"Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company." S…
81% of all breaches now originate from compromised credentials mainly acquired from 3rd party data breaches or data leaks. Most organizations believe that 2FA and SSO are the answer but this proves that 2FA/SSO are not enough.
Uber Paid Hackers to Delete Stolen Data on 57M People
131–140 of 606 posts
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#132Earlier quoted context omitted.
> laundered trillions of dollars of mega-organized-crime money While I agree with your sentiment, there is no need to use such inflated and hilarious numbers.
Edit: Thanks for the corrections. I definitely messed up the magnitudes here. Was doing some other calculation on another topic and somehow I mixed them both. Sorry about that. Please disregard this comment as it it way off :( While "trillions" is definitely inflated and hyperbole, I don't think it's THAT far off. According to this The Guardian article [0] "At least $881m in drug trafficking money was laundered throu…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#133Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#134Earlier quoted context omitted.
Please tell me more about how even less regulation would have held Uber accountable.
It wouldn't. But I'd wager that Uber isn't going to be held accountable (or not very accountable) for this, so why not write the rules so that everyone gets to be as cavalier? It'd save a lot of companies the headaches that go along with I.T security.
Let's remove the stop signs so all drivers can be as cavalier.
It'd save a lot of drivers the headaches that go along with traffic laws.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#135Yep. About that time my Uber account was 'hacked' and someone kept requesting rides in Florida and I had to cancel them as fast as they made them. I emailed Uber support and they got back to my 3 days later. Then someone proceeded to try to gain access to every account I had with that email and password (yeah, yeah, I know). The next worse was someone getting into my DigitalOcean account and launching an instance. It…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#136Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#137They stored AWS storage credentials in clear, in a (private) Github repo... This is so baffling coming from one of the largest tech companies in the world. Among other things, this shows that they do not have proper access policies to user data (e.g anybody working at Uber can get access to any user's data), which in my opinion is a larger issue than this individual hacking case.
see
https://www.forbes.com/sites/kashmirhill/2014/10/03/god-view...
https://www.cnet.com/news/god-view-under-spotlight-as-uber-i...
and
https://www.cnet.com/news/uber-lawsuit-alleges-startup-track...
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#138> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...
One snippet of the email the article didn't mention was that Sullivan's firing happened pretty much right after Dara learned of the breach and an investigation was conducted. It definitely inspires more confidence in leadership seeing that the CEO will not tolerate unethical behavior.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#139I woke up an Silicon Valley has really become an Evil place. What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? We really need to change.
It all started when Google banned all software that can not be used for Evil: http://wonko.com/post/jsmin-isnt-welcome-on-google-code
Redhat also stopped including JSMin for the same reason. [1]