His previous job... at Equifax.
Oh I found the story:
https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...
His previous job... at Equifax.
Oh I found the story:
https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...
---------
Hello Mike et al
Thank you for making yourself available. There is a security vulnerability on the delivery.panerabread.com website that exposes sensitive information belonging to every customer who has signed for an account to order Panera Bread once. This shows the customer's full name, email address, phone number and the last four digits of their saved credit card number. Moreover, the users are easily enumerable which means an attacker can crawl through the records.
I can provide the specific details of the vulnerability over email once you respond, but if you prefer (for more security), I can also encrypt the information with a PGP key you provide me. Alternatively we can hop on a phone call.
Best Regards, Dylan Houlihan
--------------
Dylan
My team received your emails however it was very suspicious and appeared scam in nature therefore was ignored. If this is a sales tactic I would highly recommend a better approach as demanding a PGP key would not be a good way to start off. As a security professional you should be aware that any organization that has a security practice would never respond to a request like the one you sent. I am willing to discuss whatever vulnerabilities you believe you have found but I will not be duped, demanded for restitution/bounty or listen to a sales pitch.
Regards, Mike
I am certainly not authorized to give away the public key but I have a private one that I would share if necessary.
https://www.theregister.co.uk/2006/03/24/tuttle_centos/
If you are in a position where you don't understand the e-mail then ASK someone who does. Or a quick google search with "PGP e-mail", wow was that so hard. The guy was probably late for a golf game or something (ok now i am being mean). Idiots.
Linus Torvalds on idiots (more specifically: people who read things one byte at a time, with system calls for each byte.)
Perhaps a contributing factor to the Peter Principle?
That's a very nasty response to an incredibly polite email.
CCPA -- the California Consumer Privacy Act -- has real penalties for data breaches [0]. When there is pure negligence in play and the business doesn't cure with 30 days notice, the law seems to explicitly provide for a minimum $100 / person penalty. And up to $750. There are amendments in play to remove the 30 day cure grace period; whether they pass this year or not, we'll have them within 5 years (personal bet).
Basically, breaches can be an extinction event for a company in California starting 1 January 2020. A couple companies are gonna take one for the team, and shortly thereafter, boards will be very interested in security postures.
[0] https://iapp.org/resources/article/california-consumer-priva...
Edit: My question and the replies are incredibly depressing as an infosec practitioner.
And I told him "His resume lists multiple cool projects that he worked on."
(Facepalming ensued.)
But a security director being suspicious of PGP encryption is a sign of a know-nothing in a position of power.
I mean, come on - do they also ask strangers to hold their wallet?