TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hamburglar strikes again, feasts on $2k in meals using customer's McDonald's app

41 pointsby t1o5about 6 years ago

6 comments

neetodavidabout 6 years ago
I saw a similar post on reddit about a week ago ( <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;canada&#x2F;comments&#x2F;bgrl7n&#x2F;canadian_mcds_app_is_not_safe&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;canada&#x2F;comments&#x2F;bgrl7n&#x2F;canadian_mcd...</a> )<p>From the top comment, speaking to support on the phone:<p>&gt; &quot;He then admitted that the issue was that The App would occasionally load the wrong user&#x27;s account, which was allowing people to purchase using someone else&#x27;s CC.&quot;<p>If that is what is happening, maybe it is similar to the caching issue Steam had when serving store pages a year or two ago.
irq-1about 6 years ago
&gt; &quot;I expected them to do the refund because it was their fault,&quot; he said. &quot;It&#x27;s their application. If it&#x27;s not secure, they should take responsibility.&quot;<p>The internet has been retelling some version of this story forever: company system screws paying customer, and company refuses to help or even admit a problem.
评论 #19779915 未加载
rhinoceraptorabout 6 years ago
This is a good PSA for never using a debit card online.
评论 #19780411 未加载
评论 #19780371 未加载
codedokodeabout 6 years ago
I don&#x27;t understand what is the problem. The victim didn&#x27;t order those food and therefore should not pay for it.
ydnaclementineabout 6 years ago
As annoying as it is, this is why I hardly ever store my credit card online for “future use”
评论 #19785439 未加载
crsvabout 6 years ago
Were these users on the Android version of the app? Would this exploit be device agnostic or would something in how Android handles in-app payments have effected this? Does the platform matter here?