TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hamburglar strikes again, feasts on $2k in meals using customer's McDonald's app

41 点作者 t1o5大约 6 年前

6 条评论

neetodavid大约 6 年前
I saw a similar post on reddit about a week ago ( <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;canada&#x2F;comments&#x2F;bgrl7n&#x2F;canadian_mcds_app_is_not_safe&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;canada&#x2F;comments&#x2F;bgrl7n&#x2F;canadian_mcd...</a> )<p>From the top comment, speaking to support on the phone:<p>&gt; &quot;He then admitted that the issue was that The App would occasionally load the wrong user&#x27;s account, which was allowing people to purchase using someone else&#x27;s CC.&quot;<p>If that is what is happening, maybe it is similar to the caching issue Steam had when serving store pages a year or two ago.
irq-1大约 6 年前
&gt; &quot;I expected them to do the refund because it was their fault,&quot; he said. &quot;It&#x27;s their application. If it&#x27;s not secure, they should take responsibility.&quot;<p>The internet has been retelling some version of this story forever: company system screws paying customer, and company refuses to help or even admit a problem.
评论 #19779915 未加载
rhinoceraptor大约 6 年前
This is a good PSA for never using a debit card online.
评论 #19780411 未加载
评论 #19780371 未加载
codedokode大约 6 年前
I don&#x27;t understand what is the problem. The victim didn&#x27;t order those food and therefore should not pay for it.
ydnaclementine大约 6 年前
As annoying as it is, this is why I hardly ever store my credit card online for “future use”
评论 #19785439 未加载
crsv大约 6 年前
Were these users on the Android version of the app? Would this exploit be device agnostic or would something in how Android handles in-app payments have effected this? Does the platform matter here?