Live data from Hacker News

I pwned half of America's fast food chains simultaneously

mrbruh.com

441–450 of 513 posts

Re: I pwned half of America's fast food chains simultaneously

#441

Earlier quoted context omitted.

> Before, one collaborator had them in a chat sneering about chattr "Wow this thing looks crappy" > checking their Javascript "I wonder if it is crappy" > then getting a GUI pwn tool for firebase. "Huh, it seems crappy. Let's just check to be sure" > with a disclosure policy of 'we emailed them once and they fixed ...' "Well, this thing is really crappy. we don't want to harm people. Let's tell them about how crappy…

Note I'm not claiming disclosure is bad , but rather, this is a copy of a copy of a copy of a copy of a copy of a copy of how professionals handle these situations, to the point there's nothing left except the "1) pick a target 2) email them 3) write a blog post when fixed" parts.

What other steps have their ever been? Getting a CVE?

Re: I pwned half of America's fast food chains simultaneously

#443
post #397

This is my problem with the whole architecture of FE -> DB. Without a middle server layer, things like token storage, authentication, and other things become really easy to screw up.

Mhhm. It's also a reason why we're making sure our developers have an easy time integrating into the platforms authn and authz systems. For example, if you need an admin interface, it should be just a library include and some bespoke framework configs to be integrated with the central authz framework over trying to think of something on their own.

It's... way too successful internally, lol, because we have a lot of permissions and privileges to manage now. And now we have to figure out good ways to assign these permissions to people more efficiently.

But that's a better problem than a GDPR relevant data breach, to be honest.

Re: I pwned half of America's fast food chains simultaneously

#445

Earlier quoted context omitted.

Weird, I don't feel nearly as touchy about some ones and zeros on a computer as I do my physical body's safety, without which I would not exist.

OK, make the comparison more direct, then. Say you have a filing cabinet with all of your important and \ or embarrassing documents in it. Are you OK with houseguests giving the handle a little wiggle when they come over to check if its locked? What about the neighborhood kids?

> Say you have a filing cabinet with all of your important and \ or embarrassing documents in it. Are you OK with houseguests giving the handle a little wiggle when they come over to check if its locked? What about the neighborhood kids?

If i leave that filing cabinet in the middle of Times Square in Manhattan (which has an insane amount of foot traffic every day), then yes, I would expect plenty of people to give it a little wiggle to check if it’s locked. And I would be rightfully given a lot of questionable looks for complaining that passerbys stop to check it out or give it a wiggle.

Having your service on the internet is not the same as having a filing a cabinet in your house. I think that the Times Square analogy is even underplaying it, given that on the internet, your audience is many many magnitudes larger and more remote/anonymous.

On the other hand, if I had a private VLAN (that wasn’t exposed to the internet) on my home network, then I would be definitely annoyed if my houseguests would try and pentest it without asking.

Re: I pwned half of America's fast food chains simultaneously

#446

Earlier quoted context omitted.

It’s an ineffective tool if your goal is change.

Shame is absolutely a valuable tool for change. Without it society would not function since many of our 'rules' are self-enforced.

I don't know why you're being downvoted, shame is one of the most powerful motivators that exists in humans; I'd put money on it being the most powerful. People who are loudly disagreeing don't understand that "shaming (v.)" doesn't always equate to shame actually being felt in the target of said shaming. The act of shaming loses a lot of effectiveness when you can find a community of people who will tell you that it's not actually shameful and that, "no actually the people shaming you are wrong" because those people will suddenly be your best friends. This can be good thing, homosexuality, or bad thing, nazis. And the internet has made every one of those communities 0 distance from everyone. It's why people who try to employ it cut you off from your support networks.

Shame is so effective when it actually lands that you can never fully deprogram it -- I will live with my Catholic guilt for the rest of my life.

Re: I pwned half of America's fast food chains simultaneously

#447

From Eva’s post: > we didnt know much about firebase at the time so we simply tried to find a tool to see if it was vulnerable to something obvious and we found firepwn, which seemed nice for a GUI tool, so we simply entered the details of chattr's firebase Genuinely curious (I’ve no infosec experience), wouldn’t there be a risk that a tool like this could phone home and log everything you find while doing research?

Sure but it's FOSS, so audits are pretty easy.

Plus as part of the pentesting I watch the network stack in Firefox sometimes so I would tell if it was trying to exfiltrate date

Re: I pwned half of America's fast food chains simultaneously

#448

Earlier quoted context omitted.

Note I'm not claiming disclosure is bad , but rather, this is a copy of a copy of a copy of a copy of a copy of a copy of how professionals handle these situations, to the point there's nothing left except the "1) pick a target 2) email them 3) write a blog post when fixed" parts.

What other steps have their ever been? Getting a CVE?

It's interesting because it's quite a postmodern situation.

They did do the most significant signifiers to a layman: hack, write a blog post, wait until fix before talking about it.

I'd have a better explanation for picking a target, avoid having competing versions of the story out there, avoid having one version having you targeting a company while another claims it was a general sweep, get the collaborators together and at least credit them in all versions of you can't get people to agree to write one post, avoid exaggerating, avoid claiming you hacked other companies, and add a contact or two before releasing the vulnerability.

Comparing a Project Zero blog post to this is a good idea, I went off of memory.

As it stands it sure sounds like some people were hanging out in Discord, scrolled through some JS in dev tools and / or ran some automated script against a site, then got puzzled and downloaded a pwner GUI to do the hard part, saw a fix, then rushed to write blog posts and stepped on each other's toes, one wildly exaggerating who was hacked while covering up details, another being honest but had ~0 idea of what they were supposed to say

Re: I pwned half of America's fast food chains simultaneously

#449
post #409

Earlier quoted context omitted.

> No rules or laws that require it It will just be FTC knocking on your door…

FTC will come knocking at your door even if you do pass an external audit and have Soc2/soc1/iso certification. Equifax is an example.

Who will promptly slap you on the wrist, wag their finger at you and send you on your way.

Re: I pwned half of America's fast food chains simultaneously

#450

Earlier quoted context omitted.

Yes, the CTO hopefully has nothing to do with lower level operations like that. But if they get a public burn they're going to issue a decree that will be addressed.

No what I mean is that it won’t even be in their org. The public website will belong to the head of corporate communications or some similar chief bullshit officer

Ah, yes. It looks like my post here did get the security folk involved -- but it appears that they've yet to fix it. The power of Hacker News!
Post reply on HN