Panera Bread did nothing about its customer data vulnerability for eight months
medium.com
medium.com
Commenting only on the speed of response (or the glacial interpretation of it in Panera's case): For companies operating in European Union, the General Data Protection Regulation (GDPR) (2) mandates that such breaches need to be disclosed under 72 hours. The implementation deadline for GDPR is by end of May 2018 (~7 weeks to go).
Underarmor, a US-based sports apparel manufacturer, who operates in EU as well, recently had a breach that affected 150-million users, and went public within 3 days of discovering the breach (3).
I believe UnderArmor's case is the norm we can expect going forward.
(1)https://news.ycombinator.com/item?id=16739753
(2)https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
In fact, as someone who would work on the API facing side of things, even that report would be enough to discover the areas to dig around and find the vulnerabilit(y|ies). There must be an API or HTTP or some other endpoint that takes in a user id, rewards card, zip code, phone number or something similar and returns data for an arbitrary user(s). Let's audit all our endpoints and see where the vulnerability might be.
I've also reported similar vulnerabilities before, and I have received a whole range of responses.
I didn't expect this to be an actual description of a security event, but just a rhetorical observation: of course Panera Bread doesn't take security seriously. There's no "security" in the name of their company. They are not in the security business. I think they do actually take bread seriously. And store location, and customer service, and stuff like that, because that's the kind of business they are.
Because of PCI you can expect they probably do handle your credit card (except apparently the last 4) reasonably well. Because of other regulations you can expect they take food safety seriously. They take basic business operations seriously because there's a bunch of professional business-runners, and they know they really have to.
We can't expect that because they didn't. Rules and best practices do not magically get followed because they exist, and in this case they definitely did not take security (of their customer data) seriously at all.
The title is intended to be a play on the most common response companies make when they experience a serious security failure: "We take security very seriously."
We should start a blog called We Take Security Seriously that links to these responses, just like Our Incredible Journey[1] for acquisition announcements.
__________
No they don't. They admit on record using same additives as Subway mostly a rubber-type chemicals invented by BASF that make bread more elastic, won't go dry this quick and has longer shell-life. Basically when you eat their bread some ingredients are the same of the tires your car was put on!
Further good read how horrible quality their food is:
Companies like this would be better off not on the internet at all. It's not like anyone needs to visit the website to know where the nearest Panera Bread is. Google will tell you, if you don't know.
If this is how they respond to security issues I think it's a fair bet that they're making the same mistakes that e.g. Target and Home Depot did. Who's to say a VPN connection for some lowest bidder third party vendor hasn't already been used to exfiltrate tons of credit card details?
What blows my mind here is the actions of a single person. The Security Director got an email about a dead simple vulnerability in his company's website/api. All he had to do was paste a single link into a browser to verify that there was a big big problem. And he did nothing?
I simply can't understand that.
What was this guy doing every day? Did he have any sense of professional self respect at all? Did he think it would just....go away? It's so confusing.
Do you think he....didn't know how to decrypt the PGP encrypted description? And that he was too embarrassed to say so? In a weird way that's my most charitable explanation.
I actually dislike bringing this up, because I respect the people the have gone through music education; while it doesn't pay in terms of salary, it's certainly something they are passionate about and love dearly. But just as they would not hire me to direct an orchestra, I would not hire them to secure critical Financial systems. This isn't to say there is a fault with them, it's just to say that we all have our strengths in certain areas.
The first part is OK, he is a director, not a grunt. The second is harder to understand. He should've handed the entire thing over, starting with the PGP thing to an actual security knowing engineer.
I have been on the receiving end of such emails a bazillion times in my carrier. My boss or the boss of my boss is certainly not going to bother with such small affairs. It is my duty to inform him when it turns out to be a big affair then he can begin to coordinate with engineering, marketing and so on to do the release. That's his job.
If you want something from a corporation, the best course of action is generally to just write (i.e. snail mail) to the CEO, because they are the only person you can be certain is capable of re-marshaling resources to deal with the root cause of the problem, whatever it may be.
Likely, but shouldn’t the director of information security be given more power to take action? I’d think that if that was my title for an outfit like Panera, and if I couldn’t enact any kind of change in face of a fairly serious vulnerability in the span of eight months, I would resign from said position. Because what’s the point of my job, if that’s what I’m dealing with?
[...] will never respond to a request like the one you sent [...]
Dylan has not asked for a bounty or it wasn't a sales pitch! This Mike guy could not even understand basic underlying tone of the message, not to mention some technical issues the problem relates to. I hope Mr. Mike Gustavison is NOT with the company anymore, or at least is off the public-facing keyboards!
[1] https://cdn-images-1.medium.com/max/2000/1*oJEZOkK6qtq2RreBN...
EDIT: okay update from Kerbs twitter -- Mr. Mike used to work at.. Equifax :)
Oh look,the guy my source initially notified at @panerabread EIGHT MONTHS AGO -- their dir. of info security - was senior dir. of security operations at Equifax until 2013. Shocker.
Maybe he should open his own security company... with all of his experience.
Paragon Initiative Enterprises.
Source: worked too many years in "Healthcare IT" and left some companies after seeing how they mistreat PII.
Archives: https://web.archive.org/web/20180403215610/https://www.akama...
If everyone - wonder if this is "effect of hackers news" :)
EDIT: down for everyone: http://www.isitdownrightnow.com/panerabread.com.html
I guess the DO eventually take security seriously :)))
And then there are decent banks that will put suspicious and/or big transactions on hold for phone authorization. And you cannot change auth data easily without knowing the account password and potentially again authorizing changes with a token. (Remember to disallow changing data over the phone. Most banks require extra work to enable phone account management anyway.)
And in any case you can dispute the suspicious transaction and probably get notifications about these.
There are no fines. People don't stop purchasing stuff from them.
The risks of not following security practices are so low that it makes logical business sense to not care much about them.
Now, say if we add fines on these security breaches. Proper fines, say % of global revenue type fines. Then yeah, they'll start caring.
Until then, wait for more of these security breaches.
Well, I am, yeah.
Especially when the future consequences barely exist. It's very rare for a breach to have serious impact on a company, relative to other areas the company could invest.
One line of code can expose 30,000,000 records. That's hard to get your head around if you are not a programmer.
You have to have a lot of bad process in place for something like this to get in.
Even in companies where good people try to do the right thing security fails not just like this case where they just chose not to act, but also because nobody else at the company cares / is knowledgeable enough to care.
Happy for someone knowledgeable to turn this into a non-rhetorical question.
Also, sometimes when I give them my phone number for my loyalty card it works, and sometimes it doesn't... an alarming number of times it doesn't work, all of which makes me think they have some questionable IT practices going on. I should have seen this coming.
Seems (just a little) like bullying. I'm sure I could do the same to lots of auto shops around my city that have really basic websites and then publicly shame them for not investing enough in security even though security is the biggest money sink ever that never gets fully solved.
If people like this don't report it, then bad actors will get their hands on it and put EVERYONE at risk.
Panera Bread is a company with over 2000 locations, almost 50,000 employees and more than $2 billion in revenue. They let highly sensitive information about millions of customers -- such as dietary requirements, contact details, credit card numbers -- remain publicly accessible for eight months, despite being alerted to it and accepting that it was a legitimate report. Then, once the media found out, they were misleading about the extent of the problem and didn’t even fix it properly.
There are not excuses for a company of Panera Bread's size, with someone actually employed as an 'Information Security Director', to be this incompetent.
Without shaming them and publicising what happened, what recourse is there to encourage better corporate behaviour?