Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

111–120 of 153 posts

Re: Panerabread.com leaks millions of customer records

#114

A- This is infuriating B- How can a company have such a bad response? I think just about every big company has put a huge emphasis on data security. But hey, companies are big and technology is complex, so maybe data leaks still happen. But when they do, how can you treat them with such a lack of care? And how can the director of Security be alerted about this and not fix it? Seems potentially criminally negligent? c…

Most the IT Managers / Directors I've worked with were never from developer backgrounds. They were either an "IT Guy" that stuck it out or the "network guy" who's extent of knowledge is seemingly plugging in a network cable.

Between that and the fact most established businesses I've been in still treat IT like it's a necessary evil and waste of money, I'm not remotely surprised when stuff like this happens. My current company had a data breach, the IT Director swept it under the rug. I contacted my attorney for what I'm required to do to (to cover my ass). I emailed my managers and moved on down the road.

Re: Panerabread.com leaks millions of customer records

#116

Earlier quoted context omitted.

> PCI makes it very hard for Panera to store complete credit card numbers (with expiration dates and the security code on the back) How about impossible. Storing the CVV number is 100% not allowed. Even storing complete cards numbers is only allowed under very specific conditions. Any deviation opens them up to liability for related fraud.

Even storing complete cards numbers is only allowed under very specific conditions. We encrypt these at the app, even before putting them into the DB, yada yada. The PCI auditor actually made us restore the DB from backup onto another server and show them the data, to prove that some magical process in the backup program didn't cause them to come un-encrypted. They also wanted us to change all corporate email address…

I find PCI compliance annoying mostly due to individual auditor predilections.

Re: Panerabread.com leaks millions of customer records

#117
post #76

Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all o…

My natural gas provider can't get my bill to print with me emailing them for over a year.

So their old 1990s site, worked fine. Upgrade to new whizbang bullshit and a steady stream of emails still can't get it to simply use a CSS print routine. Outsourcing is glorious!

Re: Panerabread.com leaks millions of customer records

#118
post #95
post #82

Earlier quoted context omitted.

HIPAA only applies to health-care providers and related entities, not random other companies.

Related entities includes the broader "clearinghouse" entity, which has been applied to debt collectors. I agree it would be a stretch to make a claim but I'm not 100% sure it would be fruitless.

A debt collector would apply since they have been contracted by a HIPAA-covered entity and the data they have likely came from that source. Grindr is completely unrelated to another HIPAA-covered entity and any health data you give them is solely your responsibility... so don't.

Re: Panerabread.com leaks millions of customer records

#120
Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...

I found his initial interaction with their head of IT Security (very first initial response) laughably appalling:

    Dylan Houlihan 
    to Mike, Geri Haight -

    Hello Mike et al,

    Thank you for making yourselves available. There is a security vulnerability on the delivery.panerabread.com website that 
    exposes sensitive information belonging to every customer who has signed up for an account to order Panera Bread online. 
    This shows the customer's full name, email address, phone number and the last four digits of their saved credit card number.
    Moreover, the customers are easily enumerable which means an attacker could crawl through all the records.

    I can provide the specific details of the vulnerability over email once you respond, but if you prefer (for more security), 
    I can also encrypt the information with a PGP key you provide me. Alternatively we can hop on a phone call.

    Best regards,
    Dylan Houlihan
And their response:

    Mike Gustavison 
    to dylan

    Dylan,

    My team received your emails however it was very suspicious and appeared scam in nature therefore was ignored. If this is
    a sales tactic I would highly recommend a better approach as demanding a PGP key would not be a good way to start off. 
    As a security professional you should be aware that any organization that has a security practice would never respond to
    a request like the one you sent. I am willing to discuss whatever vulnerabilities you believe you have found but I will 
    not be duped, demanded for restitution/bounty or listen to a sales pitch.

    Regards,
    Mike
Post reply on HN