up and down the offices to serve us tea (and instant coffee probably) and cake, and bread rolls with either sausage, or bacon.

      Marconi Instruments, circa 1986.

      1. AndrueC Silver badge
        Facepalm

        Re: The tea lady...

        We had a drinks lady back when I was working for S&S (producers of Dr Solomon's Antivirus Toolkit) back in the 90s. She was a lovely lady but she insisted on filling the kettle from the drinking water using the cold output tap. So she'd empty the cold reservoir to fill the kettle then fill a couple of glasses for those who wanted them with barely cool water.

        By the time the kettle had fought the laws of thermodynamics the water was at room temperature. I got in the habit of getting myself some water when I saw her gathering the cups. That way I could beat her to the cold water :)

    2. Anonymous Coward
      Anonymous Coward

      Re: The coffee lady...

      "Back in the day we had a coffee lady walking up and down the offices to serve us coffee (and tea) and cookies."

      In 1968 I was working in a pretty much deserted ICL Hartree House above Whiteley's department store late into the night. That place was a warren of corridors***. About 2am there was a ghostly rumbling noise in the corridor and a lady pushing a tea trolley appeared. The only other people in the building were the mainframe operators on the top floor.

      *** when the offices' lease was finally relinquished - someone pointed to the clause that said everything had to be restored to the initial condition. Where could we obtain the requisite rats?

  14. Anonymous Coward
    Anonymous Coward

    " Vanhoof was able to alter the three bytes used to store monetary value and write the a value (€167,772.15) back to the card using the nfc-mfclassic tool"

    So, about 1 coffee at *$ then.

  15. Fruit and Nutcase Silver badge

    The cult of Nespresso

    Could it really be the best cup of coffee money can buy?

    Global revenues topped £500m for the first time last year, and more than one million machines were sold (as well as more than 2.5 million coffee capsules). The brand's annual growth rate has been 30 per cent year on year since 2001, and it is the coffee industry's market leader in Europe.

    https://www.independent.co.uk/life-style/food-and-drink/features/cult-nespresso-could-it-really-be-best-cup-coffee-money-can-buy-395944.html

  16. David Roberts
    Windows

    Aeropress?

    No mention so far and it does make an exceptional cup of coffee.

    However mine rarely gets used as I start the day with a very strong instant coffee then daren't drink any more or I'm still twitching at midnight.

    1. John H Woods Silver badge

      Re: Aeropress?

      Agreed, hard to beat well-made aeropress coffee until you are spending at least half, possibly a whole, magnitude more on your coffee machine. Can be even better if you use it upside-down.

  17. DevOpsTimothyC

    Quality

    Some might say the quality of the tech that Nespresso are using is onpar with the quality of their coffee

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like