Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

11–20 of 327 posts

Re: Uber investigating breach of its computer systems

#11

They could be fake, of course, but this thread[1] of screenshots is pretty bad... internal tools, Slack Admin, Google Workspace admin, an AWS account showing admin permissions. [1] https://twitter.com/Savitar0x01/status/1570580235716014081

This is where all the secondary hackers will come into play - I expect to get “new uber signup” random texts later tonight.

Re: Uber investigating breach of its computer systems

#12
post #2

Unconfirmed method of breach: https://twitter.com/hacker_/status/1570582547415068672 - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa) - Once on VPN, scan their intranet and find a network share - Network share has powershell scripts with admin credentials for their PAM vendor, Thycotic - From there can get full access to all systems

Thycotic and Centrify have been rolled up into Delinea fwiw. https://delinea.com/

It's just multiuser keepass with integrations for active directory and such. It's not surprising that three startups building the same thing would realize they could merge and charge 10x the price they could get if they were competing. Since Delinea's rep just took a hit (due to customer error), there is easily room for two or three new players in this space.

Re: Uber investigating breach of its computer systems

#13

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

I would be shocked if they didn’t issue all employees YubiKeys.

I my experience, prepare to be shocked.

And even if they do, they likely have a “backup” for people who never seem to be able to use the Yubikey right.

Re: Uber investigating breach of its computer systems

#14

They could be fake, of course, but this thread[1] of screenshots is pretty bad... internal tools, Slack Admin, Google Workspace admin, an AWS account showing admin permissions. [1] https://twitter.com/Savitar0x01/status/1570580235716014081

Those screenshots look pretty convincing to me.

Re: Uber investigating breach of its computer systems

#15

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

I would be shocked if they didn’t issue all employees YubiKeys.

No post body was provided.

Re: Uber investigating breach of its computer systems

#16

Pour one out for our fellow sys admins & security teams that are going to be working late into the night. They took down their Slack so I wonder what out-of-band comma they’re using. EDIT: Comms not comma. I'll leave the typo because I LOVE bombcar's comment about the semicolon. Confused at first, but I smiled

Yup, gonna be a rough night for all involved.

Re: Uber investigating breach of its computer systems

#17
post #10

Pour one out for our fellow sys admins & security teams that are going to be working late into the night. They took down their Slack so I wonder what out-of-band comma they’re using. EDIT: Comms not comma. I'll leave the typo because I LOVE bombcar's comment about the semicolon. Confused at first, but I smiled

Probably a semicolon! (I’d assume going to text messaging to set something up, which is why you should know enough about your immediate coworkers to verify their identity via non-public information.)

A reasonably sophisticated attacker could arrange for the entire team to get SIM-swapped and suspended from Facebook when they launch an attack. If only there were some way to have a central rallying point for everyone to meet at. Perhaps some sort of a structure, with the company's name on it, and it would have places to sit inside, with computers connected to the company's infrastructure to use.

Re: Uber investigating breach of its computer systems

#18
post #15

Earlier quoted context omitted.

I would be shocked if they didn’t issue all employees YubiKeys.

Quoted post unavailable.

This is false, a gross oversimplification. Every organization has complexities, it doesn't reduce to a common idiocy. Even when the net result is idiotic in hindsight.

Re: Uber investigating breach of its computer systems

#19

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

I would be shocked if they didn’t issue all employees YubiKeys.

A lot of people still have legacy Yubikeys floating around, and these are replayable. What you need now is something like the Google Titan FIDO2 key or one of the Yubikey FIDO2 keys. Transitioning an entire company to these, getting everyone to self-enroll, and then removing the ability to use all the less safe options across the employee base, contractors, etc is not cheap nor easy, and of course requires a massive amount of retraining. It's not as trivial as just buying them, sadly.

Re: Uber investigating breach of its computer systems

#20
post #15

Earlier quoted context omitted.

I would be shocked if they didn’t issue all employees YubiKeys.

Quoted post unavailable.

And even when you do get it setup you end up having to make all sorts of exceptions for various people who can’t be told “no”.
Post reply on HN