8 ms·
Would You Like an IDOR With That? Leaking 64m McDonald's Job Applications
- bravesoul2 1y agoIt involves AI but AI wasn't the cause. It was an enumeration on object id, discovered because the author could access a test site with password 123456 and try things out.
- oc1 1y agoI have so many questions to the developers but i believe the answers will just crush my poor worker soul so let it be.
- ryandrake 1y agoI've been so lucky throughout my career to have almost entirely worked with competent and smart developers. I've always wondered what a conversation with one of these other ones is like, after a production site is found to use 123456/123456 as credentials. "Hey, Mike, we just had someone in the public notice that our admin interface could be accessed by anyone with default credentials. You're the manager on this project. How did this happen?" I would love to be a fly on the wall for that conversation, or read the postmortem. How does this kind of configuration even make it past code review, let alone staging and production?
- lmz 1y agoIt's config not code - and a demo interface is a nice thing to have. The cross account read, however...
- Marsymars 1y ago”Well you see, that work was outsourced to a team where none of the implementing developers are still present, our auditors and pen testers both signed off on it, and anyway we’ve got cyber insurance to cover the fallout.”
- NooneAtAll3 1y ago> How does this kind of configuration even make it past code review that's the secret - there is none
- viraptor 1y agoIt's rarely as simple as actually exposing something as a decision. Scope changes, access rules change, multiple systems interact in interesting ways, access configuration lives in a different place than the app, etc. You're implying that it wouldn't happen with competent developers, but I guarantee it does - just wait a bit longer and let the systems grow. The Swiss cheese will get everyone given enough time.
- joules77 1y ago"We outsourced it to the 3rd world cuz it costs 20 bucks a week to hire a "certified" sysadmin there" You want data of any Large corp in the US - fly to well known outsourcing destinations. Stand outside the gate of their "global delivery centers". Hand out cash. Get access to whatever you want. But the main thing to understand here in 2025 is that getting access to/monetizing user data has become so normalized, that you could legally just go to McD Biz Dev (or which ever other large corp) and say - hey guys I have this algo that can add 2 bucks of revenue per user per quarter (throw in a - just look at Meta they extract 70 bucks out of their American users and atleast 12 bucks out of everyone else per quarter just using the personal data). To test my algo, I need access to your DB. Your competitor has already given me access to theirs for testing. What is corporate robot going to do? They will hand you the data.
- TZubiri 1y agoIt certainly doesn't reflect well on AI as a BuzzWord. Execs vetted this provider and approved it, which isn't irrelevant to the disregard for safety occuring with AI in general right now. Additionally, are we certain the vendor didn't use AI to vibecode stuff?
- Y_Y 1y ago[flagged]
- heavyset_go 1y agoIt was on my desk but it disappeared because it doesn't exist. Besides, it's weird that you're still talking about this Epstein guy when things like Texas happened.
- lesuorac 1y agoIt's unfortunate the administration can only focus on one thing and can't handle Texas and Epstein at the same time.
- quantified 1y agoThey're on a test menu. Sometimes you see it, sometimes you don't.
- Proofread0592 1y agoI cannot believe the 123456 worked, it's literally a joke from SpaceBalls.
- shrubble 1y agoReminds me that I need to change the combination on my luggage…
- deleted 1y ago[deleted]
- jeffbee 1y agoIn a past life, I had an investment stake in Krispy Kreme donuts. We were poking around to see if we could learn anything about the company. We watched a training video for new store managers. It told the viewer to go to some URL and enter their credentials. In the video, the example credentials were "admin" and "admin" as the password. So we tried that, and of course it worked on their live system. We immediately had access to global, live, online revenue data for every real Krispy Kreme outlet, not some training simulation. Most people are not qualified to handle computer security, is what I learned from that.
- chasil 1y agoWhen I started my job in 2000, I introduced my fellow (emeretus) DBA to "ps -ef | grep sqlplus" and sprayed a pile of user accounts and passwords. I fixed the problem and learned about Oracle databases. I checked my apps into RCS archives later that decade with passwords. Expecting to move these archives into CVS, I changed them. Now, any code repository that I touch, I will run "git grep password" (or the [TFS] equivalent) and once again hit pay dirt. It seems to take a certain exposure, growth, and wisdom to be mindful of these things, and many are far behind.
- burnt-resistor 1y agoThat's the stupidest combination I've ever heard in my life!
- croes 1y ago
- david2ndaccount 1y ago> We immediately began disclosure of this issue once we realized the potential impact. Unfortunately, no disclosure contacts were publicly available and we had to resort to emailing random people. The Paradox.ai security page just says that we do not have to worry about security! Amazing.
- snypher 1y ago>Without much thought, we entered “123456” as the username and “123456” as the password I feel like there's more to this that I'd love to know the story behind...
- ryandrake 1y ago> The personality test was a disturbing experience powered by Traitify.com where we were asked if phrases like “enjoys overtime” are either Me or Not Me. It was simple to guess that we should probably select Me for the pro-employer questions and Not Me for questions referencing being argumentative or aggressive, but it was still quite strange. Offtopic from the security issue, but I wonder if they really get any value out of this "Personality test." It seems like it's just a CAPTCHA that makes sure the applicant knows when to lie correctly.
- veggieroll 1y agoFor the employer, the question is self fulfilling. Either way they get what they want. Even if someone knows enough to lie, the lie betrays that they’re desperate enough to be unable to resist anything management demands.
- reactordev 1y agoWhile also providing evidence that you do indeed love overtime based on your answer. Ugh… the only way to win is not to play.
- BobaFloutist 1y agoOr it shows that you put a very low value on your honesty, and will happily say or do anything other people want to hear as long as it's to your advantage.
- deleted 1y ago[deleted]
- bee_rider 1y agoWorking in retail is 99% lying that you care about your job, so might as well start it out on the right footing.
- sgerenser 1y agoWhat about working as a SWE at Google? Apparently they recently implemented a personality test as an initial screener (they call it a Googleyness test).
- Titan2189 1y agoHats off to Paradox for remediating this within 30 hours of reporting.
- RandomBacon 1y agoHopefully it shouldn't take longer than 30 hours to change a password.
- averageRoyalty 1y agoYou didn't read the article, that wasn't the primary issue or fix.
- ge96 1y agoFunny I remember trying to get a job at McD's before and had to answer those behavioral questions kill 1 or 5
- bombcar 1y agoIt’s kind of sad and yet expected that McDonald’s responds. Wyeth to security vulnerabilities than many Internet companies do.
- slipperybeluga 1y ago[dead]
- deleted 1y ago[deleted]
- trod1234 1y agoI'm sure there are a lot of McDonald's positions out there, but doesn't 64 million job applicants seem like a bit much? There are only 13,647 locations in the US, so that would be 4,689 applications for each store? Makes you wonder how many of those were actually hired because there may only be 30-50 people per store. What's it say about a company when they deceptively advertise that they are hiring when they really aren't (because all the positions were filled). Bad acting stuff like this needs cost imposed.
- Macha 1y agoHow many countries do McDonald's use this system in? It's a global company, and as big a market as the US is, McDonalds themselves claim they have "over 38,000 stores" so the US is less than half. Then how often does the typical McDonald's have a vacancy? These are not good jobs that would cause low turnover, especially once you get into touristy markets where demand is very seasonal. Let's say 10 openings per store per year. Finally when your applicant pool is basically "every college student, unqualified adult, and even some teenagers", 200-300 applications per opening seems entirely plausible. Low even, from the times I've seen the entry level hiring process close up. Of course, the thing that confuses people with application numbers like this is they assume that there's no overlap. The same people generally apply to all the jobs in an area so the local McDonalds getting a few thousand applications a year might only be a few hundred unemployed people.
- combinator_y 1y agoOn top of the shit system in place, there is no corporate control internally (5th screenshot "NGA FS" ...)
- Daviey 1y agoPerhaps I'm being overly cynical, but I'm struggling to see how this qualifies as an IDOR in the strict sense. While using UUIDs might reduce guessability, the real issue here is weak authentication, not insecure direct object references. OWASP defines an IDOR as "an access control vulnerability that occurs when an application uses user-supplied input to access objects directly… without verifying the user is authorized for the target object" (OWASP Top 10 2021 – A01: Broken Access Control). But in this case, access to highly privileged internal functionality was granted simply by logging in with default credentials, no authorization bypass was needed because authentication was effectively absent. This aligns more closely with CWE-1390: "Use of Default Credentials" and CWE-306: "Missing Authentication for Critical Function." The attacker was able to log in as a privileged user due to trivial credentials, and the lack of multi-factor authentication (MFA) further compounded the issue. Had MFA been implemented, or default credentials disabled, the ID enumeration would have been irrelevant. That makes it clear the real vulnerability lies in the authentication mechanism and not in how object references were structured.
- justusthane 1y ago> Had MFA been implemented, or default credentials disabled, the ID enumeration would have been irrelevant Not really? The vulnerability might not have been discovered if that was the case, but it doesn’t change the fact that anyone who has access to the system can gain access to all of the data in the system, right?
- Daviey 1y agoPerhaps I misunderstood, but I read it that the account they got access to was a highly privileged account, which did have general access to all data. The report didn't make it clear to me if an unauthorised user, or an account with low privilege can still access data they otherwise should not have access to. If this is true, then I agree it is an IDOR, but I read it as they had access because of their current context.
- justusthane 1y ago> It turned out we had become the administrator of a test restaurant inside the McHire system. I don’t think you would expect the administrator of a single restaurant to have access to the data of all 64M applicants globally
- Gelob 1y agoFedex uses paradox.ai too and its terrible