Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

41–50 of 327 posts

Re: Uber investigating breach of its computer systems

#41
post #18

Earlier quoted context omitted.

This is false, a gross oversimplification. Every organization has complexities, it doesn't reduce to a common idiocy. Even when the net result is idiotic in hindsight.

Quoted post unavailable.

It sounds like you're experience has been at a small firm. At scale, 2fa and yubikeys are a no brainer with regard to risk vs reward/ safety.

Do you think all security engineers or whatever you want to call them are total incompetent idiots? If yes, I can't help you. If no, then you don't need further explanation from me.

Security requires a complex balancing act, and in this case they got it wrong, end of story. As stated elsewhere in this thread, there are only those who've been breached and those who don't know they've been. End of story.

Re: Uber investigating breach of its computer systems

#42
post #34

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

Not everyone is paranoid and jaded. It's pointless to judge the stupid ones. Bottom line is Uber got pwned, and the dirty laundry is now out in the open for all to see and inspect. Tomorrow it'll be for sale on the darkweb.

“Paranoid and jaded” is reading as “not stupid” to me here.

Re: Uber investigating breach of its computer systems

#43

Seeing these huge companies with practically infinite resources get owned one after another sure makes me wonder if we even have any chance at all to do this correctly in our small business. Perhaps they just don't care about security?

You'll always have one extra layer of security that those companies can't buy... obscurity.

Just don't rely on only that layer, and watch out for oddly quiet individuals named Sam Sepiol.

Re: Uber investigating breach of its computer systems

#44
(Edited and removed) Let's start with the basics, many applications do not support webauthn, full stop. Even shops who roll it out are forced to keep holes open for business critical applications that don't support it. Security is not easy, and the entire field is not negligent - the problem is massively asymmetrically stacked against security practitioners, enhanced by poisonous attitudes like the ones expressed here.

Re: Uber investigating breach of its computer systems

#45

Seeing these huge companies with practically infinite resources get owned one after another sure makes me wonder if we even have any chance at all to do this correctly in our small business. Perhaps they just don't care about security?

You know, the longer I'm at this, I see more and more effort thrown at developing security and one thing remains the same - you've got a user sitting at a machine with network access and the ability to execute code, and sometimes you can trick that user into executing code. I guess the bigger the company, the more users which means more targets/chances.

For decades I've been told that security through obscurity is no security at all, but in the back of my mind, I think it might be the best thing I've got going for me working at a small place. Though I should say, that's far from being our only security - we do work at it too.

Re: Uber investigating breach of its computer systems

#46

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

It’s too bad the user experience across devices sucks. The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. It’s always there and you just quickly tap it. Love it.

Of course that doesn’t work with my iPhone. So I guess I need a second NFC yubikey that stays on my key chain in my pocket (which I don’t have since I don’t carry keys.). So then I have to remember to register both yubikeys. Then every time I have to login to GitHub or whatever on my phone I have to pull out my keychain (which I don’t have) and tap it on my phone.

I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. It kind of sounds like what Passkey is but I don’t want to pull out my phone to auth my laptop.

I really loved the idea and convenience trade off of SoftU2F. Too bad it’s dead now.

Re: Uber investigating breach of its computer systems

#47
post #41

Earlier quoted context omitted.

Quoted post unavailable.

It sounds like you're experience has been at a small firm. At scale, 2fa and yubikeys are a no brainer with regard to risk vs reward/ safety. Do you think all security engineers or whatever you want to call them are total incompetent idiots? If yes, I can't help you. If no, then you don't need further explanation from me. Security requires a complex balancing act, and in this case they got it wrong, end of story. As…

No post body was provided.

Re: Uber investigating breach of its computer systems

#48
The other thing of note with this is timing as yesterday an ex attorney testified against the ex security chief for the 2016 breach cover up. And the next day there is this breach. So based on the damaging nature of the testimony where further discovery could be needed it seems a bit too convenient to have a breach the next day. So is it possible this is a fake breach in order to scrub further damaging evidence of others involved in the original 2016 cover up? Something to think about plus the notice seemed to go up in record speed.

Re: Uber investigating breach of its computer systems

#49
post #41

Earlier quoted context omitted.

It sounds like you're experience has been at a small firm. At scale, 2fa and yubikeys are a no brainer with regard to risk vs reward/ safety. Do you think all security engineers or whatever you want to call them are total incompetent idiots? If yes, I can't help you. If no, then you don't need further explanation from me. Security requires a complex balancing act, and in this case they got it wrong, end of story. As…

Quoted post unavailable.

The bigcorps don't make exceptions for Tiny Tony's. If you work at these sorts of firms, you should probably start an anonymous exposé blog, it would be enlightening for the rest of us. It would also probably help get things fixed so they could avoid further embarrassment before it becomes a real problem (like in this case).

I bet you could make a fair sum from the ad impressions alone, and feel good knowing you were acting as the force multiplier for positive change.

Edit: Your personal jabs aren't in the spirit of a collaborative or curious conversation. You've revealed yourself as just another 007 wannabe. Boring.

Re: Uber investigating breach of its computer systems

#50
post #49

Earlier quoted context omitted.

Quoted post unavailable.

The bigcorps don't make exceptions for Tiny Tony's. If you work at these sorts of firms, you should probably start an anonymous exposé blog, it would be enlightening for the rest of us. It would also probably help get things fixed so they could avoid further embarrassment before it becomes a real problem (like in this case). I bet you could make a fair sum from the ad impressions alone, and feel good knowing you were…

No post body was provided.
Post reply on HN