Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

411–420 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#411

This is extremely annoying. Instead of fucking with other people’s companies why not build your own? You pwned them? What are you twelve? All you did was commit a felony and post it online.

> What are you twelve?

Read this please https://news.ycombinator.com/newsguidelines.html

Re: I pwned half of America's fast food chains simultaneously

#412

Earlier quoted context omitted.

there used to be windows GUIs for forcing new connections to ask, but i haven't seen anything like it. I can't recall the name of the one i used to use, but it scored perfectly on shieldsUp - oh, Zone Alarm. Littlesnitch iirc is macos only, but it sounds lovely for this sort of thing.

There's a very good relatively new open-source GUI firewall app like this called Portmaster: https://safing.io/ It's available for Windows and Linux

Indeed!

If anyone wants to get to know us, our next Live Q&A is tomorrow at 15:00 CET: https://m.youtube.com/watch?v=S6P8ajLECXg

Re: I pwned half of America's fast food chains simultaneously

#413

Earlier quoted context omitted.

Pretty sure that poking around for holes/exploits is part of the definition of what is a hacker. They notified the relevant organization as well. Not sure why you take that stance.

And then posted it online? If his intentions were good he wouldn’t post their name.

> If his intentions were good he wouldn’t post their name.

Why? They shouldn't be allowed to sweep it under the rug

Re: I pwned half of America's fast food chains simultaneously

#414
post #334

Earlier quoted context omitted.

A closer analogy would be your friendly neighbour warning you that you left your garage door open. And yes I would appreciate him telling me.

What if he says that he has discovered that if he stands on one foot in the street in front of your house, holds anyone's garage door opener above his head, and clicks it 25 times at precisely 9:01am while shining a laser pointer at the top of the door, your garage door will open.

I don't think that's a good analogy.

What matters is if the thing they're doing to test your security is similar to what criminals would do to breach your security.

In the case of a physical location, that bar is low. It's things like seeing if your garage door is open, or your car doors are locked, etc.

In the case of computer resources, that bar is high. Probing your database for permissions holes is absolutely something that a normal "cyber criminal" would do. It's the equivalent of a carjacker looking to see if your doors are unlocked.

So an "online neighbor" alerting you that your database is unprotected doesn't feel weird at all. It's not the equivalent of that weird laser pointer thing you talked about, it's the equivalent of looking to see if your car doors are unlocked while you're away on vacation.

Re: I pwned half of America's fast food chains simultaneously

#415
post #397

This is my problem with the whole architecture of FE -> DB. Without a middle server layer, things like token storage, authentication, and other things become really easy to screw up.

Firebase has an auth API that is free built in, it's weird that they didn't just use it. Idk if whoever built this would have built a more secure solution with a server layer or just have a public mongo instance instead

Re: I pwned half of America's fast food chains simultaneously

#416

Earlier quoted context omitted.

The solution is to have fines in place for insecurities and award them to discoverers.

This is an awesome idea. The next time a glibc CVE comes out every company in the world pays a fine, if they are impacted or not! Hey - you could even file 1000s of frivolous CVEs (which is already common) you know would affect your competition! (which is how that would pan out)

It is a shame that ideas never progress any farther than super basic principles before they are implemented so that totally predicable outcomes that cynical people on internet forums mention become inevitable.

Re: I pwned half of America's fast food chains simultaneously

#417

Earlier quoted context omitted.

Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.

Nope, shame is ineffective as a tool for change. More often people shut down or ignore you if you attempt to shame them than actually make the change you want. Besides, it's frequently just about vengeance anyway. Shame is really hate of other, for the most part. As a tool for oppression however, yes it's quite effective.

> people shut down or ignore you if you attempt to shame them

Sure, but large businesses entities (as opposed to individuals) often cannot afford such luxury.

Try being a bank in a western country and ignoring a public security blog post, outlining exactly how one can exploit your online banking auth flow to gain unauthorized access to customer accounts.

Re: I pwned half of America's fast food chains simultaneously

#418

Earlier quoted context omitted.

Deciding to sell this on the darknet is a life changing decision, white to black overnight and imagine not really something most would contemplate. Payment in BTC probably from an already compromised address so loads of factors. Probably an easy + quick 2BTC though

Yeah it's like the difference between buying a handgun to go to the range and buying one to rob a liquor store

You mean buying a handgun to give as a gift to your dad, vs buying a handgun for someone who wouldn't pass a background check and might use it for bad things (straw purchase).

Re: I pwned half of America's fast food chains simultaneously

#419

Earlier quoted context omitted.

Shame isn't always for oppression, although it certainly can be - it's also a pretty useful tool to impose reasonable rules that allow you to live peacefully among your neighbors.

That's not shame, that's guilt. Shame is existential, guilt is situational. The cost of shame is too high for whatever value it may bring.

Nope:

> According to cultural anthropologist Ruth Benedict, shame arises from a violation of cultural or social values while guilt feelings arise from violations of one's internal values.

https://en.wikipedia.org/wiki/Shame#Comparison_with_guilt

Re: I pwned half of America's fast food chains simultaneously

#420

Earlier quoted context omitted.

The issue is it is often impossible to distinguish from a white hat or a black hat hacking your live systems. It can trigger expensive incident response and be disruptive to the business. Ethically, I think it crosses a line when you are wasting resources like this, live hacking systems. There is usually a pretty clear and obvious point where you can stop, not trigger IR, and notify the companies. Not saying that was…

> Ethically, I think it crosses a line when you are wasting resources like this, live hacking systems. I agree with everything you wrote except this sentence. There is no ethical obligation not to waste a company's time.

Why not?
Post reply on HN