Skip to content
Silicon Shecky

Silicon Shecky

Infosec Practitioner

  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

BREACHES? BREACHES? Learn the term please!

Posted on April 5, 2018 By Michael Kavka No Comments on BREACHES? BREACHES? Learn the term please!

Communication and terminology is important. So why can’t we get it right?

I recently saw a poll on Twitter asking if the Cambridge Analytica situation was a breach. and saw people argue both ways. Definitely a gray area. On the other hand, the Panera situation is different. Nobody breached anything, yet Checkpoint even is calling it a breach. The information was put out on the net for all to see. Same thing with any of these misconfigured S3 buckets that give out data, unless of course the data was not suppose to go to the bucket in the first place.

We want to secure things, and we hate FUD, yet we go around throwing words like breach out there when it should not be. Talk about confusing people and sowing FUD! So how do we fix this? It has to start with us coming up with a proper, universally accepted definition for a word like breach. Most of the time we seem to use it to indicate a willing ex-filtration of data that should have been kept private. The keyword there is WILLING. That means someone who was either unauthorized to access the data did (and possible copied/removed it) or someone who had rights to the data intentionally removed it (and possibly put it out for others to access). Going by this simple and basic definition It would indicate that while Facebook was a breach, Panera definitely is not a breach. Panera would be more along the lines of a site misconfiguration, or a permissions issue. The open S3 buckets that have happened would vary depending on if the data in those buckets was permitted to be there or not. If the data was not supposed to be in an S3 bucket, it would be a breach, otherwise it would be just a security misconfiguation or a permssions issue that allowed private data access. The term breach sound so much scarier, but if everything is a breach, then nothing is, and you start to get to an area of desensitizing people to the term, and then have ot come up with a scarier word.

Personally, I think not using the term breach and instead showing that a company screwed up on a configuration is a bigger deal than a breach itself. At least with a breach someone actively had to target the data and take it. We all know there is no perfect security and breaches will happen. On the other hand, setting up a website to show PII about anyone to anyone is a bigger trust issue, as it should have been caught in the QA phase before a site goes live. Mistakes happen, and the response of the company to either a configuration issue or a breach is important, and that is the even bigger fail in Panera’s case.

Rants, Security Tags:Breach, Data Exfil, Panera

Post navigation

Previous Post: Privacy vs. Security
Next Post: Wild Thing – A Post Cyphercon post

Related Posts

  • Security is Reactionary, No Matter What Security
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

More Related Articles

Security is Reactionary, No Matter What Security
Defender, KQL and Lockbit Microsoft
Do well, not be “popular” Ramblings
Defense Layers: A Case Study Microsoft
Device vs. User Microsoft
Ransomware, Are You Ready? General

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP
  • About
  • Links
    • Burbsec
    • BSides312
    • Infosec Exchange Mastodon
    • BSidesRoc
    • Hacks4Pancakes Blog
    • Krebs On Security
    • Bleeping Computer
  • Categories
    • General
    • Computers
    • Software
    • Rants
    • Security
    • Internet/Music
    • Reviews
    • Microsoft
    • Hardware
    • Mobile Computing
  • Archives
  • Social Media

Connect

  • Bluesky
  • LinkedIn
  • Mastodon
  • RSS
  • Twitter

RSS feed: iFin Intel Feed iFin Intel Feed

  • Cyberattack hits University of Munich, potentially exposing student financial data September 21, 2026
  • ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment September 21, 2026
  • Microsoft reminds admins to migrate Entra ID users to passkeys September 21, 2026 Sergiu Gatlan
  • LinkedIn wins court order blocking mass scraping of user data September 21, 2026
  • Clop gets a taste of its own medicine after ShinyHunters hijack leak site September 21, 2026
  • Google says Gemini breached three companies during security test September 21, 2026
  • Microsoft: September updates break File History backup feature September 21, 2026 Sergiu Gatlan
  • SAML: A fractal of bad design September 21, 2026
  • TerminalFix: PNG Steganography, (Mon, Sep 21st) September 21, 2026
  • Rustaceans warned of job interviews with a malicious payload September 21, 2026
  • Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO September 21, 2026 Ahmad Zaidi Said
  • From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies September 21, 2026 Margaret Kelley

Browse by tags

2008 Active Directory Android Antivirus Apple Beta CarbonBlack Chrome Computers Exchange Exchange 2007 Firefox General Thoughts Google InfoSec Internet Explorer iOS iPad IT Linux Mac Malware Microsoft OS OSx Patches SBS SBS 2008 Security Server SMB Software Support Surface TechEd Thotcon Tweets Ubuntu Verizon Virus Vista Windows Windows 7 Windows 8 XP

RSS feed: iFin Intel Feed iFin Intel Feed

  • Cyberattack hits University of Munich, potentially exposing student financial data September 21, 2026
  • ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment September 21, 2026
  • Microsoft reminds admins to migrate Entra ID users to passkeys September 21, 2026 Sergiu Gatlan
  • LinkedIn wins court order blocking mass scraping of user data September 21, 2026
  • Clop gets a taste of its own medicine after ShinyHunters hijack leak site September 21, 2026
  • Google says Gemini breached three companies during security test September 21, 2026
  • Microsoft: September updates break File History backup feature September 21, 2026 Sergiu Gatlan
  • SAML: A fractal of bad design September 21, 2026
  • TerminalFix: PNG Steganography, (Mon, Sep 21st) September 21, 2026
  • Rustaceans warned of job interviews with a malicious payload September 21, 2026
  • Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO September 21, 2026 Ahmad Zaidi Said
  • From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies September 21, 2026 Margaret Kelley
  • Security is Reactionary, No Matter What Security
  • New Year, New Post, from the start General
  • First Defcon – The results Reviews
  • Defender, KQL and Lockbit Microsoft
  • Do well, not be “popular” Ramblings
  • Defense Layers: A Case Study Microsoft
  • Device vs. User Microsoft
  • Ransomware, Are You Ready? General

Social Media

  • Bluesky
  • Mastodon
  • Twitter

Copyright © 2026 Silicon Shecky.