Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
161–170 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#162Earlier quoted context omitted.
They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...
[flagged]
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#163Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#164Earlier quoted context omitted.
Someone should see if YC will fund an ai-first company to help individuals and companies fight back against DMCA abuse and seek compensation
Interested to hear the financial model for this one.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#165Earlier quoted context omitted.
This story is a pen test gone wrong, so somewhat different, but illustrates some of the same failure modes. https://www.darkreading.com/vulnerabilities-threats/dark-rea...
More info here: https://iowacapitaldispatch.com/2023/06/23/lawsuit-over-auth...
1) The court found that the county sheriff had the pentesters arrested and encouraged their prosecution _not_ because he believed there was any crime, but instead that was angry at some state official. (Which, y'know, sounds like a pretty serious civil rights violation.)
2) However, the civil rights / 4th amendment claims were dismissed by the federal court due to "qualified immunity", the doctrine where, in any sufficiently "unique" or "specific" situation, the police have no liability whatsoever for their actions [2].
[1] https://storage.courtlistener.com/recap/gov.uscourts.iasd.84... [2] https://en.wikipedia.org/wiki/Qualified_immunity
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#166Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#167Earlier quoted context omitted.
I still don’t get it. What does copyright have to do with the post?
[flagged]
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#168Earlier quoted context omitted.
I still don’t get it. What does copyright have to do with the post?
[flagged]
You can see on the email that the "Original work" field is just a link to the BK website.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#169Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…
You don't publish because you don't want to cause harm and you don't want to be liable for it.
You need to realize that vulnerabilities don't exist in a vacuum. They grant access to computer systems that control the life of people (millions of people) including their personal information, passwords, passport photos, card numbers, jobs, paychecks, transportation, food, etc... which is very likely to cover yourself, your mom, your family, your friends as you deal with larger companies.
When you publish a vulnerability, it will immediately be used by bad actors that intend to cause harm to all these people, including employees and customers.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#170Earlier quoted context omitted.
I still don’t get it. What does copyright have to do with the post?
[flagged]
Because the Digital Millenium Copyright Act is for copyright. You haven't stated how the blog post infringes upon BK's copyright at all, so... yes, seems like a standard fraudulent DMCA claim.
> First thing first. This is NOT DMCA abuse. The DMCA is the only way to communicate with web companies and take down content. As such, it has become the legitimate way to take down any content that needs to be taken down, in the absence of alternatives.
This assumes that companies should be able to take down any content they do not like. This is very much not the case. The DMCA is very specifically only for copyrighted content.
From copyright.gov[1]:
> To be effective, a notice must contain substantially the following information:
> ...
> (v) a statement that the person sending the notice has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law; and
> (vi) a statement that the information in the notice is accurate, and under penalty of perjury, that the person sending the notice is authorized to act on behalf of the copyright owner .
This is pretty clearly DMCA abuse. TFA isn't using any of BK's copyrighted content, which is what a DMCA claim alleges. Just because people have abused the form... pretty much since inception does not mean that it's not perjury to do so.
If BK wants to press charges for unauthorized usage of computer systems, that's another route. This would involve a police report, not perjury, and would probably not take down the website.