What's inside the QR code menu at this cafe?
281–290 of 328 posts
Re: What's inside the QR code menu at this cafe?
#282Re: What's inside the QR code menu at this cafe?
#283Earlier quoted context omitted.
> 37,529 restaurants use Dotpe for QR codes. At that scale, it would take years to get fixed without forcing it like this. It's too small for them to care about the liability of security and too large to move quickly
> At that scale, it would take years to get fixed without forcing it like this. But it also might not take years. The point of responsible disclosure is to give them the opportunity. If they don't take it, fine - that's now on them. Instead this guy is committing fraud with actual financial damages (wasted food) and then sharing how others can commit the same fraud on a massive scale, potentially causing more damage.…
Is that legally true? The legal risk of having published this without responsible disclosure vanishes if the conventional period of opportunity is ignored? That smells fishy.
Re: What's inside the QR code menu at this cafe?
#284finally someone woke up and secured
Re: What's inside the QR code menu at this cafe?
#285Earlier quoted context omitted.
This principle is clear if you apply a real world analogy. Just because you happen to have keys to a building doesn't mean you can enter without authorization from the owner. (E.g. you may have kept copies after a lease expires or a sale, it maybe you found them, etc.)
Considering it’s a API available without any authorization, the better comparison would be walking around on unfenced private land. There’s nothing to indicate they don’t want people on it but it’s also obvious it’s private land.
Re: What's inside the QR code menu at this cafe?
#286Earlier quoted context omitted.
Curious. How is this, specifically, fraud?
People have been convicted of hacking for merely editing URL strings, under the theory that were knowingly accessing systems in ways that they were not supposed to. This would be similar. Whether or not that seems reasonable to us is a different matter, but basically it boils down to the fact that "they left the door unlocked" doesn't make it legal to walk in.
Re: What's inside the QR code menu at this cafe?
#287> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.
In Japan, many chains are using tablets for their menu, and you can order through that. That's much better than having to pull whatever from a QR code.
Re: What's inside the QR code menu at this cafe?
#288> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.
Without the app I would've had to keep an eye for a roaming waiter, call them out and then place an order. This takes away from the dining experience. I also don't like to wait for the server to clear plates, take the card, swipe it and get it back. The old fashioned ways will disappear for good.
Re: What's inside the QR code menu at this cafe?
#289A guy went to prison for doing this with AT&Ts public subscriber data. The media didn't do him a favor by calling it a hack.
I almost got into big trouble at school for "hacking a teachers email". I guessed their email address (they were systematically generated) and sent an email. It's true you can get into trouble for this, but we need to all take it upon ourselves to make sure this doesn't happen. If this guy got into trouble I would hope every software engineer would be up in arms defending them.
You accidentally stumbling on something unprotected generally clears you from any liability as long as you stop as soon as you notice it.
Code of conduct for white hat hackers is to explore but not abuse, and report as soon as they have enough clarity on the issue. But there is no legal basis for this avoiding any liability except if a company runs an official bounty program.
In that sense, the OP author could face hacking charges if India has similar laws to the rest of the developed world, and the author doesn't even have the "well intentioned" for their defence since they never reached out: the only defence they have is they did not attempt to profit off it.
IANAL, though :)
Re: What's inside the QR code menu at this cafe?
#290Earlier quoted context omitted.
Seems outlandish. Citation needed? I'm aware of a couple of cases in the US, but not all over the world. Secondly: can consumers be blamed for gross negligence? It's not reasonable for a bank to post account balances in public billboard and ask people not to look at others. We should contest when private data is available publically, hidden only by small obfuscations, not professional security practices.
So for example in the UK with the computer misuse act, intent matters. If you intentionally change an id because you expect you will be able to access other data it becomes a crime. Your example is flawed because in this case the private data was not made available publicly at all – you need to intentionally exploit a software flaw to access it. Of course, it also matters how you handle it. If you do enough to just d…
Maybe a better analogy is a bank with open lockers and no vigilance: if someone enters and steals money, the police will look for them, because "the coffers were open" is not a valid defense. But customers will also demand answers from the bank - why were they so negligent and incompetent that someone can just enter and get their money?
We should hold similar values for digital systems.
Was the author's intent on stealing private data and causing harm? Did he gain from this abuse? Did the company take enough measures to safeguard their data?
Companies have been mostly not held responsible for their fuck ups, and no matter the law, that's wrong to me.