Laundering Money

Michael Orlitzky

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

In "Laundering Money," Michael Orlitzky presents a compelling and humorous exposé on the security vulnerabilities of commercial laundry machines operated by CSC Service Works. The talk details how these ubiquitous machines, found in countless apartment buildings and condominiums, are susceptible to a straightforward physical bypass that allows users to operate them for free. Orlitzky frames his investigation not merely as a hacking endeavor, but as a justified act of "laundering money" from a company he vehemently characterizes as employing predatory business practices and delivering abysmal customer service.

Watch on YouTube

Visual summary for Laundering Money by Michael Orlitzky
Visual summary for Laundering Money by Michael Orlitzky

Key moments

  1. 0:00 Introduction: "Laundering Money" explained
  2. 1:39 Common coin-based laundry hacks that fail
  3. 2:21 CSC's modifications defeat documented admin modes
  4. 3:19 Unmasking CSC Service Works: Public ratings
  5. 4:14 CSC is "less fun than Baltimore jail"
  6. 4:35 CSC's dark patterns: chip card and pricing issues
  7. 6:52 Coin-op limitations: no cycle changes after payment

Laundering Money

Speakers: Michael Orlitzky

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=dldX9UFhNTs

Overview

In "Laundering Money," Michael Orlitzky presents a compelling and humorous exposé on the security vulnerabilities of commercial laundry machines operated by CSC Service Works. The talk details how these ubiquitous machines, found in countless apartment buildings and condominiums, are susceptible to a straightforward physical bypass that allows users to operate them for free. Orlitzky frames his investigation not merely as a hacking endeavor, but as a justified act of "laundering money" from a company he vehemently characterizes as employing predatory business practices and delivering abysmal customer service.

The core of Orlitzky's presentation focuses on dissecting the physical security and internal mechanisms of CSC-branded washers and dryers. After demonstrating the futility of common "hacks" and documented administrator modes, which CSC has intentionally disabled, he reveals a surprisingly simple and universally applicable method to trigger the machines' payment system without actual monetary input. This talk is crucial for anyone interested in the intersection of physical security, consumer rights, and the often-overlooked vulnerabilities in everyday "smart" appliances.

Orlitzky's work highlights a significant oversight in the deployment of commercial IoT-style devices. Despite CSC's efforts to thwart software-based exploits, they left a fundamental physical vulnerability unaddressed, allowing a standard service key and basic electrical manipulation to bypass their payment system. This not only serves as a cautionary tale for service providers but also empowers consumers with knowledge about the operational integrity of systems they are compelled to use.

Background

▶ Watch: Introduction: "Laundering Money" explained (0:00)

The genesis of Orlitzky's investigation stems from a deeply personal frustration with CSC Service Works, the company responsible for equipping and maintaining the laundry machines in his residential building. CSC's business model involves outfitting standard commercial laundry machines, primarily Speed Queen models, with proprietary payment modules and then placing them in multi-unit dwellings. Residents are then charged to use these machines, with CSC ostensibly responsible for their maintenance and operation. However, Orlitzky paints a stark picture of CSC as a company notorious for its "dark patterns" and exceptionally poor customer service, earning abysmal ratings across platforms like the Better Business Bureau, Yelp, and Google, often scoring lower than the infamous Baltimore jail.

Orlitzky, with a background spanning two decades in programming, system administration, and hacking—including a teenage stint in taking down MySpace, now a Gentoo Linux developer, and a PhD in mathematics—was primarily motivated by a profound dislike of being exploited, especially over small sums of money, and the implied helplessness of consumers. His initial attempts to circumvent CSC's payment system involved exploring widely circulated "hacks" and documented features of the base Speed Queen machines. These included using washer-sized coins, the "string-on-a-quarter" trick, attempting to access a manual mode via a two-button sequence (documented in the original Speed Queen manuals), flipping internal dip switches to disable payment, and even shorting specific wires as seen in online videos. All these methods proved ineffective, as CSC had deliberately modified the base machines and their circuitry to disable these known vulnerabilities and administrative bypasses.

The speaker meticulously cataloged CSC's "dark patterns," which served as further justification for his actions:

  • Refillable Chip Cards: These proprietary cards suffered from common gift card pitfalls. Critically, refill machines would accept $1 bills but refuse to credit $1 to the card, requiring lengthy customer service calls to reclaim the money. CSC also abruptly replaced old card readers with app-based systems, stranding users with money on cards they could no longer use or even check the balance of, forcing them to snail-mail the cards to CSC with no guarantee of a refund. Furthermore, machines were often priced ($1.85) such that it was impossible to fully deplete a card loaded with common denominations (e.g., $10), leaving small, unusable balances that CSC effectively kept. While prices were later rounded to $2, this only served to highlight CSC's manipulative pricing strategies.
  • Quarter Payments: Using quarters removed the ability to select or change cycle options (e.g., water temperature), forcing users to move their laundry and pay again if they made a mistake.
  • App-Based Payments: While apps could accept payment over cellular data anywhere, credit redemption was contingent on the building's Wi-Fi being operational and CSC's servers being online, creating scenarios where users could pay but not use the service.
  • Customer Service: CSC was notorious for unresponsive customer service, particularly when it came to refunds or machine repairs, despite maintenance being their primary contractual obligation.
  • Legal Issues: Orlitzky noted that CSC had even lost a RICO lawsuit, further cementing their reputation for unethical business practices.

These accumulated grievances underscored Orlitzky's conviction that CSC's business model amounted to systematic exploitation, justifying his quest to reclaim his "laundering money."

Key Findings

▶ Watch: CSC's modifications defeat documented admin modes (2:21)

Michael Orlitzky's investigation into CSC Service Works laundry machines yielded several critical findings that collectively expose a significant physical security flaw in their payment systems. Despite CSC's efforts to disable software and firmware-level bypasses inherent in the base Speed Queen models, their modifications did not extend to adequately securing the underlying physical coin mechanism.

The primary key finding was the discovery that a generic Alliance Laundry Systems service key, readily available for purchase online, could open the service panels of all CSC-branded washers and dryers in his building. This standardized key provides immediate physical access, bypassing any superficial attempts at security. This highlights a common vulnerability in large-scale deployments of commercial equipment where a single master key or widely distributed service key can compromise an entire fleet of devices.

Once physical access was gained, Orlitzky identified a trio of red, black, and white wires running directly from the coin drop mechanism to the machine's control board. The crucial insight was that by physically shorting the exposed portions of the red and black wires together, the machine registered a successful coin insertion. This "chiching operation," as Orlitzky dubbed it, effectively simulates a payment without any actual money being deposited. This indicates that CSC's payment module, despite its digital interfaces (cards, apps), still relies on a rudimentary electrical signal to trigger machine operation, a signal easily manipulated with direct access.

These findings demonstrate that while CSC invested in modifying their machines to prevent basic software or button-sequence hacks, they overlooked or underestimated the impact of physical access. The simplicity of the bypass—a $5.80 key and a momentary short of two wires—underscores a fundamental flaw in their security architecture, proving that physical vulnerabilities can often negate layers of digital protection.

Technical Deep Dive

▶ Watch: Unmasking CSC Service Works: Public ratings (3:19)

The technical core of Orlitzky's exploit revolves around obtaining physical access to the machine's internal wiring and understanding the rudimentary electrical signals that trigger the payment system. The target machines were CSC-branded washers and dryers, which were identified as modified Speed Queen models, supplied by Alliance Laundry Systems.

The initial reconnaissance involved observing the machines themselves. Orlitzky noted an "Alliance Laundry Systems" sticker inside the door of the washers, providing a crucial clue. A simple Google search for "Alliance washer dryer key" yielded a single result: a generic service key available for $5.80. This Alliance washer dryer key proved to be the master key, capable of opening the service panel of all CSC washers in his building. For the dryers, the service panels were secured by standard Phillips screws, making access a matter of a simple screwdriver.

Upon gaining access to the internal compartments, Orlitzky focused on the wiring associated with the payment mechanism. In both washers and dryers, he consistently identified a specific trio of red, black, and white wires originating from the coin drop mechanism. These wires are fundamental to how traditional coin-operated machines register payment. While the exact voltage or current characteristics were not detailed, the implication is that the red and black wires carry the signal for coin detection.

The chiching operation itself is remarkably straightforward. By "smooshing" (shorting) the exposed red and black wires together with bare hands, Orlitzky demonstrated that the machine would register a credit, as if a coin had been successfully inserted. The speaker humorously (and somewhat misleadingly, from an electrical safety perspective) claimed this was safe due to "grounding," but the underlying principle is that a momentary electrical connection between these two wires completes a circuit that the machine interprets as a valid payment. In some dryer models, these wires were even found to be conveniently pre-stripped and covered with electrical tape, simplifying the process further by merely requiring the removal of the tape.

This exploit highlights that despite CSC's proprietary payment modules and their efforts to lock down software-based administrative access, they retained a very basic, physically accessible electrical interface for payment registration. This interface, likely designed for the original coin operation, was not adequately secured against physical manipulation. The company's modifications primarily focused on disabling advanced control features (like manual mode or dip switches) but failed to harden the most basic physical input mechanism. The use of a standardized, easily purchasable key for service panels further compounds this vulnerability, creating a single point of failure for an entire fleet of machines.

Demo / Proof of Concept

▶ Watch: CSC's dark patterns: chip card and pricing issues (4:35)

Michael Orlitzky presented a pre-recorded, "live" demonstration of the exploit conducted in his building's laundry room at 3 AM. The demo meticulously walked through the process for both washers and dryers, emphasizing the simplicity and effectiveness of the method.

For the washers, the primary tool was the Alliance Laundry Systems key. Orlitzky first showed a tubular lock pick and described it as an "impressing tool" that could "save your game" after picking, but quickly discarded it, citing that using a lock pick to commit a crime is illegal in Maryland. He then proceeded to use the legally purchased Alliance Laundry Systems key to effortlessly open the service panel of a CSC washer. Once open, he immediately identified the crucial trio of red, black, and white wires extending from the coin drop mechanism. To perform the chiching operation, he simply "smooshed" the exposed portions of the red and black wires together with his bare hands. The machine instantly registered a credit, emitting an audible "chiching" sound, signifying its readiness for a free cycle.

The process for the dryers was equally straightforward, albeit requiring a different initial access method. The dryer service panel was secured by Phillips screws, necessitating a standard Phillips screwdriver for removal. After removing the screws and lifting the panel, the same trio of red, black, and white wires was visible. In the specific dryer demonstrated, Orlitzky noted that someone had conveniently pre-stripped the red and black wires and covered them with electrical tape. His action involved simply removing this tape and then, as with the washer, "smooshing" the exposed red and black wires together. This action similarly resulted in the dryer registering a credit, allowing for a free drying cycle.

Orlitzky explicitly stated his constraints during the demo: he could not break the machines, as his neighbors relied on them, and he wished to avoid involving the property manager or board. The demonstration showcased a method that left no physical damage, was quick to execute, and was repeatable, successfully bypassing the payment system without any monetary input. The demonstration effectively proved that CSC's efforts to secure their machines against software and firmware exploits were undermined by a fundamental lack of physical security and an easily manipulable electrical payment trigger.

Defensive Implications

▶ Watch: Coin-op limitations: no cycle changes after payment (6:52)

The findings presented by Michael Orlitzky have significant defensive implications for CSC Service Works and, by extension, any company deploying commercial IoT or payment-enabled appliances in semi-public environments.

  1. Re-evaluate Physical Security: The most glaring vulnerability is the reliance on a standardized, easily procurable Alliance Laundry Systems key to access critical service panels. CSC must immediately implement unique, high-security locks for their machines, distinct from generic manufacturer service keys. Furthermore, dryer panels secured only by common Phillips screws represent a minimal barrier to entry and should be upgraded to more tamper-resistant fasteners or locking mechanisms.
  2. Harden Payment Trigger Mechanisms: The core exploit involves shorting two wires to simulate payment. This indicates a fundamental flaw in the design of the payment module's interface with the machine's control system. CSC should engineer more robust payment detection circuits that are not susceptible to simple electrical shorts. This could involve encrypted signals, impedance-based detection, or more complex protocols that verify legitimate payment modules rather than just a momentary electrical contact. Tamper detection mechanisms, such as sensors that alert if a service panel is opened without authorization, could also provide an early warning system.
  3. Implement Tamper Evidence and Auditing: Machines should be equipped with internal logging capabilities to record service panel openings or suspicious electrical activity. Physical tamper-evident seals on internal components or wiring could also deter or at least detect unauthorized access.
  4. Address "Dark Patterns" and Customer Service: While technical fixes are crucial, a significant motivator for Orlitzky's actions was CSC's predatory business practices and abysmal customer service. Companies like CSC must understand that frustrated customers, feeling exploited and unheard, are far more likely to seek and exploit vulnerabilities. Improving customer service, ensuring fair pricing, transparent policies, and easily accessible refunds can significantly reduce the incentive for users to bypass payment systems. A business model built on customer exploitation inadvertently creates a strong user base motivated to find and share exploits.
  5. Security by Design for IoT/Commercial Appliances: This case serves as a stark reminder that physical security is as critical as cyber security for devices deployed in the real world. Manufacturers and service providers must adopt a "security by design" philosophy that considers all attack vectors—physical, electrical, and digital—from the outset. Relying on "security by obscurity" (modifying base models to disable documented hacks) without addressing fundamental physical access points is insufficient.
  6. Supply Chain Security: The reliance on generic components or widely available service tools from manufacturers (like Alliance Laundry Systems) can introduce vulnerabilities. Service providers like CSC need to ensure their modifications extend beyond software to encompass unique physical security measures for their specific deployments.

In summary, CSC needs to move beyond superficial modifications and invest in comprehensive physical and electrical security hardening, coupled with a fundamental shift towards a customer-centric business model, to mitigate such exploits effectively.

Key Takeaways

  • Physical Access is Paramount: Despite CSC Service Works' efforts to disable software and firmware-based hacks on their laundry machines, readily available physical access via a standard service key or simple tools renders these digital defenses ineffective.
  • Standardized Service Keys are a Critical Vulnerability: The widespread use of a generic Alliance Laundry Systems key to access multiple machines creates a single point of failure, allowing an attacker to compromise an entire fleet of devices with a low-cost, easily obtainable tool.
  • Simple Electrical Signals Are Easily Exploited: The payment mechanism relies on a basic electrical signal (shorting red and black wires) to register credit, a design flaw that is easily bypassed once physical access to the coin drop mechanism wiring is achieved.
  • "Dark Patterns" Fuel Exploitation: CSC's history of predatory pricing, poor customer service, and manipulative business practices directly motivated the speaker to seek and publicize these vulnerabilities, highlighting the link between corporate ethics and security posture.
  • Physical Security Overlooked in IoT Deployment: This case exemplifies how the physical security of everyday commercial IoT devices is often neglected, allowing low-tech attacks to bypass more sophisticated digital protections.

About the Speaker(s)

Michael Orlitzky is a seasoned professional with over 20 years of experience spanning programming, system administration, and hacking. In his youth, he gained notoriety for his involvement in taking down MySpace. Today, his work focuses on more constructive endeavors, including filing CVEs against open-source projects and contributing bug fixes. He is also a dedicated Gentoo Linux developer. Academically, Orlitzky holds a PhD in Mathematics. His motivation for this particular talk, as he strongly emphasizes, stems from a deep-seated aversion to being taken advantage of, particularly over minor financial impositions, and a refusal to accept the implication that he would do nothing about it.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Orlitzky's "Laundering Money" is a brutally honest, deeply satisfying exposé of CSC Service Works' predatory practices and the glaring physical security flaws in their ubiquitous commercial laundry machines. Driven by personal frustration, Orlitzky delivers a masterclass in practical exploitation, demonstrating how a common service key and basic electrical manipulation can bypass their payment systems. This talk is a potent reminder that physical security often underpins digital defenses, and that corporate "dark patterns" can directly incentivize sophisticated, real-world bypasses. It's a clever, actionable attack against a system millions are forced to use.

Heather Calloway (CISO) — STRONG ACCEPT

Michael Orlitzky's talk on "Laundering Money" is a compelling exposé of physical security vulnerabilities in commercial laundry machines, stemming directly from CSC Service Works' predatory business practices. While focused on a niche, the presentation offers critical insights into the governance failures that enable such exploits, the real-world business impact of neglecting physical security in IoT deployments, and the profound link between corporate ethics and an organization's security posture. It serves as a stark reminder that frustrated customers, coupled with easily bypassed physical controls, create a potent attack vector that negates layers of digital protection.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage