Live data from Hacker News

Massive Breach in Panera Bread

pastebin.com

21–30 of 44 posts

Re: Massive Breach in Panera Bread

#21
post #20

Earlier quoted context omitted.

It's also possible that Panera would prosecute you for hacking their systems, if they were able to identify you. Better to be safe and disclose anonomyously.

Is sniffing and accessing an API that requires no credentials really prosecutable for "hacking"? Anyone can download a MITM proxy on their phone and replay HTTP/HTTPS calls.

Long story short, it's actually happened: https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

Re: Massive Breach in Panera Bread

#23
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

>Disclosing this as such was irresponsible

How so? Is allowing a company a chance to patch a bug a responsibility that random people have to a company? What do those people get in return? Some companies will go as far as accusing the reporter of hacking them.

I might even go as far to say that if companies expect to be told of bugs and not have the information released to the wild, they will be less concerned with security because they can always patch the bugs as they come and perform the smallest disclosure they know of. Such an idea of 'responsible disclosure' may lead to less security overall.

Perhaps the responsible thing is reporting the breach to the public because they are the ones most hurt by it, so they can take immediate corrective actions.

Re: Massive Breach in Panera Bread

#24
There whole system seemed a bit odd to me, given a password to your "account" is optional. Using the terminal you can login with no password, then at the end it asks you if you want to save your credit card to your account. Maybe it requires a password at that point, but I wasn't going to try.

Re: Massive Breach in Panera Bread

#25
post #24

There whole system seemed a bit odd to me, given a password to your "account" is optional. Using the terminal you can login with no password, then at the end it asks you if you want to save your credit card to your account. Maybe it requires a password at that point, but I wasn't going to try.

Oh no no no no no please don't tell me that's true D:

Re: Massive Breach in Panera Bread

#26
post #21
post #20

Earlier quoted context omitted.

Is sniffing and accessing an API that requires no credentials really prosecutable for "hacking"? Anyone can download a MITM proxy on their phone and replay HTTP/HTTPS calls.

Long story short, it's actually happened: https://en.wikipedia.org/wiki/Weev#AT&T_data_breach

Although Weev is a terrible person in general, this is the best case to cite for precedent.

Re: Massive Breach in Panera Bread

#27
A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals.

I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

Re: Massive Breach in Panera Bread

#28
post #3

Earlier quoted context omitted.

If in doubt, put a catputer photo. Cats always look fabulous. Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?. Wouldn…

Apparently he tried talking with Panera directly. First contact was 6 months ago. The vulnerability still exists so he decided to release it publically. I think that's reasonable.

And it's fixed immediately after release. 180 days seems about 90 days more than what major vendors get.

I bet this vulnerability was open for years.

Re: Massive Breach in Panera Bread

#29
post #27

A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

You probably still could, if they ignored you then chances are they never fixed it.

Re: Massive Breach in Panera Bread

#30
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

Given the number of times well-meaning do-gooders have been prosecuted or sued after publicly disclosing a breach, I find this approach entirely reasonable.

The caveat, of course, is that the poster should definitely have first attempted to contact Panera. I would not be surprised at all if Panera responded by doing absolutely nothing, which eventually led to this post.

Post reply on HN