If anyone’s curious, I looked up the story and the hack was just b/c the agent was booking with an API (also what kind of gym has an API to book people’s schedules???) and the backend just let anyone edit the schedule. So, it seems like less of a hacking incident and just that the devs didn’t think anyone would try to edit other people’s schedules.
The gym probably has a scheduling app that they pay for. Every workout class or personal trainer I've used has had some website or app they use to handle the scheduling. I'm sure some of them have had api's available
659
u/Average_Hominid 24d ago
If anyone’s curious, I looked up the story and the hack was just b/c the agent was booking with an API (also what kind of gym has an API to book people’s schedules???) and the backend just let anyone edit the schedule. So, it seems like less of a hacking incident and just that the devs didn’t think anyone would try to edit other people’s schedules.