7 ms·
'123456' password exposed chats for 64M McDonald's job applicants
- mediumsmart 1y agoThat’s the default pin for iPhones too.
- deafpolygon 1y agoIncredible! That’s the combination to my matched luggage!
- jonplackett 1y agoFor the uninitiated (ie probably anyone under 35) https://m.youtube.com/watch?v=a6iW-8xPw3k https://m.youtube.com/watch?v=a6iW-8xPw3k
- dylan604 1y agoEarlier this year, Mel posted a video saying they are making a sequel.
- jonplackett 1y agoAs in a sequel to that clip or a sequel to the show?
- sans_souse 1y agoThe spoof prophecies are being proven! now we're all stuck in a real-life Spaceballs movie.
- bigmattystyles 1y agoJust in time for the sequel!
- mattl 1y agoCheck your luggage for fries
- bsuvc 1y agoIt sounds like there were two separate problems: The first was that 123456 was the credentials for the admin panel. The second was an insecure direct object reference, where the lead_id querystring parameter can be changed on an API call to retrieve another applicant's data.
- hardwaresofton 1y agoA third problem that senior engineers might recognize: using numeric IDs on an outward facing object. UUIDs would have made this impossible as well
- bsuvc 1y agoNot impossible, just more difficult to guess. "Security through obscurity" isn't really good enough.
- tyre 1y agoYes and… UUIDs aren’t “just more difficult to guess.” They are inconceivably harder to guess. > Put another way, one would need to generate 1 billion v4 UUIDs per second for 85 years to have a 50% chance of a single collision.
- 0cf8612b2e1e 1y agoThe security is that your server will crash from overload long before someone can guess the ids.
- zarzavat 1y agoYou are both right. UUIDs, if randomly generated from a CSPRNG are impossible to guess. But not all UUIDs are generated from a secure RNG, or use randomness at all.
- xeromal 1y agoI may be a dingleberry but who doesn't use uuidv4 for everything?
- micw 1y agoWait, 64 million applicants, not applications? That's like 20% of the US population!
- Volundr 1y agoMaybe it includes applications outside the US?
- bigfatkitten 1y agoThey use this site for hiring globally. The number of privacy regulators they will have to notify and deal with is going to make this messy.
- atm3ga 1y agoIf this was disclosed via a vulnerability disclosure or bug bounty program and there are no indicators of a data breach then it's effectively like the findings from a pen-test so very likely no regulatory reporting requirements.
- mousethatroared 1y agoOthers have said it's for the global site, but would 64 million really be that off for the US? I just looked it up 13 of the 40k francises are in the US. Assuming linearity, thats about 21 million US applicants since they started keeping centralized, digital records. 20% of Americans younger than 40 is not a bad guess.
- crazygringo 1y agoWhich is 1,615 applicants per US franchise. Seems totally reasonable to me. 2 shifts of 12 employees is 24 employees per day. Assume they all work there for 6 months on average, then if the system's been up for 10 years, that's 480 employees per franchise over a decade. Which means for every employee they hired, 2 were either rejected or chose not to work there. Working at McD's is something a lot of people do for a few months when they're young.
- gnabgib 1y agoDiscussion (125 points, 2 days ago, 69 comments) https://news.ycombinator.com/item?id=44513940 https://news.ycombinator.com/item?id=44513940
- pyman 1y agoPlease stop giving OpenAI ideas on where to find and download more data! $ Downloading 64M transcripts...
- tonetheman 1y ago[dead]
- ajsnigrutin 1y agoIt's funny how mcdonalds did everything in their power to make it almost impossible to run their mcdonalds app on a rooted phone, but their backend infrastructure is beyond broken (security wise)
- hippich 1y agoBtw, I wondered why they flight root on the phone at all?
- ajsnigrutin 1y agoI have no idea... maybe they store their "coupons" locally and are afraid you'll clone them? Don't know, I eat there twice a year and it's not worth it :) suhide in magisk makes my banking app work, but not mcdonalds :)
- le-mark 1y agoMy theory is they store payment information on the mobile app. The app connects to the store wifi automatically, even when going through the drive thru. And processes the payment then. I theorized it so they don’t store credit card info on their servers, simplifying their PCI audits. Presumably they think all that is better than preventing the app from running on rooted phones.
- ceejayoz 1y agoThe McDonalds consumer-facing app is quite possibly the worst app from a major company I've ever encountered. It's shockingly bad.
- parpfish 1y agoThe UI is atrocious. I do computers for a living and can barely navigate and figure out what’s going on.
- Keverw 1y agoI noticed it freezes up on me sometimes when I open it. I assume something is blocking instead of being asynchronous when it pings their servers, but instead of waiting to dismiss a loading screen it just shows the full app and like freezes.
- theturtle 1y agoWait, sixty-four MILLION people actually wanted to work there? Are they counting everybody since 1954?
- chungy 1y agoIt's the second largest fast food chain, behind Subway. It is everywhere and provides steady good work. There should be no surprise here.
- notepad0x90 1y agogetting jobs is hard. majority us on this thread couldn't get a job at mcdonalds if we tried our best. and that's mostly because they think we'll quit after a few days/week. and there are harder to get jobs that pay even less! it's about supply/demand, not how desirable the job is.
- ezekiel68 1y agoThis is what happens when "Minimum Viable Product" meets modern threat environments. 'Move fast and break things' indeed.
- ChrisArchitect 1y ago[dupe] https://news.ycombinator.com/item?id=44513940 https://news.ycombinator.com/item?id=44513940
- RandomBacon 1y ago[dupe comment] https://news.ycombinator.com/item?id=44537871 https://news.ycombinator.com/item?id=44537871
- jofzar 1y agoMy favourite part form the original report was that paradox had no way to find their security team ( to contact) and their security page just had "We worry about security, so you don't have to." https://web.archive.org/web/20250208000940/https://www.paradox.ai/legal/security https://web.archive.org/web/20250208000940/https://www.parad...
- autobodie 1y agoYour favorite part? Are you sick? I can't imagine having a "favorite part" of any of this.
- nickthegreek 1y agoit’s a common expression to point out unbelievable moments in a story.
- rPlayer6554 1y agoChill out man, it’s a common ironic expression
- vivzkestrel 1y agoStupid question, if we really tried brute forcing websites with less than 100k monthly traffic, how many such cases would be actually run into?
- aaronmdjones 1y agoThere was also https://www.techspot.com/news/108619-mcdonalds.html https://www.techspot.com/news/108619-mcdonalds.html > Moreover, when Carroll attempted to alert Paradox to the breach, he was unable to find a security disclosure contact. The company's security page mostly consists of a simple assurance that users shouldn't need to worry about security. Eventually, after the researchers emailed "random people," Paradox and McDonald's confirmed that they resolved the issue in early July. Shouldn't need to worry indeed. McDonald's evidently doesn't either. Can someone tell them to put "Set a password a five-year-old child can't guess" onto their deployment checklist?