Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

181–190 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#181
post #140

Earlier quoted context omitted.

Someone should see if YC will fund an ai-first company to help individuals and companies fight back against DMCA abuse and seek compensation

Interested to hear the financial model for this one.

We’ll use an influencer for example. A false dmca claim has costs for them. Immediate costs in time, demonetizing, and reputation. It also has longer term risks - e.g., copyright strikes become bans. They are incentivized to pushback but have limited tools to do so.

When dealing with a company whose business is filing dmca complaints using an automated system, the business model isn’t a lawsuit - it’s a settlement where the influencer is made whole and you get paid. The risk to the company is existential if you have enough clients using you to push back and risking them getting a platform ban or an injunction against them filing automated dmca complaints. Say they file a thousand complaints a day against a thousand YouTube channels. If even 50 of those channels file a counter claim it’s going to set off alarm bells.

All that being said the most toxic part of this is the company calling itself a cyber security company and trying to obfuscate seemingly pretty responsible disclosures using dmca.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#183

Earlier quoted context omitted.

[flagged]

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.

> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over.

I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D

It is incorrect to think that the DMCA form is only valid for copyright.

You need to contact the other party to start a legal dispute, you can do so by any available communication channels. The website is hidden behind cloudflare which purposefully hides the identity of the author and prevents any contact, except via a DMCA form. Burger King filled the DMCA form to get in touch with the author. It's merely a mean to legally contact the author and start a dispute, in the absence of better options.

It worked, cloudflare forwarded the form to the author (and the author decided to take down the article on their own). I really can't think of any reason why it would not be considered a reasonable and legitimate use of the form. All the better because it's an official legal form.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#184
post #156

Earlier quoted context omitted.

> It's a job for teenagers to get experience It all makes sense now! So that's why all fast food chains are closed from 9-3 on school days

[flagged]

I'm not sure that was the God of Abraham, so much as The Great Caucasian God[1]

[1] https://youtu.be/RJiwovX3mNA

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#185
post #107

Earlier quoted context omitted.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

Weak doors is fun comparison. Imagine if someone regular found homes locked by Masterlock locks. And then riffled through everything just to see if they are sufficiently secured. Then reported to owners asking for security bounty... I doubt that would go down very well, neither would it if you did that with businesses instead private home.

CEO was once annoyed with me while I worked IT (we handled facilities/security, too; was It wasn't enough to just shove a folder through the gap of the doors; you had to ensure the folder opened up as it was falling, changing more of the pixels to get to the trigger threshold. It took me around 5 minutes to get it to consistently trigger. CEO was displeased dev & design team now knew how to bypass the door lock from the outside; he wasn't going to pay to fix it.

Maybe best to internalize Have It Your Way like BK's teams did.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#186
post #156

Earlier quoted context omitted.

[flagged]

I'm not sure that was the God of Abraham, so much as The Great Caucasian God[1] [1] https://youtu.be/RJiwovX3mNA

Oh, my -- that is simply brilliant.

Additionally: https://open.spotify.com/track/0YoYJw5URPqnGdOSnpeNnT?si=37a...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#188

Earlier quoted context omitted.

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.

> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…

Can you cite the law where it says DMCA is supposed to be used as a contact form to get ahold of the author?

Another commenter in the thread shared where the laws says the exact opposite (DMCA is only for copyright violations)?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#190
Wtf! I’m certain this entire stack was reviewed by low level outsourced contractors.

To the person below whining that BK should’ve had more time…absolutely not! Users have a right to know. No effort was made to protect the data. None.

Action needs to be taken. The company contracted to build this stack should be replaced asap! Including the CISO.

Post reply on HN