Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

51–60 of 153 posts

Re: Panerabread.com leaks millions of customer records

#51

Maybe someone could go in to business and provide services that would help companies prevent these things from happening?

Security consultants and contractors already exist.

But why would Panera, Equifax, et al bother investing in better security when they face no consequences for these incidents?

Markets can't solve everything

Re: Panerabread.com leaks millions of customer records

#52
post #5

So here's a fun note - as it turns out, the Panera Bread Director of Information Security mentioned in that email exchange worked at Equifax from 2009 to 2013. There's a comment mentioning it on that page, but you can find it just by looking at his LinkedIn: https://www.linkedin.com/in/mike-gustavison-b020426/ Time is a flat circle. Everything that has happened before will happen again. Every time it happens, we will…

That’s because business in America allow everyone to fail upwards after you hit a certain echelon.

There’s no accountability and it’s about protecting everyone in that class at the expense of all other employees and consumers.

Yay, America!!

Re: Panerabread.com leaks millions of customer records

#54
Commenting only on the speed of response (or the glacial interpretation of it in Panera's case):

For companies operating in European Union, the General Data Protection Regulation (GDPR) (1) mandates that such breaches need to be disclosed under 72 hours. The implementation deadline for GDPR is by end of May 2018 (~7 weeks to go).

Underarmor, a US-based sports apparel manufacturer, who operates in EU as well, recently had a breach that affected 150-million users, and went public within 3 days of discovering the breach (2).

I believe UnderArmor's case is the norm we can expect going forward.

(1)https://en.wikipedia.org/wiki/General_Data_Protection_Regula... (2) http://www.bbc.com/news/technology-43592470

Re: Panerabread.com leaks millions of customer records

#55
post #5

So here's a fun note - as it turns out, the Panera Bread Director of Information Security mentioned in that email exchange worked at Equifax from 2009 to 2013. There's a comment mentioning it on that page, but you can find it just by looking at his LinkedIn: https://www.linkedin.com/in/mike-gustavison-b020426/ Time is a flat circle. Everything that has happened before will happen again. Every time it happens, we will…

Don’t forget, “We’re sorry,” “We’ll do better,” and my personal favorite, “Trust us!” I’d prefer crippling fines.

Mark?

Re: Panerabread.com leaks millions of customer records

#56

Earlier quoted context omitted.

The Department of Justice was able to dismantle Arther Anderson after their fraudulent audits of Enron. Lots of things that are impractical are possible with sufficient effort. And the government has unlimited resources for those efforts. You must hold systemic negligence and corruption accountable, or it perpetuates the cycle.

A) The DOJ had been looking at Anderson for years prior to Enron due to irregularities with other major firms like Waste Management Inc. Enron was not an isolated incident. B) They were prosecuted for the very specific crime of obstruction of justice after they were caught destroying evidence. It wasn't some backlash against a nebulous problem. C) Their conviction was overturned! I'm not sure you could have picked a…

[deleted]

Re: Panerabread.com leaks millions of customer records

#57
post #29

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

I'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.

What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?

Re: Panerabread.com leaks millions of customer records

#58
post #57
post #29

Earlier quoted context omitted.

I'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.

What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?

Yes

Re: Panerabread.com leaks millions of customer records

#59
post #21

Earlier quoted context omitted.

Do you think it could have been some sort of investigation? Like they say, criminals aren't born, they're bread.

I can’t decide whether to flag this or upvote it. I guess I’ll settle for replying.

Come on, let's stay on topic. All I'm trying to figure out is, have I been scwned?

Re: Panerabread.com leaks millions of customer records

#60
post #33

Earlier quoted context omitted.

By that extension if a McDonald's drive thru employee accidentally spills hot coffee on a customer, the CEO is responsible and should be charged with assault?

Is that grossly negligent? No. Is keeping the coffee excessively hot for cost reasons, thereby causing the customer to receive third degree burns on their genitals and winning in court? Yes. https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Rest... Your culture is set by your leadership. Make good choices.

They keep the coffee that hot because customers like hot coffee. That's the main reason I get coffee at McDonalds, not because it's great coffee (though it's not bad) but because it's HOT. Half the time I get coffee at Starbuck's it's only a litte better than piss-warm.
Post reply on HN