Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

31–40 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#31
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

Why and what gives you the right to tell them off?

Hacking is hacking. If they wish to risk it, what's your problem?

They know the risks. Everyone knows hacking is illegal. Same with selling drugs; illegal yet folk do. Same premise. Get caught; no sympathy given.

"People may get hurt"? $country throw folk in to war; it's a harsh world we live in.

Bug bounty's are only the new norm because the younger audience want validation and compensation for their skills or that companies are being cheap to ensure security.

During my era of internet bug bounties were non-existent. You either got hired or you went to jail.

In my case I got fired from a bank accidentally boasting that I could replace printer status messages with "Out of Ink - please insert more blood". Granted I was 17.

Being banned from using any computer at school for discovering a DCOM exploit using Windows 98 Help resulting in being denied from doing my IT GCSE and from two colleges.

Or being doxxed by another hacker group for submitting their botnet to an AntiVirus firm. Good times, a living nightmare for my parents.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#32

Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…

> Why do security researchers privately inform companies of vulnerabilities and wait for them to patch before public disclosure?

Because if they don’t inform the company and wait for the fix, their disclosure would make it easier for less ethical hackers to abuse the vulnerability and do real material harm to the company’s users/customers/employees. And no company would ever want to collaborate with someone who thinks it’s ok to do that.

It’s not even really a matter of liability IMO, it’s just the right thing to do.

(main exception: if the company refuses to fix the issue or completely ignores it, sometimes researchers will disclose it after a certain period of time because at that point it’s in the public’s best interest to put pressure on the company to fix it even if it becomes easier for it to be exploited)

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#34

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

As a nitpick, you’re describing coordinated disclosure.

Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#35
Remind me to stick to my hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have with them or use any of the other gross surveillance technology that was recorded here.

The story is really about two things. Their poor information security is pathetic, but their actual surveillance tech is genuinely kind of politically concerning. Even if it is technically legal, it's unethical to record conversations without consent.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#36
post #5

I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an ex…

> They're getting paid $6 an hour. [...] Why write software to micromanage minimum wage employees?

Ironically, the less a job pays, the harsher and more demanding the bosses tend to be.

Earning six figures as a software developer, working from home, and you have to take a week off sick? No problem, take as long as you like, hope you feel better soon.

Earning minimum wage at a call centre? Missing a shift without 48 hours advance notice is an automatic disciplinary. No, we don't pay sick leave for people on a disciplinary (which is all of them). Make sure you get a doctor's note, or you're fired.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#37

The voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.

Do you need 2 party consent for recording in a public space?

You don’t get to secretly record voices in public spaces.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#38
post #20
post #5

I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an ex…

[flagged]

[flagged]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#39
post #20
post #5

I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an ex…

[flagged]

>There’s nothing wrong with flipping burgers for a living.

There is if it relegates you to shitty work environments and doesn’t afford a decent living as is generally the case in the US.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#40

Assuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to p…

IANAL, but to answer your question, maybe? The CFAA has a fairly broad scope. "intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains, information from any protected computer; " 1030(a)(2)(C)

Sandvig v. Barr tempers that a bit, with the DoJ now offering some guidance around good faith endeavors around security research.

I'd suggest Jane have a good lawyer on retainer, and a few years to spend in the tied up the legal system.

Post reply on HN