And.. its down “Blog post not found” archive link here: https://archive.is/zIteR
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
111–120 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#112Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#113Earlier quoted context omitted.
I would argue that it is an ethical thing to do so if it sends a signal to pay whitehats appropriately.
Who is getting that signal? Burger King is almost certainly going to experience no damage from this. Their takeaway will likely be entirely non-existent. They’ll fix these bugs, they’ll probably implement zero changes to their internal practices, nor will they suddenly decide to spin up a bug bounty.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#114Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#115Earlier quoted context omitted.
I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…
This seems to presume the company is ready and willing to take feedback. Maybe things are better now. Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#116Earlier quoted context omitted.
As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#117Earlier quoted context omitted.
As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#118Earlier quoted context omitted.
As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#119Earlier quoted context omitted.
No expectation of privacy in public and video can be taken. For example, security cameras that also happen to capture audio.
in which jurisdiction? Just because there's a device that breaks the law doesn't make the law go away.
Glik v. Cunniffe (1st Cir. 2011)
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#120Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
To change that calculus, the chance of that future cost needs to go up and the amount of it also needs to go up. If the choice is between a $100k bug bounty now and a $10-million-dollar penalty for a security breach, people will bite the bullet and pay the bounty. If the CEO knows he will lose his house if its discovered that he dismissed the report and benefited financially from doing so, he will pay the bounty.
The consequences need to be shifted to the companies that play fast and loose with customer data.