13 ms·
We hacked Burger King: How auth bypass led to drive-thru audio surveillance
- deleted 1y ago[deleted]
- BobDaHacker 1y agoBurger King
- johnecheck 1y agoWow. That's... impressively bad. While pretty egregious, this is sadly common. I'm certain there's a dozen other massive companies making similar mistakes.
- jrockway 1y agoI'm most surprised that they have this whole system for how drive-thru interactions should go. Positive tone. Saying "you rule" like their exceedingly-irritating television commercials. Like... what if you don't? "If you don't follow the four Sales Best Practices, you're gonna be flippin' burgers for a living. Oh. Well. Oh." They're getting paid $6 an hour. The microphone/speaker system can't reproduce audio to an extent where a customer could ever be sure if you said "you rule" or that your tone is positive. They are thrilled if at least a few items they ordered are in the bag they collect. Why write software to micromanage minimum wage employees?
- hluska 1y ago[flagged]
- stronglikedan 1y ago[flagged]
- PsylentKnight 1y ago> It's a job for teenagers to get experience It all makes sense now! So that's why all fast food chains are closed from 9-3 on school days
- ssl-3 1y ago[flagged]
- ShroudedNight 1y agoI'm not sure that was the God of Abraham, so much as The Great Caucasian God[1] [1] https://youtu.be/RJiwovX3mNA https://youtu.be/RJiwovX3mNA
- ssl-3 1y agoOh, my -- that is simply brilliant. Additionally: https://open.spotify.com/track/0YoYJw5URPqnGdOSnpeNnT?si=37a50db658ca4a6d https://open.spotify.com/track/0YoYJw5URPqnGdOSnpeNnT?si=37a...
- thfuran 1y ago>There’s nothing wrong with flipping burgers for a living. There is if it relegates you to shitty work environments and doesn’t afford a decent living as is generally the case in the US.
- jrockway 1y agoI'm not making a value judgement. I'm saying, how are they going to punish you, as a burger flipper, for not saying their TV commercial tagline? Demote you to burger flipper? That's already your job. So why pay people to build a system to track their metrics, when they realistically have no way of making this happen. Pay people $30/hour and I bet they'll say it every time without software yelling at them. (With the software in place, I have never heard the line "you rule" at Burger King, but I also only go like twice a year. So why write it? It doesn't work.)
- michaelt 1y ago> They're getting paid $6 an hour. [...] Why write software to micromanage minimum wage employees? Ironically, the less a job pays, the harsher and more demanding the bosses tend to be. Earning six figures as a software developer, working from home, and you have to take a week off sick? No problem, take as long as you like, hope you feel better soon. Earning minimum wage at a call centre? Missing a shift without 48 hours advance notice is an automatic disciplinary. No, we don't pay sick leave for people on a disciplinary (which is all of them). Make sure you get a doctor's note, or you're fired.
- parineum 1y agoThat's a correlation to how easily replaced you are.
- MangoToupe 1y agoOn the other hand, i can't imagine it's easy to find a legal citizen willing to work for that wage. Especially when school's open.
- bagacrap 1y agoI think there's a U shaped curve here. Make it all the way to Principal software engineer and you might be expected to work longer hours and bend your personal sense of ethics in service of the company's mission.
- akerl_ 1y agoThis person seems to be fishing for a CFAA indictment?
- orsorna 1y agoIt's not their first time. https://news.ycombinator.com/item?id=44997145 https://news.ycombinator.com/item?id=44997145
- deleted 1y ago[deleted]
- zackkatz 1y agoGreat write-up! I was sorry to see there wasn’t a reward for you reporting this to them. At least you didn’t find that the bathroom rating tablets had audio as well!
- foofoo12 1y ago> wasn’t a reward I'm pretty sure someone was willing to pay for this, but at least the researches acted responsibly.
- StrauXX 1y agoUnlikely. If a company does not have a formal BBP, they won't pay 99.99% of the time. Brokers are also not interested in vulnerabilities in companies. They usually only buy vulnerabilities for standard software (components).
- fragmede 1y agofoofoo12 is hinting that they could sell the exploit on the black market for money, were they so inclined
- StrauXX 1y agoAgain, there really isn't a big market for such vulnerabilities. No 0day broker will buy the vulnerabilities listed in the article. They might be able to sell to an initial access broker, but even there rhe kinds of vulnerabilites are not really interesting to them.
- ghiculescu 1y agoIf that’s the case, then why do companies run bug bounties? I’m asking earnestly; it seems like if nobody actually cares about these gaps then there shouldn’t be an economic driver to find them, and yet (in many companies, but not Burger King) there is. Is it all just cargo culting or are there cases where company vulnerabilities would be worth something?
- rafram 1y agoYou need to stop targeting companies without established bug bounties that allow penetration testing, or you’re going to go to jail.
- AndreBaltazar 1y agoNo bug bounties for this level of sloppiness is the crime itself.
- adzm 1y agoAgreed, though at the same time, RBI should be rewarding them for reporting this.
- 010101010101 1y agoI get the sentiment and it’s a wise warning that at some point most people in grey hat spaces end up adhering to, but “do exactly as you’re allowed to do by large corporations” isn’t exactly a hacker ethos.
- weitendorf 1y agoI don’t think that argument really works in situations like this because hacking Burger King requires a pretty high level of intent + ability and isn’t something that just naturally happens. Like you have to sit down and say “Today I want to try to hack Burger King” and then spend several hours doing just that. To me it seems like quite a stretch for “don’t hack me” to get framed as “Burger King is leveraging their corporate power to tell me what to do against my will”. And to be clear I actually do think that it would be better for Burger King to invite and reward responsible disclosure, in the same way that you’d want your bank to have a hotline for people to report problems like doors that won’t lock. But if the bank didn’t have that hotline it wouldn’t excuse breaking in.
- tyami94 1y agoThis is a red herring. They're obviously being silenced because they just obtained evidence that Burger King is recording and algorithmically analyzing every customer interaction to ensure that their wage-slave employees say "You rule!" the correct number of times per order. This is horrifying and dystopic, and it's certainly the bigger story here.
- lysace 1y agoThe only way this shit show will ever stop is if behavior like this is ultimately rewarded with a corporate death penalty. E.g. their trademarks being put in the public domain and assets confiscated to compensate their victims. The watch in amazement at how actual security suddenly becomes a priority.
- weitendorf 1y agoReading between the lines, it looks like the story behind the story here is that this security researcher followed responsible disclosure policies and confirmed that the vulnerabilities were fixed before making this post, but never heard back anything from the company (and thus didn’t get paid, although that’s only a fair expectation if they’ve formally set expectations for paying out on stuff like this ahead of time). I’m curious about the legal/reputational implications of this. I personally found some embarrassing security vulnerabilities in a very high profile tech startup and followed responsible disclosure to their security team, but once I got invited to their HackerOne I saw they had only done a handful of payouts ever and they were all like $2k. I was able to do some pretty serious stuff with what I found and figured it was probably more like a $10k-$50k vuln, and I was pretty busy at the time so I just never did all the formal write up stuff they presumably wanted me to do (I had already sent them several highly detailed emails) because it wouldn’t be worth a measly $2k. Does that mean I can make a post like this?
- newman8r 1y ago> I’m curious about the legal/reputational implications of this. The comments and headlines will be a bit snarkier, more likely to go viral - more likely to go national on a light news day, along with the human interest portion of not getting paid which everyone can relate to. Bad PR move
- weitendorf 1y agoI guess I mean the legal risks to both sides. Security is only a portion of what I do and I only dabble in red teaming (this is the first time I ever tried it on a third party). So I legitimately don’t know what the legalities of writing a “here’s how I hacked HypeCo” article are if you don’t have the express approval to write that article from HypeCo. Though in my case the company did have an established, public disclosure program that told people they wouldn’t prosecute people who follow responsible disclosure. TFA seems even murkier because Burger King never said they wouldn’t press charges under the CFAA…
- akerl_ 1y agoAs a nitpick, you’re describing coordinated disclosure. Branding it as “responsible” puts the thumb on the scale that somehow not coordinating with the vendor is irresponsible.
- techjamie 1y agoThe voice recordings at the drive thru without disclaimers of recording seem like maybe a two party state lawyer's wet dream? I guess they could argue shouting into a machine in public carries no expectation of privacy, but it seems like a liability to me.
- newhotelowner 1y agoDo you need 2 party consent for recording in a public space?
- techjamie 1y agoThat's what I'm getting at with the expectation of privacy part. Talking into a drive thru speaker isn't really a private activity since everyone around can kinda hear it, but it'd probably be better to disclaim it anyway since someone attempting to file on you for it still costs money.
- thimkerbell 1y agoIs there an easy effective way to tell a company not to ask its customers' phone numbers if someone parked nearby can overhear them?
- smcin 1y agoThey steer you towards ordering on the mobile app instead, which typically gives you a 4-6 digit confirmation code which you then use combined with your name, when you pick up. And/or your receipt in the app.
- ssl-3 1y agoStrolling down the sidewalk at a park with a friend and chatting with them isn't necessarily a private activity either: We're in a very public space. Anyone within earshot can hear whatever we're talking about. If the sounds of our conversation winds up being incidentally in the background of someone filming the squirrels the tree frogs or something, then there's probably nothing to be done about that. But (in some states), it seems that it would be a very different can of worms if I were to elect to deliberately record the conversation I have with my friend without their consent. Even in a public space, that would appear to run directly afoul of the applicable laws.
- hluska 1y ago[flagged]
- jmkni 1y agoI don't think it was a swipe at minimum wage employees at all, more massive corporations like Burger King making their minumum wage employees be "cheerful"
- redwall_hp 1y agoOne of many reasons I despise Trash-Fil-A. They go hard on forcing their employees to sound a certain way, and it's just creepy as well as being abuse of their workers. Paying someone a pittance, or anything at all, doesn't entitle you to control over their perceived mood or how they speak. You'll have to negotiate with SAG-AFTRA if you want to hire actors.
- MBCook 1y agoBut elsewhere in the article they show that Burger King is using AI to analyze how well the drive-through employees are doing and if they’re being cheerful enough and such. So I think it’s more a jab at corporate mandated performative forced happiness for customers then the employees themselves.
- JKCalhoun 1y agoSure, could have written "hapless Burger King employee…". I suspect they did not realize it might come across the way it did to some.
- gus_massa 1y ago> Rating bathroom experiences: because everything needs a digital feedback loop At least here in Argentina, clean bathrooms was a huge selling point in the 1990' for Burger King and McDonald's. For example you can go to study to one of them with a few friends, and be there for hours because they have clean bathrooms, and from time to time one of the employees may come to offer coffee refill and ask if you want to buy something to eat with the coffee. [The free coffee refill changes from time to time. I'm not sure it's working now.]
- alanfalcon 1y agoNow my local Burger King (in Las Vegas, NV, USA) has a sign at each table telling you that you have 30 minutes to eat your food and get out before you get thrown out for loitering.
- immibis 1y ago[flagged]
- MathMonkeyMan 1y agoWell there are some people who seem to live at my local McDonalds.
- djoldman 1y agoAssuming: 1. Jane, a security researcher, discovers a vulnerability in a Acme Corporation's public-internet-facing website in a legal manner 2. Jane is a US resident and citizen 3. Acme Corporation is a US company ... is it legal for Jane to post publicly about the vulnerability with a proof of concept exploit? Relatedly: Why do security researchers privately inform companies of vulnerabilities and wait for them to patch before public disclosure? Are they afraid of liability?
- weitendorf 1y ago> Why do security researchers privately inform companies of vulnerabilities and wait for them to patch before public disclosure? Because if they don’t inform the company and wait for the fix, their disclosure would make it easier for less ethical hackers to abuse the vulnerability and do real material harm to the company’s users/customers/employees. And no company would ever want to collaborate with someone who thinks it’s ok to do that. It’s not even really a matter of liability IMO, it’s just the right thing to do. (main exception: if the company refuses to fix the issue or completely ignores it, sometimes researchers will disclose it after a certain period of time because at that point it’s in the public’s best interest to put pressure on the company to fix it even if it becomes easier for it to be exploited)
- nycpig 1y agoIANAL, but to answer your question, maybe? The CFAA has a fairly broad scope. "intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains, information from any protected computer; " 1030(a)(2)(C) Sandvig v. Barr tempers that a bit, with the DoJ now offering some guidance around good faith endeavors around security research. I'd suggest Jane have a good lawyer on retainer, and a few years to spend in the tied up the legal system.
- immibis 1y agoI suspect the post itself is legal but it's also a confession of highly illegal hacking.
- lazide 1y ago
- mrbluecoat 1y ago> They emailed us the password in plain text. In 2025. We're not even mad, just impressed by the commitment to terrible security practices. The hilarious sarcasm throughout was the cherry on top for me.
- decasia 1y agoRemind me to stick to my hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have with them or use any of the other gross surveillance technology that was recorded here. The story is really about two things. Their poor information security is pathetic, but their actual surveillance tech is genuinely kind of politically concerning. Even if it is technically legal, it's unethical to record conversations without consent.
- deltarholamda 1y ago>hyperlocal fast food restaurant that only has one location and probably doesn't record every conversation you have Good news! With AI programming assistance, this invasive technology--with the concomitant terrible security--will be available to even the smallest business so long as nephews "who are good with computers and stuff" exist!
- deleted 1y ago[deleted]
- bblacher 1y agoBlog seems to be down. https://web.archive.org/web/20250906150322/https://bobdahacker.com/blog/rbi-hacked-drive-thrus/ https://web.archive.org/web/20250906150322/https://bobdahack...
- thenthenthen 1y agoAnd.. its down “Blog post not found” archive link here: https://archive.is/zIteR https://archive.is/zIteR
- wellwells 1y agohttps://infosec.exchange/@bobdahacker/115158347003096276 https://infosec.exchange/@bobdahacker/115158347003096276
- oasisaimlessly 1y ago> We decided to take the post down after recieving a DMCA from burger king. The DCMA report was actually sent from response@cycle.com, and Cyble [1] appears to be a DCMA-takedown-as-a-service 'solution'. [1]: https://cyble.com/ https://cyble.com/
- patcon 1y agomaybe more longterm: https://web.archive.org/web/20250906150322/https://bobdahacker.com/blog/rbi-hacked-drive-thrus/ https://web.archive.org/web/20250906150322/https://bobdahack...
- mikechalmers 1y agonope
- deleted 1y ago[deleted]
- thimkerbell 1y agoBlog post not found
- pvtmert 1y ago99.9% of the CTFs have much more difficult questions! > The password protection? Client-side only. The password? Hardcoded in HTML.
- cobbzilla 1y agoHonestly wondering if this is a legit use of DMCA. Like, what exact provision of the DMCA is being implicated here? One should have some reasonable means for challenging this kind of thing. But what do I know. It’s a scary world when you know a C&D or other legal nastygram is 100% bullshit and want to ignore it, but you’re chained to a vendor that can’t respond with any level of subtlety, just the ban-hammer for everyone So the C&Ds and nastygrams become increasingly ridiculous, but whatevs, they’re all rubber-stamped so hey corporate just push that red “lawyer” button and make my embarrassment go away real fast, before any Streisand effect can kick in!
- kevincox 1y agoIANAL but it absolutely isn't. DMCA is for copyright violations. They aren't providing any copyright protected information in the post. The nearest thing would probably be screenshots of their internal applications which seems to be to be obviously fair use.
- charcircuit 1y agoThe article did show images of the internal website including a one showing a photograph. It infringes their copyright, but it would be up to the author to prove that the usage was fair use.
- igtztorrero 1y agoIt's incredible that a chain that produces terrible food has such a large surveillance system for underpaid employees. Surely the IT workers are also underpaid, which is why they left the doors wide open. That only confirms the subpar quality of the executives, the food, and everything at Burger King.
- deleted 1y ago[deleted]
- some_random 1y agoNot to nitpick but being emailed a temporary password in cleartext doesn't seem like an issue to me, assuming you're required to change it as soon as you log in.
- bigiain 1y agoEspecially since that email address presumably is used for the forgot password authentication anyway. But it is at least the equivalent of a code smell. perhaps a "UX smell"? A couple of obvious ways it can go bad: An attacker could potentially have access your email (perhaps from a data breach elsewhere or a password stuffing attach) and use the temp password before you do. If the temp password is the one entered by the user during signup, a naive user could sign up using their commonly-reused-password which then sits in cleartext foreven in their email archive.
- lazide 1y agoThe fun one for me is when they email you your original password in email. I’ve had that happen twice, and was always an amazing wtf moment.
- hvb2 1y agoThe way I read it, the password might not have been different for each new user... But that's negated completely by the next part about there being a sign up without any email verification
- import 1y agoIt seems the post is down because of a DMCA complaint made to Cloudflare. I’m curious about the different levels of DMCA complaints. I’m sure hosting companies receive them, but what happens if I’m self-hosting and not using Cloudflare? Will my ISP or domain provider get a DMCA? Especially curious for this case.
- djfobbz 1y agoBack in 2008–2009, we had a lot of bare metal servers at SoftLayer's (Dallas, TX) facility. One of our customers ran a South American music forum, and anytime someone uploaded an MP3, the data center would honor the DMCA request and immediately stop routing traffic to the server until the issue was resolved. Now imagine what tools they might have in their arsenal in 2025.
- qingcharles 1y agoWhen I ran a torrent tracker the biggest line item was paying an ISP to put their neck on the line and ignore every DMCA.
- jimt1234 1y agoHow do we know this was because of a DMCA complaint? Edit: Never mind -- > https://infosec.exchange/@bobdahacker/115158347003096276 https://infosec.exchange/@bobdahacker/115158347003096276
- akerl_ 1y agoUsually yes, it would go to your ISP. And depending on the ISP they’ll forward it to you or not. This was way more prevalent in the era where movie studios were hiring firms to send bulk DMCAs to people downloading torrents.
- zooi 1y agoThis is written like an LLM trying to be witty and it's nearly unbearable.
- argiopetech 1y agoNot saying I agree with you, but where do you think the training data came from? The internet is full of socially awkward albeit prolific writers.
- rsingel 1y agoThe blog post got taken down in response to a bullshit DMCA claim filed by a YC-funded company called Cyble DMCA screenshot https://infosec.exchange/@bobdahacker/115158347003096276 https://infosec.exchange/@bobdahacker/115158347003096276 Cyble announcement of YC funding in 2025 https://cyble.com/press/cyble-recognized-among-ai-startups-funded-by-y-combinator-2025/ https://cyble.com/press/cyble-recognized-among-ai-startups-f...
- b1c837696ba28b 1y ago40-some years ago in L.A. some guys discovered that a Burger King drive-up kiosk was tied to the restaurant with an RF link. It was a simple matter to determine the frequency and modulation mode and program a hand-held transceiver to use the same link. They set up in an adjacent parking lot with a video camera and set about pranking the customers that drove up. The resulting video, titled "Attack on a Burger King" (these guys were video engineers,) was copied all around town by the same studio rats that shared session outtakes, Red's Tube Bar, etc. It ends with an employee coming out, jogging toward the kiosk, while the hackers convince the customer to flee the angry man approaching them. Dunno if it ever made it to streaming.
- kotaKat 1y agoAh, yes, A lot of old fast food drive-thru headsets were in VHF business band (and similar). The Phone Losers of America were well known for their exploits to that regard. https://www.youtube.com/watch?v=cyLrus1yKvI https://www.youtube.com/watch?v=cyLrus1yKvI "I'm in the freezer at QuikTrip!"
- iqasimov 1y agoi swear god nothing can be cringer and funnier than when wannabe kiddo hackers write writeups. i can assure that they did dirty things for couple months before they actually report that but i can not prove it LMAO. I love this god level smart aleckness and the level of confidence is always ultimate LOL. idk man it is very sweet hahah. 50 grades of gray ahahahahahah
- Fairburn 1y agoSince way back has it, repost that shit. Burger King, get bent.
- arcfour 1y agoThis [post] is Claude generated, isn't it? Makes it a bit painful to read, to be frank, but nice work. I can't believe people get paid to write this junk (software). It's just...so bad.
- oneturkmen 1y agoJust googling "rbictg bk gb" yields some weird domains, including dev-bk-gb-moonshot (dot) rbictg (dot) com
- deleted 1y ago[deleted]
- iask 1y agoWtf! I’m certain this entire stack was reviewed by low level outsourced contractors. To the person below whining that BK should’ve had more time…absolutely not! Users have a right to know. No effort was made to protect the data. None. Action needs to be taken. The company contracted to build this stack should be replaced asap! Including the CISO.
- ghiculescu 1y agoWhat if it was built in house?
- deleted 1y ago[deleted]
- hvb2 1y agoSo they did do the work on sentiment analysis and all that, but didn't do any of the security stuff??? So when you're making minimum wage, you can expect every word you say to be analysed and your PII to be unprotected. I guess security wasn't a feature.
- wordglyph 1y agoI think the real issue in this case is if they are marrying your voice data (personal preferences) to you. They get your name when you pay with credit card. And they get your license plate. And now with AI are they selling this married information? Not to mention the ability for AI to clone your voice and selling that.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- sergiotapia 1y agoBefore writing and publishing this did you tell them about the vulnerabilities?
- A4ET8a8uTh0_v2 1y ago<< DMCA copyright infringement complaint from Cyble Inc., acting on behalf of Burger King I am mildly amused, but it only now makes me want to dig through internnet archive ( I believe another poster already helpfully provided ). GL BK. It sounds like Streisand will strike again. edit: Good read btw. I am curious as to why employees are in that database though.