The standard "we take security very seriously" is starting to ring a bit hollow.
Panerabread.com leaks millions of customer records
91–100 of 153 posts
Re: Panerabread.com leaks millions of customer records
#92Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.
That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.
Re: Panerabread.com leaks millions of customer records
#93Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all o…
Re: Panerabread.com leaks millions of customer records
#94Let me guess. They passed their PCI audits with flying colors.
I’m sure the only reason that only partial credit card numbers were stolen is that PCI makes it very hard for Panera to store complete credit card numbers (with expiration dates and the security code on the back).
How about impossible. Storing the CVV number is 100% not allowed. Even storing complete cards numbers is only allowed under very specific conditions. Any deviation opens them up to liability for related fraud.
Re: Panerabread.com leaks millions of customer records
#95Earlier quoted context omitted.
Was that the Grindr one? That's a HIPAA violation.. big fines..
HIPAA only applies to health-care providers and related entities, not random other companies.
I agree it would be a stretch to make a claim but I'm not 100% sure it would be fruitless.
Re: Panerabread.com leaks millions of customer records
#96Re: Panerabread.com leaks millions of customer records
#97Earlier quoted context omitted.
What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?
What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…
The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured.
It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.
Re: Panerabread.com leaks millions of customer records
#98Earlier quoted context omitted.
What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?
What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…
It is very simple: with big $$ there should be a big risk.
Re: Panerabread.com leaks millions of customer records
#99Aaron Swartz faced 35 years in prison for leaking JSTOR articles. Instead of fines, the Chief Security Officer should be fully responsible and face 35 years in jail if a breach happens. You better believe they'll care about security then. Many companies would also rethink whether they need to track and keep personal information at all.
That is a terrible idea. Imagine sentencing programmers to jail for security issues in their code.
Jr. Developer - automatic pass. Low money
Sr. Developer - likely a pass, provided 'i' are dotted and 't's are crossed - decent money
Tech Lead - no pass unless tried very hard to get it resolved, big money
Exec - no pass, very big money
Re: Panerabread.com leaks millions of customer records
#100Jesus Christmas. Honestly, how many more times can they steal my ID? It's gotten so they have to run a diff to see if there's anything new.
Well, at least they didn't leak their customers' HIV statuses, unlike the other security breach I read about yesterday...