Live data from Hacker News

I reverse engineered McDonalds’ internal API

twitter.com

31–40 of 454 posts

Re: I reverse engineered McDonalds’ internal API

#31

While humorous, this seems actively malicious and I don't think McDonalds will look at it very favorably…

> I'm currently placing an order worth $18,752 every minute Agree with you that this seems actively malicious, and because of the dollar amounts involved, is liable to get him in big trouble.

The McDonalds app lets you place an order, but you have to check-in (via the app) when you arrive to pick it up. They don't start preparing anything until you do that; you can cancel, change stores, adjust order, etc. up until the "I'm here" button is hit.

Re: I reverse engineered McDonalds’ internal API

#33
AFAIK, reverse engineering APIs isn’t illegal. [1]

There are some (VC backed) start ups that are open about doing it. Teller API is an example. [2]

[1] “Reverse engineering generally doesn't violate trade secret law because it is a fair and independent means of learning information, not a misappropriation. Once the information is discovered in a fair and honest way, it also can be reported without violating trade secret law.“ https://www.eff.org/issues/coders/reverse-engineering-faq

[2] “We reverse engineer these apps to discover their secret API contracts and then implement clients for them.” https://teller.io/

Re: I reverse engineered McDonalds’ internal API

#34
post #21

He wouldn't have tweeted it if it was malicious -- he could have even kept it secret. What is it with HN? little pranks, reverse engineering, vulnerabilities, free ice-cream. I do not condone crime but let's be honest, he could have made money with his findings online...the person is just letting his curiosity go wild. If Yelp wants to fire him I'd take him in my company any day.

[deleted]

Re: I reverse engineered McDonalds’ internal API

#35
LOL! It's so ridiculous that this is a problem so often. I was in McDs once when the service guy was there. I overheard him say it would be $9,000 to fix just the shake side of the machine. I thought to myself, "That's a lot of milkshakes! There's a grocery store in the same parking lot... gallon of ice cream, some milk, and a blender. Problem solved."

Re: I reverse engineered McDonalds’ internal API

#36
post #21

He wouldn't have tweeted it if it was malicious -- he could have even kept it secret. What is it with HN? little pranks, reverse engineering, vulnerabilities, free ice-cream. I do not condone crime but let's be honest, he could have made money with his findings online...the person is just letting his curiosity go wild. If Yelp wants to fire him I'd take him in my company any day.

Sarcasm aside -- I hope this guy is joking for real...

Re: I reverse engineered McDonalds’ internal API

#37
post #26

Earlier quoted context omitted.

No, I think they're referring to the part where Aaron was "made an example of" by an overzealous prosecutor.

Well they did throw in "RIP". Which can be used in a non-literal way, but considering the context here...

Context being that he was driven to suicide by overzealous prosecution.

Re: I reverse engineered McDonalds’ internal API

#38
post #7

From creator[1]: “I reverse engineered mcdonald's internal api and I'm currently placing an order worth $18,752 every minute at every mcdonald's in the US to figure out which locations have a broken ice cream machine” [1] https://twitter.com/rashiq/status/1319346264992026624

Hard to imagine that lasts long...

Re: I reverse engineered McDonalds’ internal API

#40
post #30

Some details here: https://www.producthunt.com/posts/mcbroken A commenter asks: "How are you funding the $18k per minute this requires?" He replies: "I'm actually not paying for it! just placing an order." I'm not sure how he's placing an order without payment information, or if he is providing payment information, how he's managing to not get charged for successful orders (when the ice cream machine is not broken).…

> Perhaps the payment doesn't go through until he arrives to pick up the order?

Correct, and the order doesn't start being prepared until you hit the "I'm here" button on the app, either.

I once forgot to hit "I'm here" and they were confused because, to the store, it didn't exist, so there's no harm to the stores at all here.

Post reply on HN