Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

311–320 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#311

>With an upbeat pling my console alerted me that my script had finished running Forget the pwn how do I do this Also, HN used to think this was cool now there are 20 posts blaming the hacker…

Debian (and derivatives like Ubuntu) come with a handy shell alias called `alert`.

It is meant to be used after a command or a chain of commands to give feedback about success or failure. The alias by itself doesn't issue a ping, but can easily be amended to do so.

What worked for me is to add an invocation of `paplay`. Actually it is two different invocations, one sound for success and another one for failure.

In addition to that I also send an ASCII 0x07. I have both `tput bel` and `echo -e "\a"` in my alias, but don't remember why. Probably one of them is enough. I do this because I have my terminal emulator set to visual bell an that causes the tab to change color when the command is finished and I can immediately see it even if I am in another tab.

Re: I pwned half of America's fast food chains simultaneously

#312

Ethical hacking is a good thing. Nice to see someone doing good.

They reworded things since yesterday:

Before, one collaborator had them in a chat sneering about chattr, checking their Javascript, then getting a GUI pwn tool for firebase.

i.e targeted attack with malice, followed up a blog post wildly exaggerating what happened, with a disclosure policy of 'we emailed them once and they fixed and didn't email us back so we'll just publish'

Only spelling this out because it's important to point out the significant gaps between white hat culture and these actions, not only for the authors, but for people who are inspired and want to practice it

Re: I pwned half of America's fast food chains simultaneously

#313

Earlier quoted context omitted.

Why should the researchers or other vulnerability spotters care about the company's customers? The companies don't care further than what they can profit from the customers. Yes, I know what full disclosure is. Companies don't do full disclosure about anything. Full disclosure is better than not disclosing publicly. But monetizing the vulnerability is akin to what companies do. I find it utterly bizarre that it's tot…

Full disclosure isn't something for _companies_ to do. It's what _researchers_ do. Full disclosure isn't compatible with the monetization incentives offered by companies. You're publishing in public and immediately. I think you clearly do not understand what full disclosure is.

My understanding of Full Disclosure is that researchers publish the vulnerability (and potentially exploit) publicly without coordinating with the software vendor. This contrasts with Coordinated Disclosure (sometimes "Responsible disclosure" in corporate propaganda) or No Disclosure (and potentially e.g. selling the exploit).

I admittedly used disclosure in a bit different sense for companies in that companies typically don't give out any (truthful) information they have if they aren't required by law. And they lie when profitable.

The symmetric action from a researcher is to sell the exploit to the highest bidder. Of course if the researcher wants to do other disclosures, that's fine too. But what I don't like is the double standard that researchers are scolded for being "unethical" but companies, by design, not caring about ethics at all is just fine and the way it should be.

Re: I pwned half of America's fast food chains simultaneously

#314
post #93

I was looking at jobs for my son at Safeway supermarkets and lazily put https://www.safeway.com/jobs in the browser. That redirects to https://www.careersatsafeway.com/desktop/home -- which is very much not about jobs at safeway -- appears to be an Indonesian gambling/gaming site. Safeway.com has zero email contacts published and expects communication to be via phone call or chatbot. I found their domain admin email…

Hi Albertsons/Safeway VP of Security Engineering here. Thank you for disclosing this. I’ll have it fixed along with the fact our VDP submission link is missing from the Safeway site. Here it is for future reference https://albertsons.responsibledisclosure.com/hc/en-us

Please also add a security.txt file so that it is not necessary to navigate through a labyrinthine site to get this information.

https://datatracker.ietf.org/doc/html/rfc9116

Re: I pwned half of America's fast food chains simultaneously

#315

Earlier quoted context omitted.

Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.

Nope, shame is ineffective as a tool for change. More often people shut down or ignore you if you attempt to shame them than actually make the change you want. Besides, it's frequently just about vengeance anyway. Shame is really hate of other, for the most part. As a tool for oppression however, yes it's quite effective.

The comment above lacks essential nuance and is overly confident.

Re: I pwned half of America's fast food chains simultaneously

#316

Earlier quoted context omitted.

Nope, shame is ineffective as a tool for change. More often people shut down or ignore you if you attempt to shame them than actually make the change you want. Besides, it's frequently just about vengeance anyway. Shame is really hate of other, for the most part. As a tool for oppression however, yes it's quite effective.

There are different types of shame. Shame related to a decision situation (endogenous) and shame not related to a decision situation (exogenous). In the endogenous case the shame is said to be a 'pro-social' emotion. This is backed by studies. "Using three different emotion inductions and two different dependent measures, we repeatedly found that endogenous shame motivates prosocial behavior. After imagining shame wi…

Would you care to summarize what "related to a decision situation" means for those of us who don't have access to those articles?

Re: I pwned half of America's fast food chains simultaneously

#317
post #135
post #123

Earlier quoted context omitted.

Maybe I'm like a Luddite or something, but I feel like I keep hearing about Firebase but still have no idea what it really is or why/how I would use it in a project. I'm just sitting here on my own building projects with mostly Postgresql DBs, once in a while MySQL, and not suffering massive security breaches. Thanks I suppose for giving me a data point that I'm most likely not missing anything.

It’s a hands—off database and auth service, initially intended to be directly accessed by thick clients, with little to no backend logic (although they have since added FaaS). When mobile apps started out, most had little to no online features. As the mobile apps market grew, more and more of these apps started requiring account persistence, sharing content with other users, real-time online interactions, etc. That's…

Ahhh Backend As A Service. I guess that makes sense. Not something I could see myself ever using, but I suppose I can see how somebody might use it if they don't know how to write and run their own backends or don't have authority to spin one up.

Guess I'm a little lucky in that I can spin up personal backend services just for kicks, and even though DayJob is pretty corporate and locked down, I can still spin up a new backend on my own with not much oversight as long as it doesn't touch certain sensitive things.

Thanks for a brief and clear description - it's surprising how few people can't seem to write one, and how many official corporate sites bury what their service actually does behind 10 pages of marketing fluff and stock photos.

Re: I pwned half of America's fast food chains simultaneously

#318
post #83

Earlier quoted context omitted.

What is wrong with shaming when it's warranted?

It’s an ineffective tool if your goal is change.

With humans. With companies it's pretty effective - especially if the post hits front page.

Ask Troy Hunt: https://www.troyhunt.com/the-effectiveness-of-publicly-shami...

Re: I pwned half of America's fast food chains simultaneously

#319
post #162

Earlier quoted context omitted.

How so?

Because everyone makes mistakes, if you antagonize someone they are less likely to care about you and feel more obligation to protect their own.

This is absolutely true at the scope of personal relationships. Not at all when it comes to companies, which have a different set of incentives

Re: I pwned half of America's fast food chains simultaneously

#320
post #316

Earlier quoted context omitted.

There are different types of shame. Shame related to a decision situation (endogenous) and shame not related to a decision situation (exogenous). In the endogenous case the shame is said to be a 'pro-social' emotion. This is backed by studies. "Using three different emotion inductions and two different dependent measures, we repeatedly found that endogenous shame motivates prosocial behavior. After imagining shame wi…

Would you care to summarize what "related to a decision situation" means for those of us who don't have access to those articles?

[deleted]
Post reply on HN