Really? Evidence of deletion?
Uber Paid Hackers to Delete Stolen Data on 57M People
241–250 of 606 posts
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#242Earlier quoted context omitted.
Just pigging-backing on your comment. If you did, here's a guide from Github on how to remove it: https://help.github.com/articles/removing-sensitive-data-fro...
I am rather disappointed in github for publishing this guide. The portion at the top stating > Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one. Is a good argument as to why you shouldn't let users erase this data from history, it's already out there so no matter how painful…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#243> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...
If that were the case, there would be no authentication whatsoever to access the closed-source site; the hacker would have just needed to guess the right url.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#244Earlier quoted context omitted.
Consistency is absolutely impossible, as you already alluded to. It’s not a bad move to assess the current position, accept it for what it is, and improve it bit by bit. Pick your battles. Two wrongs don’t make a right when you try to sum them, I.e. combine them. My point is: don’t compare them at all. Don’t change the subject. Uber is one, other things are another. Being a hypocrite doesn’t make you wrong, it just m…
My overall point is that people don't actually care. It's just virtue signaling. If people cared they'd have consistency in their actions. For example, you probably are very consistent in the fact that you probably will never cause physical harm to someone. Consistency isn't impossible at all. People are already very consistent in doing what simply is convenient for them. In the case of Uber vs. Lyft, if you live in…
"Virtue signaling" is an annoying, low-effort way of dismissing something. Try harder. You haven't even provided any evidence. Here's an alternative proposal: People like doing things that they believe will make the world a better place, within their money/time/inconvenience budget, in ways that are limited by their attention. They're human - they have limited attention, limited capacity for simultaneously optimizing hundreds of metrics, and many competing demands that they're trying to satisfy, so they're not going to be perfectly consistent.
No, one person uninstalling Uber is not a massive blow against evil. But many people uninstalling it has been enough to send a pretty powerful signal that -- in conjunction with a lot of concurrent social and legal factors -- is causing Uber to do a pretty solid about-face.
(And it's not seconds, because depending on where you are, Uber may have many more drivers than Lyft -- people travel, after all, so even if Lyft is equal in your home market, it's not equal everywhere. You're also losing the prospect of alternating apps when one or the other is in surge pricing. If you're a heavy user of ride-sharing services, uninstalling Uber imposes both a time and monetary cost.)
Kudos to the GP and others for uninstalling Uber. And for every other step they've taken to try to improve the world by their own actions.
Dans ses écrits, un sage Italien Dit que le mieux est l'ennemi du bien.
(In his writings, a wise Italian says that the better is the enemy of good.)
-- Voltaire
Don't let the pursuit of perfection stop you from doing anything that matters.Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#245Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…
>and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work environment is or how hard they work to spy on their employees and customers I don't think the average Joe is up to date with this news, or even care about.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#246Earlier quoted context omitted.
2fa is just another hurdle. Good to have, but by no means a silver bullet. Just one of the many ways to bypass it in this case: hack a developer machine and look at the local checkout.
I really don't think using 2FA and the direct hacking of an individual developer's machine are all that comparable here. Who cares about access to individual dev's machines if the credentials to access code on github are obtained - 2FA at least offers some degree of protection in this scenario. The scope for attack is extremely different.
They run browsers, communication tools, all sort of product experiments and testbeds, and they even connect to random airport/hotel wifi.
Attack a laptop and all software and hardware 2FA tokens are useless. A backdoor can sit around and wait for the user to press the button.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#247A white hat hacker you have an agreement with on how the data should be handled is the same as an employee who has access to the same data, where you also have an agreement on the employees use of the data.
You might say "Ooh, but can you trust the hacker not to keep a copy of the data!?!", but it's exactly the same as saying "Can you trust the employee not to copy the data?". I don't think a company would announce a data breach just because the database administrator had access to a backup tape...
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#248Earlier quoted context omitted.
My overall point is that people don't actually care. It's just virtue signaling. If people cared they'd have consistency in their actions. For example, you probably are very consistent in the fact that you probably will never cause physical harm to someone. Consistency isn't impossible at all. People are already very consistent in doing what simply is convenient for them. In the case of Uber vs. Lyft, if you live in…
> people don't actually care. It's just virtue signaling. "Virtue signaling" is an annoying, low-effort way of dismissing something. Try harder. You haven't even provided any evidence. Here's an alternative proposal: People like doing things that they believe will make the world a better place, within their money/time/inconvenience budget, in ways that are limited by their attention. They're human - they have limited…
So yes, it is virtue signalling, pretty much by definition -- "the action or practice of publicly expressing opinions or sentiments intended to demonstrate one's good character or the moral correctness of one's position on a particular issue." That being said, I don't think virtue signalling is bad. In fact, it's virtue signalling that has led to the pressure on Uber that brought about this very discussion.
---
As an aside, I didn't realize "virtue signalling" was such a bad word, as well as "hypocrisy." I guess I'll have to stop using those words.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#249Earlier quoted context omitted.
IIRC you can't remove all payment methods from the app, so just deleting the app will leave your credit card information in their hands. Also all your previous ride data will still be on their servers. Both of these things could be lost in a data breach, and presumably account deletion deletes this data.
Deleting your account at Uber doesn't delete ride info[0] In a lot of cases companies still leave behind an email stub to prevent users signing up over and over again for signup deals The only way to ensure your data is safe is to never hand it over in the first place - signup with a fake name, prepaid card, etc. [0] https://help.uber.com/h/24010fe7-7a67-4ee5-9938-c734000b144a
That means every day I'm a new customer and get $20 off my first ride of $22. One day, they'll wise up and stop making such silly deals.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#250Earlier quoted context omitted.
Did you ask any families with a family member killed by a cartel if a fine seemed reasonable?
Why would you respond like this to someone putting forward plain facts.
"i mean look at HSBC - laundered trillions of dollars of mega-organized-crime money. for a decade. 400m dollar fine probably isnt even .01% of what they made off that endeavor"
$1.9b may sound like a lot, but there's a lot of blood attached to it.