Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

31–40 of 327 posts

Re: Uber investigating breach of its computer systems

#32

Earlier quoted context omitted.

I would be shocked if they didn’t issue all employees YubiKeys.

A lot of people still have legacy Yubikeys floating around, and these are replayable. What you need now is something like the Google Titan FIDO2 key or one of the Yubikey FIDO2 keys. Transitioning an entire company to these, getting everyone to self-enroll, and then removing the ability to use all the less safe options across the employee base, contractors, etc is not cheap nor easy, and of course requires a massive…

What retraining? You install the yubikey by plugging it in, registering it, and using it by tapping it as needed. What is complex?

There was literally no training involved for this during my time at ElGoog. One wiki page covered it adequately.

Re: Uber investigating breach of its computer systems

#33
post #26

Think about all that information you trusted uber with because now you're trusting organised crime. You /have/ to treat uber and the like as though they are organised crime even if you think they are and will always be in league with rainbows, fairies and unicorns will never put your interests behind theirs. edit: wave to uber's PR flunkies.

Given that Uber routinely tracked politicians and journos and shared it around the company, and had stood up toolsets to track and evade police so as to facilitate drivers dodging law enforcement, they always were organised crime.

Re: Uber investigating breach of its computer systems

#34

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

Not everyone is paranoid and jaded. It's pointless to judge the stupid ones.

Bottom line is Uber got pwned, and the dirty laundry is now out in the open for all to see and inspect. Tomorrow it'll be for sale on the darkweb.

Re: Uber investigating breach of its computer systems

#36
post #34

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

Not everyone is paranoid and jaded. It's pointless to judge the stupid ones. Bottom line is Uber got pwned, and the dirty laundry is now out in the open for all to see and inspect. Tomorrow it'll be for sale on the darkweb.

If the theory posted elsewhere in this thread is true there was definitely gross negligence elsewhere in the security chain so it’s not the fault of that one person for sure.

Re: Uber investigating breach of its computer systems

#37

> "Feel free to share but please don’t credit me: > at Uber, we got an “URGENT” email from IT security > saying to stop using Slack. Now anytime I request a > website, I am taken to a REDACTED page with a > pornographic image and the message “F** you wankers.” From: https://twitter.com/samwcyo/status/1570583182726266883

Ah, an old fashioned troll/artist rather than someone who just wants to make money with ransomware. How refreshing.

Re: Uber investigating breach of its computer systems

#38
post #15

Earlier quoted context omitted.

Quoted post unavailable.

What? Security is the one domain I found where you can't just waltz in because you've heard of a computer. You need to do the work upfront with Sec+ or the like, it would take months for a newbie. Past that point, what more guarantee can you have? Even work experience can be meaningless if they weren't in the right team/role.

Security is a cost center, not a profit center. Most companies cut that investment to the bone, which means paying the bare minimum that lets them check boxes.

This is true for basically any non-tech company, and is true for like 75% of the tech companies.

> You need to do the work upfront with Sec+

Sec+ is part of the paper mill parent is referring to. A book of terms to memorize for 3 months and then call it good.

Re: Uber investigating breach of its computer systems

#39
post #18
post #15

Earlier quoted context omitted.

Quoted post unavailable.

This is false, a gross oversimplification. Every organization has complexities, it doesn't reduce to a common idiocy. Even when the net result is idiotic in hindsight.

No post body was provided.

Re: Uber investigating breach of its computer systems

#40

Seeing these huge companies with practically infinite resources get owned one after another sure makes me wonder if we even have any chance at all to do this correctly in our small business. Perhaps they just don't care about security?

The thing about security is that it's perfectly fine to not have it most days. Suddenly, all at once, it's not fine at all. A very large company has an exceptionally bad time and a lot of people are affected.

Small startups and businesses can absolutely get it right. It's usually much easier, with a small number of people and systems involved. You just have to approach it knowing it will take work every day. Some things will be harder than you want them to be. It will be worth it to avoid this kind of stuff.

Post reply on HN