Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

21–30 of 328 posts

Re: What's inside the QR code menu at this cafe?

#21
post #6

Nice find! There's a problematic but not critical personal information leak, a mild business intelligence leak and that's about it. > They could keep this script running for months, even years, creating awkward scenes and uncomfortable conversations at every restaurant across the country. If that's about the worst thing you can actively do, then it's only about the data leak.

"Why were you at X when you told me you were at Y? And why did you order for 2 people? Why have you been going there for the last Z months?"

"By following the pattern of when you were there and what you ordered, I found the other person's details too"

Re: What's inside the QR code menu at this cafe?

#22
post #5
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

is it really a vulnerability if the entire thing is open by design?

Who says it was? Why would they willingly give out their customers' and customers' customers data to any anonymous person or a bot? More likely a bad oversight

Re: What's inside the QR code menu at this cafe?

#23
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

As a fully capable person I can't stand being waited on. For me the peak ordering experience is I choose an item from some written menu with prices on it, ask for said item and pay exactly the price written on the menu. Then I either take item immediately or come to collect it later to take it to the table myself.

When I want to leave I just get up and go without the stupid ask to know how much I need to pay then ask again to actually pay with expectation that I pay more than what was asked like it's my choice to pay but really it isn't.

Re: What's inside the QR code menu at this cafe?

#25
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

Is it a vulnerability when it is obvious the company do not care about security?

Yes. Because who at the "company" does even know about this? Maybe just some coder who wrote it. But the legally liable CEO? Maybe not.

Re: What's inside the QR code menu at this cafe?

#26
post #6

Nice find! There's a problematic but not critical personal information leak, a mild business intelligence leak and that's about it. > They could keep this script running for months, even years, creating awkward scenes and uncomfortable conversations at every restaurant across the country. If that's about the worst thing you can actively do, then it's only about the data leak.

No, that's the most inconvenience you can cause. There are worse things you can do: target specific people with spurious orders, cancel everything they order, or if you want add random items to every order, making the entire system useless.

Re: What's inside the QR code menu at this cafe?

#27
Now, that went rogue quite fast and easily. I still find it confusing when some dev opt for the "let's not think about security, tokens, POST requests and whatever".

I am sure some companies using that service will ask for more closed doors before everyone can lookup their revenues. That's one big example of a non technical vulnerability based on a 101 technical principle.

Re: What's inside the QR code menu at this cafe?

#28
I like to scan the "specialized" bar/QR codes I come across in my daily life in case they're not just URLs. Sometimes I find some interesting stuff and possibly some opportunities for mild exploits.

The other day I was at burger king. They allow you to refill your drink as many times as you like within 60 minutes of purchasing it, and the way this restriction is implemented is by having you scan a QR code they print on your receipt at the drink machine. I scanned the QR code with Binary Eye (android app that reads all sorts of barcodes, highly recommended). It contained some numbers I couldn't immediately recognize as interesting, a timestamp in a format similar to 202409231049, and a UUID.

Now, the UUID is probably the ID of the order in their internal system, so the question is: does the drink machine only read the timestamp or does it also use the UUID to query the internal system to re-validate it? Can you craft a QR code with the same data but change the timestamp to achieve for infinite refills?

Re: What's inside the QR code menu at this cafe?

#29

Earlier quoted context omitted.

If you discovered an incompetent healthcare provider was prescribing antibiotics for every condition would you "contact them privately" or contact the relevant authorities? Private disclosure is for when you believe the company cares about security but made a genuine mistake. For the company in the OP it would be more like free education in fundamental privacy and ethics. They're not entitled to that. Name and shame.

Sure, but what you’re describing is not what is being suggested. Responsible disclosure typically involves disclosing publicly after a reasonable period of time.

Right but would you afford the same opportunity to the healthcare provider? You'd contact them privately and expect them to go and learn why over prescription of antibiotics is a bad thing and change their ways? Of course you wouldn't. You'd go to someone who cares. In healthcare there are ways you can report it without naming and shaming publicly, but how could the author do that?
Post reply on HN