3 ms·
He has a CISSP (or so says his LinkedIn) though, and on Wikipedia it says DoD, ANSI and NSA value or approve of it and its holders have a higher salary on avera
by FRex 9y ago
He has a CISSP (or so says his LinkedIn) though, and on Wikipedia it says DoD, ANSI and NSA value or approve of it and its holders have a higher salary on average.
And we're talking about the director of security with 17 years of security experience here, (he also spoke at Akamai Edge 2015), not a common programmer or admin, I'd assume he already isn't too cheap to hire with those credentials? And that a company that size doesn't skimp on it's directors?
Then again they'll probably lose nothing over this leak and their response.
Being passive aggressive is even somewhat justifiable if they really get that much scamming but taking offense at someone asking for a PGP key isn't nor is ignoring Dylan's emails repeatedly for 6 days when he asked if his encrypted information came through.
Plus the whole "we are working on it" and then not doing anything for 8 months. Did he throw what Dylan sent him away? And then the fix that required you to login (with an ordinary customer account) to get all customers' data instead of exposing it to the internet. They also told fox only 10 000 customers were affected, treated Krebs like an idiot to the point that he went on a Twitter rant against them and he and others were posting links to other holes, web accessible admin login panels of various things, etc. and saying their website should be taken down (which it now is).
Dylan also angrily posted this after they said to the press they take security seriously: https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-security-seriously-bf078027f815 https://medium.com/@djhoulihan/no-panera-bread-doesnt-take-s...