I recall someone who was a security director at Panera Bread (a US based fast casual restaurant). Was confused and upset when a security researcher contacted them and asked to exchange a PGP key ... I suspect he straight up didn't understand what the request for a key meant or possibly even the issue as it was a very obvious issue and they did nothing about it until it hit the press. His previous job... at Equifax. O…
The initial email exchange is indeed a sight to see, so I transcribed the text in the image: --------- Hello Mike et al Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number…
In a followup this person makes some excuse about how many emails they get because they're a big company. Why even have the email address then, if you're just going to disregard everything right off the bat? The initial email was rather specific with regard to the issue, but even if it wasn't, send them the fucking PGP key and see what they send! If it's nothing worthwhile, oh well, no big deal.