Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

121–130 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#121

Earlier quoted context omitted.

That's what I'm getting at with the expectation of privacy part. Talking into a drive thru speaker isn't really a private activity since everyone around can kinda hear it, but it'd probably be better to disclaim it anyway since someone attempting to file on you for it still costs money.

Is there an easy effective way to tell a company not to ask its customers' phone numbers if someone parked nearby can overhear them?

They steer you towards ordering on the mobile app instead, which typically gives you a 4-6 digit confirmation code which you then use combined with your name, when you pick up. And/or your receipt in the app.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#123

Earlier quoted context omitted.

This seems to presume the company is ready and willing to take feedback. Maybe things are better now. Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"

Also "Oh, you hacked us? We'll call the police right away. You're going to jail." - followed by you actually going to jail for many years. Sometimes, anonymous, public, uncoordinated disclosure actually leads to the best security outcome in the long run, since security researchers in jail isn't that.

Yes. I live in a state where a journalist reported a Department of Education system leaking teacher SSNs and the governor sent state troopers after him.

Doing the right thing can be awfully unpleasant.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#125

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They want capitalism, give them capitalism. If you can make more money exploiting it and selling to mafias and gangs and nation states. Do it.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#126

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

You should consult a lawyer. The first thing they’ll probably want to see is the terms you agreed to on hackerone.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#127
It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#128
post #107

Earlier quoted context omitted.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

Weak doors is fun comparison. Imagine if someone regular found homes locked by Masterlock locks. And then riffled through everything just to see if they are sufficiently secured. Then reported to owners asking for security bounty... I doubt that would go down very well, neither would it if you did that with businesses instead private home.

[deleted]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#129
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

Some companies will keep systems vulnerable indefinitely. If a company hasn’t fixed the issue in a year, public disclosure is likely a better option than doing nothing.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#130
post #127

It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.

Back in 2008–2009, we had a lot of bare metal servers at SoftLayer's (Dallas, TX) facility. One of our customers ran a South American music forum, and anytime someone uploaded an MP3, the data center would honor the DMCA request and immediately stop routing traffic to the server until the issue was resolved. Now imagine what tools they might have in their arsenal in 2025.
Post reply on HN