Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

151–160 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#151

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

This sucks. As a developer who puts a lot of effort on security, I hate that companies can get away with such negligence.

I hope people invent AI bots which uncover vulnerabilities and make them available publicly for free, in real-time. This would create the right incentives for companies.

Modern software has become a giant house of cards, under the control of foreign powers who possess asymetric knowledge. This is because our overarching legal system protects mediocrity and this gives nefarious skilled people with a massive upper hand, while hurting well-intentioned skilled people who try to build software the right way.

The nefarious skilled people don't need to ask for permission and don't need to convince anyone to make money from their schemes... Well-intentioned skilled people build products which are impossible to sell or monetize because nobody cares enough about security... Companies mostly externalize the consequences of vulnerabilities to their users and leverage market monopolies to keep them.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#152

Earlier quoted context omitted.

There’s no liability or exposure for recording non-consensually. It’s a public space. There’s not even an edge case. If a random member if the public could walk into the drive-thru (which they can) then anything can be recorded without notification or consent. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: https://www.dmlp.org/legal-guide/massachusetts-rec…

A restaurant drive thru is private property open to the public. I think there may be a legal difference there.

There's generally not been held to be any difference for the purposes of expectation of privacy. If it's open to the public, the expectation is that anyone could overhear you.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#154
post #141

Earlier quoted context omitted.

As was I. But to extend the context: I don't see the relationship of either of those cases to anything being discussed here at all.

Drive thru conversations are not private under the Katz test, so there is no reasonable expectation of privacy. That makes video or audio recording in that setting lawful. Katz came about because the FBI recorded a gambler outside the booth with the doors closed. Hence we have the Katz test. Heck, you can even record someone making a drive thru order yourself and no one can do anything about it

If the question was about whether a warrant would be required to record a person at a Burger King drive-through, then sure: I'd bite.

But that kind of question does not appear to be related to anything in the context of the discussions here on HN.

You seem to have presented a red herring.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#155
post #154

Earlier quoted context omitted.

Drive thru conversations are not private under the Katz test, so there is no reasonable expectation of privacy. That makes video or audio recording in that setting lawful. Katz came about because the FBI recorded a gambler outside the booth with the doors closed. Hence we have the Katz test. Heck, you can even record someone making a drive thru order yourself and no one can do anything about it

If the question was about whether a warrant would be required to record a person at a Burger King drive-through, then sure: I'd bite. But that kind of question does not appear to be related to anything in the context of the discussions here on HN. You seem to have presented a red herring.

Not a red herring. The Katz test defines when a conversation is private, and a drive thru order does not meet that standard, so recording there is lawful even when it is done by a private person and not by law enforcement.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#156

Earlier quoted context omitted.

[flagged]

> It's a job for teenagers to get experience It all makes sense now! So that's why all fast food chains are closed from 9-3 on school days

[flagged]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#157

40-some years ago in L.A. some guys discovered that a Burger King drive-up kiosk was tied to the restaurant with an RF link. It was a simple matter to determine the frequency and modulation mode and program a hand-held transceiver to use the same link. They set up in an adjacent parking lot with a video camera and set about pranking the customers that drove up. The resulting video, titled "Attack on a Burger King" (t…

Ah, yes, A lot of old fast food drive-thru headsets were in VHF business band (and similar). The Phone Losers of America were well known for their exploits to that regard.

https://www.youtube.com/watch?v=cyLrus1yKvI

"I'm in the freezer at QuikTrip!"

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#158

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

[deleted]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#159
post #140

Earlier quoted context omitted.

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

Someone should see if YC will fund an ai-first company to help individuals and companies fight back against DMCA abuse and seek compensation

Interested to hear the financial model for this one.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#160
post #60

Earlier quoted context omitted.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

What about users who are affected by the vulnerability in the time it takes between reporting to the vendor and remediation?

That's the tradeoff. If you disclose it broadly without a grace period, someone who didn't even know about the vulnerability before will exploit it faster than even the best postured companies can fix it.
Post reply on HN