Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

121–130 of 153 posts

Re: Panerabread.com leaks millions of customer records

#121
post #93
post #76

Wow, this story is amazing. Companiy got notified last August of a 0 day (no authentication) to download all customer records, but no action taken for half a year. Then a very bad PR stunt leading to even more exposure - one can't make this stuff up... its April 3rd already, right?? Wondering why they couldn't just really fix the problem? Would be interesting to learn more on how they do engineering? Eg. was it all o…

That's not what 0 day means.

It's exactly a 0 day. They were notified last August of a 0 day in their website and 6 months later 6*31 days (31 for simplicity) later it was is still was not fixed.

Here the definition:

https://en.m.wikipedia.org/wiki/Zero-day_attack

Re: Panerabread.com leaks millions of customer records

#122

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key"

This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks.

Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

Re: Panerabread.com leaks millions of customer records

#123

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

>Head of IT Security

>'demanding a PGP key would not be a good way to start off'.

Please tell me this man will be fired.

Re: Panerabread.com leaks millions of customer records

#124

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

> IT workers become professionally licensed and liable, like engineers

Except for software engineers, ironically.

Re: Panerabread.com leaks millions of customer records

#125

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

Ideally you wouldn't even need to ask for it.

https://securitytxt.org

Re: Panerabread.com leaks millions of customer records

#126

Earlier quoted context omitted.

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

> IT workers become professionally licensed and liable, like engineers Except for software engineers, ironically.

I suppose there are many ways to choose the subset. Maybe software engineers in specific verticals: medical technology, avionics, etc.? Given the number of security breaches lately, CSO seems like a no-brainer, too.

Re: Panerabread.com leaks millions of customer records

#127

The guys responsible for the information security worked at Equifax before: https://www.linkedin.com/in/mike-gustavison-b020426/ Coincidence? Strike two?

Could this be a scheme to sell customer data?

I assumed for some time that installing backdoors is a good way to sell customer data you otherwise wouldn't be allowed to share.

Re: Panerabread.com leaks millions of customer records

#128

The guys responsible for the information security worked at Equifax before: https://www.linkedin.com/in/mike-gustavison-b020426/ Coincidence? Strike two?

And he joined Equifax after jumping ship from A. G. Edwards in 2008, presumably because the company was accused of fraud in that same year.

His first security gig was Senior IT Security Analyst at A. G. Edwards and Sons. His only work experience before that was Supervisor of Branch Installations.

This seems unbelievable, but that senior security position was his first IT experience.

Re: Panerabread.com leaks millions of customer records

#129

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

>it's reminiscent of the kind of incompetence that characterized the Equifax breach

Go to Mike's LinkedIn and he is the former "ISO - Sr. Director of Security Operations" for Equifax.

Re: Panerabread.com leaks millions of customer records

#130

The guys responsible for the information security worked at Equifax before: https://www.linkedin.com/in/mike-gustavison-b020426/ Coincidence? Strike two?

“The biggest concern is credit card data, a breach occurring on a digital property is devastating to companies.”

Mike Gustavison , Director of Info Sec , Panera Bread

Post reply on HN