I find it unlikely they have a database explicitly for driver names/license plates. Unless it was some flat-file dump compromised. I'm curious how much data was really obtained. If only 50k were truly stolen, it could be a shard too. The lack of technical details is sketchy to me
Maybe they have query logging turned on and saw what queries the attacker ran?
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
31–40 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#32Earlier quoted context omitted.
I'm not defending them on this because that does seem to be a long enough time to be more proactive about it. You did bring up an interesting point though, Uber is facing opposition from almost every city they are in. Whether it's small town South Carolina where I'm from and even in some of the largest cities in the world. It would be interesting to see how people deal with this on the inside and how it affects the c…
Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.
I guess we'll find out after Uber has exhausted its VC money, if Google doesn't replace them with self-driving cars first.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#33Earlier quoted context omitted.
Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.
> The lesson here is that sometimes, you do much better by breaking all the rules. I guess we'll find out after Uber has exhausted its VC money, if Google doesn't replace them with self-driving cars first.
The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Market or Mission only. All other streets will be empty and filled with pigeons.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#34The free one-year membership of Experian’s® ProtectMyID® Alert is genius, its giving away something that costs them nothing (presumably Experian are using this as a marketing opportunity) as if it's a real step in the right direction to make up for the data leak.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#35Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#36Earlier quoted context omitted.
> The lesson here is that sometimes, you do much better by breaking all the rules. I guess we'll find out after Uber has exhausted its VC money, if Google doesn't replace them with self-driving cars first.
Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#37Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#38Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#39Last year Uber was using Backbone and the JSON returned to the client included ALL information about the drivers you have used for trips including home address, phone number, etc. I wonder if this has something to do with that?
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#40Earlier quoted context omitted.
Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.
Information leakage is absolutely a security issue.