back to article McDonald's email blunder broadcasts database creds to comedy competition winners

McDonald's customers who won a prize draw competition got more than they hoped for after the burger chain emailed them login credentials for development and production databases used to power the campaign. The first person to report the blunder to McDonald's, startup founder Connor Greig, told The Register: "It's a bit weird …

  1. Anonymous Coward
    Anonymous Coward

    While this is an interesting story ...

    it does also read as a puff piece for the protagonist and his company.

  2. Roger Kynaston
    Happy

    I'm lovin it

    Their words not mine.

    1. big_D Silver badge

      Re: I'm lovin it

      I don't think I've been under the golden arches in over a decade...

      1. Roger Kynaston

        Re: I'm lovin it

        Last time I was in one was April 2014 in Fort de France, Martinique. They were the only place with decent wifi and it was worth the cost of a pretend milkshake and ersatz fishy thing.

  3. wolfetone Silver badge

    McDonald's went to shit when they got rid of Ronald.

    He wouldn't have let the Ham Burglar get away with this sort of caper.

    1. TimMaher Silver badge
      Coat

      Re: Caper

      Do McD make tartar sauce?

      I think we should be told.

      Mine has some old frittes in the pocket.

    2. Rufus McDufus

      Willard Scott, creator of Ronald McDonald, died a few days ago. Coincidence?

      1. Anonymous Coward
        Anonymous Coward

        He didn't die. He just went to hang out with Col. Sanders.

        1. Anonymous Coward
          Anonymous Coward

          KFC really did go bad when Sanders, who insisted on a voice in quality control. died. Frozen chickens were rolled out shortly afterwards by the accountants.

    3. Alumoi Silver badge

      Ronald? Are we talking about that nightmarish clown with it's face a parody of Freddy?

    4. Anonymous Coward
      Anonymous Coward

      >McDonald's went to shit when they got rid of Ronald.

      Which is ironic given the number of Ronalds who go to McDonalds to take a shit.

      1. Anonymous Coward
        Anonymous Coward

        > Which is ironic given the number of Ronalds who go to McDonalds to take a shit.

        What? Is this a joke? It doesn't even make sense.

        1. Anonymous Coward
          Anonymous Coward

          Never heard of a McShit with Lies?

  4. Shippwreck1
    FAIL

    security.txt

    Apparently The Register doesn't have a security.txt file either...

    1. Ol'Peculier

      Re: security.txt

      Until reading this I wasn't even aware of "security.txt". Then I checked El' Reg and instantly felt a little bit better.

      Neither have most of the sites I subsequently looked at, including that of the site owned by the person grumbling about Maccy D's not having one....

      1. Shippwreck1
        WTF?

        Re: security.txt

        Little bit disingenuous... if you go to either of these links they forward straight to the creatorsphere openbugbounty page. So whilst not techinally having a plain text security.txt file they have ensured that if someone wants to goto "the file" they get something other than the 404 delivered by most others!

        https://creatorsphere.co/.well-known/security.txt

        https://creatorsphere.co/security.txt

    2. Eclectic Man Silver badge

      Re: security.txt

      But the Register does have ample links allowing you to contact staff. There is a 'corrections' link for each article, and checking elsewhere on the site provides e-mail contacts for various journalists and editors.

    3. Marco Fontani (Written by Reg staff)

      Re: security.txt

      ... and we now do ;) Friday deploys are bliss.

  5. Pascal Monett Silver badge
    FAIL

    "We take data privacy very seriously"

    As usual, after the breach has happened.

    This kind of bullshit declaration is starting to wear very, very thin.

    1. Eclectic Man Silver badge

      Re: "We take data privacy very seriously"

      "Those affected will be contacted to reassure them that this was a human error and that their information remains safe. We take data privacy very seriously and apologise for any undue concern this error has caused,"

      Well, that is so reassuring. Though they are hardly going to say they don't give a toss about user data security in a country with GDPR enacted.

      I rather like the term "undue concern" in the above message. They are not apologising for genuine reasonable concern caused by the breach, just "undue concern".

    2. DevOpsTimothyC

      Re: "We take data privacy very seriously"

      I also fail to see "And we have reported this to the ICO"

    3. Anonymous Coward
      Anonymous Coward

      Re: "We take data privacy very seriously"

      it wore thin from the start, it's just taken, what, 10 years, to become bleeding obvious and tiresome.

    4. Tromos

      Re: "We take data privacy very seriously"

      I'm sure it's uttered as sincerely as the line "We come in peace." from the movie "Mars Attacks".

    5. Potemkine! Silver badge

      Re: "We take data privacy very seriously"

      No, really, we take data privacy very seriously. Just not the users one.

  6. Anonymous Coward
    Anonymous Coward

    got more than they hoped for

    serves them right!

    (sorryyyyy)

  7. Anonymous Coward
    Anonymous Coward

    Next he emailed just under a dozen McDonald's UK email addresses

    shouldn't have bothered, just post on fb or twitter, make a shitstorm how they don't have a contact number, phone line dead, no emails, basically, an mc-ghost ship, wait for shit-storm, etc, take it from there. It seems to be the only way to get through to any org these days.

    (says the fb- and twitter-less one)

    1. Drew Scriver

      Re: Next he emailed just under a dozen McDonald's UK email addresses

      For years I've based my initial security assessment of (mainly) banks on a call to their customer service phone number and ask the person who answers the phone if the company has a procedure for customers to report a security vulnerability.

      Only once did I encounter one that did.

      As for the others, the legitimate conclusion is that they don't truly care...

      Sadly, most companies don't even have a process for employees to report a vulnerability should they find one.

      Best example is a company I worked for that had a major security flaw on the main website. I could not find a published procedure for reporting it, so I called the corporate Risk Management office. They didn't know either, but begged me to please inform them if I did manage to find the answer.

      After several weeks I stumbled upon an internal web form for reporting vulnerabilities. After several more weeks someone contacted me to let me know that the mailbox for that form was no longer monitored. He did supply another form to report the issue, which I used and I did indeed receive an acknowledgement.

    2. Jay 2

      Re: Next he emailed just under a dozen McDonald's UK email addresses

      Indeed. It's a poor state of affairs nowadays when to get things done you have to resort to publicly shaming a company on its own social media.

  8. Swarthy
    Pirate

    A better man than I

    On finding that, I would have been extremely tempted to take a look at the DB, and maybe see if I could improve my winnings.

  9. Gene Cash Silver badge

    I wouldn't have given a damn

    A hole in McD's security? This is the company that can't distinguish between no onion and extra onion.

    I would have giggled and gone about my day.

  10. Mr Dogshit

    I’m lovin’ it™

  11. Tron Silver badge

    The importance of Darwin in tech.

    Any global corporation that cannot be arsed to provide an emergency contact address that is actually monitored, for such breaches, deserves all it gets.

    They want to insulate themselves from us inconsequential proles, that's up to them. If you can't get through after wasting some of your valuable time, walk away and leave them to suffer the consequences.

    1. John Brown (no body) Silver badge

      Re: The importance of Darwin in tech.

      "Any global corporation that cannot be arsed to provide an emergency contact address that is actually monitored, for such breaches, deserves all it gets."

      Wile I agree, it's probably for the same reason that postmaster@, admin@, webmaster@ abuse@ etc are rarely monitored, probably full, or don't even exist in the first place. They not only get hammered by every spammer, but also anyone who has an axe to grind and thinks they are being ignored through the usual channels.

      1. Anonymous Coward
        Anonymous Coward

        Re: axe to grind and thinks they are being ignored through the usual channels

        mind you, these days, usually, there are NO 'usual channels', there are NO channels.

  12. Terry 6 Silver badge

    That other issue

    As implied by other posters, above, these big companies go out of their way to avoid being told stuff that is to their benefit to know. .

    If a customer has a genuine complaint ( which includes a security fail) they might well want to tell the company. So what does the company do? Usually. these days it puts it's digit in it's electronic ears and sings "la la la" very loudly. Like someone ignoring the bailiff on the doorstep and hoping he'll give up and go away.

    So unless their carefully chosen focus group tells them there's an issue they won't know until sales begin to drop away.

    My assumption is that beancounters calculate that the cost of those disgruntled punters taking away their business is less than running a decent customer service department. Being beancounters they don't factor in the fact that most users don't complain - they go straight to the walking away stage.. And if the problem is widespread they'll continue to walk away.

    So for most of these organisations they hide or remove phone numbers and email addresses. Instead there's a web page with a link that says "Contact us" that leads to an FAQ page that has no FAQs with any relevance to anything that anyone would care about. Followed, possible only after you've clicked on one of these irrelevant links, by another link that says "Need more help". This takes you to a generic Help page.Which leads to the FAQ page......

    1. Jamie Jones Silver badge

      Re: That other issue

      Yep, I tried to report an issue with the NHS DNS about a year ago, but got nowhere. Emails to their contacts details, and nominet were ignored.

      Basically, one million years ago, an article for tightening up DNS servers went "viral" - stupidly, it had a list of non-assigned nets that it said you should block.

      2.0.0.0/8 was one such block.

      Many DNS servers to this day still block that range.

      The NHS servers do. Basically, If your DNS resolver sits on a 2.0.0.0/8 address, it cannot resolve the NHS addresses (all their nameservers block 2.0.0.0/8) [ Well, they did last time I checked 6 months ago, it may be fixed now. ]

      I used to generally check for sites that still blocked those addresses, and reported them. I had some successful feedback, but too much hoop-traversing that I grew tired of it. Now I just avoid setting up DNS on 2.0.0.0/8

      (I just found this article about the issue http://blog.e-shell.org/302)

    2. Anonymous Coward
      Anonymous Coward

      Re: this takes you to a generic Help page.Which leads to the FAQ page

      I wonder sometimes, whether such vicious circle was, perhaps, designed by a genius, severely underpaid / unpaid intern, bored to death, or whether this is something way above the human-based design, more of a trait of 'nature', as nature has this uncanny (?) tendency to take the path of the least resistance. Yeah, a philosophical question, nature v. nurture, mc-case study...

    3. ThatOne Silver badge

      Re: That other issue

      > My assumption is that beancounters calculate that the cost of those disgruntled punters taking away their business is less than running a decent customer service department

      Definitely. Also the crowd has a very short memory (days). So no matter what you do to them, they will quickly forget and you can catch them back with your next advertising campaign. No harm done.

      Also agree about contact information: Companies indeed don't want to be bothered, so they create this obstacle course to hide the fact there is no way for the masses to contact them. They consider that anybody who really has to contact them already has the required contact information, the rest is just annoying background noise...

  13. Anonymous Coward
    Anonymous Coward

    It's pretty much guaranteed nowadays that registering to get something for free (or even just cut price) would mean that one's name and private parts will thereafter make the rounds as a potential sucker. One might even sit down one day in a public loo to find one's name and number engraved on the door because of it.

    Frankly, this doesn't reflect well on Creatorsphere.

  14. This post has been deleted by its author

  15. Anonymous Coward
    Anonymous Coward

    Big Crap

    Do you want files with that?

  16. Kevin McMurtrie Silver badge
    Facepalm

    When something wants a configuration object

    It's a good idea to implement a custom ToString() / toString() that will not include credentials.

  17. luminous

    Why would you expect them to care about your security? They clearly don't care about serving you decent food.

  18. petethebloke

    Scores lol

    > Like scores of Britons around the country, Greig, founder of web platform toolkit Creatorsphere, enjoys munching McDonald's meaty produce.

    Great stuff. This is why we buy El Reg every morning.

  19. pip25
    Trollface

    Honestly, I would also struggle to report this

    due to uncontrollable laughter

  20. John Jennings

    I read all the comments - and am surprised

    Missed the crux of the story

    'enjoys munching McDonald's meaty produce'

    I demand a correction.

    'enjoys gagging on McDonald's grease and salt produce'

  21. steviebuk Silver badge

    Really annoys me!!!

    "We take data privacy very seriously" oh fuck off!!! No you clearly fucking don't as made it as hard as you could for the guy to contact anyone that gave a shit. And consistently ignored his emails.

    1. Alumoi Silver badge

      Re: Really annoys me!!!

      Oh, but they do! The protect their privacy as much as they can. The great unwashed? Fck them, why should they care?

      1. teebie

        Re: Really annoys me!!!

        In particular, it seems they're pretty great at maintaining the privacy of their employees email addresses. And their work phone numbers.

  22. TheProf
    Unhappy

    Prise Draws

    Do you need to enter an email address to enter McD prize draws?

    Thought so. They track your location by monitoring your burger consumption. Just a 'loyalty card' dressed up in a top hat and tails.

    I've seen a few draws recently, on crisp packets and drinks bottle, that require an email address before you can enter your 'lucky code number'. No thanks.

  23. czechitout

    Now I want a McDonald's

    1. First Light

      Man up and withstand the temptation!

      Or at least visit an independent chipper in your area . .

  24. hmmm

    Oh man I feel for their IT people. Sometimes I don't know whether to laugh or to cry when this sort of thing happens.

  25. xyz123 Silver badge

    I found a security bug (a biggy) with virgin money's android app.

    They told me to post the bug ONTO THEIR PUBLIC TWITTER FEED so they could deal with it.

    i said no.

    They said ok send it to <generic customer service email box>

    I said no.

    They said they don't have a security/programming team that can be contacted.

    So the bug remains unfixed and stupidly exploitable.

    1. jtaylor

      "I found a security bug (a biggy) with virgin money's android app. They told me to post the bug ONTO THEIR PUBLIC TWITTER FEED so they could deal with it."

      Hey, if that's how they roll...

      Someone signed up for an online service using my email address. I tried to get off their mailing list, and finally opened a support case and explained the problem: how can we remove my email from this other guy's account. Support replied that the only way is to delete the account, but that will lose any paid content. Step by step instructions with screenshots.

      I replied back thank you, I followed your instructions, reset this guy's password, and deleted his account. Jeff whoever you are, I apologize. CreativeLive are bloody idiots and I ran out of crayons.

      1. Nick Ryan Silver badge

        I had similar with Netflix, they insisted that I had an account with them and that I signed up with them despite me never having done so and having never gone through any email verification process but was still receiving account emails. Then they stated that because I didn't have an account with them that they couldn't talk to me or provide support... /genius

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon