Live data from Hacker News

Ask HN: Have you taken action regarding the Uber hack?

news.ycombinator.com

11–20 of 69 posts

Re: Ask HN: Have you taken action regarding the Uber hack?

#13
I never drove for Uber nor worked as a corporate employee (no risk for SSN leak). Have only used them as a customer.

I only paid for their services using Apple Pay. Even if that number was compromised, the CVV would no longer be valid. I think most banks would automatically re-issue the account number (not the physical card number) if they detect fraudulent use.

The only time I saved a card to Uber was before the NFC era (pre-2015/2016). Those cards have long been removed from the account and have expired.

I am not too worried. Worst case scenario, they have my address and name. Which are both publicly available anyways.

Although maybe I shouldn’t be too complacent. If the data is sold, then it will make me more vulnerable to social engineering attacks. Albeit knowing Uber has been hacked I will be much more aware.

Re: Ask HN: Have you taken action regarding the Uber hack?

#17
I was dumb and they have details for two physical cards + a virtual card that I use in a few other places + my personal phone number that is still pretty hard to find + my personal email address as I used 'sign in with Google' when I recently set it up in a rush instead of my normal 'services/spam' email :(

So yeah not great, but also too much effort to pre-emptively revoke anything so I'll just hope that the fallout isn't too bad.

Re: Ask HN: Have you taken action regarding the Uber hack?

#18
Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option.

Previous jihads against hardcoded credentials (use Vault or equivalent).

Next target after this will probably be Slack.

Re: Ask HN: Have you taken action regarding the Uber hack?

#19
post #11

PCI standard requires them to report the incident. I think most card issuers would close the affected cards (my bank had done that a few times, rather annoyingly without telling!)

I'm not pre-emptively revoking my card either. In this case the decision should be up to the issuer, not me. They have more or at least the same information as me and it's their money that's at risk.
Post reply on HN