Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

191–200 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#191

Earlier quoted context omitted.

It wouldn't. But I'd wager that Uber isn't going to be held accountable (or not very accountable) for this, so why not write the rules so that everyone gets to be as cavalier? It'd save a lot of companies the headaches that go along with I.T security.

Some drivers don't stop at stop signs. Let's remove the stop signs so all drivers can be as cavalier. It'd save a lot of drivers the headaches that go along with traffic laws.

Better example. Almost everyone performs rolling stops at stop signs. Even when people are ticketed they just pay it don't change their behavior. Why have the fine at all?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#192
post #44

Earlier quoted context omitted.

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

To use 2fa on github you need a mobile phone. Do you give every enployee a mobile phone, or do you ask your employees to use their own personal phones? Asking them to use their personal phones seems like a very bad solution. Many software companies do not routinely give developers mobile phones...

It's actually getting more common to give out phones, at least in companies that really care about security.

For companies that don't do that Github also offers the option of FIDO U2F compatible keys.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#194
post #116

Earlier quoted context omitted.

Just pigging-backing on your comment. If you did, here's a guide from Github on how to remove it: https://help.github.com/articles/removing-sensitive-data-fro...

I am rather disappointed in github for publishing this guide. The portion at the top stating > Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one. Is a good argument as to why you shouldn't let users erase this data from history, it's already out there so no matter how painful…

They are doing the right thing by letting the users control their own data, and at most they can make it more complicated to do but not impossible.

There are cases- such as complying with court orders- where removing the data is appropriate (even if a bit futile in the long run).

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#195
post #44

Earlier quoted context omitted.

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

To use 2fa on github you need a mobile phone. Do you give every enployee a mobile phone, or do you ask your employees to use their own personal phones? Asking them to use their personal phones seems like a very bad solution. Many software companies do not routinely give developers mobile phones...

> use their personal phones seems like a very bad solution

Why? You're not any less secure by using a personal phone. What are the odds that an employee is going to be phished and have their phone compromised by the same entity.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#196
post #131

Earlier quoted context omitted.

81% of all breaches now originate from compromised credentials mainly acquired from 3rd party data breaches or data leaks. Most organizations believe that 2FA and SSO are the answer but this proves that 2FA/SSO are not enough.

Do you believe this kind of thing is simply unavoidable? I wonder if this could've been avoided by simply making it impossible to access data without being connected to a VPN in addition to having some sort of physical device connected to your computer.

I agree with ajsharp, this is completely avoidable.

Along with never committing secrets to source control, implementing 3rd party data breach and data leak monitoring is necessary as recommended in NIST 800-63B

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#197
post #106

Every day we see more evidence that boards of directors and senior management should be personally accountable financially and with respect to their liberty for the company they are managing or overseeing doing foul things that they ought to have known. The "I didn't know, I just took a vast salary to play golf" argument should not be any kind of defence. If there is the real prospect of going to jail, golfers will r…

How to implement though?

You cant just give Jail-time for data breeches. It would encourage cover ups and scape goats. Also never underestimate just how disorganised large organisations are, incompetence at addressing issues is systemic and goes far beyond data protection. What seems like malice is sometimes just plain stupidity.

It has to be backed by some sort of regulatory framework. Just like a fire code or employment rights. But crafted in a way that it doesnt end up like PCI, ratings agencies or financial auditors. IE creating an industry that sells compliance and not actual security.

Perhaps something light, like mandetory minimum bug-bounty schemes for all companies, where fines (or more) are imposed for not addressing issues and an independant regulator works with larger companies to resolve issues (or penalise the company severely if they deliberately wont).

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#198

Earlier quoted context omitted.

> If the parents were fined a day's daycare fee for being ten minutes late you can bet their attitude would change. I think upping the pain works better. What's a daycare going to do with so many gallons of milk?

The very last late parent of the day has to dispose of all the milk.

By drinking it ...?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#199
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

What? Uber acted in an unethical manner? Seriously, is anyone surprised? I kinda hope (but not really) that they get hacked again in June 2018 and play the same trick.. us in the EU will have a party on Uber's corpse over GDPR.

And then we can go back to getting ripped off by taxis. I’ve lost more money in taxi rip offs than I ever spent on Uber.

Other than the sexist nonsense of the CEO, there really is an irrational hatred of Uber. Are many of us secretly moonlighting as cab drivers?

Uber’s nonsense is minuscule compared to generations of taxi corruption.

This isn’t me excusing Uber but it does seem like many people, especially Europeans have an inordinate amount of glee over anytime AirBnB or Uber get in trouble. Has the hacker ethic really devolved into statism?

We should be cheering over disruption of the status quo. Does anyone actually long for the days of getting ripped off by over-regulated and over taxed hotels and taxis?

Do you people actually like having government pick winners and losers? Do you actually trust government to do the right thing? Governments have a strong track record of stifling innovation, abridging freedom and giving regulatory handouts to the privileged classes. People here get all kinds of sanctimonious when it comes to patents and copyrights yet seem to fall firmly on the side of the entrenched incumbents when it comes to things like disrupting hotels and taxis. It’s a weird double standard; a hatred of government when they want to prevent people from stealing movies, but a love of government when they want to prop-up taxis and hotels.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#200

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

Yep, but think of all of the private keys and tokens used in automation servers (think CI) for pulling down source. Those don't have 2FA - because they don't login - but they have full access to most source.

In an organization of about 200 engineers across various products, 1000+ github repos, and 10 or so different CI systems. We enforce 2FA at github. I can still easily see how someone could easily gain access to source code with secrets in it.

Post reply on HN