The hackers who cracked Countdown’s fuel algorithm reassure retailers

  • News
  • January 21, 2016
  • Sarah Dunn
The hackers who cracked Countdown’s fuel algorithm reassure retailers

UK technology news site, The Register (no relation to this website) says the two researchers projected Countdown’s barcode scheme onto a screen during their presentation and helped the crowd spot its weaknesses. They then created useable discount codes which were distributed onto an unpublished Android app, through a barcode printer and applied to t-shirts.

Several delegates from Kiwicon reportedly told The Register (UK) that they had known about and exploited the discount scheme prior to the demonstration.

A spokeswoman from Countdown told the NZ Herald that the company was aware of the issue, and had developed a technical solution which was beign rolled out. The Register (UK) was doubtful that this would be the end of the problem, reporting that the researchers felt fixing the flaw would require the algorithm to be rewritten.

Countdown has declined to comment further. We spoke to the researchers about the implications of their discovery:

Q: You made hacking Countdown’s discount codes look very easy. Was that algorithm extraordinarily flimsy or is this representative of broader weakness in New Zealand retailers’ barcodes?

A: A barcode only makes a piece of information easy for a computer to read, they are not intended to be used to obfuscate or hide the contents of the information.

Q: Is it possible to explain, in layman’s terms, what made that algorithm so vulnerable? If so, can you have a go?

A: The discount amount and expiry date of the voucher are contained within the barcode of the receipt. We suspect this was an old system that is now being used in an automated environment that it was never intended for. The cashier at the service station would have normally validated that the receipts are genuine.

Q: Should many New Zealand retailers be concerned about this specific issue?

A:  This issue only directly affects Z pay at pump systems. It is not a new discovery of something previously believed to be secure.

Kiwicon is a conference for hackers and people interested in computer security which was held in Wellington on December 10 and 11 last year. In its FAQs, the organisers explain that the role of hackers can include testing security systems:

“They are people who enjoy exploring, understanding, and using technology creatively. Many hackers are interested in the security of computer systems, but as technology develops, hackers of different kinds are pushing the limits of cars, gadgets, and various media. However, the general perception of a 'hacker' is synonymous with 'computer criminal', and indeed some computer criminals are hackers. However, the prevention of electronic crimes and the defenses of modern networked systems are ensured by computer security professionals; the best of whom will often self-identify as hackers!”

Kiwicon’s organisers have pointed out that specific guidelines exist for those wishing to disclose gaps in New Zealand ICT security systems and the organisations which receive such disclosures. A non-profit organisation called the New Zealand Internet Task Force has released a PDF document which explains how each party can work together in “coordinated disclosure” to strengthen ICT security within New Zealand.

Among other recommendations, this report indicates organisations should have a coordinated disclosure policy; obtain a PGP key so that flaw-finders can communicate with them securely; check any flagged vulnerabilities have not been exploited; and when the vulnerability is fixed, consider making it public.

​ ​

This is a community discussion forum. Comment is free but please respect our rules:

  1. Don’t be abusive or use sweary type words
  2. Don’t break the law: libel, slander and defamatory comments are forbidden
  3. Don’t resort to name-calling, mean-spiritedness, or slagging off
  4. Don’t pretend to be someone else.

If we find you doing these things, your comments will be edited without recourse and you may be asked to go away and reconsider your actions.
We respect the right to free speech and anonymous comments. Don’t abuse the privilege.


Direct sales: How multi-level marketing works

  • News
  • April 18, 2019
  • Sarah Dunn
Direct sales: How multi-level marketing works

The $200 million-plus direct sales economy contains many lessons retailers can use. As part of a wider look at this thriving corner of retail, we created a quick explainer showing how this business model typically works.

Read more

Direct sales: Meet the upliners

  • News
  • April 18, 2019
  • Sarah Dunn
Direct sales: Meet the upliners

We profiled different participants in the direct sales industry to find out what retailers can learn from them. Meet Isagenix distributors Adam Nesbitt and Bianca Bathurst.

Read more

Direct sales: Meet the business builder

  • News
  • April 18, 2019
  • Sarah Dunn
Direct sales: Meet the business builder

As part of a wider story looking at what retailers can learn from the direct sales industry, we profiled Isagenix distributor Ben Frost.

Read more

Social scoreboard

Zavy and The Register have worked together to create a scoreboard that compares how the top 25 traditional media advertising spenders in New Zealand have performed on social media over the past 30 days, updated in real time.

Concept to closet
Business coverage of New Zealand Fashion Week.
Town centres
A positive retail environment over the past 12 ...
Amazon Arrival
Keeping up with all things Amazon as it ...
The Retail Yearbook 2017
As we battle our way through the busiest ...
Hospitality enhancing retail
Some think food and integrated hospitality offerings will ...
The future is bright
We spoke with four retailers in their twenties ...
Spotlight on signage
At first glance, the humble in-store sign might ...
Red Awards 2016
The Red Awards for retail interior design celebrate ...
Auckland Unitary Plan
Auckland is changing. The Unitary Plan will decide ...
How to open a store
Sarah Dunn considers what it would take to ...
All things to all people
Kiwi retailers share their omnichannel strategies.
Rising stars
Retail's top young achievers.
Delivering on your promises
The sale isn't over until your item is ...
Retail in heartland New Zealand
Retailers keep the regions pumping, but how strong ...
Women in retail help one another. We spoke ...
The changing face of retail
Shifting demographics are creating big changes in New ...
The retail yearbook
With the help of experts in the retail ...
Retail rogues
We put the spotlight on staff training. Jai ...
Here come the giants
Topshop has arrived in Auckland’s CBD, David Jones ...
Window shopping: A spotlight on social media
Sarah Dunn and Elly Strang look at how ...
From retail to e-tail
Ecommerce has become part of the way mainstream ...
Loyalty in the digital age
How are retailers maintaining loyalty? Sarah Dunn, Elly ...
The Innovators | In partnership with Spark Business
Technology is rapidly changing the retail industry as ...

Leveling up: Exploring multi-level marketing in New Zealand

Is the $200 million-plus direct sales economy retail by another name or something different? Regardless, what can we learn from it?


A spectrum of retailers

  • Opinion
  • April 18, 2019
  • David Farrell
A spectrum of retailers

In recognition of April being Autism Awareness Month, retail commentator Dave Farrell considers the role of those on the spectrum in retail.

Read more

How on-trend is your retail business?

  • Sponsored Content
  • April 18, 2019
  • Sponsored content
How on-trend is your retail business?

New insights from Visa highlight five evolving trends emerging from savvy retailers around the world. We’ve taken these global trends and looked at how they are playing out with merchants in New Zealand, and we’d now like to hear what you think of them.

Read more
Next page
Results for
About us.

The Register provides essential industry news and intelligence, updated daily. And the digital newsletter delivers the latest news to your inbox twice a week — for free!

©2009–2015 Tangible Media. All rights reserved.
Use of this site constitutes acceptance of our Privacy policy.

The Register

Content marketing/advertising? Email or call 022 639 3004

View Media Kit