Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

21–30 of 153 posts

Re: Panerabread.com leaks millions of customer records

#21

Earlier quoted context omitted.

It was a hundred panera bread's from all over the East Coast. Something suspicious was going on...

Do you think it could have been some sort of investigation? Like they say, criminals aren't born, they're bread.

I can’t decide whether to flag this or upvote it. I guess I’ll settle for replying.

Re: Panerabread.com leaks millions of customer records

#22
A- This is infuriating

B- How can a company have such a bad response? I think just about every big company has put a huge emphasis on data security. But hey, companies are big and technology is complex, so maybe data leaks still happen. But when they do, how can you treat them with such a lack of care? And how can the director of Security be alerted about this and not fix it? Seems potentially criminally negligent?

c- The tweets from Brian Krebs are also infuriating (and hilarious) https://twitter.com/briankrebs

Some highlights:

"Per my last tweet, Panera issued a statement to Fox News saying the breach only impacted 10,000 customer accounts. Interesting that they had no numbers for me, and yet had this 10k number all ready to go on the same day this was "discovered," eight months after it was reported."

"Hey Panera, despite your statements to the contrary, you still haven't fixed this customer info leak. Would you like to revisit the 10k number you just gave to Fox news? https://delivery.panerabread.com/foundation-api/users/12345"

"you know what, let's go for 37M instead of 7M: https://delivery.panerabread.com/foundation-api/users/12345"

"At the risk of making my job harder (or possibly, easier?) it's clear I'm going to have to write an entire series of blog posts about how not to handle a data breach from a PR perspective. I'm sputtering over here. Gave @panerabread every courtesy and they treat me like an idiot"

"Hey @panerabread : before making half-baked statements to the press to downplay the size of a breach, perhaps you should make sure the problem doesn't extend to all other parts of your business, like http://catering.panerabread.com , etc. Only proper response is to deep six entire site"

Re: Panerabread.com leaks millions of customer records

#23

Is there any hope companyies like the Y Combinator backed Request Network can save us from this happening over and over? A summary of their plan is at https://request.network . What things would prevent them from implementing this? Seems like a great way to stop losing credit card and identity info in breach after breach.

Maybe in the future, but there are plenty of companies that ar around Panera's size that had to get into the online-ordering space before SaaS was as big as it is today. Thankfully, much smaller eateries now can use Yelp or Seamless to deal with account management instead of rolling their own bespoke systems

Re: Panerabread.com leaks millions of customer records

#24
Aaron Swartz faced 35 years in prison for leaking JSTOR articles.

Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens.

You better believe they'll care about security then.

Many companies would also rethink whether they need to track and keep personal information at all.

Re: Panerabread.com leaks millions of customer records

#25
post #5

So here's a fun note - as it turns out, the Panera Bread Director of Information Security mentioned in that email exchange worked at Equifax from 2009 to 2013. There's a comment mentioning it on that page, but you can find it just by looking at his LinkedIn: https://www.linkedin.com/in/mike-gustavison-b020426/ Time is a flat circle. Everything that has happened before will happen again. Every time it happens, we will…

Don’t forget, “We’re sorry,” “We’ll do better,” and my personal favorite, “Trust us!” I’d prefer crippling fines.

I feel like there could be an xkcd-style greasemonkey script that adds a winkey face to the end of any of those phrases to make them a little more accurate.

"We take security very seriously ;)"

Re: Panerabread.com leaks millions of customer records

#26
post #8

Earlier quoted context omitted.

That could’ve easily been a really boring office lunch option binder, though. ;)

It was a hundred panera bread's from all over the East Coast. Something suspicious was going on...

At least around here, they were one of the only places to go with free public WiFi for a while. It could be something related to that, just a place to find open internet hotspots.

Re: Panerabread.com leaks millions of customer records

#27

A- This is infuriating B- How can a company have such a bad response? I think just about every big company has put a huge emphasis on data security. But hey, companies are big and technology is complex, so maybe data leaks still happen. But when they do, how can you treat them with such a lack of care? And how can the director of Security be alerted about this and not fix it? Seems potentially criminally negligent? c…

"@panerabread" ... "half-baked statements"...

Sometimes life imitates art.

Re: Panerabread.com leaks millions of customer records

#28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Re: Panerabread.com leaks millions of customer records

#29

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

I'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.

Re: Panerabread.com leaks millions of customer records

#30
post #28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Why is a software developer an engineer when it fluffs their ego, but not an engineer when regulation and consequences for failures are necessary?

Yes, if the security failure is grossly negligent, you should face criminal proceedings. As a C level executive, you are responsible for your chain of command.

Post reply on HN