Tell us what you think of our new design.
Welcome. Please log in or register.

Pizza chain caught without fully baked security

By Joris Evers
Staff Writer, CNET News.com
Published: November 7, 2005, 6:15 PM PST

Papa John's has beefed up security for its Web-based e-mail system after the pizza chain learned that internal e-mail and customer data had been exposed.

The leak at the Louisville, Ky.-based pizza chain made internal corporate e-mail and thousands of customer comments available to anyone with a Web browser. The customer comments were submitted between Sept. 29 and Nov. 7 and included names, addresses, phone numbers and e-mail addresses of customers.

"It looks like there is no password protection on Papa John's internal Web e-mail system," said Richard Smith, an Internet privacy expert who reviewed the issue at the request of CNET News.com. "This sort of Web site privacy leak happens more than it should."

Papa John's on Monday added password protection to its Web-based e-mail system and the online customer suggestion database, after it was notified of the leak by CNET News.com. The company's action came hours after information exposing the system's insecurity was published to the popular Full Disclosure security mailing list.

"Today we learned that customer feedback over the last five weeks...could be viewed by a user who would have to enter a very specific, unpublished URL," said Chris Sternberg, a Papa John's spokesman.

"We're not certain that anybody has accessed this information," Sternberg said. "We don't think the ability to access this information breached our disclosure policy, but we don't want it accessed by anyone outside the Papa John's system, so we have taken steps to fix this."

The consumer information that was disclosed did not include credit card numbers or other sensitive data, which limits the risk of fraud, said James Van Dyke, principal analyst at Javelin Strategy & Research in Pleasanton, Calif.

"There is no reason to expect that this will lead to identity fraud, as the exposed information is not of the type used by financial companies to grant access to capital," he said. "In the most extreme case, a fraudster could call one of the listed individuals and pretend to be a Papa John's employee, asking for a credit card number or bank number."

While the Web-based system now requires a password, some of the information is still available in the cache of Google's search engine. For example, one internal Papa John's e-mail discusses the company's challenges in re-establishing itself in Mexico and Puerto Rico after the departure of a key employee.

 1 comments
Post a comment

TalkBack

security

Roman Kim   Nov 7, 2005, 7:05 PM PST

advertisement

Did you know?

Select a tab below to set your default view.

Scan the 15 newest and most read stories on News.com right now. Learn more

Updated: 8:52 PM PST
View as:
Why they say spyware is good for you Microsoft launches long-awaited updates Open source, open wallet Cable goes for the quadruple play 'Madden': The next generation Cablevision revs up its broadband EMI: We don't use rootkits Woz tells Homebrew how Apple grew Windows AntiSpyware becomes 'Defender' World's next fuel source could be designer organisms Just Googling it is striking fear into companies Own Robby the Robot Technology zeroes in on bird flu New worm targets Linux systems Pizza chain caught without fully baked security
Legend:
Older
Newer
Larger boxes indicate hotter stories.

Resource center from News.com sponsors

Concerned About Computer Security?

Education is the best defense

Computer security threats are part of daily life. But today's malware techniques present unprecedented challenges for businesses of all sizes. Learn how to protect yourself.

Learn from the experts>>

Markets

Market news, charts, SEC filings, and more

Related quotes

  Symbol Lookup

Daily spotlight

Video: Building Apples on the cheap

Apple co-founder and speed coder Steve Wozniak recalls building early Apples on the cheap.

Open source, open wallet

Venture money going to companies with an "open source" plan is rising rapidly. Is that a good thing?

Photos: Historic PCs

At the Vintage Computer Festival, which played host to the Homebrew Computer Club's 30th anniversary, a look at yesterday's computers.

Video: Federico Faggin's chip shot

Microprocessor pioneer says that in terms of American technology research, there's too much emphasis on short-term goals.

Perspective: Why they say spyware is good for you

CNET News.com's Declan McCullagh explains the growing trend behind installing spyware on Windows PCs without obtaining proper permission.

Newsmaker: 'Madden' meets the Xbox 360

EA's Jeremy Strauser says the venerable football franchise was rebuilt "with online gaming in mind."

Wireless is more for cable sector

High Impact Fighting phone companies for consumer dollars, cable providers see promise in offering cellular service.

Disney hatches 3D movie plan

reporter's notebook Is 3D debut of 'Chicken Little' a gimmick or a sign of moviemaking's future?
Images: 3D goes digital

Wireless: The new backseat driver?

The family sedan might soon be able to talk to the SUV in the next lane. GM is getting the tech in gear.
Photos: Crash-free Caddies

Don't blame the online mappers

reporter's notebook The guys in the atlas maker's van are doing their best to get you where you're going. Really.
Photos: Mapping in the Net era

Hey, you got your iPod in my Xbox 360

Microsoft has cooked up a way to stream songs and photos from the music player to its next-generation game console. Will Apple push back?

Perspective: Can the wizard of Oz pull it off?

Ray Ozzie will face the challenge of a lifetime turning Microsoft's new services mantra into a success, CNET News.com's Charles Cooper says.


CNET.com
Copyright ©2005 CNET Networks, Inc. All Rights Reserved. Privacy Policy | About CNET Networks | Jobs | Terms of Use