Earlier quoted context omitted.
That's what I'm getting at with the expectation of privacy part. Talking into a drive thru speaker isn't really a private activity since everyone around can kinda hear it, but it'd probably be better to disclaim it anyway since someone attempting to file on you for it still costs money.
Is there an easy effective way to tell a company not to ask its customers' phone numbers if someone parked nearby can overhear them?
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
121–130 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#122Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#123Earlier quoted context omitted.
This seems to presume the company is ready and willing to take feedback. Maybe things are better now. Years ago the only contact for many companies was through customer service. "What do you mean you're in our computer? You're obviously on the phone!"
Also "Oh, you hacked us? We'll call the police right away. You're going to jail." - followed by you actually going to jail for many years. Sometimes, anonymous, public, uncoordinated disclosure actually leads to the best security outcome in the long run, since security researchers in jail isn't that.
Doing the right thing can be awfully unpleasant.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#124Burger King
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#125Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#126Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#127Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#128Earlier quoted context omitted.
But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?
Weak doors is fun comparison. Imagine if someone regular found homes locked by Masterlock locks. And then riffled through everything just to see if they are sufficiently secured. Then reported to owners asking for security bounty... I doubt that would go down very well, neither would it if you did that with businesses instead private home.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#129Earlier quoted context omitted.
As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#130It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.