Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

31–40 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#31

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . .

[1] https://help.github.com/articles/requiring-two-factor-authen...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#33
post #9
post #2

I am amazed at the things Uber gets through and is still standing after...

Never underestimate the power of marketing. My mother for instance would use Uber over any ride-sharing system due to its insane exposure and the fact that these stories remain relatively unheard of in comparison.

It's already way more common to use "Uber" as a verb, or even a noun, that doesn't necessarily even mean Uber the company itself.

People have asked me before if I'm about "to uber" or "take an uber" someplace and they say it in an obvious way that implies "any ridesharing company" (or lyft in my case since most people know I only lyft nowadays).

Uber just as a word for ride-sharing has become ingrained and won't be easy to get rid of, IMO.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#34

Earlier quoted context omitted.

Money.

how does this stop being the case? money > all else.

Laws & strong enforcement, with an informed population.

While money gives power, the concern is that it's concentrated in a small number of people. Voting is not, and can result in controls of essentially any level.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#35

I woke up an Silicon Valley has really become an Evil place. What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? We really need to change.

It all started when Google banned all software that can not be used for Evil: http://wonko.com/post/jsmin-isnt-welcome-on-google-code

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#36

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

From what I hear it's pretty common...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#38

> Uber said it will provide drivers whose licenses were compromised with free credit protection monitoring and identity theft protection This got to be a running joke now. Companies lose the data and offer credit/theft protection than facing the consequences. If Equifax could get away with the giant breach, I am sure Uber will not even feel the heat. smh.

It'd be nice if I could register for 2FA with all the various agencies. Commenters have suggested paying a fee to 'freeze' credit activities but the process to 'unfreeze' them requires no new information than what's already in most of these leaks...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#39
post #29
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

Even larger fines seem to draw weak behavior change. The U.S. corporate structure is remarkable in that sense. It shields employees (especially executives who often don't carry out orders) from criminal and financial responsibility for their actions.

This is not true. Back when JPM was being fined billions of dollars when the Southern District of NY was after them, they were quaking in their boots internally while at the same time redlining PR efforts to project external calmness.

Huge fines do exactly what they’re intended to do. JPM for instance responded by making legitimate operational changes to detect all manner of financial malfeasance within their organization.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups.

The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willing to pay. If the parents were fined a day's daycare fee for being ten minutes late you can bet their attitude would change.

I see company fines in the same light - they formalise the process of absolving responsibility and moving on. Just pay the toll and continue to handle your customer data cavalierly.

Post reply on HN