Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

101–110 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#101

> Rating bathroom experiences: because everything needs a digital feedback loop At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's. For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy…

Now my local Burger King (in Las Vegas, NV, USA) has a sign at each table telling you that you have 30 minutes to eat your food and get out before you get thrown out for loitering.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#102

Earlier quoted context omitted.

Please stop spreading misinformation . There are so many court cases about this. A quick google will give you dozens you can read. Legally there is no “reasonable expectation of privacy” in public spaces and the only limit on that are extreme telephoto lenses looking from public spaces into private spaces. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: htt…

Unfortunately, you are not correct.[1] Recording police in a public place-- sure. Otherwise, eh, at best you're over-extrapolating (and ungenerously!) from your local circumstance. [1] https://www.dmlp.org/legal-guide/massachusetts-recording-law

Okay, wow -- I stand corrected. I will edit my comments. It will take me awhile to wrap my head around Massachusett's-style state-level restrictions. While I wouldn't personally expect this to survive a Supreme Court adjudication, apparently there exists no Supreme Court ruling either upholding or striking down the prohibition on secretly recording oral conversations in public.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#103

Earlier quoted context omitted.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

You're assuming that the choice is between immediate public disclosure and coordinated disclosure. Doing "the responsible thing" takes effort that is often disrespected (sometimes to the extreme). I'm so sick and tired of some companies that any vulnerability I find in their products going forward is an immediate public disclosure. It's either that or no disclosure, and it would be irresponsible not to disclose it at…

Agreed.

Cracked a thrift store IoT medical device. Contacted vendor. They sent me a one way NDA. Lol no.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#104
post #54

Earlier quoted context omitted.

Why and what gives you the right to tell them off? Hacking is hacking. If they wish to risk it, what's your problem? They know the risks. Everyone knows hacking is illegal. Same with selling drugs; illegal yet folk do. Same premise. Get caught; no sympathy given. "People may get hurt"? $country throw folk in to war; it's a harsh world we live in. Bug bounty's are only the new norm because the younger audience want va…

It’s a free country, etc. Obviously I have the “right” to comment a warning on the internet. The point of bug bounties isn’t “validation” (as if old-school hackers didn’t want validation!), it’s that companies with responsible disclosure programs explicitly allow you to pentest them as long as you follow their guidelines. That removes the CFAA indictment risk. The guidelines generally aren’t much stricter than common…

> It’s a free country, etc.

But it didn't come across a warning. "You need to stop" is a demand not a warning. And I would like to believe they would know this when post online. if not /shrug.

Maybe they're working on behalf of an organization, a country that doesn't follow CFAA; Russia, China? Maybe they're state sponsored or under protection. They're obviously not stupid if they can infiltrate Fast-Food chains and social engineer others but I've been wrong before.

> is a bad idea

I would be surprised if they didn't. If not, okay well if shit hits the fan; no sympathy for me. Unlucky. They're doing it at their own risk.

> Isn’t it better that hackers today have a way to find real vulnerabilities without going to jail?

A doubled edged sword, I personally wouldn't count them as hackers. They're not hacking, they're penetrating based on T&C of an agreement. Yes, it could be called "ethical hacking" but I still wouldn't call it hacking.

A hacker is one who gains unauthorized access to computer. Hacking isn't such when your granted restricted access on a basis of T&C.

> Isn’t it better that hackers today have a way to find real vulnerabilities without going to jail?

I don't disagree, if that's your skill then go for it. It's the safest route allowing you to harness your skills, and which may provide future prospects. A dispensary selling drugs is better than the dealer on the corner of the street.

"To hack a bank" is different then to "hack a bank based on some agreement". One carries more weight then the other. Your penetrating a bank on an agreement. Your not hacking.

Bug bounty hunters to have faced jail, lawsuits, or threats — even when acting in good faith, it doesn't make you invulnerable.

I admire the persona of who this is, their acts highlights concern to us who use such conveniences. It exposes truth and tackles the issue at hand where others may exploit you because of. It shows negative light to corporations that many folk who daily.

Their title as on their blog "Ethical Hacker" I would say suitable to describe them as that. It's not like they're siphoning money off folk from ransomware.

> Most of what you’re saying just seems like nostalgia talking.

What I was demonstrating as someone who's been in trouble due to misunderstanding computer mishaps as a teen back when, also to establish my point that I know what I am talking about.

Yeah, it turned in to a nostalgia trip. I'd call myself more of a script kiddie and one who I'd see myself as white-hat.

Black-hat can be interesting however my moral compass has caught up with me and that my life has more worth that it would be jeopardous to do such besides I don't have the time and among other things.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#105

Earlier quoted context omitted.

Thats only for private phone calls not for public spaces. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: https://www.dmlp.org/legal-guide/massachusetts-recording-law The laws prohibiting these recordings have neither been upheld nor overturned by the US Supreme Court.

I could easily see a judge regarding the conversation over a drive thru speaker as not a public space and more like a telephone call.

No expectation of privacy in public and video can be taken. For example, security cameras that also happen to capture audio.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#106
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

This seems to presume the company is ready and willing to take feedback.

Maybe things are better now.

Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#107
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

Weak doors is fun comparison. Imagine if someone regular found homes locked by Masterlock locks. And then riffled through everything just to see if they are sufficiently secured. Then reported to owners asking for security bounty...

I doubt that would go down very well, neither would it if you did that with businesses instead private home.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#108
post #34

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed.

Even the most security-aware companies have a process to fix vulnerabilities, which takes time.

I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement.

In the case of bobdajrhacker? Both.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#109
It's incredible that a chain that produces terrible food has such a large surveillance system for underpaid employees.

Surely the IT workers are also underpaid, which is why they left the doors wide open.

That only confirms the subpar quality of the executives, the food, and everything at Burger King.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#110

Earlier quoted context omitted.

I could easily see a judge regarding the conversation over a drive thru speaker as not a public space and more like a telephone call.

No expectation of privacy in public and video can be taken. For example, security cameras that also happen to capture audio.

in which jurisdiction? Just because there's a device that breaks the law doesn't make the law go away.
Post reply on HN