Live data from Hacker News

We hacked Burger King: How auth bypass led to drive-thru audio surveillance

bobdahacker.com

91–100 of 239 posts

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#91
post #35

Remind me to stick to my hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have with them or use any of the other gross surveillance technology that was recorded here. The story is really about two things. Their poor information security is pathetic, but their actual surveillance tech is genuinely kind of politically concerning. Even if it is technically leg…

[deleted]

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#93

Earlier quoted context omitted.

Funny, whenever they show the CCTV footage it doesn't seem to have any sound.... Secretly recording voices is a felony is many places in 'merica.

Please stop spreading misinformation . There are so many court cases about this. A quick google will give you dozens you can read. Legally there is no “reasonable expectation of privacy” in public spaces and the only limit on that are extreme telephoto lenses looking from public spaces into private spaces. Edit: Another commenter has made me aware that some states do ban non-consensual audio recordings in public: htt…

Unfortunately, you are not correct.[1] Recording police in a public place-- sure. Otherwise, eh, at best you're over-extrapolating (and ungenerously!) from your local circumstance.

[1] https://www.dmlp.org/legal-guide/massachusetts-recording-law

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#94

And.. its down “Blog post not found” archive link here: https://archive.is/zIteR

https://infosec.exchange/@bobdahacker/115158347003096276

> We decided to take the post down after recieving a DMCA from burger king.

The DCMA report was actually sent from response@cycle.com, and Cyble [1] appears to be a DCMA-takedown-as-a-service 'solution'.

[1]: https://cyble.com/

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#96
post #62

Earlier quoted context omitted.

and removed so that i don't get sued for gross misinterpretation, ignorance and misinformation spreading. What was here was a link to a California statute that is apparently misinformation somehow. Who knows, I'm just some igorant redneck apparently.

Did you read that law? It applies to “Confidential communication…carried on among the parties in the presence of one another or by means of a telegraph, telephone, or other device, except a radio”. Conversation in public is by nature not “confidential”. You are grossly misinterpreting this law and (unintentionally/ignorantly) spreading misinformation. Edit: Another commenter has made me aware that some states do ban…

Grossly misinterpreting and spreading misinformation? I clarified a location and linked to the relevant statute.

You may have a smudge on your optics, mr. sniper.

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#97
Honestly wondering if this is a legit use of DMCA. Like, what exact provision of the DMCA is being implicated here?

One should have some reasonable means for challenging this kind of thing. But what do I know.

It’s a scary world when you know a C&D or other legal nastygram is 100% bullshit and want to ignore it, but you’re chained to a vendor that can’t respond with any level of subtlety, just the ban-hammer for everyone

So the C&Ds and nastygrams become increasingly ridiculous, but whatevs, they’re all rubber-stamped so hey corporate just push that red “lawyer” button and make my embarrassment go away real fast, before any Streisand effect can kick in!

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#99

Earlier quoted context omitted.

genuinely interested in the last known story of someone going to prison for this type of pen testing without an established bug bounty.

This story is a pen test gone wrong, so somewhat different, but illustrates some of the same failure modes. https://www.darkreading.com/vulnerabilities-threats/dark-rea...

More info here:

https://iowacapitaldispatch.com/2023/06/23/lawsuit-over-auth...

Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance

#100
post #22
post #19

[flagged]

I don't think it was a swipe at minimum wage employees at all, more massive corporations like Burger King making their minumum wage employees be "cheerful"

One of many reasons I despise Trash-Fil-A. They go hard on forcing their employees to sound a certain way, and it's just creepy as well as being abuse of their workers.

Paying someone a pittance, or anything at all, doesn't entitle you to control over their perceived mood or how they speak. You'll have to negotiate with SAG-AFTRA if you want to hire actors.

Post reply on HN