Panerabread.com leaks millions of customer records
111–120 of 153 posts
Re: Panerabread.com leaks millions of customer records
#112Re: Panerabread.com leaks millions of customer records
#113Coincidence? Strike two?
Re: Panerabread.com leaks millions of customer records
#114A- This is infuriating B- How can a company have such a bad response? I think just about every big company has put a huge emphasis on data security. But hey, companies are big and technology is complex, so maybe data leaks still happen. But when they do, how can you treat them with such a lack of care? And how can the director of Security be alerted about this and not fix it? Seems potentially criminally negligent? c…
Between that and the fact most established businesses I've been in still treat IT like it's a necessary evil and waste of money, I'm not remotely surprised when stuff like this happens. My current company had a data breach, the IT Director swept it under the rug. I contacted my attorney for what I'm required to do to (to cover my ass). I emailed my managers and moved on down the road.
Re: Panerabread.com leaks millions of customer records
#115And I was worried about the acrylamide.
Re: Panerabread.com leaks millions of customer records
#116Earlier quoted context omitted.
> PCI makes it very hard for Panera to store complete credit card numbers (with expiration dates and the security code on the back) How about impossible. Storing the CVV number is 100% not allowed. Even storing complete cards numbers is only allowed under very specific conditions. Any deviation opens them up to liability for related fraud.
Even storing complete cards numbers is only allowed under very specific conditions. We encrypt these at the app, even before putting them into the DB, yada yada. The PCI auditor actually made us restore the DB from backup onto another server and show them the data, to prove that some magical process in the backup program didn't cause them to come un-encrypted. They also wanted us to change all corporate email address…
Re: Panerabread.com leaks millions of customer records
#117Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all o…
So their old 1990s site, worked fine. Upgrade to new whizbang bullshit and a steady stream of emails still can't get it to simply use a CSS print routine. Outsourcing is glorious!
Re: Panerabread.com leaks millions of customer records
#118Earlier quoted context omitted.
HIPAA only applies to health-care providers and related entities, not random other companies.
Related entities includes the broader "clearinghouse" entity, which has been applied to debt collectors. I agree it would be a stretch to make a claim but I'm not 100% sure it would be fruitless.
Re: Panerabread.com leaks millions of customer records
#119Re: Panerabread.com leaks millions of customer records
#120I found his initial interaction with their head of IT Security (very first initial response) laughably appalling:
Dylan Houlihan
to Mike, Geri Haight -
Hello Mike et al,
Thank you for making yourselves available. There is a security vulnerability on the delivery.panerabread.com website that
exposes sensitive information belonging to every customer who has signed up for an account to order Panera Bread online.
This shows the customer's full name, email address, phone number and the last four digits of their saved credit card number.
Moreover, the customers are easily enumerable which means an attacker could crawl through all the records.
I can provide the specific details of the vulnerability over email once you respond, but if you prefer (for more security),
I can also encrypt the information with a PGP key you provide me. Alternatively we can hop on a phone call.
Best regards,
Dylan Houlihan
And their response: Mike Gustavison
to dylan
Dylan,
My team received your emails however it was very suspicious and appeared scam in nature therefore was ignored. If this is
a sales tactic I would highly recommend a better approach as demanding a PGP key would not be a good way to start off.
As a security professional you should be aware that any organization that has a security practice would never respond to
a request like the one you sent. I am willing to discuss whatever vulnerabilities you believe you have found but I will
not be duped, demanded for restitution/bounty or listen to a sales pitch.
Regards,
Mike