Live data from Hacker News

Massive Breach in Panera Bread

pastebin.com

11–20 of 44 posts

Re: Massive Breach in Panera Bread

#11
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

To bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.

Did you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached.

Good work, in any case.

Re: Massive Breach in Panera Bread

#12
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

It's also possible that Panera would prosecute you for hacking their systems, if they were able to identify you. Better to be safe and disclose anonomyously.

Re: Massive Breach in Panera Bread

#13
post #3

Wow, this looks pretty bad.

If in doubt, put a catputer photo. Cats always look fabulous. Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?. Wouldn…

Apparently he tried talking with Panera directly. First contact was 6 months ago. The vulnerability still exists so he decided to release it publically. I think that's reasonable.

Re: Massive Breach in Panera Bread

#14
That's exactly what you should do when you see a vulnerability. "Internet" "businesses" has proven that they don't understand kind words. Take all those lawsuits, or promises thereof, and shove.

Do this until they plead mercy. Are they? No they aren't yet!

Re: Massive Breach in Panera Bread

#15

Earlier quoted context omitted.

To bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.

Did you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached. Good work, in any case.

I sent this to Krebs and Troy shortly after uploading it.

Re: Massive Breach in Panera Bread

#17
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

It was given 6 months of lead time, but furthermore no researcher is under any obligation at all to consider corporate profits when releasing their research

Re: Massive Breach in Panera Bread

#18
post #9

Verified the vulnerability, but it looks like they have taken down the API now. Hopefully they will publicly acknowledge.

I anticipated this and made archived copies of the hyperlink referenced in the Pastebin entry in case they tried to pretend there was no leak.

https://www.webcitation.org/6yNwbyvu0

https://archive.fo/h9mjp

Re: Massive Breach in Panera Bread

#19
post #3

Wow, this looks pretty bad.

If in doubt, put a catputer photo. Cats always look fabulous. Update: It seems that error-cat has gone now. In resume, anybody could download a list of all people eating at this restaurants, their telephones, addresses, pastry preferences and last four numbers of their credit cards. Am I right? It seems that entering a single telephone they obtain a dozen of diferent users. Is a sort of wildcard or something?. Wouldn…

I'm going to pick on your post a little:

Why would you assume a security researcher who put in that much effort and kept the pastebin mostly anonymous didn't put in the effort to contact Panera Bread?

Is there a reason you automatically assume that the security researcher is irresponsible, but companies, who almost daily, have data breaches, are responsible in these scenarios?

"Hey, maybe you should contact the company?!" Thank you captain fucking obvious.

Re: Massive Breach in Panera Bread

#20
post #4

Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation. Disclosing this as such was irresponsible, despite being an important discovery.

It's also possible that Panera would prosecute you for hacking their systems, if they were able to identify you. Better to be safe and disclose anonomyously.

Is sniffing and accessing an API that requires no credentials really prosecutable for "hacking"?

Anyone can download a MITM proxy on their phone and replay HTTP/HTTPS calls.

Post reply on HN