Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

161–170 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#161

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

[flagged]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#162

Earlier quoted context omitted.

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

[flagged]

I still don’t get it. What does copyright have to do with the post?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#164
post #140

Earlier quoted context omitted.

Someone should see if YC will fund an ai-first company to help individuals and companies fight back against DMCA abuse and seek compensation

Interested to hear the financial model for this one.

Flat fee, plus percentage of the winnings from damage claims?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#165

Earlier quoted context omitted.

This story is a pen test gone wrong, so somewhat different, but illustrates some of the same failure modes. https://www.darkreading.com/vulnerabilities-threats/dark-rea...

More info here: https://iowacapitaldispatch.com/2023/06/23/lawsuit-over-auth...

Oh, this is a rabbit hole. As far as I can tell the pentesters' suit against the sheriff is still ongoing, but back in Iowa courts. The federal court's ruling is ... not good [1]:

1) The court found that the county sheriff had the pentesters arrested and encouraged their prosecution _not_ because he believed there was any crime, but instead that was angry at some state official. (Which, y'know, sounds like a pretty serious civil rights violation.)

2) However, the civil rights / 4th amendment claims were dismissed by the federal court due to "qualified immunity", the doctrine where, in any sufficiently "unique" or "specific" situation, the police have no liability whatsoever for their actions [2].

[1] https://storage.courtlistener.com/recap/gov.uscourts.iasd.84... [2] https://en.wikipedia.org/wiki/Qualified_immunity

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#167
post #162

Earlier quoted context omitted.

I still don’t get it. What does copyright have to do with the post?

[flagged]

Just because it's the tool they have doesn't legitimize the use of a copyright takedown just to take down information they do not like. DMCA is specific and in theory limited (though many companies abuse it) the proper channel for non infringing content you don't like is the courts.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#168
post #162

Earlier quoted context omitted.

I still don’t get it. What does copyright have to do with the post?

[flagged]

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over.

You can see on the email that the "Original work" field is just a link to the BK website.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#169

Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…

> Why do security researchers privately inform companies of vulnerabilities and wait for them to patch before public disclosure? Are they afraid of liability?

You don't publish because you don't want to cause harm and you don't want to be liable for it.

You need to realize that vulnerabilities don't exist in a vacuum. They grant access to computer systems that control the life of people (millions of people) including their personal information, passwords, passport photos, card numbers, jobs, paychecks, transportation, food, etc... which is very likely to cover yourself, your mom, your family, your friends as you deal with larger companies.

When you publish a vulnerability, it will immediately be used by bad actors that intend to cause harm to all these people, including employees and customers.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#170
post #162

Earlier quoted context omitted.

I still don’t get it. What does copyright have to do with the post?

[flagged]

> Why do you think copyright has anything to do with the post?

Because the Digital Millenium Copyright Act is for copyright. You haven't stated how the blog post infringes upon BK's copyright at all, so... yes, seems like a standard fraudulent DMCA claim.

> First thing first. This is NOT DMCA abuse. The DMCA is the only way to communicate with web companies and take down content. As such, it has become the legitimate way to take down any content that needs to be taken down, in the absence of alternatives.

This assumes that companies should be able to take down any content they do not like. This is very much not the case. The DMCA is very specifically only for copyrighted content.

From copyright.gov[1]:

> To be effective, a notice must contain substantially the following information:

> ...

> (v) a statement that the person sending the notice has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law; and

> (vi) a statement that the information in the notice is accurate, and under penalty of perjury, that the person sending the notice is authorized to act on behalf of the copyright owner .

This is pretty clearly DMCA abuse. TFA isn't using any of BK's copyrighted content, which is what a DMCA claim alleges. Just because people have abused the form... pretty much since inception does not mean that it's not perjury to do so.

If BK wants to press charges for unauthorized usage of computer systems, that's another route. This would involve a police report, not perjury, and would probably not take down the website.

[1]: https://www.copyright.gov/512/

Post reply on HN