haley.io
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Pro@programming.dev to Technology@programming.devEnglish ·
edit-2
5 months ago

McDonald’s AI Hiring Bot exposed 64 Million McDonald’s job applications to security researchers Who Tried the Password ‘123456’

ian.sh

external-link
message-square
14
fedilink
288
external-link

McDonald’s AI Hiring Bot exposed 64 Million McDonald’s job applications to security researchers Who Tried the Password ‘123456’

ian.sh

Pro@programming.dev to Technology@programming.devEnglish ·
edit-2
5 months ago
message-square
14
fedilink
Would you like an IDOR with that? Leaking 64 million McDonald’s job applications
ian.sh
external-link
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We discovered a vulnerability that could allow an attacker to access more than 64 million job applications. This data includes applicants' names, resumes, email addresses, phone numbers, and personality test results.
alert-triangle
You must log in or register to comment.
  • /home/pineapplelover@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 months ago

    Lmao they called it the Mchire

    • jqubed@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      5 months ago

      I’ve seen hiring ads referring to them as McJobs

  • chemical_cutthroat@lemmy.world
    link
    fedilink
    English
    arrow-up
    41
    ·
    5 months ago

    That’s the stupidest combination I’ve ever heard in my life! That’s the kinda thing an idiot would have on his luggage!

  • SaltSong@startrek.website
    link
    fedilink
    English
    arrow-up
    2
    ·
    5 months ago

    If anyone wanted this information, they could just post a bogus job, and people will just send them the data.

  • otter@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    13
    ·
    5 months ago

    Mel Brooks has entered the chat

  • zzz711@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    20
    ·
    5 months ago

    Here’s a crazy idea maybe you shouldn’t require applicants to create an account just to apply for a job. Lord knows how many workday accounts I’ve created.

    • TechLich@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      5 months ago

      Agreed, but it’s not the applicants’ accounts that was compromised.

      That’s the password for the admin panel that lets you see every single application and all their conversations with the stupid hiring bot. An order of magnitude more silly.

    • CaffeinatedCubits@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      I quit applying for jobs if they use workday

    • AlecSadler@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      7
      ·
      5 months ago

      Fuck workday.

  • Tronn4@lemmy.world
    link
    fedilink
    English
    arrow-up
    31
    ·
    5 months ago

  • HugeNerd@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    5 months ago

    Anyone still worried about AI taking over the world and killing all the humans?

  • Honse@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    46
    ·
    5 months ago

    McSecurity

  • stupidcasey@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    5 months ago

    Glad there smarter than me, I would have stopped at 12345

    • /home/pineapplelover@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      I wonder what other logins they tried

Technology@programming.dev

Technology@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !Technology@programming.dev

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No external video links, only native(.mp4,…etc) links under 5 mins.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

  • Al Jazeera;
  • NBC;
  • CNBC;
  • Substack;
  • Tom’s Hardware;
  • ZDNet;
  • TechSpot;
  • Ars Technica;
  • Vox Media outlets(including Axios, due to new changes related to trackers on their website);
  • Engadget;
  • TechCrunch;
  • Gizmodo;
  • Futurism;
  • PCWorld;
  • ComputerWorld;
  • Mashable;
  • Hackaday;
  • WCCFTECH;
  • Neowin;
  • Jacobin;
  • Yahoo;
  • Freethink;
  • Big Think;
  • Newsweek.

More sites will be added to the blacklist as needed.

Encouraged:

  • Archive links in the body of the post.
  • Linking to the direct source, instead of linking to an article talking about the source.

Misc:

Relevant Lemmy Communities:

  • Beehaw Technology discussion.
  • Hard Tech news.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 98 users / day
  • 437 users / week
  • 481 users / month
  • 7.87K users / 6 months
  • 1 local subscriber
  • 741 subscribers
  • 1.93K Posts
  • 4.48K Comments
  • Modlog
  • mods:
  • irelephant [he/him]@programming.dev
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org