Live data from Hacker News

Massive Breach in Panera Bread

pastebin.com

31–40 of 44 posts

Re: Massive Breach in Panera Bread

#31
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

Given the number of times well-meaning do-gooders have been prosecuted or sued after publicly disclosing a breach, I find this approach entirely reasonable. The caveat, of course, is that the poster should definitely have first attempted to contact Panera. I would not be surprised at all if Panera responded by doing absolutely nothing, which eventually led to this post.

If you contacted them, you just opened yourself to potential persecution, even if it would not be you who actually pastebined it later.

Not even once.

Re: Massive Breach in Panera Bread

#32
post #19
post #3

Earlier quoted context omitted.

If in doubt, put a catputer photo. Cats always look fabulous. Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?. Wouldn…

I'm going to pick on your post a little: Why would you assume a security researcher who put in that much effort and kept the pastebin mostly anonymous didn't put in the effort to contact Panera Bread? Is there a reason you automatically assume that the security researcher is irresponsible, but companies, who almost daily, have data breaches, are responsible in these scenarios? "Hey, maybe you should contact the compa…

> Why would you assume...?

Because there is not data that specifies the opposite in the link (and extra info was lacking when I wrote it), thus is a reasonable and logical first thing to check.

> Is there a reason you automatically assume that the security researcher is irresponsible...?

Please, don't put words in my mouth. I didn't called irresponsible anybody and I didn't automatically assume anything. To be honest, I couldn't care less about who, if one, has the responsibility here. I'm trying to learn something. Not more, not less.

Captain fucking obvious is a nice title. We'll have a safer world when people start paying notice to a lot of fucking obvious and boring things. This reminds me a lot to the outrageous lexNET case (that was much, much, worse than internet knowing who has a sweet tooth for buns).

Re: Massive Breach in Panera Bread

#34
post #27

A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

You should post your method. I could scrape it for data if you want

Re: Massive Breach in Panera Bread

#35
post #34
post #27

A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

You should post your method. I could scrape it for data if you want

Would rather not. I've made scripts that take all the data possible, I'll probably post a dump and repro instructions some time later.

Re: Massive Breach in Panera Bread

#36
post #28

Earlier quoted context omitted.

Apparently he tried talking with Panera directly. First contact was 6 months ago. The vulnerability still exists so he decided to release it publically. I think that's reasonable.

And it's fixed immediately after release. 180 days seems about 90 days more than what major vendors get. I bet this vulnerability was open for years.

I certainly have a few open reports to companies that I've been trying to reach for, in several cases, _years_. Or, in other cases, I found something but trying to reach the right person is nigh impossible. security@ bounces, general support is useless, no one responds on linkedin, no one responds to direct emails, pinging them on twitter does nil. Extremely sad.

Re: Massive Breach in Panera Bread

#37
post #35
post #34

Earlier quoted context omitted.

You should post your method. I could scrape it for data if you want

Would rather not. I've made scripts that take all the data possible, I'll probably post a dump and repro instructions some time later.

Might be worth getting in touch with Troy Hunt, over at https://haveibeenpwned.com/

Re: Massive Breach in Panera Bread

#38
post #28

Earlier quoted context omitted.

Apparently he tried talking with Panera directly. First contact was 6 months ago. The vulnerability still exists so he decided to release it publically. I think that's reasonable.

And it's fixed immediately after release. 180 days seems about 90 days more than what major vendors get. I bet this vulnerability was open for years.

It wasn't fixed immediately after release. Apparently all they did at first was:

1.) Take down site for 2 hours 2.) Require logins to access api. 3.) Get on fox news and say it's "fixed" ... then we come to find out you can still access all data from the API once you login

Re: Massive Breach in Panera Bread

#39
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

Given the number of times well-meaning do-gooders have been prosecuted or sued after publicly disclosing a breach, I find this approach entirely reasonable. The caveat, of course, is that the poster should definitely have first attempted to contact Panera. I would not be surprised at all if Panera responded by doing absolutely nothing, which eventually led to this post.

Panera was contacted in August of last year.

Re: Massive Breach in Panera Bread

#40
post #27

A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

You should contact Troy Hunt or Krebs. They can make that public to get companies to actually change it.
Post reply on HN