Tiffin Tom: Fish, chips and a side of identity theft
paul.reviews
paul.reviews
In Australia, I’m yet to use a QR menu that doesn’t force me to provide my phone number. Why is my phone number necessary to order a bowl of chips? Ah, I see, Liven needs my phone number so they can sell it, according to their Privacy Policy. Mr Yum apparently doesn’t sell it, but still forces me to provide it anyway.
You would think that, wouldn't you?
I routinely see my real number printed on store receipts when the store has no reason to have them. GrubHub is supposed to anonymize numbers; the drivers always come through on a particular area code that I can recognize.
I've had drivers call me when lost, and it's always lost within my apartment complex (even though I've given really specific notes for every step of the way). I just explain it the same way I did in the notes, but they sometimes have a really poor sense of direction.
I've had a couple drivers call me because they refused to leave their car or come to the doorstep to put the food where they're supposed to. In fact, one of them sent me a photo of the Dumpster where I guess he tossed my meal.
Also, driver numbers are disclosed to the customer so that we can contact them. Drivers never answer their phones nor reply to texts. Their voice mail box is always full. If your order disappeared then the driver won't be answerable for that.
And the especially responsible will print the (human-readable...) URL under the QR code.
A restaurant in California has menu available only at QR code, and QR code is printed in MS word with skewed dimensions (rectangle instead of a square).
Besides needing to provide unnecessary amounts of information, it also requires a well working internet connection to load their bloated website. Which is often spotty so... very frustrating.
Luckily QR menus are going out of style.
Compared to Melbourne where half the pubs I visit tell me to order via the QR menu where I have to punch in my number and get an OTP before I can order anything.
That's insane.
I never use the QR menus -- I always ask for a printed one -- so I don't know if that's how it works around here, but I certainly hope not.
It's a very useful phrase in some circumstances and I have stolen it shamelessly.
Maybe as a backup for whatever unique device ID your phone gives them? The goal with QR menus right now is mostly conditioning people to accept them, but the long term goal is making it so that they can figure out who you are, what your income level is, what your eating habits are, what your order history has been, plus whatever else they feel like gathering and then using all that data to dynamically generate a menu with the highest possible prices they think they can wring out of you.
They want to make it so that when you order a bowl of chips they can charge you more than the person next to you who orders that same menu item without you ever being aware of that fact. They want to be able to adjust your prices with each visit to algorithmically determine the maximum amount you'll pay for something.
I'd suggest staying away from QR menus and rejecting the idea that discriminatory pricing is acceptable.
What about a group of people with different wealth profiles sitting at the same table? Would John who orders a steak and drives a Mercedes be charged $85 while Amy who drives a Honda Civic pay only $65 for that same steak?
Plane tickets are going into that direction, though no direct differentiation between people for now.
But routes/connections/timings indicating for example business travel will induce higher price than the same seat sold as part of flight indicating client more influenced by cost of flight.
And price differs between various places even in case buying the same seat for the same flight. For example you can effectively pay to skip deliberately annoying parts.
many stores (including grocery stores) have already been testing it out.
The biggest hurdle they face is the fact that most people (if aware that it's happening at all) find it offensive, which it is. Even those store loyalty cards are conditioning us to accept the idea that certain people get, or even deserve to get, different prices because of who or what they are. Prices should be transparent and it shouldn't matter how much money you have, or who you know, or how "loyal" you are (what a sick concept!) to a grocery store.
It seems like a more complicated process in every way.
If I’m eating out at a bar by myself, it means I don’t have to lose my table to get up and order. I also have social anxiety, if the bar is packed it’s a real problem for me. I’ll usually end up hovering while everyone else takes advantage and pushes in front of me.
The Wetherspoons app in the UK is a great example. Easy and fast to use, requires no account/PII just pay with Apple Pay.
Perhaps what they are used more is to start testing cards (we've had this attack happen to our production site on stripe's checkout.js... it'd be much easier if the attackers had our secret key)!
Additionally... if their site is this trivially insecure it won't end here.
Unsurprisingly, this company isn't as (in screenshot) their key starts with sk_live_.
But if it was, say, Authorize.net (I can't be the only one?) I'd probably take direct-action (via an anonymous proxy, of course - legacy companies just can't stop themselves shooting the messenger first...)
(Disclaimer: I haven't had to deal with Authorize.net since 2016 - can anyone say if things improved since then?)
$('#Fish & Chips').on('change', function () {
if ($('#Fish & Chips').is(':checked')) {
$('.Fish & Chips').css('background-color', '#3a606e;');
$('.Fish & Chips').css('color', '#fff;');
} else {
$('.Fish & Chips').css('background-color', '#fff');
$('.Fish & Chips').css('color', '#3a606e;');
}
});I have a good feeling this is more of copy-pasta code from either Copilot or ChatGPT or StackOverflow. That also explains why they handled encryption the way described in the article.
Dev: "Hey LLM, how do I pass data around in a secure way ?"
Bot: "You can encrypt the data before you send it, so that only users who have the relevant keys can read them"
Dev: "Hey LLM, it is not possible to access the data I have encrypted on the frontend"
Bot: "Here is the javascript code to decrypt the data you have passed then"
But seriously, those selectors are making me cringe. Does it even work with the spaces?
$('[id="Fish & Chips"]')
$('[class="Fish & Chips"]')So using newer CSS selector features, like attribute value selectors, will work fine in post-Sizzle jQuery versions.
There's all sorts of weird stuff, and it definitely looks like the kind of thing you'd see a beginner copy-pasting code and trying things out would create. The site sets a cookie containing the key-value pair "key":"value", for example.
This reminds me of when I first started programming professionally. I’d write loops in PHP like
foreach($orders_by_id as $key => $value) {
$id = $key;
$order = $value;
# ...
}
This was at a small logistics company you’ve never heard of (read: not the best development practices) so the habit was eventually caught in a code review and corrected. I must have written a dozen or so of those prior to that.Anyway its on HN now. FAFO
No idea what the legal precedent for negligent software engineering would be…
I suppose it depends what you consider agreement to social rules and how you define liability. I can certainly be held liable for damages for my actions to others which do not require me to hold any license - merely break the law.
Did I agree to the “rules of the road” when I was born? Do I consent by not emigrating?
(nits, picked…)
I jump into the firebase console and look at the security rules.
allow read, write: if true;
Turns out that the whole customer database was wide open. After fixing it up, I tried to work out how things had ended up like this. The entire system had been written by an intern...The last rule of programming is make it secure.
At least this appears to be the case from observation.
https://find-and-update.company-information.service.gov.uk/c...
Companies house is a goldmine of information.
Instant strike-off.
But the real problem here is that the data they collect isn't seen as a liability. If anything, it's an asset. This externality means that forfeiting people's personal info costs them nothing or nearly nothing.
If they change the tokens, rinse and repeat until you can't find them anymore.
This is illegal don't do this.
The worst part for me is that the blog reads like a short story instead of a technical analysis. And, given that it's published via ghost.org, makes me think there's just a bunch of scams and meta-scams going on... one layered on top of the other.
In addition, the tone of the article seems overly condescending to me. I certainly don't want to minimize accountability and the severity of security holes, but in the real world where startups are trying to hastily bring products to market, they are often understaffed and there is a certain reality that can't be denied.
The author may have indeed found flagrant problems but, in even moderately complex systems, there are big struggles with a diffusion of responsibility and a lot that can be lost in translation; for many reasons besides technical ineptitude.
Ultimately there was too much punditry and not enough of a clinical postmortem for my taste. Of course I don't seem to hold the popular opinion here given that my comment got down-voted rather severely, which seems unjustified. Oh well.