We hacked Burger King: How auth bypass led to drive-thru audio surveillance
1–10 of 239 posts
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#2[deleted]
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#3Burger King
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#4Wow. That's... impressively bad.
While pretty egregious, this is sadly common. I'm certain there's a dozen other massive companies making similar mistakes.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#5I'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an extent where a customer could ever be sure if you said "you rule" or that your tone is positive. They are thrilled if at least a few items they ordered are in the bag they collect. Why write software to micromanage minimum wage employees?
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#6This person seems to be fishing for a CFAA indictment?
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#7[deleted]
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#8Great write-up! I was sorry to see there wasn’t a reward for you reporting this to them.
At least you didn’t find that the bathroom rating tablets had audio as well!
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#9You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.
Re: We hacked Burger King: How auth bypass led to drive-thru audio surveillance
#10You need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.
No bug bounties for this level of sloppiness is the crime itself.