The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.
Do you need 2 party consent for recording in a public space?
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
201–210 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#202Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
They want capitalism, give them capitalism. If you can make more money exploiting it and selling to mafias and gangs and nation states. Do it.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#203Earlier quoted context omitted.
Yes, that is why responsible disclosure almost always comes with deadlines. You give the chance for the company to resolve the issue and mitigate user impact. But if they are taking so long that the user impact will be higher than you just disclose.
What if your assessment is that the user impact is already high enough that the right time to disclose is immediately?
But I find that this case is rare. Typically it would be something like many of the following being met:
- It is likely to be discovered by an attacker soon.
- History shows that the company is unlikely to fix it soon.
- Users have some way to protect themselves.
- Your disclosure is likely to reach a significant number of users.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#204> Rating bathroom experiences: because everything needs a digital feedback loop At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's. For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy…
Now my local Burger King (in Las Vegas, NV, USA) has a sign at each table telling you that you have 30 minutes to eat your food and get out before you get thrown out for loitering.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#205Earlier quoted context omitted.
Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.
Audio cannot be recorded without consent in CA. Security cameras have an option to disable audio for this reason. People never do it but it's the case. It's related to wiretapping laws that are very broad.
If there is a big obvious security camera staring at you, in a public place, that is the opposite of an expectation of privacy.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#206Earlier quoted context omitted.
Unfortunately, you are not correct.[1] Recording police in a public place-- sure. Otherwise, eh, at best you're over-extrapolating (and ungenerously!) from your local circumstance. [1] https://www.dmlp.org/legal-guide/massachusetts-recording-law
Okay, wow -- I stand corrected. I will edit my comments. It will take me awhile to wrap my head around Massachusett's-style state-level restrictions. While I wouldn't personally expect this to survive a Supreme Court adjudication, apparently there exists no Supreme Court ruling either upholding or striking down the prohibition on secretly recording oral conversations in public.
If you have an obvious security camera, or an obvious camera that normally would record audio, and you’re in public waving it around and it records audio? You are not secretly recording audio.
Same if someone is standing next to a obvious and clearly visible security camera which normally could also record audio, also, not secretly recording audio.
A hidden mic in your jacket, or like in that case, hiding the camera under a jacket? That is hidden recording.
The general rule of thumb is - if everyone can clearly see what you’re doing, it’s not secret.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#207Not to nitpick but being emailed a temporary password in cleartext doesn't seem like an issue to me, assuming you're required to change it as soon as you log in.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#208Earlier quoted context omitted.
What if your assessment is that the user impact is already high enough that the right time to disclose is immediately?
If you assess that the best time to publicly disclose is immediately then disclose immediately. But I find that this case is rare. Typically it would be something like many of the following being met: - It is likely to be discovered by an attacker soon. - History shows that the company is unlikely to fix it soon. - Users have some way to protect themselves. - Your disclosure is likely to reach a significant number of…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#209Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…
I suspect the post itself is legal but it's also a confession of highly illegal hacking.
Most of these things are best done across non-cooperative international borders, just to reduce the incentive for ‘throw them in jail’ as a easy ass covering measure.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#210Not to nitpick but being emailed a temporary password in cleartext doesn't seem like an issue to me, assuming you're required to change it as soon as you log in.
But that's negated completely by the next part about there being a sign up without any email verification