Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

91–100 of 153 posts

Re: Panerabread.com leaks millions of customer records

#92
post #28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Didn't Iran put a developer in jail cause some of his open source code was used on a porn site?

Re: Panerabread.com leaks millions of customer records

#93
post #76

Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all o…

That's not what 0 day means.

Re: Panerabread.com leaks millions of customer records

#94

Let me guess. They passed their PCI audits with flying colors.

I’m sure the only reason that only partial credit card numbers were stolen is that PCI makes it very hard for Panera to store complete credit card numbers (with expiration dates and the security code on the back).

> PCI makes it very hard for Panera to store complete credit card numbers (with expiration dates and the security code on the back)

How about impossible. Storing the CVV number is 100% not allowed. Even storing complete cards numbers is only allowed under very specific conditions. Any deviation opens them up to liability for related fraud.

Re: Panerabread.com leaks millions of customer records

#95
post #82

Earlier quoted context omitted.

Was that the Grindr one? That's a HIPAA violation.. big fines..

HIPAA only applies to health-care providers and related entities, not random other companies.

Related entities includes the broader "clearinghouse" entity, which has been applied to debt collectors.

I agree it would be a stretch to make a claim but I'm not 100% sure it would be fruitless.

Re: Panerabread.com leaks millions of customer records

#97
post #62
post #57

Earlier quoted context omitted.

What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…

Pull the plug.

The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured.

It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.

Re: Panerabread.com leaks millions of customer records

#98
post #62
post #57

Earlier quoted context omitted.

What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…

Which is why we need jail time for execs.

It is very simple: with big $$ there should be a big risk.

Re: Panerabread.com leaks millions of customer records

#99
post #28

Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.

That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.

Sounds like an excellent idea:

Jr. Developer - automatic pass. Low money

Sr. Developer - likely a pass, provided 'i' are dotted and 't's are crossed - decent money

Tech Lead - no pass unless tried very hard to get it resolved, big money

Exec - no pass, very big money

Re: Panerabread.com leaks millions of customer records

#100

Jesus Christmas. Honestly, how many more times can they steal my ID? It's gotten so they have to run a diff to see if there's anything new.

Well, at least they didn't leak their customers' HIV statuses, unlike the other security breach I read about yesterday...

Arguably that wasn't a leak, they're intentionally putting that data into an analytics store. Whether that's okay is a different issue, but it wasn't leaked to the public.
Post reply on HN