Live data from Hacker News

Ask HN: Have you taken action regarding the Uber hack?

news.ycombinator.com

51–60 of 69 posts

Re: Ask HN: Have you taken action regarding the Uber hack?

#51
post #18

Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option. Previous jihads against hardcoded credentials (use Vault or equivalent). Next target after this will probably be Slack.

Slack had it already in 2015...

Re: Ask HN: Have you taken action regarding the Uber hack?

#52
post #42

> [From the end of the article] Lawyers for Mr. Sullivan have argued that other employees were responsible for regulatory disclosures and said the company had scapegoated Mr. Sullivan. Unless and until CEOs are held personally responsible for such security breaches there will be no solution to the problem. A Chief Security Officer job looks more and more as a designated scape-goat for hire.

It is an idea I hear often, but I don't think it will solve anything. The CEO will be the scapegoat, and may get paid better for the risk taken. So having a CEO scapegoat or a CSO scapegoat, same thing.

You have to realize that a CEO is just an employee. An important employee, but like any other employee, he is paid to do a job, and can be fired if his employers are not satisfied with his work.

If we want to punish the people who have the ultimate responsibility, that would be the shareholders. And it may include you if you have stock in that company. The CEO could also be punished as a shareholder (CEOs usually are), but not as a CEO unless he commit fraud against the shareholders.

We could imagine prison sentences for the most important shareholders, but really, financial sanctions are the most fair. Shareholders will lose money proportional to their share. And if the CEO really is the problem, shareholders will be very unhappy and he won't last long and may even get sued.

Re: Ask HN: Have you taken action regarding the Uber hack?

#53
post #50

Earlier quoted context omitted.

Yes, because I’m sure none of the places you do business with have ever been compromised.

That's true. But like the parent poster, I'm likewise glad I had avoided using them. What I hated about Uber and why I never ended up using it was that their app wanted so much info from my phone for no discernibly good reason. And Lyft didn't seem to be much better. I just wanted a ride man, I didn't want a 500 MB app that sucked all the data out of my phone and sent it to god knows where. So I've just ended up call…

What data can app get from you that you don’t specifically allow? The Uber app only knows my location while I’m using it. If I choose not to give it my credit card number, I can just pay using Apple Pay and they have a one time use credit card.

Not to mention with Uber/Lyft, I know exactly where my driver is, I don’t have to flag down a taxi, I know the price before I sit in the car, etc.

Re: Ask HN: Have you taken action regarding the Uber hack?

#54

Why are you assuming that any sensitive information about customers have been compromised? Uber is legally required to report to its users what is at risk of having been stolen, and so far they haven't said anything. Canceling cards preemptively is a nuclear option.

> Uber is legally required

Uber is infamous for not following the law¹. There is at least one other known case of them not disclosing a data leak²:

> In 2016, hackers stole information from 57 million driver and rider accounts and then approached Uber and demanded $100,000 to delete their copy of the data. Uber arranged the payment but kept the breach a secret for more than a year.

¹ https://www.theguardian.com/news/2022/jul/10/uber-files-leak...

² https://www.nytimes.com/2022/09/15/technology/uber-hacking-b...

Re: Ask HN: Have you taken action regarding the Uber hack?

#55
post #50

Earlier quoted context omitted.

Yes, because I’m sure none of the places you do business with have ever been compromised.

That's true. But like the parent poster, I'm likewise glad I had avoided using them. What I hated about Uber and why I never ended up using it was that their app wanted so much info from my phone for no discernibly good reason. And Lyft didn't seem to be much better. I just wanted a ride man, I didn't want a 500 MB app that sucked all the data out of my phone and sent it to god knows where. So I've just ended up call…

500MB? On what platform?

Re: Ask HN: Have you taken action regarding the Uber hack?

#56

Earlier quoted context omitted.

I get the spirit of your conversation but I urge you to not normalize a term like jihad. It’s sole purpose is to exterminate people by means of brutal violence who don’t fall in line in the name of religion.

Pretty weird since in the original language it just means Struggle. Cleaner connotation than the western equivalent 'Crusade' which is used secularly all the time tbh.

It's simply a matter of how many people are affected by jihad vs crusade in the last few decades. This is the first time I'm seeing jihad used in something not associated with terrorism.

Re: Ask HN: Have you taken action regarding the Uber hack?

#57

Earlier quoted context omitted.

Currently there is an 18 year old hacker bragging everywhere on the internet and seems he/she has no clue what to do with his/her newfound god mode.

Yeah I heard that. I read on Techcrunch. Do you have any links to this person?

None, no idea.

Re: Ask HN: Have you taken action regarding the Uber hack?

#58
post #51
post #18

Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option. Previous jihads against hardcoded credentials (use Vault or equivalent). Next target after this will probably be Slack.

Slack had it already in 2015...

No, I meant that the systematic elimination of the use of Slack is my next holy war/crusade/jihad objective after coming solving the mfa problem. (Team communications should be e2ee, with no external party having access; for group chats up 10-20 that's viable; beyond that, company-encrypted to keys held by the company only.)

Re: Ask HN: Have you taken action regarding the Uber hack?

#59

What harm can be done to me, as an uber user that has their cc data in the uber system by this? Is my credit card information compromised in a way that allows attackers stealing my money?

It shouldn’t be an issue given that for compliance reasons they don’t store credit card data and instead use a third party, and even if they got access to the API keys for that provider, they shouldn’t have access to enough data to somehow use your card.

Re: Ask HN: Have you taken action regarding the Uber hack?

#60

I drove for Uber a couple of years ago. They have my DL and bank routing number. Should I be worried?

I did too, don't they also have a picture of your ID they took when you signed up, for "verification purposes"?

Yes they have a picture of my ID. They have quite a big of info about me since did a background check
Post reply on HN