This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
FTC says Uber took a wrong turn with misleading privacy, security promises
11–20 of 30 posts
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#12From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…
Mindboggling huh? Imagine how deep the hands go or who is on Uber side that the result of FTC settlement is statement tht forbids Uber from... breaking the law. Amazing! Me and you would be heading to jail for the claims they did. Not uber. It also somehow reminds me of 911 commision. It eventually got so sidetracked that the result of the findings were that pretty much two planes hit towers and then they collapsed.…
(2) this is a pretty good ruling in that it can't put the horse back into the barn but it can make sure Uber ups their game.
(3) this has absolutely nothing whatsoever to do with 9/11, either peripherally or through analogy, and misrepresenting the findings of the 911 commission to this extent is pretty poor. I have some friends who are total conspiracy nuts when it comes to 9/11 and even they do a better job that this.
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#13This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security pr…
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#14Earlier quoted context omitted.
I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security pr…
edit: ah, nevermind, just a reference that went over my head
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#15From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…
> prohibited from misrepresenting how it monitors internal access to consumers’ personal information; I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator? > required to implement a comprehensive privacy program … > required to obtain within 180 days, and every two years after that for the n…
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#16The craziest part to me: "As a result of the failures described in Paragraph 18, on or about May 12, 2014, an intruder was able to access consumers’ personal information in plain text in Respondent’s Amazon S3 Datastore using an access key that one of Respondent’s engineers had publicly posted to GitHub, a code-sharing website used by software developers. The publicly posted key granted full administrative privileges…
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#17Earlier quoted context omitted.
edit: ah, nevermind, just a reference that went over my head
It's a play on words about the pointy haired boss
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#18This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
People right here on HN advocate against start-ups taking security seriously because it slows them down. Really bugs me.
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#19Earlier quoted context omitted.
It's a play on words about the pointy haired boss
I meant not offense to those with neon-colored hair, correct on the PHB read. Also, Wally is based on a person I worked with. Apparently, he worked with Scott Adams back in the PacBell days.
Re: FTC says Uber took a wrong turn with misleading privacy, security promises
#20This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…
I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security pr…
Nothing is secure by design because anyone that can make it secure by design can get a job somewhere they're taken seriously.