Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

41–50 of 153 posts

Re: Panerabread.com leaks millions of customer records

#41
post #28

Earlier quoted context omitted.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Why is a software developer an engineer when it fluffs their ego, but not an engineer when regulation and consequences for failures are necessary? Yes, if the security failure is grossly negligent, you should face criminal proceedings. As a C level executive, you are responsible for your chain of command.

Is there any evidence that software engineers are protected in some way from criminal negligence cases?

The reality is that it is vanishingly rare for any engineer to face criminal charges for their professional actions. It doesn’t seem to me that software is held to much lower a standard.

Re: Panerabread.com leaks millions of customer records

#42

Earlier quoted context omitted.

Why is a software developer an engineer when it fluffs their ego, but not an engineer when regulation and consequences for failures are necessary? Yes, if the security failure is grossly negligent, you should face criminal proceedings. As a C level executive, you are responsible for your chain of command.

Is there any evidence that software engineers are protected in some way from criminal negligence cases? The reality is that it is vanishingly rare for any engineer to face criminal charges for their professional actions. It doesn’t seem to me that software is held to much lower a standard.

Not protected, simply not pursued, although it’s usually outright fraud that is the target of most prosecutions.

Watching the SEC closely to see how many ICOs they prosecute. Also was helpful to see someone involved with their breech response who attempted to profit from non public material information prosecuted (although that’s tangential to the breach itself).

Someone relatively important is going to have to get burned before more software professionals are pursued for grossly negligent security failings.

Re: Panerabread.com leaks millions of customer records

#43
post #20

Earlier quoted context omitted.

Don’t forget, “We’re sorry,” “We’ll do better,” and my personal favorite, “Trust us!” I’d prefer crippling fines.

"I’d prefer crippling fines" Probably won't happen until some Senator gets personally burned. Equifax hasn't suffered much, for example, and they released almost all of their info for every adult in the US that ever used a credit card or had a mortgage. I'm almost wishing some activist hacker would buy the data for the House and Senate reps and go to town...just to get their attention. Purchase pornhub accounts , sha…

Some Senators might already have such arrangements ;)

Re: Panerabread.com leaks millions of customer records

#44

Years ago, I was assigned to clean up an office building that had recently been vacated by a government cybersecurity contractor. While throwing away all the trash that had been left behind I discovered a binder that had at least a hundred pages of print outs from mapquest with the location of the panera bread on each circled in pen.

What years?

I'm pretty sure the intersection of time between Panera's spread to the east coast and map quest's prevalence don't line up

Re: Panerabread.com leaks millions of customer records

#45
post #38

Earlier quoted context omitted.

I'm familiar with the case, that's why I mentioned it. My point was that although they lost the civil suit, there weren't any criminal proceedings against C-levels. I understand the argument of negligence being as guilty as malicious intent but it creates a sweeping blanket that's hardly fair or enforceable. I agree with your principles in theory but it's just impractical.

The Department of Justice was able to dismantle Arther Anderson after their fraudulent audits of Enron. Lots of things that are impractical are possible with sufficient effort. And the government has unlimited resources for those efforts. You must hold systemic negligence and corruption accountable, or it perpetuates the cycle.

A) The DOJ had been looking at Anderson for years prior to Enron due to irregularities with other major firms like Waste Management Inc. Enron was not an isolated incident.

B) They were prosecuted for the very specific crime of obstruction of justice after they were caught destroying evidence. It wasn't some backlash against a nebulous problem.

C) Their conviction was overturned!

I'm not sure you could have picked a worse example for arguing your point.

Re: Panerabread.com leaks millions of customer records

#46

Earlier quoted context omitted.

Is there any evidence that software engineers are protected in some way from criminal negligence cases? The reality is that it is vanishingly rare for any engineer to face criminal charges for their professional actions. It doesn’t seem to me that software is held to much lower a standard.

Not protected, simply not pursued, although it’s usually outright fraud that is the target of most prosecutions. Watching the SEC closely to see how many ICOs they prosecute. Also was helpful to see someone involved with their breech response who attempted to profit from non public material information prosecuted (although that’s tangential to the breach itself). Someone relatively important is going to have to get b…

You misunderstand my point. Are there examples of other sorts of engineers being brought up on charges?

It only happens in the most egregious of negligence cases as it is and even then convictions are rare.

I'm saying your impression that software engineering is protected is wrong, because no engineers (to any normal approximate) are brought up on criminal charges.

Re: Panerabread.com leaks millions of customer records

#47
post #20

Earlier quoted context omitted.

Don’t forget, “We’re sorry,” “We’ll do better,” and my personal favorite, “Trust us!” I’d prefer crippling fines.

"I’d prefer crippling fines" Probably won't happen until some Senator gets personally burned. Equifax hasn't suffered much, for example, and they released almost all of their info for every adult in the US that ever used a credit card or had a mortgage. I'm almost wishing some activist hacker would buy the data for the House and Senate reps and go to town...just to get their attention. Purchase pornhub accounts , sha…

We just need Pence's Grindr details.

Re: Panerabread.com leaks millions of customer records

#49
post #20

Earlier quoted context omitted.

"I’d prefer crippling fines" Probably won't happen until some Senator gets personally burned. Equifax hasn't suffered much, for example, and they released almost all of their info for every adult in the US that ever used a credit card or had a mortgage. I'm almost wishing some activist hacker would buy the data for the House and Senate reps and go to town...just to get their attention. Purchase pornhub accounts , sha…

We just need Pence's Grindr details.

Heh. Fabricated or real, that would get a fair amount of news time and attention. Maybe Romney too.

Re: Panerabread.com leaks millions of customer records

#50
post #33

Earlier quoted context omitted.

Why is a software developer an engineer when it fluffs their ego, but not an engineer when regulation and consequences for failures are necessary? Yes, if the security failure is grossly negligent, you should face criminal proceedings. As a C level executive, you are responsible for your chain of command.

By that extension if a McDonald's drive thru employee accidentally spills hot coffee on a customer, the CEO is responsible and should be charged with assault?

If they create a work situation where by cutting corners on container safety, protocols, and employee attentiveness I think they are guilty.

And in the modern security context we're pushing deadlines just to race to the latest features with almost no regard for security in the process.

Something has to change. If this kind of negligence were causing similar problems in physical realms there would be regulations.

The tech companies behind these mistakes won't have that free roam forever. Every major screw-up is a step closer to regulations and everyone will cry about it when it happens... But so many companies today don't seem like they're ready to behave responsibly.

Post reply on HN