Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

231–239 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#231

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

They heard back from the company alright, they DMCA'd the post: https://infosec.exchange/@bobdahacker/115158347003096276 The screenshot of the email lacks detail so I don't know what part of the DMCA the author breached here, but this feels a lot like your standard DMCA abuse. This AI generated takedown was funded in part by a Y-Combinator: https://cyble.com/press/cyble-recognized-among-ai-startups-f...

Just imagining the world without Gary Tan and his ilk...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#232

Earlier quoted context omitted.

Again, there really isn't a big market for such vulnerabilities. No 0day broker will buy the vulnerabilities listed in the article. They might be able to sell to an initial access broker, but even there rhe kinds of vulnerabilites are not really interesting to them.

If that’s the case, then why do companies run bug bounties? I’m asking earnestly; it seems like if nobody actually cares about these gaps then there shouldn’t be an economic driver to find them, and yet (in many companies, but not Burger King) there is. Is it all just cargo culting or are there cases where company vulnerabilities would be worth something?

Oh no. They do get exploited. Just not bought. Buying vulnerabilities is by itself time intensive, complex work. grey market escrow, finding trusted sellers and buyers, etc. So buying and selling bulnerabilities only really happens for really impactful und generally useful ones.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#233
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

genuinely interested in the last known story of someone going to prison for this type of pen testing without an established bug bounty.

Not prison but in Germany someone was fined last year because he reported a plaintext password inside an EXE: https://www.heise.de/en/news/Modern-Solution-Court-of-Appeal... The company in questions is the Modern Solution GmbH & Co. KG.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#234
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

It is irresponsible. It brings attention to an issue that has not yet been resolved, which will likely lead to users getting data stolen/scammed. Even the most security-aware companies have a process to fix vulnerabilities, which takes time. I would never hire someone that doesn't reaponsibly coordinate with the vendor. In most cases it's either malicious or shows a complete lack of good judgement. In the case of bob…

It was resolved? In the 'Timeline: The Speed Run' section they list:

"Day 1, same day: RBI fixes everything faster than you can say "code red""

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#235

Earlier quoted context omitted.

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.

> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…

It's fraud and perjury to file a DMCA claim for any reason other than someone infringed your copyright. A DMCA claim is only valid if you swear on penalty of perjury that the target infringed your copyright. Otherwise it's meaningless.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#236
post #208

Earlier quoted context omitted.

If you assess that the best time to publicly disclose is immediately then disclose immediately. But I find that this case is rare. Typically it would be something like many of the following being met: - It is likely to be discovered by an attacker soon. - History shows that the company is unlikely to fix it soon. - Users have some way to protect themselves. - Your disclosure is likely to reach a significant number of…

How do you know it hasn’t been discovered by another attacker already?

You don't, but you make a judgement call based on different criteria, such as how difficult the issue was to find, maybe how popular/big the site is, etc., as to whether or not you think anyone else is likely to know about it already.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#237
post #127

It seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.

Back in 2008–2009, we had a lot of bare metal servers at SoftLayer's (Dallas, TX) facility. One of our customers ran a South American music forum, and anytime someone uploaded an MP3, the data center would honor the DMCA request and immediately stop routing traffic to the server until the issue was resolved. Now imagine what tools they might have in their arsenal in 2025.

When I ran a torrent tracker the biggest line item was paying an ISP to put their neck on the line and ignore every DMCA.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#239

Earlier quoted context omitted.

It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. You can see on the email that the "Original work" field is just a link to the BK website.

> It's DMCA abuse because that process is only legal to use in case of actual copyright infringement, not just any content you might have a moral claim over. I will reply to this comment because it's the easier to address, you're really hitting on the main misconception :D It is incorrect to think that the DMCA form is only valid for copyright. You need to contact the other party to start a legal dispute, you can do…

It's really really not. Cloudflare has the appropriate method to contact the owner of a domain behind it's anonymization: https://domaincontact.cloudflareregistrar.com/bobdahacker.co...

DMCA is NOT a contact form. Part of the process is an attestation that you are the owner of a copyright and the content is infringing on that copyright, lying on that is perjury (even though I've never seen it enforced, perjury in general is rarely enforced). The convenience of DMCA as a contact and takedown form does not legitimize it's use as one.

Post reply on HN