Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

71–80 of 327 posts

Re: Uber investigating breach of its computer systems

#71
post #46

Earlier quoted context omitted.

It’s too bad the user experience across devices sucks. The best experience by far is a yubikey nano since it is mostly permanently attached to your laptop. It’s always there and you just quickly tap it. Love it. Of course that doesn’t work with my iPhone. So I guess I need a second NFC yubikey that stays on my key chain in my pocket (which I don’t have since I don’t carry keys.). So then I have to remember to registe…

Android has a built-in FIDO2/webauthn authenticator these days (well, built-in to Chrome, and by Android I mean Pixel phones). I'm sure Apple will build something similar as they have the hardware for it.

They called them Passkeys. It's FIDO2 with resident keys only AFAIK though https://developer.apple.com/passkeys/

Re: Uber investigating breach of its computer systems

#72

(Edited and removed) Let's start with the basics, many applications do not support webauthn, full stop. Even shops who roll it out are forced to keep holes open for business critical applications that don't support it. Security is not easy, and the entire field is not negligent - the problem is massively asymmetrically stacked against security practitioners, enhanced by poisonous attitudes like the ones expressed her…

> many applications do not support webauthn, full stop

You don't need the application to, only your IDP. Everything should be SSO from there.

Re: Uber investigating breach of its computer systems

#73

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

> How do you work at a company like Uber and do something like click on a link in an email to claim a gift card?

This is bottom of the barrel phishing. Attacks against big companies get _far_ more sophisticated. Things like complete mocks of internal login sites, realistic internal emails. There's big money in hacking big companies, and plenty of shady characters willing to invest in a potential payoff

Re: Uber investigating breach of its computer systems

#74

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

First, people have fundamental drives that can override logical reason. Gift cards probably aren't your button. Maybe your buttons aren't even ones that are easily poked at by e-mail, I dunno. But EVERYONE has buttons somewhere that make them exploitable, and a lot of them ARE e-mail accessible... maybe as easy as offering free money, which is a pretty common one, and it's why marketers have been obsessed with it for ages.

Another factor is that a lot of people have jobs where they're really busy and deal with a lot of e-mail from people with all kinds of bizarre communication styles. Catch one of them with the right e-mail on the right day, and you'll get a careless click.

Black hats get to try every day across lots of people, and they only need it to work one time against one person to score.

Re: Uber investigating breach of its computer systems

#75
post #32

Earlier quoted context omitted.

A lot of people still have legacy Yubikeys floating around, and these are replayable. What you need now is something like the Google Titan FIDO2 key or one of the Yubikey FIDO2 keys. Transitioning an entire company to these, getting everyone to self-enroll, and then removing the ability to use all the less safe options across the employee base, contractors, etc is not cheap nor easy, and of course requires a massive…

What retraining? You install the yubikey by plugging it in, registering it, and using it by tapping it as needed. What is complex? There was literally no training involved for this during my time at ElGoog. One wiki page covered it adequately.

For someone who claims to have worked in big corporations and accuses others of not having worked in them, you sure are optimistic about the capabilities of the average user. Not every company is Google.

For starters, how do you register the Yubikey? On Okta, this is a multi-step process with at least one non-obvious step, and one easy way to screw it up.

Re: Uber investigating breach of its computer systems

#76

Earlier quoted context omitted.

> Security is not easy, and the entire field is not negligent - the problem is massively asymmetrically stacked against security practitioners, enhanced by poisonous attitudes like the ones expressed here. Is remaining in a role in which it's not possible to be effective negligent?

What is your alternative? Should we do nothing instead? Should all SWEs quit because they can't stop writing security bugs?

Should doctors quit and find another field because people keep on breaking their legs?

Re: Uber investigating breach of its computer systems

#77
post #15

Earlier quoted context omitted.

Quoted post unavailable.

What? Security is the one domain I found where you can't just waltz in because you've heard of a computer. You need to do the work upfront with Sec+ or the like, it would take months for a newbie. Past that point, what more guarantee can you have? Even work experience can be meaningless if they weren't in the right team/role.

Sec+ is laughably insufficient.

Re: Uber investigating breach of its computer systems

#78
post #2

Unconfirmed method of breach: https://twitter.com/hacker_/status/1570582547415068672 - Socially engineer an employee to get on their VPN (could have been prevented with webauthn / hardware 2fa) - Once on VPN, scan their intranet and find a network share - Network share has powershell scripts with admin credentials for their PAM vendor, Thycotic - From there can get full access to all systems

>scan their intranet and find a network share Did their IDS/IPS not go off on this? I wonder if this was a sophisticated scan designed to go slow and evade detection or if it was just nmap lol I can't wait for the post-mortem, hopefully lots of good lessons to learn.

>scan their intranet and find a network share

Assuming screenshot is real[0], they have over 1PB in their Google Drive, so chances are everyone just uses Google Drive with shared drives, and employees use Drive for Desktop (previously drive file stream)[1]. Shared drives are pretty powerful and access to them can be gated at the same level as you can regular Drive files.

My theory is that some high-level IT person either got phished and didn't have hardware 2fa, or that high-level IT person downloaded malware / got RAT'd and the Google Drive scanning was done in the background on their machine. Depending on the hierarchy, it might not have even been a scan, could've been the attackers sating their curiosity by browsing through all their internal files and happening to find some PAM credentials.

0: https://twitter.com/praise_terryd/status/1570583105123258369...

1: https://support.google.com/a/answer/7491144?hl=en#zippy=%2Cw...

Re: Uber investigating breach of its computer systems

#79

> "Feel free to share but please don’t credit me: > at Uber, we got an “URGENT” email from IT security > saying to stop using Slack. Now anytime I request a > website, I am taken to a REDACTED page with a > pornographic image and the message “F** you wankers.” From: https://twitter.com/samwcyo/status/1570583182726266883

> at Uber, we got an “URGENT” email from IT security

> saying to stop using Slack. Now anytime I request a

How does an employee know if that message is legitimate or not? If you break into a secure system, mass-emailing all employees saying "URGENT: WE HAVE BEEN HACKED. PLEASE EMAIL YOUR PASSWORD AND SSN TO THIS ADDRESS IMMEDIATELY." is sure to get some percentage of success.

Re: Uber investigating breach of its computer systems

#80

Forgive me for being frank, but how do people seriously fall for phishing scams? How do you work at a company like Uber and do something like click on a link in an email to claim a gift card? It’s insane to me.

everyone is susceptible to it,,, everyone

We don't run internal honeypots and no one has ever been caught in our company, so I disagree. And yes, a reply may be "That you know of...", but considering that we run weekly audits and nothing has leaked, I can be 100% sure of it.
Post reply on HN