Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

371–380 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#371
post #303

Earlier quoted context omitted.

Is conservative media berating Musk? I thought progressive media was souring on him?

I think it's more the "anti-fact" wing of the media (which does mostly overlap "conservative" on the Venn diagram). Unabashed alt-right agitprop outlets like Breitbart news, for instance, or climate change deniers. There are a couple different things at play. First, one plank in their infowar strategy is to combat anything that even indirectly propagates any understanding of climate change among the proles. They take…

I thought that it was Lockheed in partnership with some other major aerospace player using the Russian rockets.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#372

Earlier quoted context omitted.

>and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work environment is or how hard they work to spy on their employees and customers I don't think the average Joe is up to date with this news, or even care about.

I don't know. I've received a lot of flak for even using Uber from non-tech friends/dates recently. I think the continual tide of negative publicity is definitely having a material effect on their brand image.

Because they don't like the company or because they don't like newfangled apps?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#373
post #365

Earlier quoted context omitted.

I'm in charge of security at a large e-commerce company. I do not play golf. I mostly live in fear. No sensible person would sign up for the CSO position if they risked jail time when their company gets hacked. You can't really control it. A random engineer could make a mistake that gets hackers a step closer. Or it could be a zero-day vulnerability that nobody knows how to protect against. There are millions of moti…

You're in charge of security at a large e-commerce company, and your view is that your company is bound to get hacked? I think that's a very sad commentary on how little your company values security.

Our company cares more about security than anyone in our space, if you look at how much we invest relative to the others. We have full time penetration testers on staff. We contract out to countless third party security vendors. We take their advice.

This has nothing to do with not valuing security, it's just about being realistic. Can you guarantee that your company is hacker-proof? No? Then we're on the same page.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#374
post #159

I woke up an Silicon Valley has really become an Evil place. What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? We really need to change.

> What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? The kool-aid wore off and everyone realized it never had any meaning to begin with.

"Don't be evil" - a command not a mantra.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#375

Earlier quoted context omitted.

I don't know. I've received a lot of flak for even using Uber from non-tech friends/dates recently. I think the continual tide of negative publicity is definitely having a material effect on their brand image.

Because they don't like the company or because they don't like newfangled apps?

Because they don't like the company. Most of them have switched to Lyft.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#376

Earlier quoted context omitted.

You can't say anything approaching positive about Trump. You will be down voted. The vehement supporters of freedom of speech doesn't support this. Well, the irony.

the daily reminder that freedom of speech does not imply that anybody has to like what you have to say

That is exactly my point ;) The irony is lost.

User starik36's comment was in a downvoted state. Which is what prompted me to write that comment. I didn't think what he said deemed a down vote because from general observation what he stated seems true.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#377

Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…

I never quite know how to think about them. On the one hand, they’d changed an entire industry in a way that people wanted but was getting serious resistance from the entrenched players. They had to break a lot of rules and go around a lot of people with a whole lot of connections to get where they are and in the process made a lot of enemies. I expect blowback. I expect negative news. They essentially pulled it off…

But how do we really know if it was misogynistic ?

Even Tesla has had allegations of misogyny and rampant racism.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#378

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

You couldn't enforce 2FA on GHE for the longest time. GHE version 2.8.0 lists [0] "Enforce two-factor authentication" as a feature. 2.8.0 was released November 2016. According to the article, > Kalanick, Uber’s co-founder and former CEO, learned of the hack in November 2016, a month after it took place, the company said. I don't know if they were using GHE. If they were, at the time it did not come with a good way fo…

Yeah this was such a PITA several years ago... To solve the problem we ended up building a small proxy in Perl for the express purpose of adding 2FA to Github Enterprise.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#379

Earlier quoted context omitted.

But the coverup persisted until just now. Kalanick has been gone for almost half a year.

The new CEO has only been around for a month or two. I imagine it's a lot of information slowly coming forth.

The SoftBank due diligence team likely uncovered it.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#380
post #365

Earlier quoted context omitted.

I'm in charge of security at a large e-commerce company. I do not play golf. I mostly live in fear. No sensible person would sign up for the CSO position if they risked jail time when their company gets hacked. You can't really control it. A random engineer could make a mistake that gets hackers a step closer. Or it could be a zero-day vulnerability that nobody knows how to protect against. There are millions of moti…

You're in charge of security at a large e-commerce company, and your view is that your company is bound to get hacked? I think that's a very sad commentary on how little your company values security.

I think your perspective is either immature or unrealistic.

OP's a realistic. His perspective is nothing to do with how a company values security.

No one in security assumes they won't get hacked, we assume we will and when we do get compromised. Our metrics aren't measured on if, our success metrics are:

* How quickly we find out * How much damage we can mitigate * How quickly we mitigate the risks and controls for X vulnerability and * How we incorporate our reporting to find trends to find the event quicker next time

Now we report on many compromises. I'm not talking just about data breaches here, there's a whole spectrum of compromises that we manage and mitigate.

I don't know anyone who operates in Security who has a different mindset to OP.

Post reply on HN