Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.
That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.
Panerabread.com leaks millions of customer records
61–70 of 153 posts
Re: Panerabread.com leaks millions of customer records
#62Earlier quoted context omitted.
I'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.
What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?
This security director handled Dylan's bug report badly and deserves the reputation hit he's getting. But if we're going to suggest liability (let alone criminal liability) for security flaws, we should at least have some idea of what it is we're regulating.
Re: Panerabread.com leaks millions of customer records
#63So here's a fun note - as it turns out, the Panera Bread Director of Information Security mentioned in that email exchange worked at Equifax from 2009 to 2013. There's a comment mentioning it on that page, but you can find it just by looking at his LinkedIn: https://www.linkedin.com/in/mike-gustavison-b020426/ Time is a flat circle. Everything that has happened before will happen again. Every time it happens, we will…
Well, it costs nothing to put out a press release saying something “is out top priority” and “being taken seriously” and not do anything.
So I was once told by cop when i told them defendant is lying not showing up that he has good reasons. Unless you are under oath by very few LE organizations, its not illegal to lie.
Of course I'm not saying its a good thing; just pointing out they can say whatever they want to - there is no liability.
Re: Panerabread.com leaks millions of customer records
#64Let me guess. They passed their PCI audits with flying colors.
Re: Panerabread.com leaks millions of customer records
#65Maybe someone could go in to business and provide services that would help companies prevent these things from happening?
Security consultants and contractors already exist. But why would Panera, Equifax, et al bother investing in better security when they face no consequences for these incidents? Markets can't solve everything
Thanks for that protip.
Re: Panerabread.com leaks millions of customer records
#66Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.
It's a shame it ended the way it did, but please don't downplay what he did and use his name to push an agenda.
Re: Panerabread.com leaks millions of customer records
#67Re: Panerabread.com leaks millions of customer records
#68Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.
That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.
They were eventually acquitted, but the very fact that they were even charged in the first place is ridiculous.
Re: Panerabread.com leaks millions of customer records
#69Earlier quoted context omitted.
Is that grossly negligent? No. Is keeping the coffee excessively hot for cost reasons, thereby causing the customer to receive third degree burns on their genitals and winning in court? Yes. https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Rest... Your culture is set by your leadership. Make good choices.
They keep the coffee that hot because customers like hot coffee. That's the main reason I get coffee at McDonalds, not because it's great coffee (though it's not bad) but because it's HOT. Half the time I get coffee at Starbuck's it's only a litte better than piss-warm.
There seems to be an unlimited supply of people always popping up to "debunk" the "myths" about the Liebeck case who seem to deflect from the fact that it is normal for coffee to be brewed at near boiling temperatures[1] that cause the sort of damage that was at issue. I could burn myself severely while draining pasta too, if I pour hot water all over my pants and don't remove them; it doesn't mean boiling water is too hot for cooking nor that say, a manufacturer of a non-defective pot is to blame.
Added reference due to downvoting:
[1] http://www.ncausa.org/About-Coffee/How-to-Brew-Coffee
"Your brewer should maintain a water temperature between 195 to 205 degrees Fahrenheit for optimal extraction."
Re: Panerabread.com leaks millions of customer records
#70Let me guess. They passed their PCI audits with flying colors.
As long as that Nessus scan passed, they're in the clear, right?