Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

531–540 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#531

Earlier quoted context omitted.

Full disclosure: I'm the founder of CloudSploit[1] which aims to reduce these risks. You're definitely on to something here. While I wouldn't call AWS security "broken," it is next to impossible to implement it correctly in any medium to large size business. There are 30+ services that AWS provides, each with an infinite number of security controls, JSON-based policies, etc. Cross-service access is even worse. Almost…

> While I wouldn't call AWS security "broken," ... That doesn't match with the rest of your comment. At all. What would you call broken, then?

The security itself is sound. AWS has very very few security incidents where their security was compromised. KMS hasn't been broken (to anyone's public knowledge). If you mark an S3 bucket as private, they've never been accidentally exposed at the fault of AWS.

The issue is in the user's use of the security features. Do you call bcrypt broken if someone uses a weak password and only 1 round of salting? Do you call TLS broken if someone misconfigures their NGINX installation?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#532

Earlier quoted context omitted.

I don't know. I've received a lot of flak for even using Uber from non-tech friends/dates recently. I think the continual tide of negative publicity is definitely having a material effect on their brand image.

Do you live outside of the bay area or seattle?

Yes, I live in NYC.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#533
post #529
post #506

Earlier quoted context omitted.

“Just” leaking full source could be enough to destroy a lot of IP-based companies. A lot of companies stay wealthy because their IP is so huge than nobody can afford to develop competitive alternatives anymore (Adobe, Microsoft Office, Salesforce etc). Some of them have actual “secret sauce” that they cannot afford to share (suggestion engines, biotech processes etc). Even a service like Github, which relies on other…

> Adobe, Microsoft Office, Salesforce I don't think either of those companies would cease to exist if their code bases leaked online today. Sure, someone might get something to build, but there is surely A LOT of things around the code bases to support all of this, which means the code bases would mostly serve as a study for software in general (and finding holes obviously). Github is a bit unfair comparision, as the…

[deleted]

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#534
post #510

Earlier quoted context omitted.

I think your perspective is either immature or unrealistic. OP's a realistic. His perspective is nothing to do with how a company values security. No one in security assumes they won't get hacked, we assume we will and when we do get compromised. Our metrics aren't measured on if, our success metrics are: * How quickly we find out * How much damage we can mitigate * How quickly we mitigate the risks and controls for…

Having practices in case for the event of a hack is obviously good, but it doesn't imply believing that you can't control getting hacked and can't win against the hackers (previous poster's exact words).

It's because you can't control it. There are limitless attackers and vectors. Security is mostly a game of being hardened enough to where most of those attackers will give up and go off looking for easier targets. Against a zero-day that nobody knows about yet, or an extremely determined attacker with a lot of patience? You will eventually lose, and you have to do your best to detect when it happens and act accordingly, as stated previously.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#535
post #365

Earlier quoted context omitted.

You're in charge of security at a large e-commerce company, and your view is that your company is bound to get hacked? I think that's a very sad commentary on how little your company values security.

I think your perspective is either immature or unrealistic. OP's a realistic. His perspective is nothing to do with how a company values security. No one in security assumes they won't get hacked, we assume we will and when we do get compromised. Our metrics aren't measured on if, our success metrics are: * How quickly we find out * How much damage we can mitigate * How quickly we mitigate the risks and controls for…

> OP's a realistic. His perspective is nothing to do with how a company values security.

Of course it does. The stick is not big enough so CSOs just do not care enough. Increase a size of the stick and it would split the group of CSOs into two:

1. Like OP will run away saying "I'm not going to put myself in a line of fire if crap gets hacked". We need broomsticks for those.

2. The ones that will say "OK, two years", do their best and probably succeed.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#537

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I really wish AWS would stop enabling master API keys by default. As soon as you create an AWS account you are given API keys which basically have SUDO permissions to your entire account. That is super dangerous and is probably the same key set that these hackers got ahold of. AWS needs to disable these full access API keys by default and instead should encourage users to generate keys for specific access to limit what they can do.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#538
post #19

If the FTC doesn't act on this they are toothless. Uber's blatant disregard to anything accountable or respectable is astounding: "In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014. After last year’s cyberattack, the company was negotiating with the FTC on a privacy settlement even as it haggled with the hackers on containing the breach,…

I hope the earlier agreement contains language that allows it to be voided, and put all the original violations back on the table. If there is no such term, this is one relatively straightforward way to improve the handling of these matters in future (if a company was unaware of other breaches at the time and appeared to act in good faith, the FTC could always choose to let the original agreement stand.)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#539

Earlier quoted context omitted.

I never quite know how to think about them. On the one hand, they’d changed an entire industry in a way that people wanted but was getting serious resistance from the entrenched players. They had to break a lot of rules and go around a lot of people with a whole lot of connections to get where they are and in the process made a lot of enemies. I expect blowback. I expect negative news. They essentially pulled it off…

AirBnb had to fight a very similar path and the only bad press I can remember about them was that tone deaf/ offensive political marketing campaign they had.

Headlines like "Airbnb hosts violently murder houseguest, police say" have stuck with me.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#540

Earlier quoted context omitted.

The new CEO will not tolerate new unethical behaviour. Hopefully he will also slowly eradicate the existing unethical behaviour.

The new CEO will fix everything just like the last 3 GM CEO's changed their corporate culture and stopped them from making cars that kill teenagers... ... crap. My kids won't be buying a GM car.

The downvotes are likely because you're taking an Uber thread veering it off to GM's management and your children, neither of which have any relevance here.
Post reply on HN