No info as to how this was exposed. Were they storing data as plain text?
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
41–50 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#42Listen, guys. I don't care how small you are. If you are handling PII or credit card data or anything that, if leaked, would harm your business or your customers, you need a security guy. Not a programmer who knows some security stuff. Not a manager who checks off the online PCI self-assessment. Not "we outsource to an MSSP". At least one security guy, full time. Make sure that everything you do is run past that person. If you're so busy that you can't run everything past that person, hire another.
It's not a joke. Stop fucking ruining people's lives. It's 2015, four years past "the year of the breach" [1]. Get with the program. It's not okay to have a breach. It's not. It doesn't matter how much money you saved from not having a security guy or the tools they need. Get someone who knows what they're talking about and listen to them.
[1] http://news.softpedia.com/news/IBM-2011-is-The-Year-of-the-S...
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#43Uber really needs to have a public data retention policy stating that they anonymize or delete all data older than a couple weeks. I'm just waiting for them to be hacked and have to reveal that people's trip data for years has been released.
Starting with the user story: "As a Pawn Shop Clerk, I scan a copy of the customer’s drivers’ license because the company is required by law to keep this record at least two years from the date we purchase a used valuable from a customer."
https://www.youtube.com/watch?v=dj196NhPyWs&t=26m00s
There was a good Q&A about data retention, that included a lawyer in the audience.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#44Earlier quoted context omitted.
Not just Uber. Obama's proposing data privacy regulations. I think it's worth considering what you'd like to see involved in same.
Meanwhile, Australia is about to legislate mandatory data retention :( https://stopthespies.org/
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#45I'd be keen to see if every driver's info aligns with the license number (for those states that use encoding systems that embed PII into the number).
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#46Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#47I accidentally stumbled upon employee admin screens, all by changing a key, isAdmin = true. https://news.ycombinator.com/item?id=9121004
That is by definition not accidental.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#48No info as to how this was exposed. Were they storing data as plain text?
probably, yes. storing data in plain text is common practice and not really a problem.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#49I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#50I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
The costs of engineering time and hiring a security professional may be much more expensive than the lost business due to breaches.
In this particular case they likely have enough resources to have made it happen, but it remains to be seen whether this will actually cost them much if anything.