Live data from Hacker News

What's inside the QR code menu at this cafe?

peabee.substack.com

31–40 of 328 posts

Re: What's inside the QR code menu at this cafe?

#31
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

Even worse when the weird ass website has links to multiple PDF documents to download.

Then you find out all the items you looked at aren't available when the waiter stares blankly at you about your order.

Turns out the dinner menu requires horizontal scrolling on the page to find.

Re: What's inside the QR code menu at this cafe?

#32
Not to be a party pooper, but posting detailed financial analysis of the exact sales data of a multi-million dollar business using numbers obtained through an obviously overlooked backdoor seems like a very bad idea. Haven't people have gone to jail for less? (iirc "but it was an insecure API" has not held up in court in the past)

On a more positive note, I've used a QR menu recently and it really is a game changer. Scanned a code, pressed a few buttons, and my food was there in minutes! Looking forward to seeing it more often, especially in places where you're not looking for stellar service.

Re: What's inside the QR code menu at this cafe?

#33
this is fun because i can confidently say, "bureaucracy" runs on adverts. Whatever flashy, big banner photo op you can find, people lap that up. why? because of the immense population of india. EVERYTHING works here.

You can spend countless hours trying to break your application, finding holes but who cares.

Police cares about financial fraud. Did someone clickbait you into swindling money from you? well they will pounce on it because they will extract their cut from all involved and it gives them nice PR on the daily newspaper.

PII fraud or vulnerability, eh well. whose gonna notice? we have enough on our plates.

second thing. whatever government is doing, they protect themselves at all costs. they WILL throw you under the bus if it protects their interests.

why? because of the massive population, jobs are scarce, people get college degrees and stuff to pad up their resumes because employers, govt or private REQUIRE documentary evidence you did something. doesn't matter your skills,y ou have the papers or not.

this dotpe company, whatever its doing is indicative of the systemic problems in india. You have lots of people, lots of smart people, lots of dumb people and in the long run, bigger, cheaper, faster. that's all that matters

Re: What's inside the QR code menu at this cafe?

#34

Earlier quoted context omitted.

If you discovered an incompetent healthcare provider was prescribing antibiotics for every condition would you "contact them privately" or contact the relevant authorities? Private disclosure is for when you believe the company cares about security but made a genuine mistake. For the company in the OP it would be more like free education in fundamental privacy and ethics. They're not entitled to that. Name and shame.

Sure, but what you’re describing is not what is being suggested. Responsible disclosure typically involves disclosing publicly after a reasonable period of time.

Why? Why should they be the responsible ones, when the well-funded, well-connected service provider is acting like the fly-by-night startup (that they probably started as)?

There's little public benefit in responsible disclosure here; all it would lead to is the whole thing being swept under the rug with some trivial "fix". There's lots of public benefit in immediate, wide disclosure - the scramble to fix this under pressure from vendors before potential abuse, and any real or imagined attempt at abuse, and subsequent lawsuits, would go far towards educating people and the industry about privacy, security, and bad business practice. It's a nice low real damage, high publicity case.

It's not like this stuff is new. But without serious pressure, the businesses will never learn and never stop making or enrolling into such systems.

Anyway, if it happened over here in the EU, I'd do the responsible disclosure thing and give a full, detailed advance expose to the local Data Protection Authority.

(And if I sound adversarial, then consider that neither the vendor developing such systems, nor the venues using them, are doing it in the interest of the customers.)

Re: What's inside the QR code menu at this cafe?

#35

Not to be a party pooper, but posting detailed financial analysis of the exact sales data of a multi-million dollar business using numbers obtained through an obviously overlooked backdoor seems like a very bad idea. Haven't people have gone to jail for less? (iirc "but it was an insecure API" has not held up in court in the past) On a more positive note, I've used a QR menu recently and it really is a game changer.…

eh. this is india my dude

Re: What's inside the QR code menu at this cafe?

#36

Earlier quoted context omitted.

Is it a vulnerability when it is obvious the company do not care about security?

Yes. Because who at the "company" does even know about this? Maybe just some coder who wrote it. But the legally liable CEO? Maybe not.

> Because who at the "company" does even know about this?

Everyone who designed engineering requirements, technical requirements, test plan, everyone who wrote technical specifications, everyone who performed traceability. It was all approved by security engineers and management.

> The company was founded during the pandemic when contactless dining became popular.

There were tons of people intimately aware of the issue, yet for four years nobody cared.

Re: What's inside the QR code menu at this cafe?

#37
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

I’m not sure if this could be considered “peak”. The ratio of waiting staff to customers is an obvious bottleneck.

This inefficiency is simply accepted and not even really thought about, it’s just the way things are. But one thing I can say for this tech is it fixed it and the difference is noticeable.

Re: What's inside the QR code menu at this cafe?

#38
post #37
post #13

> Is this what the peak ordering experience looks like? Call me old-fashioned, but to me the peak experience is a paper menu to choose from, and a waiter that patiently takes the order. Far prefer that to everyone at the table fiddling on their phones in some weird-ass website or even god forbid custom app.

I’m not sure if this could be considered “peak”. The ratio of waiting staff to customers is an obvious bottleneck. This inefficiency is simply accepted and not even really thought about, it’s just the way things are. But one thing I can say for this tech is it fixed it and the difference is noticeable.

inefficiency? It's part of the experience. I'm not in a restaurant or café to drink as fast as possible. I'm there to socialize as well. Waiting a bit is not a bottleneck, but a feature. (If I wanted speed, I'd take the drive-through).

Re: What's inside the QR code menu at this cafe?

#39
post #22
post #5

Earlier quoted context omitted.

is it really a vulnerability if the entire thing is open by design?

Who says it was? Why would they willingly give out their customers' and customers' customers data to any anonymous person or a bot? More likely a bad oversight

For 3 years? That would mean that no developer has ever raised these issues with management, to speak nothing of an actual pentest being conducted.

No, this is not some obscure security hole they forgot about. This is plain incompetence and/or deliberate design decisions.

I agree that full public disclosure like this is irresponsible, but exposing issues like this to the public is the only way for such companies to make a change or, preferably, lose business and shutdown.

Re: What's inside the QR code menu at this cafe?

#40
post #26
post #6

Nice find! There's a problematic but not critical personal information leak, a mild business intelligence leak and that's about it. > They could keep this script running for months, even years, creating awkward scenes and uncomfortable conversations at every restaurant across the country. If that's about the worst thing you can actively do, then it's only about the data leak.

No, that's the most inconvenience you can cause. There are worse things you can do: target specific people with spurious orders, cancel everything they order, or if you want add random items to every order, making the entire system useless.

people are underestimating the havoc this could create in a country like India. Imagine serving chicken at a table that is strictly vegetarian (many people in India are vegetarian due to religious reasons), will lead to a lot of outrage.
Post reply on HN