Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

131–140 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#131

"Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company." S…

81% of all breaches now originate from compromised credentials mainly acquired from 3rd party data breaches or data leaks. Most organizations believe that 2FA and SSO are the answer but this proves that 2FA/SSO are not enough.

Do you believe this kind of thing is simply unavoidable? I wonder if this could've been avoided by simply making it impossible to access data without being connected to a VPN in addition to having some sort of physical device connected to your computer.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#132
post #61

Earlier quoted context omitted.

> laundered trillions of dollars of mega-organized-crime money While I agree with your sentiment, there is no need to use such inflated and hilarious numbers.

Edit: Thanks for the corrections. I definitely messed up the magnitudes here. Was doing some other calculation on another topic and somehow I mixed them both. Sorry about that. Please disregard this comment as it it way off :( While "trillions" is definitely inflated and hyperbole, I don't think it's THAT far off. According to this The Guardian article [0] "At least $881m in drug trafficking money was laundered throu…

Isn't that 0.881 billion? They're still off by 3 orders of magnitude

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#133
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

I also do this where possible, but Lyft doesn't operate outside the US. I wish they would launch in the UK, at least.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#134

Earlier quoted context omitted.

Please tell me more about how even less regulation would have held Uber accountable.

It wouldn't. But I'd wager that Uber isn't going to be held accountable (or not very accountable) for this, so why not write the rules so that everyone gets to be as cavalier? It'd save a lot of companies the headaches that go along with I.T security.

Some drivers don't stop at stop signs.

Let's remove the stop signs so all drivers can be as cavalier.

It'd save a lot of drivers the headaches that go along with traffic laws.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#135

Yep. About that time my Uber account was 'hacked' and someone kept requesting rides in Florida and I had to cancel them as fast as they made them. I emailed Uber support and they got back to my 3 days later. Then someone proceeded to try to gain access to every account I had with that email and password (yeah, yeah, I know). The next worse was someone getting into my DigitalOcean account and launching an instance. It…

[deleted]

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#137

They stored AWS storage credentials in clear, in a (private) Github repo... This is so baffling coming from one of the largest tech companies in the world. Among other things, this shows that they do not have proper access policies to user data (e.g anybody working at Uber can get access to any user's data), which in my opinion is a larger issue than this individual hacking case.

We already knew that -- viz Uber showing off their ability to track famous users at a party.

see

https://www.forbes.com/sites/kashmirhill/2014/10/03/god-view...

https://www.cnet.com/news/god-view-under-spotlight-as-uber-i...

and

https://www.cnet.com/news/uber-lawsuit-alleges-startup-track...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#138

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

Github 2FA has been part of the first-day training/laptop setup for a while now (I joined in may) and there's security-related training in place as well. I was told there are also scanners in place now that check repos, gists, etc for secrets for exactly this type of mistake.

One snippet of the email the article didn't mention was that Sullivan's firing happened pretty much right after Dara learned of the breach and an investigation was conducted. It definitely inspires more confidence in leadership seeing that the CEO will not tolerate unethical behavior.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#139
post #35

I woke up an Silicon Valley has really become an Evil place. What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? We really need to change.

It all started when Google banned all software that can not be used for Evil: http://wonko.com/post/jsmin-isnt-welcome-on-google-code

People keep bringing this link up every time, but obscure the actual reason that was done: it puts the developers depending on the library in legal jeopardy. Licenses like "Do Whatever The Fuck You Want To" [0] are in the same boat.

Redhat also stopped including JSMin for the same reason. [1]

[0] https://en.wikipedia.org/wiki/WTFPL

[1] https://bugzilla.redhat.com/show_bug.cgi?id=455507

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#140
At what point can we just let a company die? Is there even such a line to be crossed anymore? Personal data leaks and illegal cover-ups, Greyball, utter disregard for regulations, IP theft, a culture systemic harassment and sexism, etc etc etc. Uber just needs to die so that the rest of us can have some semblance of faith in the system left.
Post reply on HN