Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

151–160 of 328 posts

Re: What's inside the QR code menu at this cafe?

#151
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

> custom app.

That is always the worst experience. The most painful apps always require you to spend another 7 minutes after installation; typing in and verifying your credit card information... That has to be the most convoluted paying experience.

I was almost shocked when I rented a Hertz car (via IKEA), that everything was done through a website. The website asked for permission to use the phone camera to take pictures of the car etc. and off we went. Such a good experience compared to fiddling with a new app..

Re: What's inside the QR code menu at this cafe?

#152

Next up: "How I became a millionaire by consulting restaurants on Menu items and targeted Text Message Ads" ... Seriously, its a PII leak and it should be reported. And since you said Google is an investor someone (theoretically) should care.

I looked around to find a security contact at DotPe, and couldn’t find anything. Hopefully, this HN post raises enough alarms.

The fastest way to get in contact with DotPe would be to contact their biggest customer and informing them of this. They'd be on the phone with DotPe within an hour.

Good thing the APIs can be used to easily identify that company. /s

Re: What's inside the QR code menu at this cafe?

#153
post #83

> I would have thought about privately disclosing these findings to Dotpe. But all the API requests are right there in plain sight... There are pretty common ethical standards about disclosing vulnerabilities privately before disclosing them publicly. I don't see how the obviousness of the vulnerability changes the situation. By warning the company, you give them the opportunity to remedy the problem before announcin…

In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls. I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for…

Fully agree with you!

The API being unauthd is clearly a core design choice, and finding out any customer or service data is openly accessible with consecutive numbers through that API is not a zero day or something.

There is no "responsible disclosure" to be made here, going to the company and explaining what's the issue with all of this amounts to "handing out free consulting" if anything

Re: What's inside the QR code menu at this cafe?

#154
post #40
post #26

Earlier quoted context omitted.

No, that's the most inconvenience you can cause. There are worse things you can do: target specific people with spurious orders, cancel everything they order, or if you want add random items to every order, making the entire system useless.

people are underestimating the havoc this could create in a country like India. Imagine serving chicken at a table that is strictly vegetarian (many people in India are vegetarian due to religious reasons), will lead to a lot of outrage.

This could even be lethal if you are ordering something you know the target is allergic to...

Re: What's inside the QR code menu at this cafe?

#155
post #83

> I would have thought about privately disclosing these findings to Dotpe. But all the API requests are right there in plain sight... There are pretty common ethical standards about disclosing vulnerabilities privately before disclosing them publicly. I don't see how the obviousness of the vulnerability changes the situation. By warning the company, you give them the opportunity to remedy the problem before announcin…

In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls. I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for…

Just because someone or something is unethical doesn't mean we should be unethical as a response.

We shouldn't limit ourselves to only be responsible and disclose properly when the vulnerability suits us.

That is both unfair and irrational.

Re: What's inside the QR code menu at this cafe?

#156
I was waiting for a "I disclosed the vulnerability and this is how they reacted" story arc but there wasn't one. Pretty disappointed OP went this route. The golden rule is to always disclose the issue and wait for them to fix it before you publish. The only exception to this rule is if the company isn't acknowledging, responding, or communicating in any way. In that case you'd wait around three months, send a follow-up email warning them you'll publicly disclose the vulnerability, wait another three months, and then publish it.

Re: What's inside the QR code menu at this cafe?

#157
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

You're right, you are old-fashioned. I love order by phone. Any amount of time I'm sitting at a table trying to get a waiter to notice me and come by just feels like agony. Let me tell you exactly what I want, exactly when I want it.

Re: What's inside the QR code menu at this cafe?

#158
post #83

> I would have thought about privately disclosing these findings to Dotpe. But all the API requests are right there in plain sight... There are pretty common ethical standards about disclosing vulnerabilities privately before disclosing them publicly. I don't see how the obviousness of the vulnerability changes the situation. By warning the company, you give them the opportunity to remedy the problem before announcin…

Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.

Curious.

How is this, specifically, fraud?

Re: What's inside the QR code menu at this cafe?

#159
post #37

Earlier quoted context omitted.

I’m not sure if this could be considered “peak”. The ratio of waiting staff to customers is an obvious bottleneck. This inefficiency is simply accepted and not even really thought about, it’s just the way things are. But one thing I can say for this tech is it fixed it and the difference is noticeable.

inefficiency? It's part of the experience. I'm not in a restaurant or café to drink as fast as possible. I'm there to socialize as well. Waiting a bit is not a bottleneck, but a feature. (If I wanted speed, I'd take the drive-through).

To socialize with the people at your table, surely? Not do socialize with the waiter?

Re: What's inside the QR code menu at this cafe?

#160
post #83

> I would have thought about privately disclosing these findings to Dotpe. But all the API requests are right there in plain sight... There are pretty common ethical standards about disclosing vulnerabilities privately before disclosing them publicly. I don't see how the obviousness of the vulnerability changes the situation. By warning the company, you give them the opportunity to remedy the problem before announcin…

In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls. I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for…

Author is in India, I would be very careful because it's much more likely the government will prosecute them for unauthorised access and irresponsible disclosure than do anything to the company.

Truth is even in the west this kind of irresponsible disclosure could land you in jail, much more so in a developing country where these laws are all relatively new.

Post reply on HN