5 ms·
Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that th
by bt3 9y ago
Perhaps I'm naïve, but the fact this "breach" is being disclosed anonoymously, via a medium commonly associated with nefarious data dumps suggests to me that there really was little consideration paid to allowing Panera an opportunity to correct this situation.
Disclosing this as such was irresponsible, despite being an important discovery.
- pnrabrdthrwy 9y agoTo bypass the responsible disclosure versus full disclosure debate: I provided them with well over six months of time to fix this and reported it last year. My own data is in this set.
- ocdtrekkie 9y agoDid you try reaching out to Troy Hunt, by chance? In the event of failed response from the site, I would maybe pass breaches to him, as he seems to be fairly successful at getting responses from breached organizations, and has an effective setup for notifying those breached. Good work, in any case.
- pnrabrdthrwy 9y agoI sent this to Krebs and Troy shortly after uploading it.
- technion 9y agoWhilst that does appear to have had the desired effect in this case, I do hope to never find ourselves into the position where "responsible disclosure" includes "consulted with Troy Hunt" as a step.
- mcthorogood 9y agoIt's also possible that Panera would prosecute you for hacking their systems, if they were able to identify you. Better to be safe and disclose anonomyously.
- mcast 9y agoIs sniffing and accessing an API that requires no credentials really prosecutable for "hacking"? Anyone can download a MITM proxy on their phone and replay HTTP/HTTPS calls.
- Kalium 9y agoLong story short, it's actually happened: https://en.wikipedia.org/wiki/Weev#AT&T_data_breach https://en.wikipedia.org/wiki/Weev#AT&T_data_breach
- CiPHPerCoder 9y agoAlthough Weev is a terrible person in general, this is the best case to cite for precedent.
- BrainInAJar 9y agoIt was given 6 months of lead time, but furthermore no researcher is under any obligation at all to consider corporate profits when releasing their research
- PurpleBoxDragon 9y ago>Disclosing this as such was irresponsible How so? Is allowing a company a chance to patch a bug a responsibility that random people have to a company? What do those people get in return? Some companies will go as far as accusing the reporter of hacking them. I might even go as far to say that if companies expect to be told of bugs and not have the information released to the wild, they will be less concerned with security because they can always patch the bugs as they come and perform the smallest disclosure they know of. Such an idea of 'responsible disclosure' may lead to less security overall. Perhaps the responsible thing is reporting the breach to the public because they are the ones most hurt by it, so they can take immediate corrective actions.
- CobrastanJorji 9y agoGiven the number of times well-meaning do-gooders have been prosecuted or sued after publicly disclosing a breach, I find this approach entirely reasonable. The caveat, of course, is that the poster should definitely have first attempted to contact Panera. I would not be surprised at all if Panera responded by doing absolutely nothing, which eventually led to this post.
- thriftwy 9y agoIf you contacted them, you just opened yourself to potential persecution, even if it would not be you who actually pastebined it later. Not even once.
- ethanwillis 9y agoPanera was contacted in August of last year.