Good read outlining the timeline of events from the person who originally reported the leak: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s... I found his initial interaction with their head of IT Security (very first initial response) laughably appalling: Dylan Houlihan to Mike, Geri Haight - Hello Mike et al, Thank you for making yourselves available. There is a security vulnerability on the delivery.…
"...demanding a PGP key" This kind of incompetence directly endangers the privacy and security of anyone who does business with Panera. And it's reminiscent of the kind of incompetence that characterized the Equifax breach and other recent high-profile hacks. Maybe it's time that a subset of IT workers become professionally licensed and liable, like engineers.
>Requiring a license would wind up making such qualified people more expensive to hire, and companies would ignore it and hire those without licenses to save money.
It would be just about impossible to enforce, naturally, and would be like firing the Senior Developers and hiring fresh graduates.