Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

281–290 of 328 posts

Re: What's inside the QR code menu at this cafe?

#283
post #172

Earlier quoted context omitted.

> 37,529 restaurants use Dotpe for QR codes. At that scale, it would take years to get fixed without forcing it like this. It's too small for them to care about the liability of security and too large to move quickly

> At that scale, it would take years to get fixed without forcing it like this. But it also might not take years. The point of responsible disclosure is to give them the opportunity. If they don't take it, fine - that's now on them. Instead this guy is committing fraud with actual financial damages (wasted food) and then sharing how others can commit the same fraud on a massive scale, potentially causing more damage.…

> fine - that's now on them

Is that legally true? The legal risk of having published this without responsible disclosure vanishes if the conventional period of opportunity is ignored? That smells fishy.

Re: What's inside the QR code menu at this cafe?

#285
post #237

Earlier quoted context omitted.

This principle is clear if you apply a real world analogy. Just because you happen to have keys to a building doesn't mean you can enter without authorization from the owner. (E.g. you may have kept copies after a lease expires or a sale, it maybe you found them, etc.)

Considering it’s a API available without any authorization, the better comparison would be walking around on unfenced private land. There’s nothing to indicate they don’t want people on it but it’s also obvious it’s private land.

It doesn't matter. It's still just as illegal to get into an unlocked car or one with wide open doors without permission. The same premise applies to computers in a lot of places, access controls don't matter. If you access something on a computer not indented to be accessible, it's considered a crime.

Re: What's inside the QR code menu at this cafe?

#286

Earlier quoted context omitted.

Curious. How is this, specifically, fraud?

People have been convicted of hacking for merely editing URL strings, under the theory that were knowingly accessing systems in ways that they were not supposed to. This would be similar. Whether or not that seems reasonable to us is a different matter, but basically it boils down to the fact that "they left the door unlocked" doesn't make it legal to walk in.

I believe the conviction of which you are thinking was overturned on appeal, though.

Re: What's inside the QR code menu at this cafe?

#287
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

In Japan, many chains are using tablets for their menu, and you can order through that. That's much better than having to pull whatever from a QR code.

Also in Japan, many restaurants have a vending machine you order from and pay at, then you get a ticket that you hand to the kitchen staff, who make your meal. They have been doing this for a long time.

Re: What's inside the QR code menu at this cafe?

#288
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

Will call you old fashioned for that. I recently went to a restaurant with a large group of friends and they used toast tab for online ordering. The experience was much better than ordering in person. Each family was able to order and pay for themselves. We could add extra items to our order whenever we wanted.

Without the app I would've had to keep an eye for a roaming waiter, call them out and then place an order. This takes away from the dining experience. I also don't like to wait for the server to clear plates, take the card, swipe it and get it back. The old fashioned ways will disappear for good.

Re: What's inside the QR code menu at this cafe?

#289

A guy went to prison for doing this with AT&Ts public subscriber data. The media didn't do him a favor by calling it a hack.

I almost got into big trouble at school for "hacking a teachers email". I guessed their email address (they were systematically generated) and sent an email. It's true you can get into trouble for this, but we need to all take it upon ourselves to make sure this doesn't happen. If this guy got into trouble I would hope every software engineer would be up in arms defending them.

It's not as simple: if you accessed something simply because it was badly protected yet you were obviously not supposed to access it, it's more of a grey area. I mean, imagine an uber-hacker for whom many a network is trivial to break in: they can always argue how it was insufficiently protected.

You accidentally stumbling on something unprotected generally clears you from any liability as long as you stop as soon as you notice it.

Code of conduct for white hat hackers is to explore but not abuse, and report as soon as they have enough clarity on the issue. But there is no legal basis for this avoiding any liability except if a company runs an official bounty program.

In that sense, the OP author could face hacking charges if India has similar laws to the rest of the developed world, and the author doesn't even have the "well intentioned" for their defence since they never reached out: the only defence they have is they did not attempt to profit off it.

IANAL, though :)

Re: What's inside the QR code menu at this cafe?

#290
post #239
post #218

Earlier quoted context omitted.

Seems outlandish. Citation needed? I'm aware of a couple of cases in the US, but not all over the world. Secondly: can consumers be blamed for gross negligence? It's not reasonable for a bank to post account balances in public billboard and ask people not to look at others. We should contest when private data is available publically, hidden only by small obfuscations, not professional security practices.

So for example in the UK with the computer misuse act, intent matters. If you intentionally change an id because you expect you will be able to access other data it becomes a crime. Your example is flawed because in this case the private data was not made available publicly at all – you need to intentionally exploit a software flaw to access it. Of course, it also matters how you handle it. If you do enough to just d…

I concede that intent matters.

Maybe a better analogy is a bank with open lockers and no vigilance: if someone enters and steals money, the police will look for them, because "the coffers were open" is not a valid defense. But customers will also demand answers from the bank - why were they so negligent and incompetent that someone can just enter and get their money?

We should hold similar values for digital systems.

Was the author's intent on stealing private data and causing harm? Did he gain from this abuse? Did the company take enough measures to safeguard their data?

Companies have been mostly not held responsible for their fuck ups, and no matter the law, that's wrong to me.

Post reply on HN