Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

211–220 of 327 posts

Re: Uber investigating breach of its computer systems

#211

Earlier quoted context omitted.

> So if your workplace is letting you authenticate with SMS codes There's an old saying in photography, "the best camera is the one you have with you". IMHO its very much the same thing with 2FA. Any 2FA is better than no 2FA. Sure some 2FA options are more secure than others, but by the same token, there's also a scary number of websites out there that have zero 2FA options. Others make it inordinately difficult to…

Any 2FA is better than no 2FA That's simply false because of the poor customer service of the providers and fates of many phones.

How is that false? Name a single example where SMS 2FA is worse than none. And just because it will always come up: 2FA, not treating the second factor as only factor.

Re: Uber investigating breach of its computer systems

#212

Earlier quoted context omitted.

> ...or whatever, and need the damn TOTP code to telework _right now_. Do you? Really? "Your lack of planning is not my emergency" Unless you're the founder+owner, I'd expect that tech support at your company wouldn't expedite your access request just because you feel entitled to it. Will a million dollar sales call fail and/or have to be rescheduled because you didn't have 2FA access? You should accept the responsib…

> Will a million dollar sales call fail and/or have to be rescheduled because you didn't have 2FA access? You should accept the responsibility, apologise with whoever it is that you let down and move on. Spoken as someone who has clearly never had any tech duties in the financial sector. You don't understand what time critical means until a dealer's access stops working / computer freezes 10 minutes before market clo…

The answer there, clearly, is to not have an individual be a potential SPOF. If failure of that kind of support costs millions of dollars, you absolutely need to have the ‘walked in front of a bus’ scenarios worked out.

Re: Uber investigating breach of its computer systems

#213
post #148

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stol…

I just travelled eight time zones away and (apparently) lost my security key there. It caused pretty much zero issues, I just stopped by the office and picked up a new one to bootstrap off a spare key. Then I revoked the old one. If you don't have another key (you should really get one!) you can call in and they'll figure it out.

Re: Uber investigating breach of its computer systems

#214
post #84

Earlier quoted context omitted.

TouchID unfortunately does not work with Firefox. Making it non viable for a large rollout. Yubikeys have the advantage of working with all browsers

Corporate environments usually have no problem mandating a specific browser be used.

Right, that's how we got IE6 :)

Re: Uber investigating breach of its computer systems

#215
post #193

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

You think that it is worth repeating that multifactor authentication not based on the latest unproven marketing hype technology, Webauthn, is dangerously insecure? You don't know what you're talking about.

> not based on the latest unproven marketing hype technology, Webauthn

WebAuthn is an ongoing project but the history goes back almost a decade to U2F, and the ongoing work has been carefully reviewed by a number of industry heavy-hitters. We know that it’s robust against phishing, too, which is why it’s so relevant to this conversation.

I’d also like to know more about your rationale for describing a system all of the major players have implemented as “unproven marketing hype”.

Re: Uber investigating breach of its computer systems

#216
post #148

Earlier quoted context omitted.

> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stol…

I just travelled eight time zones away and (apparently) lost my security key there. It caused pretty much zero issues, I just stopped by the office and picked up a new one to bootstrap off a spare key. Then I revoked the old one. If you don't have another key (you should really get one!) you can call in and they'll figure it out.

How did you drop into the office to get a new key? Is your office eight time zones away from where you live?

Re: Uber investigating breach of its computer systems

#217
post #83

Seeing these huge companies with practically infinite resources get owned one after another sure makes me wonder if we even have any chance at all to do this correctly in our small business. Perhaps they just don't care about security?

It's the weakest link problem. Uber can have near perfect security but all it takes is a single one out of 20K+ employees to click on the wrong link, install the wrong app or trust the wrong person and suddenly the entire system is compromised. So in that sense your small business is more secure since there are way fewer possible targets.

>Uber can have near perfect security but all it takes is a single one out of 20K+ employees to click on the wrong link, install the wrong app or trust the wrong person and suddenly the entire system is compromised.

In a well run organization it takes a lot more than that. There were a dozen steps in this exploit chain where it could have been detected and blocked. Likely Uber didn't care about security and their security team lacked both political power and resources.

Re: Uber investigating breach of its computer systems

#218
post #32

Earlier quoted context omitted.

What retraining? You install the yubikey by plugging it in, registering it, and using it by tapping it as needed. What is complex? There was literally no training involved for this during my time at ElGoog. One wiki page covered it adequately.

For someone who claims to have worked in big corporations and accuses others of not having worked in them, you sure are optimistic about the capabilities of the average user. Not every company is Google. For starters, how do you register the Yubikey? On Okta, this is a multi-step process with at least one non-obvious step, and one easy way to screw it up.

The people who work at Google are not smarter than the people who work at Uber, or any other tech company. Getting people to understand 2FA might take a little bit of work but it's not hard.

Re: Uber investigating breach of its computer systems

#219

Earlier quoted context omitted.

I just travelled eight time zones away and (apparently) lost my security key there. It caused pretty much zero issues, I just stopped by the office and picked up a new one to bootstrap off a spare key. Then I revoked the old one. If you don't have another key (you should really get one!) you can call in and they'll figure it out.

How did you drop into the office to get a new key? Is your office eight time zones away from where you live?

Nope, I was traveling on business to a place with another office. This is true of a significant portion of business travel, no?

Re: Uber investigating breach of its computer systems

#220
post #72

Earlier quoted context omitted.

> many applications do not support webauthn, full stop You don't need the application to, only your IDP. Everything should be SSO from there.

What if that application doesn't support that setup either? So many services online barely manage to let you setup TOTP, nothing like this...

Stick it behind something like authentik before exposing it
Post reply on HN