I guess I need to change the password on my luggage
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
Yes. Do that. Thanks to the TSA, I can now open any luggage without traces. Saves a lot of time. Don’t have to enter 123456 anymore.
"Hacker" when the password could be guessed by an elementary student. Jfc.
Pool on the roof must have a leak
If you answer these three questions...... Say no more Mr. Sphinx!
123456!
There is no exclamation Mark!
12345? Amazing, I have the same combination on my luggage!
No.
This is completely different and unhackable. 12345......6!
Such a great movie!
"hackers"....
Back in my day all the social engineering was done to humans.
Love, secret, sex, and god.
The greatest hackers of all time: Crash Override and Acid Burn.
What was it? "Mess with the best, die like the rest" lol. Classic. Also Penn Jilette from Penn & Teller is in that.
I'm so lucky that my password is hunter2
All I see is *******?
That's cause I copied your password but it shows up as *******
See: hunter2
I forgot what it was referring to and searched a bit
https://web.archive.org/web/20060212043925/http://www.bash.org/?244321
I hate any company that uses or builds AI to screen out hires so, so much. Tagging metadata is OK, but filtering is just evil (am/have been a hiring manager).
The company also added that it’s instituting a bug bounty program to better catch security vulnerabilities in the future. “We do not take this matter lightly, even though it was resolved swiftly and effectively,”
I also hate it more that I can't hate them for doing the right thing.
They only did the right thing after getting caught openly doing the wrong thing, so I'd say I'd still be pissed.
They should have never put the system in place with such a simple vulnerability (which to me) says they take such a laxodasical approach to security that I wouldn't trust them even now.
McDonalds gets millions of applications? wtf?
ETA: Yeah, I guess they do.
https://eu.usatoday.com/story/money/2025/05/13/mcdonalds-hiring-surge/83595827007/
I don't think you were quite grasping the scope the McDonald's operates at. That's only a couple hundred per location, and fast food restaurants tend to have extremely high turnover, so that's definitely not an unrealistic number.
ETA? Estimated Time of Arrival?
One of us doesn't know what that stands for. I feel like the time my grandpa died, and mom sent me an email telling me "We're going to the funeral this Friday to pay respects to grandpa. LOL!"
I was quite confused. Turns out she grew up with "Lots Of Love". For a second she seemed like she turned into an absolute psychopath, for like....no reason.
ETA? Estimated Time of Arrival?
In this context, it means "Edited To Add". I do wish they abbreviated it some other way, since "Estimated Time of Arrival" is a much more common meaning. I would accept "E2A" or something stupid, as long as it was more unique. Alternatively, they could just use "Edit:".
Edit: added link.
This is my first time reading about this alternate "ETA" initialism. Interesting...
ETA: Mine, too.
(ETA in this context means "Entering Text As:")
What an ~~Enternaining~~ Entertaining Twist of an Acronym.
ETA = Edit to add
Just trying to explain why my comment changed, in case anyone saw it before that LOL.
They have over 40k locations. Many are 24/7. They also surely churn through employees, have many part time employees, and probably get many more applicants than they hire.
The employees will be hired by the franchisees but they still use the McDonalds software.
Millions is not a surprise to me at all. Perhaps that it's tens of millions is a little surprising, but it still seems within the realm of possibility.
i mean there's a shit ton of unskilled labor out there whose vertical reach isn't that great.
A lot of companies use Paradox. They shit canned all their HR down to the bare bones and hired Olivia, which the Paradox recruiter I worked with said is so bad he has to take over answering in chat half the time.
Why do you even need a hiring bot for McDonalds? Maybe for managers but a McJob is a McJob.
I help folks with disabilities get jobs, so I'm familiar. I generally avoid fast food for my people, because it's degrading and no one really wants a McJob. That being said, the bot actually makes it easier to apply, and they immediately schedule an interview...because they don't care what your resume says and they just need warm bodies to throw at angry customers. Again, I avoid it for my folks wherever possible.
In the future, actual hacking will just involve social engineering corporate ai systems ( aka prompt hijacking )
Wasnt it a security researcher and not a hacker?
"Hacker" doesn't always imply one acting with malicious intent.
If the 90s taught me anything, it's that hacking is done exclusively on monochrome green monitors, with dos. Except once they hack in, the monitor is full color, and somehow has access to every video camera on the planet. With the ability to enhsnce resolution seemingly to magical levels where you can see a clear reflection in someones pupil.
ENHANCE!!!
Nah, they evolved way past that in the following decades.
Sometimes when they're in a hurry they create GUI interfaces using Visual Basic to track IP adresses.
And sometimes, if they're very good, a hacker can manually carve a virus in a piece of bone using fractal patterns. They can use that to hack the computer scanning the bone so it adds a zero in thresholds for CPU heat monitoring and make it instantly catch fire.
The risk is that some unknown hacker discovered this vulnerability and abused it before the researchers discovered and reported it. It sounds like the company has confirmed that didn't happen, but they aren't 100% trustworthy in that regard, simply because they might have missed something.
yeah i know the risk, but the headline implies the data was exposed to a hacker who tried the password 123456 but thats not the case. A security researcher was investigating the application and accessed a test application with the password 123456 then found an API call which exposed the data and then he instantly reported it.
"Spaceballs: the HR Robot"
Seriously though, who the fuck uses 123456 as the password for anything? The morons pulling shit like this are making bank while the people brought onboard by McDonalds make scratch by comparison, and would be crucified for fucking up even a fraction as much as this. Millions, with six zeroes, millions of applicants' data stolen from an account with the kind of password that a kid would use on their home computer. Fuck, this makes me so mad, the sheer incompetence.