Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

21–30 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#21
post #14

Earlier quoted context omitted.

How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.

Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.

This is a good point, but there should be more awareness towards the issue as a whole. I've seen many apps who expose data dangerously. Some developers may not be aware that these values are exposed (even with SSL), so they should architect their apps accordingly, reinforcing the fact that you should never trust the client. I also briefly touch on the fact about this dynamic architecture and some of the implications it brings.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#23
post #14

Earlier quoted context omitted.

How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.

Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.

Information leakage is absolutely a security issue.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#24

Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.

It sounds like they realized the API was improperly exposed on 9/17/2014, but didn't necessary know if it had ever been accessed by an unauthorized request.

I could see it taking a while to find one bad request in the entire history of the API's lifespan -- presuming that they had to find the logs, weed out false positives, different sites and versions that behaved differently, etc.

That still doesn't explain a 5 month gap. The only (charitable) explanation that makes sense to me is that they discovered the API was exposed, thought they had proven it was never improperly accessed, and then only much later realized that it had been after all.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#25
The free one-year membership of Experian’s® ProtectMyID® Alert is genius, its giving away something that costs them nothing (presumably Experian are using this as a marketing opportunity) as if it's a real step in the right direction to make up for the data leak.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#26

Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.

As eddieZone mentions in a post [currently] below this [0], Uber says names and driver's license numbers, which is a good deal worse [1].

[0] https://news.ycombinator.com/item?id=9122369 [1] http://blog.uber.com/2-27-15

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#27

Uber really needs to have a public data retention policy stating that they anonymize or delete all data older than a couple weeks. I'm just waiting for them to be hacked and have to reveal that people's trip data for years has been released.

Not just Uber. Obama's proposing data privacy regulations. I think it's worth considering what you'd like to see involved in same.

Meanwhile, Australia is about to legislate mandatory data retention :( https://stopthespies.org/

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#30
post #29

Between this breach, and the impending classification as a cab company by more and more major cities. I think that we can consider Uber to be either the walking dead or something very close to it at this point.

I think it's a bit premature to count Uber out. They have an absurd amount of money in the bank, and they take on a very small amount of the risk of their business. I don't think that this data breach will have the slightest impact to their bottom line.

If they get classified as a cab company in a particular market, they'll sue. If they don't get their way, they'll exit the market. They could also move into other businesses which are clearly not cabs, as shown by their dabblings in courier and delivery services. Consider how many startups are paying people to drive things from point A to point B -- that entire industry could be outsourced to Uber.

If they do exit a market, they won't lose anything besides face -- it's the drivers who will carry all of the capital investment and most of the operating costs, they're the ones who will be hurt.

Post reply on HN