4 ms·
I don't really like these kinds of articles. It's like "Hey, look, publicly shame this non-technology company that probably never gets bug reports for not jumpi
by ythn 9y ago
I don't really like these kinds of articles. It's like "Hey, look, publicly shame this non-technology company that probably never gets bug reports for not jumping to immediately fix my bug report!"
Seems (just a little) like bullying. I'm sure I could do the same to lots of auto shops around my city that have really basic websites and then publicly shame them for not investing enough in security even though security is the biggest money sink ever that never gets fully solved.
- wgerard 9y agoidk, 8 months is a pretty long time not to fix something as egregious as this. This is definitely not "immediate" by anyone's definition.
- aaomidi 9y agoHey look! I told this company about this security breach months ago! They did nothing to resolve it. They literally have a way to find a person's CC info using their phone number. If people like this don't report it, then bad actors will get their hands on it and put EVERYONE at risk.
- nkozyra 9y agoCannot disagree with this more. There was far more than due diligence demonstrated here.
- thomasfoster96 9y agoCome on - Panera Bread just isn’t some auto shop in your city. Panera Bread is a company with over 2000 locations, almost 50,000 employees and more than $2 billion in revenue. They let highly sensitive information about millions of customers -- such as dietary requirements, contact details, credit card numbers -- remain publicly accessible for eight months, despite being alerted to it and accepting that it was a legitimate report. Then, once the media found out, they were misleading about the extent of the problem and didn’t even fix it properly. There are not excuses for a company of Panera Bread's size, with someone actually employed as an 'Information Security Director', to be this incompetent.
- prawn 9y agoSlight difference between the average auto shop and a company of this scale (billions in revenue) with dedicated security/technical staff. And it wasn't an expectation of an "immediate" fix, but somewhere well within the eight months it apparently took. Without shaming them and publicising what happened, what recourse is there to encourage better corporate behaviour?
- mikesickler 9y agoI hear what you're saying, but the only way to get this industry to take customer data security seriously is to shame them. Fast food operations place a spotlight on food safety now, as a result of several high-profile outbreaks in the past. The same thing needs to happen for data security.
- foobaw 9y agoThis would be understandable if it was for a mom and pop shop. Panera has the profit/revenue to hire a competent technical team. They obviously didn't.