Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

111–120 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#112

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

I was about to repost that blog post on another site and now it looks like it was taken down.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#113
post #61
post #53

Earlier quoted context omitted.

I would argue that it is an ethical thing to do so if it sends a signal to pay whitehats appropriately.

Who is getting that signal? Burger King is almost certainly going to experience no damage from this. Their takeaway will likely be entirely non-existent. They’ll fix these bugs, they’ll probably implement zero changes to their internal practices, nor will they suddenly decide to spin up a bug bounty.

Yeah, the signal is not exclusively to Burger King.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#115

Earlier quoted context omitted.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

This seems to presume the company is ready and willing to take feedback. Maybe things are better now. Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"

Also "Oh, you hacked us? We'll call the police right away. You're going to jail." - followed by you actually going to jail for many years. Sometimes, anonymous, public, uncoordinated disclosure actually leads to the best security outcome in the long run, since security researchers in jail isn't that.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#116
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

users at large have a right to know if their data is being handled recklessly by any person or group, and just because some entity has arbitrary rules and poor communication/practices on how they want to tell them disclosures, it doesn't in any way make it irresponsible to let the public know: hey, your shit is getting recorded and is available for anyone to download and listen to.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#117
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

Are you in a position to hire security engineers?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#118
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

It could never be anywhere near as irresponsible as the original bad security practices, though. At some point, if you wanna make money by handling people's sensitive data, you are the responsible party, not everyone else.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#119

Earlier quoted context omitted.

No expectation of privacy in public and video can be taken. For example, security cameras that also happen to capture audio.

in which jurisdiction? Just because there's a device that breaks the law doesn't make the law go away.

Katz v. United States (1967)

Glik v. Cunniffe (1st Cir. 2011)

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#120

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

It won't change until there is better regulation with muscular enforcement. Right now the choice is between paying an $X bug bounty and the vague possibility of some problem for not paying a bounty (e.g., someone sues you, or a PR fiasco causes you to lose customers). That basically means a choice between a 100% chance of losing $X right now (to pay the bounty) or an unknown but probably low chance of an unknown but probably high cost later on. Without any specific incentives, most people making decisions at companies will just choose to gamble on the future, hoping that they can somehow dodge the consequences.

To change that calculus, the chance of that future cost needs to go up and the amount of it also needs to go up. If the choice is between a $100k bug bounty now and a $10-million-dollar penalty for a security breach, people will bite the bullet and pay the bounty. If the CEO knows he will lose his house if its discovered that he dismissed the report and benefited financially from doing so, he will pay the bounty.

The consequences need to be shifted to the companies that play fast and loose with customer data.

Post reply on HN