Live data from Hacker News

Panerabread.com leaks millions of customer records

krebsonsecurity.com

151–153 of 153 posts

Re: Panerabread.com leaks millions of customer records

#151
post #62

Earlier quoted context omitted.

What if the CSO informed engineering teams, got stonewalled, and, a few weeks later, escalated through the company's risk process (Panera is public, or was before it was bought by a public company, and will have a risk process). What do people here think a CSO does? If your mental model is: "decree that something is safe to deploy publicly, or else forbid its deployment", your model is broken. Most CSOs have an advis…

If we were running under the liability model the CSO's final option would be to resign which sucks. But he is basically in the same situation that any employee is who is being forced to do something that is clearly illegal. But, I guess that is a good argument for why liability might not work because you end up not having a security team or you put good people into legal dilemmas that they shouldn't have to deal with…

For example (issue may or may not have been legal, but point is the guy resigned): https://arstechnica.com/tech-policy/2016/10/report-fbi-andor...

Re: Panerabread.com leaks millions of customer records

#152
Cases like this are why I think the general public vastly overestimate the capabilities of government surveillance. These same people work at NSA, CIA, etc.

Not to insult the intelligence of these fine agency folk; my point is security is only as strong as its weakest link. And whether public or private, people can make some very weak choices.

Re: Panerabread.com leaks millions of customer records

#153
post #139

Earlier quoted context omitted.

Could this be a scheme to sell customer data? I assumed for some time that installing backdoors is a good way to sell customer data you otherwise wouldn't be allowed to share.

Equifax didn't fall victim to a backdoor but to an outdated Apache Struts that no one noticed.

I'm not only talking about this particular case, but in general. "Accidental" backdoors let companies share data they legally couldn't share.

Look at Facebook and how their API was surprisingly abused for years until they noticed it.

Post reply on HN