Live data from Hacker News

Ice cream machine hackers sue McDonald's

wired.com

111–120 of 162 posts

Re: Ice cream machine hackers sue McDonald's

#111

Earlier quoted context omitted.

Regardless, like I said, the Kytch box (a Raspberry Pi) is overriding the code that accesses the secret menu of the ice-cream machines [1]. That's outside the intended operation. And that's liability if McD knows about it and says nothing. The machine produces food that goes into people's bodies. Ie, if it were to produce a poisonous glycol ice-cream (glycol one of the pasteurization ingredients) all of a sudden, eve…

Wow, you are going to be horrified when you find out what goes on inside a family-run restaurant or food cart. They actually make food using humans .

That is the difference between family business and industrial food production. The cleaning products used in small restaurants are basically harmless. A little bleach residue in someone's food will taste horrible but probably won't kill anyone. Glycol tastes like sugar. It very much will do harm if it leaks into the food. But using glycol allows a food producer to reduce labor costs via automation, automation being a bright line between mom-and-pop burger bars serving perhaps 10 customers per hour and a busy MacDonald's location serving 500.

Re: Ice cream machine hackers sue McDonald's

#112
post #72
post #53

Earlier quoted context omitted.

It also needs to be said that similar machines provided by Taylor to McDonalds' competitors do not have anywhere close to the amount of downtime that McDonalds' machines have. There's also ample evidence that software updates to Taylor's McDonalds machines have made the error codes more cryptic and the machines more unreliable over time. I think there's a pretty strong legal case to be made that these machines are de…

>There's also ample evidence that software updates to Taylor's McDonalds machines have made the error codes more cryptic and the machines more unreliable over time. Source? >It also needs to be said that similar machines provided by Taylor to McDonalds' competitors do not have anywhere close to the amount of downtime that McDonalds' machines have >I think there's a pretty strong legal case to be made that these machi…

Here's a little investigation about it: https://www.youtube.com/watch?v=SrDEtSlqJC4

Re: Ice cream machine hackers sue McDonald's

#114

I am actually on McDonalds’ side in this. Many of the startups have made a lot of their money by arbitraging regulation and safety (see Uber , AirBnB, Tesla self driving). McDonalds is a company that literally serves billions of people. If there is any food borne illness, it can literally kill people and it will be front page news all over. As such, McDonalds keeps a very tight lid on what franchisees are allowed to…

I think the core of the problem was less food safety failures and more "user error" reasons. Then instead of saying "there is to much milk in the hopper remove some, and restart", or providing an error code lookup they just flash "error call your technician". This device just told the user what was actually wrong with the machine so they could choose to correct it, or call the technician to actually repair it. I don'…

Yeah, the other element is that successful operation is dependent on a complex process that happens overnight, takes multiple hours, and cannot be bypassed (for legitimate safety reasons). The hacker device deciphers the error messages and also provides notifications to the owner during these processes. Thus, if the system runs into a common issue at 11pm, early in the cleaning, the issue can be addressed immediately, and the cleaning re-started. Without the hacker device, the problem is often not discovered until much later, by which time it's too late to complete the cleaning process by lunch; or, even worse, the extended delay means that a technician needs to be called to reset/clean the machine, adding more delays.

Re: Ice cream machine hackers sue McDonald's

#115
post #69

Earlier quoted context omitted.

I don't have any first-hand knowledge of what the Kytch device did. But nothing I've read about it ever gave me the impression that it was overriding lockouts. It was intended as a remote monitoring device and troubleshooting tool. For example, instead of an employee having to read a pattern of blinking lights on the machine itself, a franchise owner might receive an email that says "soft serve machine cleaning requi…

Regardless, like I said, the Kytch box (a Raspberry Pi) is overriding the code that accesses the secret menu of the ice-cream machines [1]. That's outside the intended operation. And that's liability if McD knows about it and says nothing. The machine produces food that goes into people's bodies. Ie, if it were to produce a poisonous glycol ice-cream (glycol one of the pasteurization ingredients) all of a sudden, eve…

Wow, you're really going to hate how people mod their cars. At some point we have to ignore hypotheticals because they are too divorced from what is actually happening.

Case in point, when someone mods their car it is not somehow the manufacturer's responsibility for a crash. It fails the pre-hearing test of "can we even have a lawsuit about this" if someone even tries to bring it up.

Re: Ice cream machine hackers sue McDonald's

#116
post #69

Earlier quoted context omitted.

I don't have any first-hand knowledge of what the Kytch device did. But nothing I've read about it ever gave me the impression that it was overriding lockouts. It was intended as a remote monitoring device and troubleshooting tool. For example, instead of an employee having to read a pattern of blinking lights on the machine itself, a franchise owner might receive an email that says "soft serve machine cleaning requi…

Regardless, like I said, the Kytch box (a Raspberry Pi) is overriding the code that accesses the secret menu of the ice-cream machines [1]. That's outside the intended operation. And that's liability if McD knows about it and says nothing. The machine produces food that goes into people's bodies. Ie, if it were to produce a poisonous glycol ice-cream (glycol one of the pasteurization ingredients) all of a sudden, eve…

Again, I have no first-hand experience with this device so I can only infer things from the articles and documents we have available.

I fear I am being overly pedantic here, but to me, "override" implies that the device is circumventing sensor readings or physical interlocks or something similar to manipulate the machine's mechanisms to doing something they weren't intended to. However, I've see no indication of that. The device is described as, essentially, a second control panel. Anything the Kytch device can do is something an operator could already do by pushing buttons on the factory-installed control panel. The difference is that it interprets the data to be easier to understand, and provides remote monitoring.

It's really no different than plugging a ScanGauge into a car's ODB-II port. The ScanGauge can tell you all sorts of things about the state of the engine, but it isn't going to stop the brakes from working.

I remember reading that Wired article when it first came out. Near the beginning, it says:

> As O'Sullivan says, this menu isn’t documented in any owner's manual for the Taylor digital ice cream machines

This is demonstrably false. It's clearly documented on page 22 of the service manual: https://static-pt.com/modelManual/TAF-C602_spm.pdf

Frankly, the manuals Taylor has made for these machines are quite thorough and well written. The claims from the article about how this is "secret" and "undisclosed" seem disingenuous when a simple Google search reveals evidence to the contrary. I suppose one could argue that a "service manual" is not an "owner's manual", but that seems overly pedantic (even to me!).

Re: Ice cream machine hackers sue McDonald's

#117
post #101
post #53

Earlier quoted context omitted.

It also needs to be said that similar machines provided by Taylor to McDonalds' competitors do not have anywhere close to the amount of downtime that McDonalds' machines have. There's also ample evidence that software updates to Taylor's McDonalds machines have made the error codes more cryptic and the machines more unreliable over time. I think there's a pretty strong legal case to be made that these machines are de…

This is maybe backed up by the fact that in other countries, McDonalds serves the same ice-cream from machines that seem to always be working. The "McDonalds ice-cream machine is always broken" meme seems to be a uniquely US phenomenon - or at least it's not completely worldwide.

Definitely true in Australia. You very often can’t get ice cream after a certain time of night.

Re: Ice cream machine hackers sue McDonald's

#118
post #106

Earlier quoted context omitted.

The fact that the design intent is to reduce downtime does not mean it is achieved in practice. McDonald's ice cream machines constantly being "broken" is so well known that it's a meme among normal people. This is not the case for other fast food places that use Taylor machines. I've seen statements from employees confused about why it's such a big deal to clean the machine once a day because it's not that hard. (Pe…

Does this mean that the ice cream machines at other places are just happily dispensing unsafe food?

I worked for McDonald's in my teenaged years and saw the inspection report on one of the old-style machines. It was pretty horrible. The self-cleaning machine was created for a reason.

Unlike the fryers and grills the soft-serve machine is filled with dairy product, loaded by hand via human interaction, and just hovering underneath the safe zone temperature-wise.

Re: Ice cream machine hackers sue McDonald's

#119
post #69

Earlier quoted context omitted.

I don't have any first-hand knowledge of what the Kytch device did. But nothing I've read about it ever gave me the impression that it was overriding lockouts. It was intended as a remote monitoring device and troubleshooting tool. For example, instead of an employee having to read a pattern of blinking lights on the machine itself, a franchise owner might receive an email that says "soft serve machine cleaning requi…

Regardless, like I said, the Kytch box (a Raspberry Pi) is overriding the code that accesses the secret menu of the ice-cream machines [1]. That's outside the intended operation. And that's liability if McD knows about it and says nothing. The machine produces food that goes into people's bodies. Ie, if it were to produce a poisonous glycol ice-cream (glycol one of the pasteurization ingredients) all of a sudden, eve…

Chemist here. The use of propylene glycol in the clean/sterilize cycle is OK, it is related to 3 carbon glycerol and is not toxic and any breakdown product(glycerol) is safe and edible. Ethylene glycol, a 2 carbon polyol, is metabolized to poisonous oxalic acid and 1000's of pets and other animals are killed every year. Most states require Bitrex, a very foul tasting additive to be added to various products people/animals might eat. https://www.bitrex.com/ There is a pet safe antifreeze based on Propylene Glycol, which I use, that is a good antifreeze and not toxic. So save a pet/animal https://safeantifreeze.com/

Re: Ice cream machine hackers sue McDonald's

#120

Earlier quoted context omitted.

Regardless, like I said, the Kytch box (a Raspberry Pi) is overriding the code that accesses the secret menu of the ice-cream machines [1]. That's outside the intended operation. And that's liability if McD knows about it and says nothing. The machine produces food that goes into people's bodies. Ie, if it were to produce a poisonous glycol ice-cream (glycol one of the pasteurization ingredients) all of a sudden, eve…

Again, I have no first-hand experience with this device so I can only infer things from the articles and documents we have available. I fear I am being overly pedantic here, but to me, "override" implies that the device is circumventing sensor readings or physical interlocks or something similar to manipulate the machine's mechanisms to doing something they weren't intended to. However, I've see no indication of that…

> This is demonstrably false. It's clearly documented on page 22 of the service manual: https://static-pt.com/modelManual/TAF-C602_spm.pdf

I can't find it from Taylor, though. I think the point they're making with the "secret" is that the manufacturer won't give them to you. The 3rd party copies are likely illegal; I would presume the service manual is copyrighted.

> Anything the Kytch device can do is something an operator could already do by pushing buttons on the factory-installed control panel. The difference is that it interprets the data to be easier to understand, and provides remote monitoring.

It does allow access to things that users weren't meant to be able to access, and some of them are dangerous. E.g. you can change the temperature of the boil cycle down to something too low to kill bacteria.

> It's really no different than plugging a ScanGauge into a car's ODB-II port. The ScanGauge can tell you all sorts of things about the state of the engine, but it isn't going to stop the brakes from working.

The ScanGauge can't actually change any parameters, afaik. This is closer to replacing the ECU. It gives you more data on what you car is doing, but also gives you the option to tune the engine. You can either make it more efficient, or you can destroy the engine, depending on how you tune the settings. Except in this case, "destroy the engine" roughly translates to "give a bunch of people listeria infections".

In my opinion, it's unreasonable for McDonald's to block off access to the data, but it is reasonable for them to not want franchisee's to be able to change parameters like the boil temperature, or how frequently cleanings need to be done (which is another parameter in that secret menu). The whole situation is a mess, because I can't see a way to allow access to the data without access to the whole secret menu, other than replacing all the hardware. I think I saw McDonald's trying to sell their own device on that front; likely because then they can ensure that the parameters aren't exposed.

The C602 was released in 2003 afaict. I don't think this was a malicious decision so much as no one in 2003 predicting that it would be beneficial (or cost-effective) to have a WiFi/Bluetooth remote data port. That was 4 years before the iPhone, and interestingly, also only 5 years after the first consumer bluetooth device was unveiled. I don't find it shocking that a behemoth like McDonald's isn't putting nascent technology in an ice cream machine they plan to use for decades.

Post reply on HN