frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Would You Like an IDOR With That? Leaking 64m McDonald's Job Applications

https://ian.sh/mcdonalds
49•samwcurry•5h ago

Comments

bravesoul2•3h ago
It involves AI but AI wasn't the cause. It was an enumeration on object id, discovered because the author could access a test site with password 123456 and try things out.
oc1•3h ago
I have so many questions to the developers but i believe the answers will just crush my poor worker soul so let it be.
ryandrake•1h ago
I've been so lucky throughout my career to have almost entirely worked with competent and smart developers. I've always wondered what a conversation with one of these other ones is like, after a production site is found to use 123456/123456 as credentials. "Hey, Mike, we just had someone in the public notice that our admin interface could be accessed by anyone with default credentials. You're the manager on this project. How did this happen?" I would love to be a fly on the wall for that conversation, or read the postmortem. How does this kind of configuration even make it past code review, let alone staging and production?
lmz•1h ago
It's config not code - and a demo interface is a nice thing to have. The cross account read, however...
Marsymars•21m ago
”Well you see, that work was outsourced to a team where none of the implementing developers are still present, our auditors and pen testers both signed off on it, and anyway we’ve got cyber insurance to cover the fallout.”
NooneAtAll3•6m ago
> How does this kind of configuration even make it past code review

that's the secret - there is none

TZubiri•2h ago
It certainly doesn't reflect well on AI as a BuzzWord.

Execs vetted this provider and approved it, which isn't irrelevant to the disregard for safety occuring with AI in general right now.

Additionally, are we certain the vendor didn't use AI to vibecode stuff?

Proofread0592•3h ago
I cannot believe the 123456 worked, it's literally a joke from SpaceBalls.
shrubble•3h ago
Reminds me that I need to change the combination on my luggage…
jeffbee•49m ago
In a past life, I had an investment stake in Krispy Kreme donuts. We were poking around to see if we could learn anything about the company. We watched a training video for new store managers. It told the viewer to go to some URL and enter their credentials. In the video, the example credentials were "admin" and "admin" as the password. So we tried that, and of course it worked on their live system. We immediately had access to global, live, online revenue data for every real Krispy Kreme outlet, not some training simulation.

Most people are not qualified to handle computer security, is what I learned from that.

david2ndaccount•2h ago
> We immediately began disclosure of this issue once we realized the potential impact. Unfortunately, no disclosure contacts were publicly available and we had to resort to emailing random people. The Paradox.ai security page just says that we do not have to worry about security!

Amazing.

eth0ws•22m ago
Having a security.txt would be best, but they've updated the page to include a security email address which is a start.
snypher•1h ago
>Without much thought, we entered “123456” as the username and “123456” as the password

I feel like there's more to this that I'd love to know the story behind...

gruez•1h ago
Maybe they ran a simple wordlist attack and wanted to launder the methods they used?
ryandrake•1h ago
> The personality test was a disturbing experience powered by Traitify.com where we were asked if phrases like “enjoys overtime” are either Me or Not Me. It was simple to guess that we should probably select Me for the pro-employer questions and Not Me for questions referencing being argumentative or aggressive, but it was still quite strange.

Offtopic from the security issue, but I wonder if they really get any value out of this "Personality test." It seems like it's just a CAPTCHA that makes sure the applicant knows when to lie correctly.

veggieroll•1h ago
For the employer, the question is self fulfilling. Either way they get what they want. Even if someone knows enough to lie, the lie betrays that they’re desperate enough to be unable to resist anything management demands.
reactordev•1h ago
While also providing evidence that you do indeed love overtime based on your answer. Ugh… the only way to win is not to play.
bee_rider•1h ago
Working in retail is 99% lying that you care about your job, so might as well start it out on the right footing.
msgodel•29m ago
Is it simple to guess? I always assumed if you went too hard with those answers they'd assume you were lying and reject you.

Maybe this is why I never got the mcdonalds call back last time I was layed off.

HPsquared•21m ago
Overtime can be enjoyable if you get paid overtime rates.
Titan2189•1h ago
Hats off to Paradox for remediating this within 30 hours of reporting.

The case for building operator interfaces before AI agents

https://www.henrypray.com/writings/the-only-saas-feature-you-should-be-building
1•henrypray•1m ago•0 comments

USB-C Scented Cables: Lychee, Strawberry, Apple

https://www.fivebelow.com/products/up-tech-type-c-to-type-c-scented-cable-48in-9184770
1•rendx•2m ago•0 comments

Show HN: ColorConJ – Explore Spanish color names by letter

https://colorconj.com/
1•lur0913•2m ago•0 comments

Eval AI jobs new market for Mercor

https://www.gardinercolin.com/p/marketplace-memo-13
1•predogger•3m ago•0 comments

In search of more efficient learning algorithms, researchers look to infants

https://www.thetransmitter.org/neuroai/the-babylm-challenge-in-search-of-more-efficient-learning-algorithms-researchers-look-to-infants/
1•domofutu•6m ago•0 comments

HIV-1 latency reversal via ectopic expression of a viral antisense transcript

https://www.science.org/doi/10.1126/sciadv.adu8014
1•PaulHoule•7m ago•0 comments

Our Missing Pieces

https://docs.google.com/document/d/1-KSIE89xHnipRBm8T6BRbxEQb5_byr5CwkB-S7XIwjQ/edit?tab=t.0
1•jger15•7m ago•0 comments

Claude Code OAuth Authentication Fails - "OAuth account information not found

https://github.com/anthropics/claude-code/issues/1484
1•rakken•10m ago•0 comments

CatchIdeas – Find High-Traffic Keywords for Product and Content Ideas

https://catchideas.com
1•labubulive•10m ago•0 comments

Fact Sheet: Autism Prevalence

https://www.thetransmitter.org/spectrum/prevalence-autism-u-s-remains-steady-new-data-suggest/
1•domofutu•11m ago•0 comments

No Tax on Overtime Calculator

https://notaxonovertimecalculators.org/
1•dond1986•11m ago•0 comments

V0 Platform API now in beta

https://vercel.com/changelog/v0-platform-api-now-in-beta
1•tzury•12m ago•0 comments

Research suggests electricity markets are using suboptimal pricing

https://arxiv.org/abs/2507.06035
1•cfata•13m ago•1 comments

Thoughts on Motivation and My 40-Year Career

https://charity.wtf/2025/07/09/thoughts-on-motivation-and-my-40-year-career/
1•zdw•14m ago•0 comments

Learning in living mice defies classic synaptic plasticity rule

https://www.thetransmitter.org/learning/learning-in-living-mice-defies-classic-synaptic-plasticity-rule/
1•domofutu•15m ago•0 comments

Doctest is a new C++ testing framework

https://github.com/doctest/doctest
1•BiraIgnacio•18m ago•0 comments

Most people who buy your game won't play it

https://howtomarketagame.com/2025/06/03/most-people-who-buy-your-game-wont-play-it/
1•walterbell•24m ago•0 comments

The #1 Reason Your GenAI Project Will Fail in Production

https://www.mlwhiz.com/p/from-prototype-to-production-mlops
1•ai_unwrapped•29m ago•0 comments

Andreessen Horowitz Leaves Delaware for Nevada, Tells Startups to Follow

https://www.bloomberg.com/news/articles/2025-07-09/andreessen-horowitz-leaves-delaware-for-nevada-tells-startups-to-follow
4•pilingual•30m ago•0 comments

Concorde – The 24 Hour World (1973) [video]

https://archive.org/details/concorde-the-24-hour-world
1•petethomas•33m ago•0 comments

Bug report forms powered by AI – No more duplicates, spam or lackluster reports

https://bugspot.dev
1•PaulPlay•36m ago•1 comments

A warning to sword-makers, and sword buyers

https://www.youtube.com/watch?v=nLIcohyT5Dc
1•duxup•38m ago•0 comments

Firnas: AI Native Travel for Business

https://www.firnas.ai/
1•b0xtch•40m ago•0 comments

Nvidia Became the First $4T Company

https://www.wsj.com/tech/ai/nvidia-nvda-4-trillion-market-cap-466c1c9c
3•ViktorRay•40m ago•0 comments

PoPo: MMD Anime Char Model Pose Generation Using Fine Tuned LLM

https://popo.love
2•Amyang•41m ago•0 comments

Army tests robotic coyotes to defend fighter jets from wildlife

https://www.armytimes.com/news/your-army/2025/07/07/army-tests-robotic-coyotes-to-defend-fighter-jets/
2•bookofjoe•43m ago•0 comments

Music for Heathrow

https://mediacentre.heathrow.com/pressrelease/detail/23253
3•dijksterhuis•47m ago•1 comments

AI Can't Take over Soon Enough for Me

https://rodyne.com/?p=2911
3•boznz•50m ago•0 comments

Using Protobuf to make Jira Cloud faster

https://www.atlassian.com/blog/atlassian-engineering/using-protobuf-to-make-jira-cloud-faster
1•ksec•53m ago•0 comments

Dépanneurs

https://walkmontreal.com/curiosities/depanneurs/
2•thomassmith65•55m ago•0 comments