Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

231–240 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#231

I would have stopped once I confirmed the leaked keys were valid. Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that. If there was a pentester agreement, safe harbor, or other protection that's different. Be careful out…

> Looking at what types of data you had access to wasn't required. Downloading plaintext passwords of other people is probably too far. Impacted users may need to be notified about a breach. If needed, create an account of your own and target only that.

I'd argue that it was absolutely necessary to gauge the severity of this misconfiguration and furthermore, that Chattr.ai must contact every affected user, not MrBruh.

Their configuration allowed anyone to create an account and access plaintext passwords. There is no telling whether and how many outside of this disclosure have previously accessed this information and may intend to use it. This was negligence of the highest order, and it shouldn't be on the one finding and reporting this issue to rectify it.

Re: I pwned half of America's fast food chains simultaneously

#232
post #56

It's not clear if the author was hired to do this pentest or is a guerilla/good samaritan. If it is indeed the latter, I wonder how they are so brazen about it. Does chattr.ai have a responsible disclosure policy? In my eyes people should be free to pentest whatever as long as there is no intent to cause harm and any findings are reported. Sadly, many companies will freak out and get the law involved, even if you are…

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#233

Firebase is a shitshow. I say this as someone who really tried to like it and sadly built a project for a client using it. Other than this security vuln, the issues vs. just using postgres are: * It is more work! Despite being a backend as a service it is much less code to just write a simple API backend for your thing both in time to do it and time to learn how to do it. Think of Firebase as being on the abstraction…

[deleted]

Re: I pwned half of America's fast food chains simultaneously

#234
post #25

Who's to say they're the first to discover this? They're the first to discover it and do something to fix it. I thought there was a US law now where breaches like this have to be reported?

You're probably thinking of recent SEC regulations requiring disclosure for public companies - https://www.sec.gov/news/statement/gerding-cybersecurity-dis... Chattr is a private company - https://www.crunchbase.com/organization/chatrr

the clients are public companies, and in the contracts they've signed with Chattr there will definitely be a clause that Chattr has to disclose everything to their clients, so that they themselves can raise to the markets

Re: I pwned half of America's fast food chains simultaneously

#236

Earlier quoted context omitted.

what the hell, i see the same thing. it's crazy to me when large companies don't even have an option for: in case of dumpster fire, send an email here.

Technically it's not my problem (or on any other basis), but it bothers me because I'm weird. I was tempted to find their CTO on linked in and post a message there, along with the fact that there was no reply to my outreach nor a proper channel to do so. I think the only think in their defense is that they must get a lot of angry customer messages and they just don't want to deal with that.

I very much doubt it's got anything to do with their CTO - the management of a corporate website is usually jealously guarded by marketing/corporate communications

Re: I pwned half of America's fast food chains simultaneously

#237
post #13

Earlier quoted context omitted.

It exposed PII of the managers & employees of ~half of the most popular fast food companies. Personally I feel the title is justified but I understand and respect your viewpoint. Also keep in mind that trying to clarify the such would also make the title much longer than I desired.

Title: I pwned Chattr.ai via Firebase misconfiguration That’s what you should call it. It explains to readers what’s going on without over sensationalism. That isn’t too long either.

that's a bit unfair, I think it's pretty important that it has real world consequences. nobody knows what Chattr is and who their users are

Re: I pwned half of America's fast food chains simultaneously

#240
post #138

Earlier quoted context omitted.

Unfortunately, door 1 is maybe $200 bounty and weeks or months of back and forth (if the corp doesn't have a clear bounty program) whereas door 2 has infinite upside. Honestly, it might make sense for a gov group to run a standardized bounty program for exploits with notable financial / privacy impact.

The solution is to have fines in place for insecurities and award them to discoverers.

What a wonderful idea. Im sure our nobel politicians will ignore their donors this time and craft legislation that puts large companies at constant threat of more fines. This could never be weaponized against small businesses that pose competition to the bigger fish.
Post reply on HN