Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

421–430 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#421

Earlier quoted context omitted.

There are different types of shame. Shame related to a decision situation (endogenous) and shame not related to a decision situation (exogenous). In the endogenous case the shame is said to be a 'pro-social' emotion. This is backed by studies. "Using three different emotion inductions and two different dependent measures, we repeatedly found that endogenous shame motivates prosocial behavior. After imagining shame wi…

There’s a reason your citations are nearly a decade old at best; the science has changed. A 2021 meta-analysis showed that, “shame correlates negatively with self-esteem and is large effect size.” [0] So unless the goal of your shame is to actively harm the people involved, then no, shame is not an effective tool at behavior change, given the damage it causes. You may be thinking of “guilt” rather than shame: > In su…

Regarding your sources:

One has to do with self-esteem, which has nothing to do with whether it is pro-social or beneficial, just that some types of shame harm self-esteem, which was never contested.

The second study is about criminal populations, and I specifically mentioned that shame is about self-policing, and that obviously didn't work if someone is incarcerated for a crime.

Re: I pwned half of America's fast food chains simultaneously

#422

Earlier quoted context omitted.

There’s a reason your citations are nearly a decade old at best; the science has changed. A 2021 meta-analysis showed that, “shame correlates negatively with self-esteem and is large effect size.” [0] So unless the goal of your shame is to actively harm the people involved, then no, shame is not an effective tool at behavior change, given the damage it causes. You may be thinking of “guilt” rather than shame: > In su…

Regarding your sources: One has to do with self-esteem, which has nothing to do with whether it is pro-social or beneficial, just that some types of shame harm self-esteem, which was never contested. The second study is about criminal populations, and I specifically mentioned that shame is about self-policing, and that obviously didn't work if someone is incarcerated for a crime.

Did you read them? If your goal is to effect change, hurting people's self esteem is a negative effect that is entirely unnecessary to change.

And criminals aren't some ungovernable animals...

Re: I pwned half of America's fast food chains simultaneously

#423
post #316

Earlier quoted context omitted.

Would you care to summarize what "related to a decision situation" means for those of us who don't have access to those articles?

Just a guess, but I imagine it's the difference between "I'm ashamed I can't make enough money to save anything" vs. "I'm ashamed I blew all my savings on crypto". One is shame about your situation (which are likely to be out of your own desires and control too), the other is shame about your decision (which you likely had better control over).

This is correct, according my understanding of the study I sourced.

Re: I pwned half of America's fast food chains simultaneously

#424
post #52

Earlier quoted context omitted.

Supabase is the iPhone to Firebase's Palm V -- highly recommend, if you're a fellow millenial like me who grew up on mobile, and things like "much less code to just write a simple API backend for your thing" sounds like 6 months and paying another engineer. EDIT: loud buzzer Careful, Icarus: "permissions can be setup to allow global read-writes" is a "vuln" of every system. p.s. Any comment on why her blog has you gu…

loud buzzer Sorry, but supabase has a similar issue. Another blog going over that has or will be made by Eva (referenced on the site)

Would be very interested in reading about SB. Has it already been posted?

Re: I pwned half of America's fast food chains simultaneously

#425

Earlier quoted context omitted.

That's not shame, that's guilt. Shame is existential, guilt is situational. The cost of shame is too high for whatever value it may bring.

Nope: > According to cultural anthropologist Ruth Benedict, shame arises from a violation of cultural or social values while guilt feelings arise from violations of one's internal values. https://en.wikipedia.org/wiki/Shame#Comparison_with_guilt

Yep:

> In sum, shame and guilt refer to related but distinct negative “self-conscious” emotions. Although both are unpleasant, shame is the more painful self-focused emotion linked to hiding or escaping. Guilt, in contrast, focuses on the behavior and is linked to making amends. [0]

[1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3328863/

Re: I pwned half of America's fast food chains simultaneously

#426
post #138

Earlier quoted context omitted.

Unfortunately, door 1 is maybe $200 bounty and weeks or months of back and forth (if the corp doesn't have a clear bounty program) whereas door 2 has infinite upside. Honestly, it might make sense for a gov group to run a standardized bounty program for exploits with notable financial / privacy impact.

Giving corps even more excuse not to run proper bug bounties, or care even less about shipping secure code? Pass.

There are two entities that constantly and consistently stomp all over human rights and sovereignty - governments and corporations. It also seems that most people are comfortable with asking them to increase the amount of control they have over our collective affairs.

It's quite the thing.

Re: I pwned half of America's fast food chains simultaneously

#427

If they're already using firebase, can anyone think why they are storing passwords? Firebase Authentication is incredibly easy and quick to setup and use (less than a day for someone new to it), which means you have no need to worry about passwords.

Not a direct answer, but I can tell you I see crazily idiotic mistakes in apps all the time. I think people are hiring the lowest of the low. FWIW, I don't think AI will replace coders anytime soon, but I think it'll replace these coders.

For example, my school's laundry app. Takes 8s to load because it continually refreshes the screen while it is trying to make a connection to their portal. Even now I just checked, it logged me out, took 5 seconds to let me touch the login, I placed in my email, grabbed my password form my password manager, it clearerd my email, retyped, and now the login is grayed out. Looks like I'm currently locked out. Looking at the laundry rooms, it takes 45s to load (literally, I timed it), and then the rooms aren't in order. It'll be like A4, A6, A7, A3, A11, A9, and so on. I'm not sure it's even manually filled in because they seem to change. Plus I have to unplug and replugin the machines constantly because they disconnect from the server. The dryer is a pain. This happens enough that the cords are worn down and it is a fire issue.

Yesterday I ordered from Jersey Mikes. They have a field where you can specify instructions. They do keyword filtering so you can't place a word like "cheese" in it, because they want you to click the box, but the box doesn't let you specify what kind of cheese. You also can't use words like "extra." Employees have always understood my shorthand or leet speak.

My housing processes applications via LIFO instead of FIFO. So all the students who renew their applications a month after the deadline get approved for their housing before anyone who does it within a reasonable time.

Electric bikes are known to light on fire when charging them. Teslas doesn't cover warranty for water damage. Google Maps routinely tells me to be in the wrong lane or miscalculates the number of lanes that exist. Google drive's solution to scrolling through music too fast is to lock you out, which just results in the user picking up the phone. Mine also likes to frequently disconnect itself and there's no low data mode so sometimes it just overloads my car's infotainment computer. Classic halt and catch fire situation.

I can go on about this stuff and it astounds me. Something is fundamentally broken when we can have computers that can talk to us in natural language but we are unable to design a system where employees understand the concept of a sorted list. Not to mention that I won't be surprised when that building catches fire.

Edit: I got logged in. My username was pasting into my password because their password field is labeled as a username field... but it is also hidden... They also double charged me in the past, said they didn't, and their solution was for me to issue a clawback with my bank. These people just don't care.

I really believe a lot of people are building things that they never test and never use. Even at big companies.

Re: I pwned half of America's fast food chains simultaneously

#428
post #384

If they're already using firebase, can anyone think why they are storing passwords? Firebase Authentication is incredibly easy and quick to setup and use (less than a day for someone new to it), which means you have no need to worry about passwords.

offshore workers

this is racist

Re: I pwned half of America's fast food chains simultaneously

#429

Earlier quoted context omitted.

I very much doubt it's got anything to do with their CTO - the management of a corporate website is usually jealously guarded by marketing/corporate communications

Yes, the CTO hopefully has nothing to do with lower level operations like that. But if they get a public burn they're going to issue a decree that will be addressed.

No what I mean is that it won’t even be in their org. The public website will belong to the head of corporate communications or some similar chief bullshit officer

Re: I pwned half of America's fast food chains simultaneously

#430

Earlier quoted context omitted.

Deciding to sell this on the darknet is a life changing decision, white to black overnight and imagine not really something most would contemplate. Payment in BTC probably from an already compromised address so loads of factors. Probably an easy + quick 2BTC though

This is an easy and obvious exploit so an attacker would need to extract the data from all sources ASAP. High risk of getting caught and ending in jail to be honest for measly 2BTC. Not worth it for anyone in the US or even Europe.

2 BTC in most of the world is a life changing amount! And there are multiple measures the wannabe criminal could take to minimise exposure risks.

No wonder PII keeps getting leaked and sold all the time...

Post reply on HN