Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

131–140 of 153 posts

Re: Panerabread.com leaks millions of customer records

#131

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

I made this recommendation a couple of years ago when a careless sysadmin left a MySQL dump on a public web share. The response I received is still relevant:

>Requiring a license would wind up making such qualified people more expensive to hire, and companies would ignore it and hire those without licenses to save money.

It would be just about impossible to enforce, naturally, and would be like firing the Senior Developers and hiring fresh graduates.

Re: Panerabread.com leaks millions of customer records

#132

Earlier quoted context omitted.

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

>it's reminiscent of the kind of incompetence that characterized the Equifax breach Go to Mike's LinkedIn and he is the former "ISO - Sr. Director of Security Operations" for Equifax.

I tell you, if I was this incompetent, I'd be homeless. Not in a cushy, high paying corporate job.

Re: Panerabread.com leaks millions of customer records

#133

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

>Head of IT Security >'demanding a PGP key would not be a good way to start off'. Please tell me this man will be fired.

[deleted]

Re: Panerabread.com leaks millions of customer records

#134
post #62

Earlier quoted context omitted.

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…

Pull the plug. The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured. It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.

What happens when the CIO plugs it back in?

Re: Panerabread.com leaks millions of customer records

#135
post #132

Earlier quoted context omitted.

>it's reminiscent of the kind of incompetence that characterized the Equifax breach Go to Mike's LinkedIn and he is the former "ISO - Sr. Director of Security Operations" for Equifax.

I tell you, if I was this incompetent, I'd be homeless. Not in a cushy, high paying corporate job.

Which means he's not incompetent. He's competent, just not at information security.

Re: Panerabread.com leaks millions of customer records

#136
post #62

Earlier quoted context omitted.

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…

Pull the plug. The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured. It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.

"Pulling the plug" is almost never a capability provided to a company security team.

Re: Panerabread.com leaks millions of customer records

#137
post #121
post #93

Earlier quoted context omitted.

That's not what 0 day means.

It's exactly a 0 day. They were notified last August of a 0 day in their website and 6 months later 6*31 days (31 for simplicity) later it was is still was not fixed. Here the definition: https://en.m.wikipedia.org/wiki/Zero-day_attack

I think your original statement was confusing because you put 'no authentication' in parenthesis, implying that to be the definition of 0-day

Re: Panerabread.com leaks millions of customer records

#138

Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…

"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.

On his LinkedIn page it says he has CISSP[0] and has had four security jobs (Panerabread being his fourth) so far between 2000 and now.

He also might have spoke at Akamai Edge 2015 as a security expert (some internal page comes up if you Google his name called 'speaker details' and in the URL the ID of the event leads to Akamai Edge 2015).

[0] - I've no idea if it's good for anything but according to Wikipedia DoD, NSA and ANSI approve of it and it makes the salaries of its holders higher.

Re: Panerabread.com leaks millions of customer records

#139

The guys responsible for the information security worked at Equifax before: https://www.linkedin.com/in/mike-gustavison-b020426/ Coincidence? Strike two?

Could this be a scheme to sell customer data? I assumed for some time that installing backdoors is a good way to sell customer data you otherwise wouldn't be allowed to share.

Equifax didn't fall victim to a backdoor but to an outdated Apache Struts that no one noticed.

Re: Panerabread.com leaks millions of customer records

#140

Earlier quoted context omitted.

Even storing complete cards numbers is only allowed under very specific conditions. We encrypt these at the app, even before putting them into the DB, yada yada. The PCI auditor actually made us restore the DB from backup onto another server and show them the data, to prove that some magical process in the backup program didn't cause them to come un-encrypted. They also wanted us to change all corporate email address…

I find PCI compliance annoying mostly due to individual auditor predilections.

I've heard that there's a fair amount of variability. Obviously at least part of our audit team were lunatics.
Post reply on HN