Live data from Hacker News

Trusting clients is probably a security flaw

liberda.nl

71–80 of 150 posts

Re: Trusting clients is probably a security flaw

#71
post #6

Earlier quoted context omitted.

This sort of things happens a lot. A few years ago a British bus company put certificates in the app to sign tickets. The HSBC UK app will not run if you have any apps installed from outside play store. I cannot log into the website without the app. Luckily all I have with them is a lightly used credit card with a low limit so I have just stopped using it and rely on paper statement. I find it disturbing that any app…

The app works for me just fine despite having lots of non-google play apps installed, is this an Android 15 thing?

It works fine for me on Android 15 with non-Google Play apps installed too.

Re: Trusting clients is probably a security flaw

#72
I'm about 90% sure that for some inane reason, McDonalds outsources and creates separate apps for each country/region with these disastrous security flaws, except that at HQ they universally demand horrifically counter-productive "anti-root" measures for every locale, to a larger extent than even finance apps.

Why am I so sure about this? I live on the other side of the world, the app is almost certainly an entirely separate codebase from the Polish one the article is about, and yet here too it has the worst anti-root measures of any app by any remotely large company, including finance, healthcare and government apps. Enormous numbers of false positives. Even for those with the most mainstream Android models around.

This will all just come down to one person at McD's HQ who is forcing through these ridiculous ideas and costing their company a bunch of money in the process. No other multinational employs this strategy to any similar degree.

Re: Trusting clients is probably a security flaw

#74
post #72

I'm about 90% sure that for some inane reason, McDonalds outsources and creates separate apps for each country/region with these disastrous security flaws, except that at HQ they universally demand horrifically counter-productive "anti-root" measures for every locale, to a larger extent than even finance apps. Why am I so sure about this? I live on the other side of the world, the app is almost certainly an entirely…

think of it as each country being its own company, contracting out to a local software house which may have different ideas of what security means

Re: Trusting clients is probably a security flaw

#75

In reality, since COVID, the coupons in Polish McD are so bad the app is almost useless. And the current version loads so sluggishly.

Coupons aside, the whole process of eating at McD in PL is demeaning to me every time I'm there. From the clunky app that you basically must have to get anything at a decent price, to the kiosks that work slower that ATMs 20 years ago, to the whole flow of selecting your meal that requires like 15 taps that feels like installing Windows 98, up to the end where it tries to sell you some dessert that you would have selected if you wanted it in the first place.

Re: Trusting clients is probably a security flaw

#76

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

> professional body membership is becoming more important for programmers. People need to be able to say "I studied what you asked me to make, and refuse to work on this illegal, insecure, depressing cruft, and if you fire me for having professional ethics my lawyers will empty your company bank account." I think this might be an interesting one to consider, other than the "depressing" bit of course. The problem is,…

And who's the "you" in that case? If you're on a team of ten developers working for a shoddy company - because your family can't eat lofty principles - and a bad piece of software is released, who loses their accreditation? Is it the whole team? Do we go through the commits one by one? Is it just the tech lead, or the PM, or the engineering manager?

Re: Trusting clients is probably a security flaw

#77

In reality, since COVID, the coupons in Polish McD are so bad the app is almost useless. And the current version loads so sluggishly.

Coupons aside, the whole process of eating at McD in PL is demeaning to me every time I'm there. From the clunky app that you basically must have to get anything at a decent price, to the kiosks that work slower that ATMs 20 years ago, to the whole flow of selecting your meal that requires like 15 taps that feels like installing Windows 98, up to the end where it tries to sell you some dessert that you would have sel…

Yeah, other fast food chains use M4B kiosks which work much smoother. Although upsells are still there ;)

Re: Trusting clients is probably a security flaw

#78

Ick. That turned my stomach. Sure it's bad for end users that corporate mobile app development is a swamp. In this case it only affects the vendor who lost out on users and reputation. But cavalier, reckless engineering equally causes harm to the client device or end user - if only in wasted time. Given the audience here, I hope many would agree it's pitiful that developers are wasting their time building this junk.…

I think you should study how well such professional posturing helps groups that have it (civil engineers, lawyers, etc). In my experience it’s a symbolic political power that management has effective ways of limiting.

Uhh... lawyers are doing quite well for themselves, aren't they?

Re: Trusting clients is probably a security flaw

#79
post #2

This is like the fifth article I've read about the McDonald's app not having any sort of server-side validation. How do they keep getting this wrong???

More importantly, why would anyone care? Is this some 5th dimensional chess marketing strategy by McDonald's? I hear more about their app these days than ever, and more than about any other security issue anywhere else.

I think it's the combination of trying very hard to usurp the user's control over their device, the lack of obvious reasons to do so, and the size of the brand. It doesn't surprise anybody when a bank does this, and nobody cares when some crappy pay to win game does, but McDonalds?!

I haven't eaten food from McDonalds in years and have never even considered installing their app, but if inspecting and reverse-engineering Android apps was my thing, theirs would have almost certainly caught my interest.

Re: Trusting clients is probably a security flaw

#80
post #78

Earlier quoted context omitted.

I think you should study how well such professional posturing helps groups that have it (civil engineers, lawyers, etc). In my experience it’s a symbolic political power that management has effective ways of limiting.

Uhh... lawyers are doing quite well for themselves, aren't they?

The ones who own the firm do. They are the managers.

Also I think you mistook my comment for something about financial success. I am questioning how much power a lawyer has to invoke moral authority (unless they own the firm).

Post reply on HN