Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

21–30 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#21
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

I get the sentiment and it’s a wise warning that at some point most people in grey hat spaces end up adhering to, but “do exactly as you’re allowed to do by large corporations” isn’t exactly a hacker ethos.

I don’t think that argument really works in situations like this because hacking Burger King requires a pretty high level of intent + ability and isn’t something that just naturally happens. Like you have to sit down and say “Today I want to try to hack Burger King” and then spend several hours doing just that.

To me it seems like quite a stretch for “don’t hack me” to get framed as “Burger King is leveraging their corporate power to tell me what to do against my will”.

And to be clear I actually do think that it would be better for Burger King to invite and reward responsible disclosure, in the same way that you’d want your bank to have a hotline for people to report problems like doors that won’t lock. But if the bank didn’t have that hotline it wouldn’t excuse breaking in.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#23
post #19

[flagged]

But elsewhere in the article they show that Burger King is using AI to analyze how well the drive-through employees are doing and if they’re being cheerful enough and such.

So I think it’s more a jab at corporate mandated performative forced happiness for customers then the employees themselves.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#24
> Rating bathroom experiences: because everything needs a digital feedback loop

At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's.

For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy something to eat with the coffee. [The free coffee refill changes from time to time. I'm not sure it's working now.]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#25

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

> I’m curious about the legal/reputational implications of this.

The comments and headlines will be a bit snarkier, more likely to go viral - more likely to go national on a light news day, along with the human interest portion of not getting paid which everyone can relate to.

Bad PR move

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#26
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

Stop targeting anything and just use anything as is! Especially, don't you even dare hit "view source" on a website. Believe it or not, straight to jail. /s

[1] https://www.vice.com/en/article/this-is-the-hacking-investig...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#27

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

Do you need 2 party consent for recording in a public space?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#28
Assuming:

1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner

2. Jane is a US resident and citizen

3. Acme Corporation is a US company

... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit?

Relatedly:

Why do security researchers privately inform companies of vulnerabilities and wait for them to patch before public disclosure? Are they afraid of liability?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#29

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

> I’m curious about the legal/reputational implications of this. The comments and headlines will be a bit snarkier, more likely to go viral - more likely to go national on a light news day, along with the human interest portion of not getting paid which everyone can relate to. Bad PR move

I guess I mean the legal risks to both sides. Security is only a portion of what I do and I only dabble in red teaming (this is the first time I ever tried it on a third party).

So I legitimately don’t know what the legalities of writing a “here’s how I hacked HypeCo” article are if you don’t have the express approval to write that article from HypeCo. Though in my case the company did have an established, public disclosure program that told people they wouldn’t prosecute people who follow responsible disclosure. TFA seems even murkier because Burger King never said they wouldn’t press charges under the CFAA…

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#30

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

Do you need 2 party consent for recording in a public space?

That's what I'm getting at with the expectation of privacy part. Talking into a drive thru speaker isn't really a private activity since everyone around can kinda hear it, but it'd probably be better to disclaim it anyway since someone attempting to file on you for it still costs money.
Post reply on HN