Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

11–20 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#11
The only way this shit show will ever stop is if behavior like this is ultimately rewarded with a corporate death penalty.

E.g. their trademarks being put in the public domain and assets confiscated to compensate their victims.

The watch in amazement at how actual security suddenly becomes a priority.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#13
Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time).

I’m curious about the legal/reputational implications of this.

I personally found some embarrassing security vulnerabilities in a very high profile tech startup and followed responsible disclosure to their security team, but once I got invited to their HackerOne I saw they had only done a handful of payouts ever and they were all like $2k. I was able to do some pretty serious stuff with what I found and figured it was probably more like a $10k-$50k vuln, and I was pretty busy at the time so I just never did all the formal write up stuff they presumably wanted me to do (I had already sent them several highly detailed emails) because it wouldn’t be worth a measly $2k. Does that mean I can make a post like this?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#14
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

I get the sentiment and it’s a wise warning that at some point most people in grey hat spaces end up adhering to, but “do exactly as you’re allowed to do by large corporations” isn’t exactly a hacker ethos.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#15
post #8

Great write-up! I was sorry to see there wasn’t a reward for you reporting this to them. At least you didn’t find that the bathroom rating tablets had audio as well!

> wasn’t a reward

I'm pretty sure someone was willing to pay for this, but at least the researches acted responsibly.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#16
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#17
The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream?

I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#18
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

genuinely interested in the last known story of someone going to prison for this type of pen testing without an established bug bounty.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#20
post #5

I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an ex…

[flagged]
Post reply on HN