Earlier quoted context omitted.
In this case? Nope. This must be treated as willful design decision to open up API to entire public (including PII/phone-number leak as per design), even if they say they totally didn't meant that to happen. Government itself should then be notified to go after these guys for failing to do the most basic access controls. I mean, come on! To treat this as a proper security vulnerability just gives too much leeway for…
Fully agree with you! The API being unauthd is clearly a core design choice, and finding out any customer or service data is openly accessible with consecutive numbers through that API is not a zero day or something. There is no "responsible disclosure" to be made here, going to the company and explaining what's the issue with all of this amounts to "handing out free consulting" if anything
What's inside the QR code menu at this cafe?
161–170 of 328 posts
Re: What's inside the QR code menu at this cafe?
#162Earlier quoted context omitted.
Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.
Curious. How is this, specifically, fraud?
Whether or not that seems reasonable to us is a different matter, but basically it boils down to the fact that "they left the door unlocked" doesn't make it legal to walk in.
Re: What's inside the QR code menu at this cafe?
#163Earlier quoted context omitted.
Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.
Curious. How is this, specifically, fraud?
If any person without permission of the owner or any other person who is incharge of a computer, computer system or computer network
- (a) accesses or secures access to such computer, computer system or computer network or computer resource;
- (b) downloads, copies or extracts any data, computer data base or information from such computer, computer system or computer network including information or data held or stored in any removable storage medium;
[...]
- (e) disrupts or causes disruption of any computer, computer system or computer network;
[...]
- (g) provides any assistance to any person to facilitate access to a computer, computer system or computer network in contravention of the provisions of this Act, rules or regulations made thereunder;
If any person, dishonestly or fraudulently, does any act referred, he shall be punishable with imprisonment for a term which may extend to three years or with fine which may extend to five lakh rupees or with both.
====
Though, I prefer a lot the poster of the blog post than the company...
Re: What's inside the QR code menu at this cafe?
#164> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.
Re: What's inside the QR code menu at this cafe?
#165> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.
In Japan, many chains are using tablets for their menu, and you can order through that. That's much better than having to pull whatever from a QR code.
Re: What's inside the QR code menu at this cafe?
#166Re: What's inside the QR code menu at this cafe?
#167I am confused, they didn't contact the company at all and just disclose this publicly? Very immature handling of a vulnerability finding.
is it really a vulnerability if the entire thing is open by design?
It would be different if for example the application was showing data for other customers through normal use of it, but even if there is no other barrier to access than changing an id that is considered bypassing access control and can result in jail time in most places. Now I'm not an expert in India's computer misuse laws but I am willing to wager they are not the most progressive when it comes to this kind of thing.
Re: What's inside the QR code menu at this cafe?
#168Earlier quoted context omitted.
Adding to this, in some countries he is already past the gray-area to what constitutes as computer fraud. Pissing off the company, whose systems you accessed without authorization, is one way of getting to experience the full force of the justice system.
Curious. How is this, specifically, fraud?
Types of computer fraud include: * [...] * Accessing unauthorized computers * [...]
He accessed their computers to access purchase information of other people (e.g. his friend) and business data. I guess making it public, thereby damaging the companies reputation and potentially getting sued by their lawyers is one way to find out, whether he was "unauthorized" to do so.
Re: What's inside the QR code menu at this cafe?
#169Earlier quoted context omitted.
Have to disagree with this. At a group meet-up where everyone arrives at different times and wants their order to come shortly after they do, a digital system is so much better. These type of meetups are quite common as a parent.
> where everyone arrives at different times and wants their order to come shortly after they do Good god man! At a social meal, we eat together; children included as this is how they learn to socialise. One would be a little concerned and puzzled if arriving for a meal, one finds others have already eaten.
Re: What's inside the QR code menu at this cafe?
#170> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.