Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

201–210 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#201

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

Do you need 2 party consent for recording in a public space?

Depends on the country. In Finland, it's ok to record your own discussions. Whether the recorder is BK (a third party) or the cashier is an interesting question, though.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#202

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They want capitalism, give them capitalism. If you can make more money exploiting it and selling to mafias and gangs and nation states. Do it.

[deleted]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#203
post #179

Earlier quoted context omitted.

Yes, that is why responsible disclosure almost always comes with deadlines. You give the chance for the company to resolve the issue and mitigate user impact. But if they are taking so long that the user impact will be higher than you just disclose.

What if your assessment is that the user impact is already high enough that the right time to disclose is immediately?

If you assess that the best time to publicly disclose is immediately then disclose immediately.

But I find that this case is rare. Typically it would be something like many of the following being met:

- It is likely to be discovered by an attacker soon.

- History shows that the company is unlikely to fix it soon.

- Users have some way to protect themselves.

- Your disclosure is likely to reach a significant number of users.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#204

> Rating bathroom experiences: because everything needs a digital feedback loop At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's. For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy…

Now my local Burger King (in Las Vegas, NV, USA) has a sign at each table telling you that you have 30 minutes to eat your food and get out before you get thrown out for loitering.

Well there are some people who seem to live at my local McDonalds.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#205

Earlier quoted context omitted.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Audio cannot be recorded without consent in CA. Security cameras have an option to disable audio for this reason. People never do it but it's the case. It's related to wiretapping laws that are very broad.

Only if there is an expectation of privacy.

If there is a big obvious security camera staring at you, in a public place, that is the opposite of an expectation of privacy.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#206

Earlier quoted context omitted.

Unfortunately, you are not correct.[1] Recording police in a public place-- sure. Otherwise, eh, at best you're over-extrapolating (and ungenerously!) from your local circumstance. [1] https://www.dmlp.org/legal-guide/massachusetts-recording-law

Okay, wow -- I stand corrected. I will edit my comments. It will take me awhile to wrap my head around Massachusett's-style state-level restrictions. While I wouldn't personally expect this to survive a Supreme Court adjudication, apparently there exists no Supreme Court ruling either upholding or striking down the prohibition on secretly recording oral conversations in public.

The key element here that everyone seems to be confused about, is secret vs non-secret.

If you have an obvious security camera, or an obvious camera that normally would record audio, and you’re in public waving it around and it records audio? You are not secretly recording audio.

Same if someone is standing next to a obvious and clearly visible security camera which normally could also record audio, also, not secretly recording audio.

A hidden mic in your jacket, or like in that case, hiding the camera under a jacket? That is hidden recording.

The general rule of thumb is - if everyone can clearly see what you’re doing, it’s not secret.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#207

Not to nitpick but being emailed a temporary password in cleartext doesn't seem like an issue to me, assuming you're required to change it as soon as you log in.

The fun one for me is when they email you your original password in email. I’ve had that happen twice, and was always an amazing wtf moment.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#208
post #179

Earlier quoted context omitted.

What if your assessment is that the user impact is already high enough that the right time to disclose is immediately?

If you assess that the best time to publicly disclose is immediately then disclose immediately. But I find that this case is rare. Typically it would be something like many of the following being met: - It is likely to be discovered by an attacker soon. - History shows that the company is unlikely to fix it soon. - Users have some way to protect themselves. - Your disclosure is likely to reach a significant number of…

How do you know it hasn’t been discovered by another attacker already?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#209

Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…

I suspect the post itself is legal but it's also a confession of highly illegal hacking.

Yes. The underlying problem is that knowing about the vulnerability is not an issue. Getting to the point you know about and are sure it’s a vulnerability almost certainly will implicate whoever discovered it in a CFAA crime (and those punishments are ridiculously severe for what counts as committing them in most cases).

Most of these things are best done across non-cooperative international borders, just to reduce the incentive for ‘throw them in jail’ as a easy ass covering measure.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#210

Not to nitpick but being emailed a temporary password in cleartext doesn't seem like an issue to me, assuming you're required to change it as soon as you log in.

The way I read it, the password might not have been different for each new user...

But that's negated completely by the next part about there being a sign up without any email verification

Post reply on HN