Earlier quoted context omitted.
What if the CSO ignored bug reports about this for a full 8 months? Would that make it negligent?
What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…
Panerabread.com leaks millions of customer records
141–150 of 153 posts
Re: Panerabread.com leaks millions of customer records
#142Earlier quoted context omitted.
"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.
I made this recommendation a couple of years ago when a careless sysadmin left a MySQL dump on a public web share. The response I received is still relevant: >Requiring a license would wind up making such qualified people more expensive to hire, and companies would ignore it and hire those without licenses to save money. It would be just about impossible to enforce, naturally, and would be like firing the Senior Deve…
And we're talking about the director of security with 17 years of security experience here, (he also spoke at Akamai Edge 2015), not a common programmer or admin, I'd assume he already isn't too cheap to hire with those credentials? And that a company that size doesn't skimp on it's directors?
Then again they'll probably lose nothing over this leak and their response.
Being passive aggressive is even somewhat justifiable if they really get that much scamming but taking offense at someone asking for a PGP key isn't nor is ignoring Dylan's emails repeatedly for 6 days when he asked if his encrypted information came through.
Plus the whole "we are working on it" and then not doing anything for 8 months. Did he throw what Dylan sent him away? And then the fix that required you to login (with an ordinary customer account) to get all customers' data instead of exposing it to the internet. They also told fox only 10 000 customers were affected, treated Krebs like an idiot to the point that he went on a Twitter rant against them and he and others were posting links to other holes, web accessible admin login panels of various things, etc. and saying their website should be taken down (which it now is).
Dylan also angrily posted this after they said to the press they take security seriously: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...
Re: Panerabread.com leaks millions of customer records
#143Jesus Christmas. Honestly, how many more times can they steal my ID? It's gotten so they have to run a diff to see if there's anything new.
Well, at least they didn't leak their customers' HIV statuses, unlike the other security breach I read about yesterday...
Re: Panerabread.com leaks millions of customer records
#144Re: Panerabread.com leaks millions of customer records
#145Earlier quoted context omitted.
My guess is that senators that have been burned have been done so secretly and are being blackmailed. The Equifax dump was apparently huge.
> My guess is that senators that have been burned have been done so secretly and are being blackmailed. The whole bunch has been blackmailed for decades. Just not "ordinary" blackmailing, but threatening by big funders to cut said funding unless, for example, the politician keeps supporting NRA/BigAg/BigFinance-favorable policies...
Re: Panerabread.com leaks millions of customer records
#146Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…
Perhaps Mike knew that law and that's why he took Dylan's email as not genuine. Perhaps "yo fucka, I pwn'd your shit, tomorrow it's on the dark web if u no patch this link" would be the proper way to inform them of a leak.
Then again some people say it's good they didn't try to get Dylan arrested for "hacking".
Re: Panerabread.com leaks millions of customer records
#147Earlier quoted context omitted.
> IT workers become professionally licensed and liable, like engineers Except for software engineers, ironically.
I suppose there are many ways to choose the subset. Maybe software engineers in specific verticals: medical technology, avionics, etc.? Given the number of security breaches lately, CSO seems like a no-brainer, too.
Infosec is an area where there is already a problem with credential collectors, and in many places it is just a dressed up audit/compliance function. It’s not a standalone vertical imo.
Re: Panerabread.com leaks millions of customer records
#148Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…
"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.
Re: Panerabread.com leaks millions of customer records
#149Earlier quoted context omitted.
It wouldn't be breaking and entering. And a house is different than a school. MIT has an open campus. MIT has a long history of celebrating students who transgress boundaries and go where it is unexpected[1]. I don't have a history of celebrating people who enter my house uninvited. > Swartz had connections to [MIT]: "He was a regular visitor to the MIT campus and interacted with MIT people and groups both on campus…
> MIT has a long history of celebrating students who transgress boundaries and go where it is unexpected[1] Only when it's conservative enough and doesn't break the law too much. And not officially. In fact the very wikipedia link says: "Although the practice is unsanctioned by the university, and students have sometimes been arraigned on trespassing charges for hacking, hacks have substantial significance to MIT's h…
I don't see any reason to think they would be upset about him going in an unlocked closet. The previous quote mentions he was part of a puzzle hunt. If he was creating a part of that hunt and used that closet as a part of a puzzle I would think they would have been ok with it. The walls were covered with graffiti. How many years of prison were the students who drew the graffiti threatened with?
[1] https://institute-events.mit.edu/sites/default/files/documen...
Re: Panerabread.com leaks millions of customer records
#150Earlier quoted context omitted.
Pull the plug. The final "stick" and reason for a C in the title is the responsibility to shut down the data (and website) until such a point it can be secured. It's should be considered more of a fiduciary duty (protect shareholders, customers) to protect data as making the right investment or HR decisions.
What happens when the CIO plugs it back in?