Live data from Hacker News

Uber investigating breach of its computer systems

nytimes.com

261–270 of 327 posts

Re: Uber investigating breach of its computer systems

#263
post #177

Earlier quoted context omitted.

No – the problem here is really the reverse: they limit the number of devices which can gate access to your account, on the theory that you'll handle a breach by contacting them. That's theoretically more secure but slower. (Non-root MFA can be reset by another admin or root so this is most of a concern for the root account)

Slowing things down is the right approach when resetting/reissuing/rebinding auth devices.

When removing MFA, yes. What I'd like would be changing n=1 to n=2 so you could have a backup against a single failure.

Re: Uber investigating breach of its computer systems

#264
post #192

Earlier quoted context omitted.

The way I view these types of objections - I know one or two people who have lost their wallet more than a couple times in their live ("I need new ID!") and the rest of the people I have know have NEVER lost their wallet. Even people who have their wallet stolen often recover it later (thieves remove valuable part and throw it away so they aren't caught with it). We probably shouldn't design our security procedures a…

"User lost their token/forgot their password/lost access to their e-mail/lost their phone/changed their phone number/changed their mailing address" may only be 0.1% of users - but it's 100% of social engineering attacks :)

Yep, and the GP is saying that you should optimize your procedures to deal with the attacks, not with the honest errors. Exactly because the honest errors almost never happen (even when there are thousands of people on the organization).

Anyway, if a complaint about procedures makes exactly as much sense if you replace the cause with "gets sick and spend a day at the hospital" without losing meaning, then it's not a valid complaint.

Re: Uber investigating breach of its computer systems

#265
post #177

Earlier quoted context omitted.

> That last part is important because AWS has a huge barrier: the number of MFA devices you get is one, which means you either need insecure things like synced TOTP seeds or you have to be comfortable never losing your Yubikey. I have been asking our TAM to prioritize fixing that for years so backups can be a real thing. Actually, can we mark AWS as insecure? Seriously, it was a bother at the time it was rolled out b…

No – the problem here is really the reverse: they limit the number of devices which can gate access to your account, on the theory that you'll handle a breach by contacting them. That's theoretically more secure but slower. (Non-root MFA can be reset by another admin or root so this is most of a concern for the root account)

> That's theoretically more secure

I fail to see how that can be true. How will they validate that it is you on the phone?

Re: Uber investigating breach of its computer systems

#266
post #215

Earlier quoted context omitted.

> not based on the latest unproven marketing hype technology, Webauthn WebAuthn is an ongoing project but the history goes back almost a decade to U2F, and the ongoing work has been carefully reviewed by a number of industry heavy-hitters. We know that it’s robust against phishing, too, which is why it’s so relevant to this conversation. I’d also like to know more about your rationale for describing a system all of t…

Well, they have recently added a bunch of weirdness to the spec. At one point U2F was simple - a USB token with a hardwired user presence button, providing a second factor alongside a username and password. Trivial to move between different computers and OSes. Secure even if the host OS can't be trusted. Physically unpluggable. These days there's a mad variety of options. Options that are only secure if the host OS c…

When you make a communications protocol open, people create all kinds of crazy endpoints for it.

Re: Uber investigating breach of its computer systems

#267
post #147

Former Uber employee. I'm not a fan of the company. But don't shit on the efforts of the security team please. They were actually quite thorough. We used online MFA (you had to respond to MFA requests on your phone). Not even sure why this is a discussion as the hacker confirmed it was a case of social engineering. No MFA protects against social engineering (no, not even ____ - don't try to convince me). And yes, at…

> No MFA protects against social engineering

That's true - some kinds of social engineering cannot be prevented by technical means. BUT hardware keys prevent an entire class of extremely common attacks that every other form of MFA is vulnerable to. It would have prevented the method of compromise used here.

Any company not using FIDO/WebAuthn in 2022 is behind on best practices.

Re: Uber investigating breach of its computer systems

#268

Earlier quoted context omitted.

> So if your workplace is letting you authenticate with SMS codes There's an old saying in photography, "the best camera is the one you have with you". IMHO its very much the same thing with 2FA. Any 2FA is better than no 2FA. Sure some 2FA options are more secure than others, but by the same token, there's also a scary number of websites out there that have zero 2FA options. Others make it inordinately difficult to…

> Any 2FA is better than no 2FA. False. SMS 2FA is significantly, uncategorically, undeniably worse than no 2FA at all. If your SIM card is hijacked, most websites/companies will quite happily let the impostor click a "Forgot password" link and get a SMS code to verify their identity, which will allow them into the account to take/change whatever other details they want at that time.

> most websites/companies will quite happily let the impostor click a "Forgot password" link and get a SMS code to verify their identity

That's not 2FA. There is one single factor there, the SMS code.

SMS 2FA does not require you to have a 1FA backdoor, so you can't claim the latter is an inherent fault of the former.

For example, pairing "enter the SMS code" with "click the link we sent to your backup e-mail address" gets you a two-factor password recovery process.

That isn't the best or only method of 2FA password resets, it just comes to mind first because it's the last one I used and it is sufficient to prevent access via SIM hijacking alone.

Re: Uber investigating breach of its computer systems

#269
post #15

Earlier quoted context omitted.

I would be shocked if they didn’t issue all employees YubiKeys.

Quoted post unavailable.

> Security exists just to check boxes at most firms

And then you get the bullshit solutions that the OP was complaining about.

Nobody serious ever claimed that SMS based MFA was secure. Large companies implemented it anyway, and pushed it into unknowing developers nonetheless.

Re: Uber investigating breach of its computer systems

#270
post #148

I think it's worth repeating: at this point, MFA that is not based on Webauthn ( https://webauthn.guide/#about-webauthn ) should be considered dangerously insecure. Uber almost certainly enforces MFA for remote access; I strongly suspect we'll end up hearing that it was successfully provided during the authentication step (update: screenshots on Twitter appear to confirm this). As we saw in the case of the 0ktapus ca…

> you need to start banging on pots and pans up your reporting chain to get your security team Not sure how Webauthn works, but as long as it can be stored in the cloud, I'm fine. Industry is going towards this scheme of physical 2FAs that assume some living conditions appropriate for whoever designs things, without alternatives for people who don't fit that ideal way of doing things. Physical stuff gets lost or stol…

I'm curious what problems physical tokens have that don't have easy workarounds. I have a Yubikey on my keychain with home/vehicle keys that supports USB and NFC (so it works with my phone).

For work, I use that as a backup. For personal use, I just leave a cheap Feitian plugged into my desktop. For work, I just leave a slim USB-C plugged into my laptop all the time (if the laptop gets stolen, they still need the first/password factor)

In addition, emergency recovery codes just get copied to a note in my password manager. You don't need to lock recovery codes in a safe--they're only 1 of the two factors. You just need to make sure you don't store them in the same place as the other factor (or, if you do, that place is protected with multiple factors)

Post reply on HN