Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

71–80 of 153 posts

Re: Panerabread.com leaks millions of customer records

#71

Jesus Christmas. Honestly, how many more times can they steal my ID? It's gotten so they have to run a diff to see if there's anything new.

Well, at least they didn't leak their customers' HIV statuses, unlike the other security breach I read about yesterday...

Re: Panerabread.com leaks millions of customer records

#72

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

True but worth mentioning different forces were at stake there and here (although both very dark).

In Swartz case, prosecutor was trying to make example of him because his public University made/is making tons of money for providing information that should be free (or already is)

In this case, I would imagine they want peoples info to be leaked and exposed as much as possible, just to have a good reason to fine those for-profit private companies.

Edit: in other words - show me a priest who doesn't want you to sin, or a cop who doesn't want you to break the law, or a doctor who is not fine with people getting sick. Otherwise they would all be out of job.

Re: Panerabread.com leaks millions of customer records

#74
post #33

Earlier quoted context omitted.

By that extension if a McDonald's drive thru employee accidentally spills hot coffee on a customer, the CEO is responsible and should be charged with assault?

Is that grossly negligent? No. Is keeping the coffee excessively hot for cost reasons, thereby causing the customer to receive third degree burns on their genitals and winning in court? Yes. https://en.m.wikipedia.org/wiki/Liebeck_v._McDonald%27s_Rest... Your culture is set by your leadership. Make good choices.

While I fully understand that without universal insurance in the US, it may be most expedient to go after someone like McDonald's with deep pockets, I am tired of hearing how shocking and unconscionable it is that coffee could be served at a near boiling temperature.

I make coffee nearly every morning by boiling water in a tea kettle and pouring it over coffee grounds in a Melitta filter. If I poured or spilled it on my genitals, that would be bad. Doesn't make an approximately 200F temperature incorrect though.[1]

[1] See the National Coffee Association on how to brew coffee at http://www.ncausa.org/About-Coffee/How-to-Brew-Coffee

Re: Panerabread.com leaks millions of customer records

#76
Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all outsourced and someone else tries to fix it now? This year is going to be good!

Re: Panerabread.com leaks millions of customer records

#77

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

Aaron Swartz faced 35 years in prison for breaking and entering and unauthorized access of a computer network / hacking amongst other things. It's a shame it ended the way it did, but please don't downplay what he did and use his name to push an agenda.

> breaking and entering

Is that true? It was an unlocked closet. The walls were covered in graffiti.

Re: Panerabread.com leaks millions of customer records

#78

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

Aaron Swartz faced 35 years in prison for breaking and entering and unauthorized access of a computer network / hacking amongst other things. It's a shame it ended the way it did, but please don't downplay what he did and use his name to push an agenda.

35 years for any victimless crime is ridiculous.

Re: Panerabread.com leaks millions of customer records

#79

A- This is infuriating B- How can a company have such a bad response? I think just about every big company has put a huge emphasis on data security. But hey, companies are big and technology is complex, so maybe data leaks still happen. But when they do, how can you treat them with such a lack of care? And how can the director of Security be alerted about this and not fix it? Seems potentially criminally negligent? c…

Krebs doesn't have to write his own blog series on how to handle breaches (although I might be interested in his version as well) Troy wrote a nice post about it

https://www.troyhunt.com/data-breach-disclosure-101-how-to-s...

Re: Panerabread.com leaks millions of customer records

#80

Jesus Christmas. Honestly, how many more times can they steal my ID? It's gotten so they have to run a diff to see if there's anything new.

Well, at least they didn't leak their customers' HIV statuses, unlike the other security breach I read about yesterday...

Was that the Grindr one? That's a HIPAA violation.. big fines..
Post reply on HN