Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

151–160 of 327 posts

Re: Uber investigating breach of its computer systems

#151
post #150
post #147

Former Uber employee. I'm not a fan of the company. But don't shit on the efforts of the security team please. They were actually quite thorough. We used online MFA (you had to respond to MFA requests on your phone). Not even sure why this is a discussion as the hacker confirmed it was a case of social engineering. No MFA protects against social engineering (no, not even ____ - don't try to convince me). And yes, at…

Quoted post unavailable.

You clearly don't understand how SE can be used even if Yubikey or WebAuthn are used here.

Perhaps you'd like to explain instead of insult someone you know nothing about (which violates HN guidelines).

Re: Uber investigating breach of its computer systems

#152
post #148

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stol…

I think the tradeoff between "the entire company is breached" vs "I lost my device while on vacation and I have a tight deadline" is probably best geared to help prevent the former than the latter.

(Webauthn by design requires physical hardware tokens, not cloud storage.)

Re: Uber investigating breach of its computer systems

#153
post #140
post #66

Earlier quoted context omitted.

> I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. Last year, Apple shipped the first version of this: you can enroll your phone (or TouchID-equipped Mac) on sites like GitHub.com and it’ll use the Secure Enclave for WebAuthn secrets. I’ve been doing this since 15.4 came out and it’s great. Prior to that, I used a Yubikey 5 with USB and NFC, which is still ha…

Recently my phone broke and it took a day to get a new one. I was so glad to have my 2fa codes somewhere else as well. I'd never want to rely solely on one device for access to everything. Apples plan is that I need to own several Apple devices for that, this is a non-starter for me.

The backup option can be a Yubikey rather than another Apple device.

Re: Uber investigating breach of its computer systems

#154
post #84
post #66

Earlier quoted context omitted.

> I wonder when I can just get a virtual yubikey built into my phone. No extra device. My phone is my device. Last year, Apple shipped the first version of this: you can enroll your phone (or TouchID-equipped Mac) on sites like GitHub.com and it’ll use the Secure Enclave for WebAuthn secrets. I’ve been doing this since 15.4 came out and it’s great. Prior to that, I used a Yubikey 5 with USB and NFC, which is still ha…

TouchID unfortunately does not work with Firefox. Making it non viable for a large rollout. Yubikeys have the advantage of working with all browsers

Corporate environments usually have no problem mandating a specific browser be used.

Re: Uber investigating breach of its computer systems

#155

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

So, where does it end? Cybersecurity has been playing those silly games of "increasing security" and some 80% of recommendations were frankly BS "longer passwords" yes. "password has to have symbols, numbers and be rotated every 3 mo" no 2FA yes, but not SMS, but not OTP because people get fished, blah blah blah Not to forget the "put everything in a password manager" then you lose or forget your "extra safe random p…

It ends when you have an internet that has consequences. To get proper consequences, you need all users on the network to be identifiable and every device linked to that identity. With ipv6, you can give each person a (few?) static ipv6 address(es). This will basically allow you to determine where and who originated every piece of information on the internet. Next to every comment/photo or other upload, your real name/surname and facial photo needs to show. For each country you travel to, you get an IP address and you are bound to all laws for that country. Your IP address basically becomes your online passport. Anonymity is a source of massive amounts of nastiness online, there are things that people say/do online that they would never do in real life as there are social consequences. The same rules can be applied (or even stricter ones) to businesses or any server, that way you know who your attackers are. It should also be easier to block out whole countries from connecting to you, if you want that (not enforced).

Obviously, no children should be allowed online even in a clean / locked down version of the internet. Ideally no ads/marketing should ever target children either.

I have the same impulse as most people that locking the internet down is a bad idea, but it seems like that is the only natural outcome eventually. We either stop abusing the internet and keep some form of freedom of speech / freedom (some countries values this more than others), or eventually the internet might become heavily regulated/controlled, which is the path we are currently on. Companies are already testing the waters with this, in some cases they are all ready committed to this (see self-hosting email vs big providers blocking small sender).

The problem of security is just an arms race towards the above, it is just a side effect because it is tolerated / no real consequences for misuse of the internet in most countries (that includes leaking data, being breached and data stolen, or just plain ol phishing - companies face zero consequences for data breaches).

Another way to think of it, you have a scale: on one side you have ultimate control, ultimate safety, no freedom - on the other side you have less control, less safety, but absolute freedom. The security arms race is just the shifting of balance between the two extremes.

Re: Uber investigating breach of its computer systems

#156
post #151
post #150

Earlier quoted context omitted.

Quoted post unavailable.

You clearly don't understand how SE can be used even if Yubikey or WebAuthn are used here. Perhaps you'd like to explain instead of insult someone you know nothing about (which violates HN guidelines).

I get what you are saying now. Agree if the right actors are on it, all those doesn’t matter. Sorry about that.

Re: Uber investigating breach of its computer systems

#157
post #148

Earlier quoted context omitted.

> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stol…

I think the tradeoff between "the entire company is breached" vs "I lost my device while on vacation and I have a tight deadline" is probably best geared to help prevent the former than the latter. (Webauthn by design requires physical hardware tokens, not cloud storage.)

[deleted]

Re: Uber investigating breach of its computer systems

#158
post #141
post #33

Earlier quoted context omitted.

Given that Uber routinely tracked politicians and journos and shared it around the company, and had stood up toolsets to track and evade police so as to facilitate drivers dodging law enforcement, they always were organised crime.

> evade police so as to facilitate drivers dodging law enforcement Isn't this illegal as fuck?

The law doesn't apply if you're a big company.

Re: Uber investigating breach of its computer systems

#159

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

> So if your workplace is letting you authenticate with SMS codes

There's an old saying in photography, "the best camera is the one you have with you".

IMHO its very much the same thing with 2FA.

Any 2FA is better than no 2FA.

Sure some 2FA options are more secure than others, but by the same token, there's also a scary number of websites out there that have zero 2FA options. Others make it inordinately difficult to find (e.g. I'm looking at you Slack ... finding where to turn on 2FA in Slack is a nightmare).

Ironically there's no 2FA option for HN either. ;-)

Re: Uber investigating breach of its computer systems

#160

Pour one out for our fellow sys admins & security teams that are going to be working late into the night. They took down their Slack so I wonder what out-of-band comma they’re using. EDIT: Comms not comma. I'll leave the typo because I LOVE bombcar's comment about the semicolon. Confused at first, but I smiled

Generally speaking infra and sec folk tend to have OOB comms setup because of frequency of Slack outages
Post reply on HN