Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

11–20 of 328 posts

Re: What's inside the QR code menu at this cafe?

#11
post #6

Nice find! There's a problematic but not critical personal information leak, a mild business intelligence leak and that's about it. > They could keep this script running for months, even years, creating awkward scenes and uncomfortable conversations at every restaurant across the country. If that's about the worst thing you can actively do, then it's only about the data leak.

Aren't phone numbers being leaked if you iterate over the tables?

Yeah, that's the PII leak.

Re: What's inside the QR code menu at this cafe?

#12
reminds me of this Aussie cleaning company's website that forced you to create an account to take an order.

With a couple of clicks on the web app, you'd encounter a bug... and then you can see every single person's orders, email, and personal addresses. And it was my partner who discovered it (she was struggling to order service through the website bc it kept failing).

Oh and they also never charged us for service despite multiple emails asking them how we should pay (somehow we were able to order service through the site but never paid?)

Clearly they're not a serious company...

Re: What's inside the QR code menu at this cafe?

#13
> Is this what the peak ordering experience looks like?

Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

Re: What's inside the QR code menu at this cafe?

#14

A guy went to prison for doing this with AT&Ts public subscriber data. The media didn't do him a favor by calling it a hack.

I almost got into big trouble at school for "hacking a teachers email". I guessed their email address (they were systematically generated) and sent an email. It's true you can get into trouble for this, but we need to all take it upon ourselves to make sure this doesn't happen. If this guy got into trouble I would hope every software engineer would be up in arms defending them.

Re: What's inside the QR code menu at this cafe?

#17
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

The author says "I refuse to believe they’re unaware of this. This doesn’t feel like an oversight, it's either a deliberate design decision or they just don't care." Agree that this is an uncharitable way of looking at it.

Yep. It’s just working backwards from some pre existing very negative worldview.

Re: What's inside the QR code menu at this cafe?

#18
post #12

reminds me of this Aussie cleaning company's website that forced you to create an account to take an order. With a couple of clicks on the web app, you'd encounter a bug... and then you can see every single person's orders, email, and personal addresses. And it was my partner who discovered it (she was struggling to order service through the website bc it kept failing). Oh and they also never charged us for service d…

Isn't service taken into account in the price of the meals?

Re: What's inside the QR code menu at this cafe?

#19
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

If you discovered an incompetent healthcare provider was prescribing antibiotics for every condition would you "contact them privately" or contact the relevant authorities? Private disclosure is for when you believe the company cares about security but made a genuine mistake. For the company in the OP it would be more like free education in fundamental privacy and ethics. They're not entitled to that. Name and shame.

Sure, but what you’re describing is not what is being suggested. Responsible disclosure typically involves disclosing publicly after a reasonable period of time.

Re: What's inside the QR code menu at this cafe?

#20
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

Disagree.

Most likely the company will blame them for trying to help. Also, if the company is so incompetent that they allow this why bother. He's not getting paid to be their test engineer.

Post reply on HN