* They got some data
* The data has a "description" field
* They naively displayed that description field
* They then found to our horror that sometimes this
description field contains CC numbers :/
I don't think you can really blame them too much for that.It would be another story if they were actually storing CC numbers and 'accidentally' published them, but that doesn't seem to be what happened.
if(/\d{4}((\s|-)?\d{4}){3}/){
# don't print it
}n.b. not trying to be a smart-ass, just saying it can't be that hard.
It seems like a ridiculous idea, and while it makes sense in some corner cases, I'm not surprised that they missed something that was only a problem for four users ever.
Perhaps what we should be doing here is asking why Google kept a cache of months-old HTML instead of updating their cache instead?
To that I would say, one should be very very very paranoid about what you print, given that you know that you're printing things from people's credit card bill statement.
Blippy shouldn't have output'd the cc numbers, whether or not Google caches it or not is a secondary to this. Note that Google's cache wasn't explicitly out to get Blippy, they just happened to cache whatever Blippy was emitting.
...to a point.
What other 'bad information' might be in that description? Social Security # for a USA customer? Social Insurance # for a Canadian customer? Pretty soon you'll have a laundry list of 'bad numbers' that you have to try and filter out.
And I agree, that a root cause analysis should be done. E.g. asking the 5 why's (as Eric Ries advocates), for behind every technical problem, there's a human problem.