The CSO was able to arrange for $100K to be paid out without any oversight of what that money was for? If it was paid to hackers it's unlikely that finance cut a check. I'm imagining this was paid in bitcoin or similar. How was this able to be approved? I'm guessing someone created a fake invoice? Wouldn't that constitute fraud?
Uber Paid Hackers to Delete Stolen Data on 57M People
451–460 of 606 posts
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#452Earlier quoted context omitted.
Uber will not tolerate unethical behavior, you got to be joking!?!?
I think the commenter meant the new CEO will not tolerate unethical behavior.
Hopefully he will also slowly eradicate the existing unethical behaviour.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#453> Uber said it will provide drivers whose licenses were compromised with free credit protection monitoring and identity theft protection. This happened more than a year ago, and only now that they're planning on offering identity theft protection? That's ridiculous.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#454Earlier quoted context omitted.
You raise a difficult issue - how you would honestly resolve it. On one hand, CSOs cannot be personally liable for every hack. On the other, they shouldn't be given a pass on everything either. So how does one draw the lines between bad luck, reasonable security problems, everyday poor performance, civil liability, and criminal negligence? > A random engineer could make a mistake that gets hackers a step closer That…
> So how does one draw the lines between bad luck, reasonable security problems, everyday poor performance, civil liability, and criminal negligence? By analyzing how they prepared for the inevitable attack (mitigation), as well as how they respond to it after the fact.
Essentially we need a price tag on personal data. Let's say 1$ for each email and password leaked to an unknown number of entities. That would be a 114M$ incentive for Uber to keep their data secure.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#455Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#456Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#457> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#458> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#459> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
But you have to put them somewhere; how is idk, AWS credential management secured?
If someone gains access to a system that uses the credentials, then there is, in principle, no difference between puppeteering that system versus stealing its credentials.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#460> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
Really surprising to see that sensitive credentials were checked in to VCS. Apart from peer code review, how can a company avoid developers checking in sensitive data to VCS?
Quick google yielded this https://github.com/awslabs/git-secrets