Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

561–570 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#561
post #558

Earlier quoted context omitted.

Just curious, are you speaking as an Uber employee

Well, I am one, but the things I say here are my individual opinions and observations. I just think that as an insider I get some insights that you'd normally not get from the media, and I figured I'd share them.

I'll believe it when they stop having stories like this every few months. They had over a year to report the breach, and they paid hush money instead. Typical Uber

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#562
post #558

Earlier quoted context omitted.

Well, I am one, but the things I say here are my individual opinions and observations. I just think that as an insider I get some insights that you'd normally not get from the media, and I figured I'd share them.

I'll believe it when they stop having stories like this every few months. They had over a year to report the breach, and they paid hush money instead. Typical Uber

> They had over a year to report the breach, and they paid hush money instead.

Yeah, I'm totally with you there. Not cool :(

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#563

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

No, 2FA would not have prevented disclosure of credentials in GitHub. The fix for that is to not check credentials in to GitHub. Nothing else.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#566
post #514

Earlier quoted context omitted.

More a sad commentary of how many people think there's some magic bullet of security practices and if they just follow those, then they won't be hacked. If you don't assume that you will be hacked, then you won't design in auditing, alerting and containment that will tell you when you've been hacked, let you determine what data was compromised, and prevent the attacker from having free reign over all of your systems.…

> If you don't assume that you will be hacked, then you won't design in auditing, alerting and containment that will tell you when you've been hacked, let you determine what data was compromised, and prevent the attacker from having free reign over all of your systems. I see a big difference between preparing for the event of a hack, and believing that a hack is inevitable no matter what practices are in place.

How do you get your CEO to pay for the monitoring and other breach preparation if you've just told him that "We have air-tight security, we cannot get hacked"?

CSO: We have airtight security, we cannot get hacked.

CEO: Great!

CSO: Please approve and fund this plan to handle a breach in case we are hacked.

CEO: But you just told me we can't get hacked.

CSO: Right, it's impossible.

CEO: So why do we need to spend money preparing for it?

CSO: Just in case.

CEO: Just in case what? You just told me it can't happen.

That seems a little like asking for money to prepare for an alien invasion or a zombie attack.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#567
post #235
post #197

Earlier quoted context omitted.

How to implement though? You cant just give Jail-time for data breeches. It would encourage cover ups and scape goats. Also never underestimate just how disorganised large organisations are, incompetence at addressing issues is systemic and goes far beyond data protection. What seems like malice is sometimes just plain stupidity. It has to be backed by some sort of regulatory framework. Just like a fire code or emplo…

No, don't get hung up on unnecessary details. The reasonable company director should have known X and when found out was bound to report it. Person Y did not report it, should have known as it was their job to know and there aren't extenuating circumstances. Guilty. 6 months. Next case. "I don't know anything about this company I accept 7 figure sums to oversee as a director." Should never be any kind of legal defenc…

So person Y read an email late at night and forgot about it. So you send a director to jail. Tomorrow many of the "good" directors feel scared and they simply do not accept any new appointments.

Who will fill the void ? People who are overconfident and people who are not scared of going to jail.

It's much better to impose financial penalties. Should the directors or the shareholders pay ? Let them figure it out between themselves!

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#568
post #303

Earlier quoted context omitted.

Is conservative media berating Musk? I thought progressive media was souring on him?

I think it's more the "anti-fact" wing of the media (which does mostly overlap "conservative" on the Venn diagram). Unabashed alt-right agitprop outlets like Breitbart news, for instance, or climate change deniers. There are a couple different things at play. First, one plank in their infowar strategy is to combat anything that even indirectly propagates any understanding of climate change among the proles. They take…

On your first point, I don't think most (fiscal, small-gov't) conservatives would have much problem with tax incentive for electric vehicles, or anything that generally reduces taxpayer burden. But they are typically vocally against subsidies and grants that favor particular individuals or companies over others -- which is not only unfair, but also adds to more spending. It does little, but to help justify a bigger gov't.

Secondly, SpaceX have been spending millions in political lobbying and McCain's political campaign is among many who benefited from such largess (and his own McCain institute) from Musk. Most Americans don't see this kind of lobbying activities with millions dollars spent on politicians as a "fundamental building block" of a well-functioning gov't, but a corrosive force that serves interests of a few at the expense of the majority, however well-meaning in the eyes of Musk supporters. I personally don't see any problem with organizing an interest group to better represent their views -- or lobbyists -- but when it involves so much money and the final outcome ends in lopsided legislation favoring one particular individual or company over others, it's probably a good time to question their "invest-in-politicians-who-can-help-you" relationship.

Ideologically, McCain's views are aligned with those of the "neoconservative" wing of the republican party -- he's mostly known for aggressive foreign policies, American democracy everywhere, and subsequently pro-Military Industry Complex (MIC) which inevitably all leads to a bigger gov't. While most conservatives are also for strong national defense, not everyone is necessarily on board with permanent warfare and welfare (and police) state and that's why "other" conservatives are so annoyed with McCain.

So, once you put these together, it's not too difficult to see why the holy alliance between Must and McCain is criticized by those on the right. They are not necessarily grounded on "anti-facts" or alt-right views as you mischaracterized here. It's just too bad that your pathetic, uninformed comment had to start with the poisoning the well logical fallacy.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#569
post #540

Earlier quoted context omitted.

The new CEO will fix everything just like the last 3 GM CEO's changed their corporate culture and stopped them from making cars that kill teenagers... ... crap. My kids won't be buying a GM car.

The downvotes are likely because you're taking an Uber thread veering it off to GM's management and your children, neither of which have any relevance here.

Except for the CEO being changed and having a toxic corporate culture that didn't change and produced the same deadly car across CEO's after promising change but did nothing different--including not stopping production of a deadly vehicle.

I probably should have spoonfed the readers more. They grew up in a world that doesn't need critical thinking anymore so it's probably too much to ask for their brains to activate while reading on a website and have them put distinct ideas together to form a grander one.

Must. Downvote. Comments full of facts but from people I dislike. Must.... errooorrrrroooorrrrrr. 505.

It's okay. Every time I see downvotes here, I know I said something great but I just pissed someone in power off. I'm used to being a minority oppressed by a majority in power. It's no big deal. The system just builds people like that these days.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#570

Earlier quoted context omitted.

Yep, but think of all of the private keys and tokens used in automation servers (think CI) for pulling down source. Those don't have 2FA - because they don't login - but they have full access to most source. In an organization of about 200 engineers across various products, 1000+ github repos, and 10 or so different CI systems. We enforce 2FA at github. I can still easily see how someone could easily gain access to s…

> In an organization of about 200 engineers across various products, 1000+ github repos Wait, what? That's 5+ repos per engineer. What on earth would warrant that level of granularity? I've only worked once in my career in a place that used more than 2-3 repositories total, and that was a "MegaTechGiant" with thousands of engineers.

It's normal and expected. I have a few dozen. git makes it great to create little repos for lots of different things. They don't have to be production apps. They can be libraries, utilities, documentation, scripts, or just random crap I may want to refer to someday.
Post reply on HN