Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

51–60 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#51
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

You're assuming that the choice is between immediate public disclosure and coordinated disclosure. Doing "the responsible thing" takes effort that is often disrespected (sometimes to the extreme).

I'm so sick and tired of some companies that any vulnerability I find in their products going forward is an immediate public disclosure. It's either that or no disclosure, and it would be irresponsible not to disclose it at all.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#52

Earlier quoted context omitted.

Yes, You can in America. Video recording is permitted without consent in the public places. Example CCTVs.

Audio cannot be recorded without consent in CA. Security cameras have an option to disable audio for this reason. People never do it but it's the case. It's related to wiretapping laws that are very broad.

California or Canada?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#53

Reading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time…

I would argue that it is an ethical thing to do so if it sends a signal to pay whitehats appropriately.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#54
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

Why and what gives you the right to tell them off? Hacking is hacking. If they wish to risk it, what's your problem? They know the risks. Everyone knows hacking is illegal. Same with selling drugs; illegal yet folk do. Same premise. Get caught; no sympathy given. "People may get hurt"? $country throw folk in to war; it's a harsh world we live in. Bug bounty's are only the new norm because the younger audience want va…

It’s a free country, etc. Obviously I have the “right” to comment a warning on the internet.

The point of bug bounties isn’t “validation” (as if old-school hackers didn’t want validation!), it’s that companies with responsible disclosure programs explicitly allow you to pentest them as long as you follow their guidelines. That removes the CFAA indictment risk. The guidelines generally aren’t much stricter than common sense (don’t publish user data, don’t hurt people, give them time to patch before publishing).

Unfortunately, the existence of bug bounties has made some people forget that hacking a company without an agreement in place is still a crime, and publishing evidence of crimes to a wide audience on the internet is a bad idea.

Most of what you’re saying just seems like nostalgia talking. Isn’t it better that hackers today have a way to find real vulnerabilities without going to jail?

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#55
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

Yes. Talk to your congresspeople.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#57
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

genuinely interested in the last known story of someone going to prison for this type of pen testing without an established bug bounty.

This story is a pen test gone wrong, so somewhat different, but illustrates some of the same failure modes.

https://www.darkreading.com/vulnerabilities-threats/dark-rea...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#58
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

What you're describing as branding is actually an opinion. Calling it branding (with it's negative connotations) is putting the thumb on the scale.

I’m saying out loud “I think rebranding coordinated disclosure as responsible disclosure has negative impacts and we shouldn’t do it”.

Thats not putting my thumb on the scale so much as shouting my opinion. The rebrand puts its thumb on the scale specifically because it avoids saying “we think non-coordinated disclose is irresponsible”; it sneaks it under the name change.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#59
post #9

You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.

But why? Is it because we don’t have consent from companies to try /check whether they are secure? If so who protects customers from weak doors? or shareholders?

They sound like it should be avoided to analyse the river waters next to factories.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#60
post #34

Earlier quoted context omitted.

As a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.

I would say that it is responsible disclosure. Or anyways, not doing that is irresponsible disclosure. The corporation may be hurt by early disclosure, and that’s whatever, but very often, there are a ton of ordinary people that are collateral damage, and the only thing they did wrong was exist in a society where handing over hoards of personal data to a huge corporation is unavoidable. So yes, anyone who discloses b…

What about users who are affected by the vulnerability in the time it takes between reporting to the vendor and remediation?
Post reply on HN