Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…
They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
231–239 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#232Earlier quoted context omitted.
Again, there really isn't a big market for such vulnerabilities. No 0day broker will buy the vulnerabilities listed in the article. They might be able to sell to an initial access broker, but even there rhe kinds of vulnerabilites are not really interesting to them.
If that’s the case, then why do companies run bug bounties? I’m asking earnestly; it seems like if nobody actually cares about these gaps then there shouldn’t be an economic driver to find them, and yet (in many companies, but not Burger King) there is. Is it all just cargo culting or are there cases where company vulnerabilities would be worth something?
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#233You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.
genuinely interested in the last known story of someone going to prison for this type of pen testing without an established bug bounty.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#234Earlier quoted context omitted.
As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…
"Day 1, same day: RBI fixes everything faster than you can say "code red""
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#235Earlier quoted context omitted.
It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.
> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#236Earlier quoted context omitted.
If you assess that the best time to publicly disclose is immediately then disclose immediately. But I find that this case is rare. Typically it would be something like many of the following being met: - It is likely to be discovered by an attacker soon. - History shows that the company is unlikely to fix it soon. - Users have some way to protect themselves. - Your disclosure is likely to reach a significant number of…
How do you know it hasn’t been discovered by another attacker already?
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#237It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.
Back in 2008–2009, we had a lot of bare metal servers at SoftLayer's (Dallas, TX) facility. One of our customers ran a South American music forum, and anytime someone uploaded an MP3, the data center would honor the DMCA request and immediately stop routing traffic to the server until the issue was resolved. Now imagine what tools they might have in their arsenal in 2025.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#238Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#239Earlier quoted context omitted.
It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.
> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…
DMCA is NOT a contact form. Part of the process is an attestation that you are the owner of a copyright and the content is infringing on that copyright, lying on that is perjury (even though I've never seen it enforced, perjury in general is rarely enforced). The convenience of DMCA as a contact and takedown form does not legitimize it's use as one.