Live data from Hacker News

Ask HN: Have you taken action regarding the Uber hack?

news.ycombinator.com

21–30 of 69 posts

Re: Ask HN: Have you taken action regarding the Uber hack?

#21
post #14

Well now that you mention it, I enabled 2FA :awkward:

Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.

I'm not sure what you mean, unless they have access to my 2FA app how can they get access to my codes?

Re: Ask HN: Have you taken action regarding the Uber hack?

#22

I was dumb and they have details for two physical cards + a virtual card that I use in a few other places + my personal phone number that is still pretty hard to find + my personal email address as I used 'sign in with Google' when I recently set it up in a rush instead of my normal 'services/spam' email :( So yeah not great, but also too much effort to pre-emptively revoke anything so I'll just hope that the fallout…

also the credit card security model has fraud protection built in so just gotta look out on the monthly statements

Re: Ask HN: Have you taken action regarding the Uber hack?

#23
post #19
post #11

PCI standard requires them to report the incident. I think most card issuers would close the affected cards (my bank had done that a few times, rather annoyingly without telling!)

I'm not pre-emptively revoking my card either. In this case the decision should be up to the issuer, not me. They have more or at least the same information as me and it's their money that's at risk.

I always used Apple Pay to pay for Uber rides, so I'm not sure there's any card # to be stolen. I'm sure someone who knows better than I do will chime in :)

Re: Ask HN: Have you taken action regarding the Uber hack?

#24
Why are you assuming that any sensitive information about customers have been compromised? Uber is legally required to report to its users what is at risk of having been stolen, and so far they haven't said anything.

Canceling cards preemptively is a nuclear option.

Re: Ask HN: Have you taken action regarding the Uber hack?

#25
post #4

No action. I'm rarely anxious so it doesn't bother me.

Agreed. The financial aspect doesn’t bother me as it is very likely that action can be taken to prevent future misuse, and reparations can be made for past abuse.

Drivers seem to be hit with a PII breach though, and I’d have concerns if pickup and drop off locations were exposed, particularly for those where that information might be sensitive (e.g. journalists in some jurisdictions).

Re: Ask HN: Have you taken action regarding the Uber hack?

#26
post #21
post #14

Earlier quoted context omitted.

Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.

I'm not sure what you mean, unless they have access to my 2FA app how can they get access to my codes?

By setting up a dummy login screen that you unwittingly enter a valid code into (which I believe is the current best guess for how it was achieved in this case.)

Re: Ask HN: Have you taken action regarding the Uber hack?

#28

Why are you assuming that any sensitive information about customers have been compromised? Uber is legally required to report to its users what is at risk of having been stolen, and so far they haven't said anything. Canceling cards preemptively is a nuclear option.

Absence of proof is not proof of absence. Uber has no fucking idea what's happening, just like Heroku a few months ago. They got completelly pwned. Assume everything has been leaked.

Re: Ask HN: Have you taken action regarding the Uber hack?

#29
post #21
post #14

Earlier quoted context omitted.

Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.

I'm not sure what you mean, unless they have access to my 2FA app how can they get access to my codes?

Some corporate 2FA apps send a push notification to a mobile device. Because of how that is set up, it doesn't always (A) show what the login is for because it shows the name of the SSO app instead of the actual application, (B) show other correct data, e.g. if the user is on a VPN, the location may be the VPN endpoint because of IP-address based locations, and (C) it doesn't always show on the user's device that a login needs to take place, because it may be an Exchange connection refreshing periodically in the background

So, some people just accept whatever pushes they get.

Post reply on HN