Well now that you mention it, I enabled 2FA :awkward:
Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.
Ask HN: Have you taken action regarding the Uber hack?
21–30 of 69 posts
Re: Ask HN: Have you taken action regarding the Uber hack?
#22I was dumb and they have details for two physical cards + a virtual card that I use in a few other places + my personal phone number that is still pretty hard to find + my personal email address as I used 'sign in with Google' when I recently set it up in a rush instead of my normal 'services/spam' email :( So yeah not great, but also too much effort to pre-emptively revoke anything so I'll just hope that the fallout…
Re: Ask HN: Have you taken action regarding the Uber hack?
#23PCI standard requires them to report the incident. I think most card issuers would close the affected cards (my bank had done that a few times, rather annoyingly without telling!)
I'm not pre-emptively revoking my card either. In this case the decision should be up to the issuer, not me. They have more or at least the same information as me and it's their money that's at risk.
Re: Ask HN: Have you taken action regarding the Uber hack?
#24Canceling cards preemptively is a nuclear option.
Re: Ask HN: Have you taken action regarding the Uber hack?
#25No action. I'm rarely anxious so it doesn't bother me.
Drivers seem to be hit with a PII breach though, and I’d have concerns if pickup and drop off locations were exposed, particularly for those where that information might be sensitive (e.g. journalists in some jurisdictions).
Re: Ask HN: Have you taken action regarding the Uber hack?
#26Earlier quoted context omitted.
Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.
I'm not sure what you mean, unless they have access to my 2FA app how can they get access to my codes?
Re: Ask HN: Have you taken action regarding the Uber hack?
#27Re: Ask HN: Have you taken action regarding the Uber hack?
#28Why are you assuming that any sensitive information about customers have been compromised? Uber is legally required to report to its users what is at risk of having been stolen, and so far they haven't said anything. Canceling cards preemptively is a nuclear option.
Re: Ask HN: Have you taken action regarding the Uber hack?
#29Earlier quoted context omitted.
Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.
I'm not sure what you mean, unless they have access to my 2FA app how can they get access to my codes?
So, some people just accept whatever pushes they get.
Re: Ask HN: Have you taken action regarding the Uber hack?
#30Is it likely to affect Uber eats or are they completely separate?