Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

161–170 of 328 posts

Re: What's inside the QR code menu at this cafe?

#161

Earlier quoted context omitted.

In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls. I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for…

Fully agree with you! The API being unauthd is clearly a core design choice, and finding out any customer or service data is openly accessible with consecutive numbers through that API is not a zero day or something. There is no "responsible disclosure" to be made here, going to the company and explaining what's the issue with all of this amounts to "handing out free consulting" if anything

Unfortunately that is not how the law works, at least in most countries. As soon as you enumerate ids regardless of whether there is any security in place it is unauthorised access and it's illegal.

Re: What's inside the QR code menu at this cafe?

#162

Earlier quoted context omitted.

Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.

Curious. How is this, specifically, fraud?

People have been convicted of hacking for merely editing URL strings, under the theory that were knowingly accessing systems in ways that they were not supposed to. This would be similar.

Whether or not that seems reasonable to us is a different matter, but basically it boils down to the fact that "they left the door unlocked" doesn't make it legal to walk in.

Re: What's inside the QR code menu at this cafe?

#163

Earlier quoted context omitted.

Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.

Curious. How is this, specifically, fraud?

He is in India:

If any person without permission of the owner or any other person who is incharge of a computer, computer system or computer network

- (a) accesses or secures access to such computer, computer system or computer network or computer resource;

- (b) downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium;

[...]

- (e) disrupts or causes disruption of any computer, computer system or computer network;

[...]

- (g) provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder;

If any person, dishonestly or fraudulently, does any act referred, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both.

====

Though, I prefer a lot the poster of the blog post than the company...

Re: What's inside the QR code menu at this cafe?

#164
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

Peak is to me where we can sit and order and pay, and do not get interrupted so we can actually talk.

Re: What's inside the QR code menu at this cafe?

#165
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

In Japan, many chains are using tablets for their menu, and you can order through that. That's much better than having to pull whatever from a QR code.

It is almost exactly the same.

Re: What's inside the QR code menu at this cafe?

#167
post #5
post #2

I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.

is it really a vulnerability if the entire thing is open by design?

Yes! You as a user are not meant to knowingly access data that does not belong to you. Even something like changing the id from 1 to 2 is legally considered unauthorised access.

It would be different if for example the application was showing data for other customers through normal use of it, but even if there is no other barrier to access than changing an id that is considered bypassing access control and can result in jail time in most places. Now I'm not an expert in India's computer misuse laws but I am willing to wager they are not the most progressive when it comes to this kind of thing.

Re: What's inside the QR code menu at this cafe?

#168

Earlier quoted context omitted.

Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.

Curious. How is this, specifically, fraud?

I don't know Indian laws. But this wikipedia page [1] gives a list of types of computer fraud in the US under the CFAA:

Types of computer fraud include: * [...] * Accessing unauthorized computers * [...]

He accessed their computers to access purchase information of other people (e.g. his friend) and business data. I guess making it public, thereby damaging the companies reputation and potentially getting sued by their lawyers is one way to find out, whether he was "unauthorized" to do so.

[1] https://en.wikipedia.org/wiki/Computer_fraud

Re: What's inside the QR code menu at this cafe?

#169
post #90
post #55

Earlier quoted context omitted.

Have to disagree with this. At a group meet-up where everyone arrives at different times and wants their order to come shortly after they do, a digital system is so much better. These type of meetups are quite common as a parent.

> where everyone arrives at different times and wants their order to come shortly after they do Good god man! At a social meal, we eat together; children included as this is how they learn to socialise. One would be a little concerned and puzzled if arriving for a meal, one finds others have already eaten.

As another commenter said, this is probably partly down to cultural expectations. The ideal would be to sit and eat together. In reality, one family might get held by up to an hour because their baby napped later than normal; another family is half an hour late because of traffic; another family had an nightmare nappy blowout situation and has to go back home for new clothes etc... . Being relaxed about arrival times is less stressful all round. The children will still socialise with each other in the overlapping times they are together.

Re: What's inside the QR code menu at this cafe?

#170
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

Similarly old fashioned here. If there's no menu and/or no table (or bar) staff to take an order, I simply walk out.
Post reply on HN