Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

21–30 of 327 posts

Re: Uber investigating breach of its computer systems

#23
> "Feel free to share but please don’t credit me:

> at Uber, we got an “URGENT” email from IT security

> saying to stop using Slack. Now anytime I request a

> website, I am taken to a REDACTED page with a

> pornographic image and the message “F** you wankers.”

From: https://twitter.com/samwcyo/status/1570583182726266883

Re: Uber investigating breach of its computer systems

#24
post #17
post #10

Earlier quoted context omitted.

Probably a semicolon! (I’d assume going to text messaging to set something up, which is why you should know enough about your immediate coworkers to verify their identity via non-public information.)

A reasonably sophisticated attacker could arrange for the entire team to get SIM-swapped and suspended from Facebook when they launch an attack. If only there were some way to have a central rallying point for everyone to meet at. Perhaps some sort of a structure, with the company's name on it, and it would have places to sit inside, with computers connected to the company's infrastructure to use.

In the old days you’d have physical restrictions on access to the datacenter - in a major breach you’d get there physically and shut it down and disconnect it.

With everything cloud now, how do you recover your cloud account of the master got compromised?

Re: Uber investigating breach of its computer systems

#25
post #2

Unconfirmed method of breach: https://twitter.com/hacker_/status/1570582547415068672 - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa) - Once on VPN, scan their intranet and find a network share - Network share has powershell scripts with admin credentials for their PAM vendor, Thycotic - From there can get full access to all systems

Thoroughly basic and preventable attack.

Re: Uber investigating breach of its computer systems

#26
Think about all that information you trusted uber with because now you're trusting organised crime.

You /have/ to treat uber and the like as though they are organised crime even if you think they are and will always be in league with rainbows, fairies and unicorns will never put your interests behind theirs.

edit: wave to uber's PR flunkies.

Re: Uber investigating breach of its computer systems

#27
post #2

Unconfirmed method of breach: https://twitter.com/hacker_/status/1570582547415068672 - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa) - Once on VPN, scan their intranet and find a network share - Network share has powershell scripts with admin credentials for their PAM vendor, Thycotic - From there can get full access to all systems

> - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa)

Zero-trust may be a security meme at this point, the whole point of zero-trust is to make it so that once on your VPN, all of your stuff isn't immediately pwned. You're supposed to have authentication at all layers, not just the corporate VPN edge. An insecure network share is a ticking time bomb, even if it's behind a VPN, because you now have to hope and pray all of your VPN users aren't bribable, aren't morally bankrupt, aren't disgruntled, etc. The same thing could have happened via insider from the lowest level of employee with VPN access if that report is true.

Re: Uber investigating breach of its computer systems

#28
post #15

Earlier quoted context omitted.

I would be shocked if they didn’t issue all employees YubiKeys.

Quoted post unavailable.

What? Security is the one domain I found where you can't just waltz in because you've heard of a computer. You need to do the work upfront with Sec+ or the like, it would take months for a newbie. Past that point, what more guarantee can you have? Even work experience can be meaningless if they weren't in the right team/role.

Re: Uber investigating breach of its computer systems

#29
post #24
post #17

Earlier quoted context omitted.

A reasonably sophisticated attacker could arrange for the entire team to get SIM-swapped and suspended from Facebook when they launch an attack. If only there were some way to have a central rallying point for everyone to meet at. Perhaps some sort of a structure, with the company's name on it, and it would have places to sit inside, with computers connected to the company's infrastructure to use.

In the old days you’d have physical restrictions on access to the datacenter - in a major breach you’d get there physically and shut it down and disconnect it. With everything cloud now, how do you recover your cloud account of the master got compromised?

That's the fun part, you don't!

Re: Uber investigating breach of its computer systems

#30
post #17
post #10

Earlier quoted context omitted.

Probably a semicolon! (I’d assume going to text messaging to set something up, which is why you should know enough about your immediate coworkers to verify their identity via non-public information.)

A reasonably sophisticated attacker could arrange for the entire team to get SIM-swapped and suspended from Facebook when they launch an attack. If only there were some way to have a central rallying point for everyone to meet at. Perhaps some sort of a structure, with the company's name on it, and it would have places to sit inside, with computers connected to the company's infrastructure to use.

Who controls the database of RFID cards allowed to open the doors?
Post reply on HN