Live data from Hacker News

Massive Breach in Panera Bread

pastebin.com

41–44 of 44 posts

Re: Massive Breach in Panera Bread

#41
For non-Americans and as their page is down: What kind of accounts do you have at such a company? I never had an account with a restaurant, why would you use that and store personal information there?

Re: Massive Breach in Panera Bread

#42

Earlier quoted context omitted.

To bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.

Did you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached. Good work, in any case.

Whilst that does appear to have had the desired effect in this case, I do hope to never find ourselves into the position where "responsible disclosure" includes "consulted with Troy Hunt" as a step.

Re: Massive Breach in Panera Bread

#43
post #41

For non-Americans and as their page is down: What kind of accounts do you have at such a company? I never had an account with a restaurant, why would you use that and store personal information there?

I’m American but I have made accounts with restaurants to order for pickup (or delivery). It’s especially helpful if you eat in an a busy area with long lunch lines. It’s also less error prone having the order in written form than trying to order over the phone. I think most restaurants use a vendor like Yelp for their ordering service, but I guess some big ones like Panera can afford to build one themselves (poorly).

Re: Massive Breach in Panera Bread

#44
post #27

A similar flaw exists in the Denny's Canada app. Reveals usernames, email, full name and phone number. The API is entirely unauthenticated and account hijacking is very easy. The app is used for reward points that grant you free meals. I tried reaching out to them multiple times and was ignored. I tried contacting the firm that developed the app, and they ignored me. Maybe I should have made a pastebin dump :)

Hey, I work at Symantec Research Labs. If you still have not been able to get this looked at by someone from Denny's, I can probably have the right people take a look.

e-mail me at daniel_kats [at] symantec [dot] com

EDIT: please do not post your method publicly. That is a bad idea.

Post reply on HN