Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

41–50 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#41

Earlier quoted context omitted.

Do you need 2 party consent for recording in a public space?

You don’t get to secretly record voices in public spaces.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#42
post #34

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable.

So yes, anyone who discloses before the company has had a reasonable chance to fix things is indeed irresponsible.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#43

Earlier quoted context omitted.

You don’t get to secretly record voices in public spaces.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Apparently the system was global, and BK has locations in GDPR countries.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#44
post #34

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

What you're describing as branding is actually an opinion. Calling it branding (with it's negative connotations) is putting the thumb on the scale.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#45
post #35

Remind me to stick to my hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have with them or use any of the other gross surveillance technology that was recorded here. The story is really about two things. Their poor information security is pathetic, but their actual surveillance tech is genuinely kind of politically concerning. Even if it is technically leg…

>hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have

Good news! With AI programming assistance, this invasive technology--with the concomitant terrible security--will be available to even the smallest business so long as nephews "who are good with computers and stuff" exist!

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#46

Earlier quoted context omitted.

You don’t get to secretly record voices in public spaces.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Funny, whenever they show the CCTV footage it doesn't seem to have any sound....

Secretly recording voices is a felony is many places in 'merica.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#47

Earlier quoted context omitted.

You don’t get to secretly record voices in public spaces.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Audio cannot be recorded without consent in CA. Security cameras have an option to disable audio for this reason. People never do it but it's the case.

It's related to wiretapping laws that are very broad.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#48
post #5

I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an ex…

> They're getting paid $6 an hour. [...] Why write software to micromanage minimum wage employees? Ironically, the less a job pays, the harsher and more demanding the bosses tend to be. Earning six figures as a software developer, working from home, and you have to take a week off sick? No problem, take as long as you like, hope you feel better soon. Earning minimum wage at a call centre? Missing a shift without 48 h…

That's a correlation to how easily replaced you are.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#49

Earlier quoted context omitted.

You don’t get to secretly record voices in public spaces.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

That is a farily broad statement.

How would you reconcile your statement against state laws that require all-party consent for audio recordings? e.g. CISA, or FSCA

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#50

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

This is software.

There is basically zero consequences for whatever fuckups you do, thus no incentives for companies to pay for vulnerabilities.

Post reply on HN