Live data from Hacker News

I reverse engineered McDonalds’ internal API

twitter.com

51–60 of 454 posts

Re: I reverse engineered McDonalds’ internal API

#51
post #33

AFAIK, reverse engineering APIs isn’t illegal. [1] There are some (VC backed) start ups that are open about doing it. Teller API is an example. [2] [1] “Reverse engineering generally doesn't violate trade secret law because it is a fair and independent means of learning information, not a misappropriation. Once the information is discovered in a fair and honest way, it also can be reported without violating trade sec…

Placing bogus orders using a reverse-engineered API, however, is likely illegal. Especially at the speed and scale at which he is purportedly doing it.

Re: I reverse engineered McDonalds’ internal API

#52
post #45
post #21

He wouldn't have tweeted it if it was malicious -- he could have even kept it secret. What is it with HN? little pranks, reverse engineering, vulnerabilities, free ice-cream. I do not condone crime but let's be honest, he could have made money with his findings online...the person is just letting his curiosity go wild. If Yelp wants to fire him I'd take him in my company any day.

You probably have a different definition of malicious than most of us. What you're thinking is, "Did he do this to break things at McDonald's or actively hurt them in some way?" But if he's hitting an internal API and creating a bunch of fake orders for the purpose of gathering data, that's malicious, whether or not it breaks anything on McDonald's side.

When will this guy realize that the only acceptable pastime for hackers, post-2020, is having long discussions that involve the word "policy" many times?

Re: I reverse engineered McDonalds’ internal API

#53

WTF is wrong with ice cream machines? It isn't just mcdonalds where they are almost always broken. I don't remember that being the case when I was a kid.

This question comes up frequently on reddit, and the oft repeated reasoning is: 1. the machines need to be cleaned every n hours 2. there's no failover 3. you're likely to visit the mcdonalds at the same time (eg. getting home from work) so if you're unlucky with timing, the machine would appear to be always broken from your perspective.

Re: I reverse engineered McDonalds’ internal API

#55

LOL! It's so ridiculous that this is a problem so often. I was in McDs once when the service guy was there. I overheard him say it would be $9,000 to fix just the shake side of the machine. I thought to myself, "That's a lot of milkshakes! There's a grocery store in the same parking lot... gallon of ice cream, some milk, and a blender. Problem solved."

Yep, and two folks in a garage can build FB in a week, its just a DB right?

Re: I reverse engineered McDonalds’ internal API

#56

LOL! It's so ridiculous that this is a problem so often. I was in McDs once when the service guy was there. I overheard him say it would be $9,000 to fix just the shake side of the machine. I thought to myself, "That's a lot of milkshakes! There's a grocery store in the same parking lot... gallon of ice cream, some milk, and a blender. Problem solved."

In my view, the costs of equipment, service, and goods really drive franchisee profit down. Don't know why you'd want to be a franchisee, you need a whole stable of stores to make it work and profitable.

Re: I reverse engineered McDonalds’ internal API

#57

Isn't this very illegal?

Not a Lawywer:

What law is he breaking (relative to both the US and Germany)?

In US criminal law, there is the Computer Fraud and Abuse Act, which has very specific narrow provisions, including the test of "has to intentionally cause damages to a computer system part of interstate or foreign commerce."

Which does not apply here.

McD's would have to pursue, instead, a civil case, based around a EULA or ToS, tantamount to breach of contract, and to recover damages.

I would assume that Ronald McDonald Esq would just issue a form Cease and Desist, and call it a day.

Re: I reverse engineered McDonalds’ internal API

#59
post #49

Just a note, the machines are not broken, they have shut themselves down for sanitary reasons. Ice cream, as a food that is very close to neutral in pH and without much in the way of preservatives, is a common source of listeria bacteria. To prevent serious health issues, the machine must be sanitized regularly. As I understand it, the process is involved, and any given McDonalds may not have a person with the time a…

How hard is it to devise an ice cream machine with a simpler sanitation process?

Re: I reverse engineered McDonalds’ internal API

#60
post #49

Just a note, the machines are not broken, they have shut themselves down for sanitary reasons. Ice cream, as a food that is very close to neutral in pH and without much in the way of preservatives, is a common source of listeria bacteria. To prevent serious health issues, the machine must be sanitized regularly. As I understand it, the process is involved, and any given McDonalds may not have a person with the time a…

I recently saw a video that actually showed the machine (allegedly) was sterilizing itself. The video showed all the ice cream in the hopper melted and soupy, presumably heated to kill bacteria in it. The video creator claimed it took some hours to complete, thus the common claim that the machine is "broken"
Post reply on HN