Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

191–200 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#191

Earlier quoted context omitted.

Unlikely. If a company does not have a formal BBP, they won't pay 99.99% of the time. Brokers are also not interested in vulnerabilities in companies. They usually only buy vulnerabilities for standard software (components).

foofoo12 is hinting that they could sell the exploit on the black market for money, were they so inclined

Again, there really isn't a big market for such vulnerabilities. No 0day broker will buy the vulnerabilities listed in the article. They might be able to sell to an initial access broker, but even there rhe kinds of vulnerabilites are not really interesting to them.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#193
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

Why do you think this? It clearly says that RBI fixed the issue on the day they it was found and disclosed.

It seems pretty reasonable to publish, given that?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#194

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

I did not know Cloudflare treats fake DMCAs the same way as Youtube. Since when!?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#195

Earlier quoted context omitted.

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.

> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…

> The website is hidden behind cloudflare which purposefully hides the identity of the author and prevents any contact, except via a DMCA form

The blog post says that the author contacted Burger King and they had some sort of communication channel available, Burger King just chose not to use it.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#196

Honestly wondering if this is a legit use of DMCA. Like, what exact provision of the DMCA is being implicated here? One should have some reasonable means for challenging this kind of thing. But what do I know. It’s a scary world when you know a C&D or other legal nastygram is 100% bullshit and want to ignore it, but you’re chained to a vendor that can’t respond with any level of subtlety, just the ban-hammer for ever…

The article did show images of the internal website including a one showing a photograph. It infringes their copyright, but it would be up to the author to prove that the usage was fair use.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#197

Earlier quoted context omitted.

You're assuming that the choice is between immediate public disclosure and coordinated disclosure. Doing "the responsible thing" takes effort that is often disrespected (sometimes to the extreme). I'm so sick and tired of some companies that any vulnerability I find in their products going forward is an immediate public disclosure. It's either that or no disclosure, and it would be irresponsible not to disclose it at…

Agreed. Cracked a thrift store IoT medical device. Contacted vendor. They sent me a one way NDA. Lol no.

I've been trapped in a quasi-NDA on bug bounty platforms too. The vendor just refused to make the report public long after the vulnerability had been fixed, likely to cover it up in case of any resulting damages claims (it was a financial platform and the bug affected withdrawals of customer funds).

The platform knows my identity, publishing the details would be against their terms, there's an implied threat that they could take legal action against me if I published the details, and they even low-balled the severity to avoid paying out the appropriate amount. Awesome experience overall.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#198
post #190

Wtf! I’m certain this entire stack was reviewed by low level outsourced contractors. To the person below whining that BK should’ve had more time…absolutely not! Users have a right to know. No effort was made to protect the data. None. Action needs to be taken. The company contracted to build this stack should be replaced asap! Including the CISO.

What if it was built in house?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#199

Earlier quoted context omitted.

foofoo12 is hinting that they could sell the exploit on the black market for money, were they so inclined

Again, there really isn't a big market for such vulnerabilities. No 0day broker will buy the vulnerabilities listed in the article. They might be able to sell to an initial access broker, but even there rhe kinds of vulnerabilites are not really interesting to them.

If that’s the case, then why do companies run bug bounties?

I’m asking earnestly; it seems like if nobody actually cares about these gaps then there shouldn’t be an economic driver to find them, and yet (in many companies, but not Burger King) there is.

Is it all just cargo culting or are there cases where company vulnerabilities would be worth something?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#200

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

There’s no liability or exposure for recording non-consensually. It’s a public space. There’s not even an edge case. If a random member if the public could walk into the drive-thru (which they can) then anything can be recorded without notification or consent. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: https://www.dmlp.org/legal-guide/massachusetts-rec…

Creating a database of recordings without user being able to know/influence is clearly violation of GDPR IF there is PII. That's going to be costly for BK.
Post reply on HN