Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

511–520 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#511

Earlier quoted context omitted.

I never quite know how to think about them. On the one hand, they’d changed an entire industry in a way that people wanted but was getting serious resistance from the entrenched players. They had to break a lot of rules and go around a lot of people with a whole lot of connections to get where they are and in the process made a lot of enemies. I expect blowback. I expect negative news. They essentially pulled it off…

No excuses for a systemically misogynistic corporate culture. I deleted Uber. You probably should too. https://www.theguardian.com/technology/2017/jun/13/uber-ceo-...

Yea, probably a good idea. I only even need them when I travel but all the cars I saw at the last airport had Uber and Lyft stickers anyway.

The biggest part of the comment was seeing the taxi driver protest in Seattle when I was there on business. My hotel room window had a view of city hall and I watched a bunch of cabs with a news crew pull up for about 45 seconds and start honking their horns. Then they all left and went back to taking fares.

When I watched the local news that night, the broadcast made it look as if they'd blockaded city hall for the day in protest.

It's the things like that that give me pause when I see bad press around a company that has upset entrenched interests.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#512
post #475

Earlier quoted context omitted.

What makes you think you (or most devs for that matter) know more about security than Github's security team?

It's not just about who knows more about security. It's a trade-off, and you need to account for other factors like cost, availability/uptime, data integrity, total attack surface area and others. Honestly, I'm surprised this is such a controversial point of view, but judging by the downvotes it appears it is. You learn something new every day, I guess.

> Honestly, I'm surprised this is such a controversial point of view

HN users tend toward a very pro-SaaS stance.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#513
post #365

Earlier quoted context omitted.

You're in charge of security at a large e-commerce company, and your view is that your company is bound to get hacked? I think that's a very sad commentary on how little your company values security.

Our company cares more about security than anyone in our space, if you look at how much we invest relative to the others. We have full time penetration testers on staff. We contract out to countless third party security vendors. We take their advice. This has nothing to do with not valuing security, it's just about being realistic. Can you guarantee that your company is hacker-proof? No? Then we're on the same page.

I'm not sure why we have to accept a dichotomy between guaranteeing hacker-proofness and throwing up your hands and saying you're bound to get hacked no matter what you do.

It's great that you take all those steps and investment. The fact that you still don't believe you can control whether or not you get hacked is a sad reflection of modern software practices, which are akin to throwing together a house out of plywood, newspaper, and gasoline, then asking the security team to place fire extinguishers.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#514
post #365

Earlier quoted context omitted.

You're in charge of security at a large e-commerce company, and your view is that your company is bound to get hacked? I think that's a very sad commentary on how little your company values security.

More a sad commentary of how many people think there's some magic bullet of security practices and if they just follow those, then they won't be hacked. If you don't assume that you will be hacked, then you won't design in auditing, alerting and containment that will tell you when you've been hacked, let you determine what data was compromised, and prevent the attacker from having free reign over all of your systems.…

> If you don't assume that you will be hacked, then you won't design in auditing, alerting and containment that will tell you when you've been hacked, let you determine what data was compromised, and prevent the attacker from having free reign over all of your systems.

I see a big difference between preparing for the event of a hack, and believing that a hack is inevitable no matter what practices are in place.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#515
post #81

Earlier quoted context omitted.

uber engineer here, we have 2fa set up for everything. Starting my day takes about 5 different 2fa checks (ssh access, aws, phabricator, team chat, etc)

That sounds really inefficient

Although more and more applications support SAML for SSO, much of the SaaS world is disparate and siloed. There's definitely something to be said for centralised user management on a homogeneous system. User leaves your organisation? Just retire them in LDAP.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#516

... so honestly, at this point, we basically have another Uber thing every 2nd week. I do not get why there is no legal action taken against Uber or even steps to shut it down. So much of the stuff violate basic laws how to run a business, apart from the humongous flaws in Ubers ethics and damaging effects on society.

From the article: "After Uber’s disclosure Tuesday, New York Attorney General Eric Schneiderman launched an investigation into the hack, his spokeswoman Amy Spitalnick said. The company was also sued for negligence over the breach by a customer seeking class-action status."

I read that, what I do not get is how the difference in judgement can be justified.

Small companies will instantly get sued and pay fees ruining them for this things. And that already the 1st time it happens. For Uber this is beyond ten finger counting in terms of issues in the past two years.

It is just not having any consequences and by now from the legal side you can conclude that Uber is a repeated offender which has not learned anything from previous cases.

So, my point stands. When will this actually lead to consequences and justice being served?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#517
post #504

Earlier quoted context omitted.

> If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games I'm intrigued. Why would that be a higher-value target?

AAA games have budgets in the millions. Threatening full release would likely net you much more than a few hundred thousands, and without requiring any secondary attack.

Are many (any?) AAA studios using private Github repos for development?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#518

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

Dumb question: What's the best practice to share authentication credentials across the team for services that don't have an IAM feature?

I've never used it in production (my last shop was heavily AWS based and relied on IAM), but I always like the look of Hashicorp's Vault [0]

https://www.vaultproject.io/

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#519
post #454

Earlier quoted context omitted.

(In the EU) companies are already required to tell where my personal data goes to. There is no specific fine for violations as far as I know though. Essentially we need a price tag on personal data. Let's say 1$ for each email and password leaked to an unknown number of entities. That would be a 114M$ incentive for Uber to keep their data secure.

> There is no specific fine for violations as far as I know though. It's a shame this happened pre-GDPR because that has steep fines - 4% of worldwide revenue - which would be north of $260M going off their 2015 numbers. And that's assuming they get off with a single fine.

GDPR is pretty much the thing that will - if properly executed - mean the end of these things.

As CEO, former engineer and customer I really hope this gets some serious traction. IMHO if you are making money from customers, it should be mandatory to follow compliance regulations and protect all data.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#520

Earlier quoted context omitted.

Yep, but think of all of the private keys and tokens used in automation servers (think CI) for pulling down source. Those don't have 2FA - because they don't login - but they have full access to most source. In an organization of about 200 engineers across various products, 1000+ github repos, and 10 or so different CI systems. We enforce 2FA at github. I can still easily see how someone could easily gain access to s…

> In an organization of about 200 engineers across various products, 1000+ github repos Wait, what? That's 5+ repos per engineer. What on earth would warrant that level of granularity? I've only worked once in my career in a place that used more than 2-3 repositories total, and that was a "MegaTechGiant" with thousands of engineers.

Some CI setups benefit from a one-repo-per-service approach, as it makes it easier to figure out when an individual app has changed. In orgs where everything is in one giant repo, it can be difficult to establish what subset of your applications needs to be rebuilt when a commit is pushed.

I personally don't have a strong opinion about either way - they both have tradeoffs.

Post reply on HN