Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

61–70 of 153 posts

Re: Panerabread.com leaks millions of customer records

#61
post #28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Engineers in other disciplines are held liable for their mistakes. Imagine a civil engineer signing off on a building and then having it collapse. If it was found that the engineer was negligent then you can bet your ass there will be reprucussions. As an engineer, you are the top of your field and with that comes a professional responsibility that is important to fully realize. Mistakes are mistakes sure, but if those mistakes end up being responsible for criminal activity then you’re fully responsible. It’s why the chain of command exists.

Re: Panerabread.com leaks millions of customer records

#62
post #57
post #29

Earlier quoted context omitted.

I'd revise that from "if a breach happens" to "if a breach happens and the CSO demonstrated criminal negligence." The attack surface for security is too large, and it's not fair to hold a CSO of a cafe chain to such a standard when zero-days are also possible. Punish for being negligent, not for being attacked by a zero-day, or something else really obscure.

What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advisory role in the organization, and the real institutional power comes either from engineering or from the CIO.

This security director handled Dylan's bug report badly and deserves the reputation hit he's getting. But if we're going to suggest liability (let alone criminal liability) for security flaws, we should at least have some idea of what it is we're regulating.

Re: Panerabread.com leaks millions of customer records

#63
post #5

So here's a fun note - as it turns out, the Panera Bread Director of Information Security mentioned in that email exchange worked at Equifax from 2009 to 2013. There's a comment mentioning it on that page, but you can find it just by looking at his LinkedIn: https://www.linkedin.com/in/mike-gustavison-b020426/ Time is a flat circle. Everything that has happened before will happen again. Every time it happens, we will…

Well, it costs nothing to put out a press release saying something “is out top priority” and “being taken seriously” and not do anything.

Correct me if I'm wrong - its also NOT illegal to do so, even if you are lying it is immoral but not illegal.

So I was once told by cop when i told them defendant is lying not showing up that he has good reasons. Unless you are under oath by very few LE organizations, its not illegal to lie.

Of course I'm not saying its a good thing; just pointing out they can say whatever they want to - there is no liability.

Re: Panerabread.com leaks millions of customer records

#65

Maybe someone could go in to business and provide services that would help companies prevent these things from happening?

Security consultants and contractors already exist. But why would Panera, Equifax, et al bother investing in better security when they face no consequences for these incidents? Markets can't solve everything

> Security consultants and contractors already exist.

Thanks for that protip.

Re: Panerabread.com leaks millions of customer records

#66

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

Aaron Swartz faced 35 years in prison for breaking and entering and unauthorized access of a computer network / hacking amongst other things.

It's a shame it ended the way it did, but please don't downplay what he did and use his name to push an agenda.

Re: Panerabread.com leaks millions of customer records

#68
post #28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Italy jailed scientists for failing to predict an earthquake, despite the fact that it's not possible to predict an earthquake.

They were eventually acquitted, but the very fact that they were even charged in the first place is ridiculous.

Re: Panerabread.com leaks millions of customer records

#69
post #60

Earlier quoted context omitted.

Is that grossly negligent? No. Is keeping the coffee excessively hot for cost reasons, thereby causing the customer to receive third degree burns on their genitals and winning in court? Yes. https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Rest... Your culture is set by your leadership. Make good choices.

They keep the coffee that hot because customers like hot coffee. That's the main reason I get coffee at McDonalds, not because it's great coffee (though it's not bad) but because it's HOT. Half the time I get coffee at Starbuck's it's only a litte better than piss-warm.

I don't think forbidding hot coffee at drive-thrus is unambiguously in favor of safety, since not-so-hot coffee encourages people to drink while driving, which could cause an accident. Some people want to drink on their way to the office or home, and others want coffee that is still hot when they get there. The consequence of the litigation seems to be that the former group of customers is privileged, but I'm not certain that is an overall social good even if you prioritize safety - and some would of course be happy to trade off others safety for their own hot coffee.

There seems to be an unlimited supply of people always popping up to "debunk" the "myths" about the Liebeck case who seem to deflect from the fact that it is normal for coffee to be brewed at near boiling temperatures[1] that cause the sort of damage that was at issue. I could burn myself severely while draining pasta too, if I pour hot water all over my pants and don't remove them; it doesn't mean boiling water is too hot for cooking nor that say, a manufacturer of a non-defective pot is to blame.

Added reference due to downvoting:

[1] http://www.ncausa.org/About-Coffee/How-to-Brew-Coffee

"Your brewer should maintain a water temperature between 195 to 205 degrees Fahrenheit for optimal extraction."

Re: Panerabread.com leaks millions of customer records

#70
post #64

Let me guess. They passed their PCI audits with flying colors.

As long as that Nessus scan passed, they're in the clear, right?

My (potentially limited) understanding: Certification by an ASV doesn't free you from any responsibilities. You could still violate the DSS even if an ASV clears you.
Post reply on HN