Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

141–150 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#141
post #136

Earlier quoted context omitted.

I don't see how either of those cases apply to regular people making recordings of regular citizens (in public, or not) using a microphone.

I was referring to video with a camera which has a microphone

As was I.

But to extend the context: I don't see the relationship of either of those cases to anything being discussed here at all.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#142
post #8

Great write-up! I was sorry to see there wasn’t a reward for you reporting this to them. At least you didn’t find that the bathroom rating tablets had audio as well!

> wasn’t a reward I'm pretty sure someone was willing to pay for this, but at least the researches acted responsibly.

Unlikely. If a company does not have a formal BBP, they won't pay 99.99% of the time. Brokers are also not interested in vulnerabilities in companies. They usually only buy vulnerabilities for standard software (components).

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#143
i swear god nothing can be cringer and funnier than when wannabe kiddo hackers write writeups. i can assure that they did dirty things for couple months before they actually report that but i can not prove it LMAO. I love this god level smart aleckness and the level of confidence is always ultimate LOL. idk man it is very sweet hahah. 50 grades of gray ahahahahahah

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#144
post #141

Earlier quoted context omitted.

I was referring to video with a camera which has a microphone

As was I. But to extend the context: I don't see the relationship of either of those cases to anything being discussed here at all.

Drive thru conversations are not private under the Katz test, so there is no reasonable expectation of privacy. That makes video or audio recording in that setting lawful.

Katz came about because the FBI recorded a gambler outside the booth with the doors closed. Hence we have the Katz test.

Heck, you can even record someone making a drive thru order yourself and no one can do anything about it

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#145
post #129

Earlier quoted context omitted.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

Some companies will keep systems vulnerable indefinitely. If a company hasn’t fixed the issue in a year, public disclosure is likely a better option than doing nothing.

Yes, that is why responsible disclosure almost always comes with deadlines. You give the chance for the company to resolve the issue and mitigate user impact. But if they are taking so long that the user impact will be higher than you just disclose.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#146

Honestly wondering if this is a legit use of DMCA. Like, what exact provision of the DMCA is being implicated here? One should have some reasonable means for challenging this kind of thing. But what do I know. It’s a scary world when you know a C&D or other legal nastygram is 100% bullshit and want to ignore it, but you’re chained to a vendor that can’t respond with any level of subtlety, just the ban-hammer for ever…

IANAL but it absolutely isn't.

DMCA is for copyright violations. They aren't providing any copyright protected information in the post. The nearest thing would probably be screenshots of their internal applications which seems to be to be obviously fair use.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#147
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

I get the sentiment and it’s a wise warning that at some point most people in grey hat spaces end up adhering to, but “do exactly as you’re allowed to do by large corporations” isn’t exactly a hacker ethos.

Those people don't announce what they did traceably to their real name and address, because they know if they do, they'll go to jail.

The police and the judge and the jury don't care what colour fabric you put on your head this morning. They (in theory) care if you committed a crime and they can prove it. Which you did and they can, since you confessed. So you go to jail for a long time.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#148

> Rating bathroom experiences: because everything needs a digital feedback loop At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's. For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy…

Now my local Burger King (in Las Vegas, NV, USA) has a sign at each table telling you that you have 30 minutes to eat your food and get out before you get thrown out for loitering.

[flagged]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#149

Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…

I suspect the post itself is legal but it's also a confession of highly illegal hacking.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#150
post #20

Earlier quoted context omitted.

[flagged]

[flagged]

> It's a job for teenagers to get experience

It all makes sense now! So that's why all fast food chains are closed from 9-3 on school days

Post reply on HN