Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

51–60 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#51
post #11

Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.

Ermahgerd why do you hate bidness and jawbs...

...will be the response by many Congresspersons. Nothing will happen on this until a number of public figures are doxxed to hell and back.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#52

Earlier quoted context omitted.

Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.

This is a good point, but there should be more awareness towards the issue as a whole. I've seen many apps who expose data dangerously. Some developers may not be aware that these values are exposed (even with SSL), so they should architect their apps accordingly, reinforcing the fact that you should never trust the client. I also briefly touch on the fact about this dynamic architecture and some of the implications…

You mean throwing up a Meteor app with a direct db feed and no fine grained security at the server side can lead to exploits?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#54

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

> It's not okay to have a breach. It's not. It doesn't matter how much money you saved...

If only this were true, they would be hiring security people.

Nothing is going to change until companies are held accountable for the damages caused by negligence. If someone in the infosec field wants to make a difference, I'd reckon their best bet is lobbying to make this happen.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#55

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

"Stop fucking ruining people's lives"

Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach?

Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I think we also have to be non-hyperbolic about the consequences of not doing so.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#56
post #7

I find it unlikely they have a database explicitly for driver names/license plates. Unless it was some flat-file dump compromised. I'm curious how much data was really obtained. If only 50k were truly stolen, it could be a shard too. The lack of technical details is sketchy to me

Why wouldn't they? I imagine there's some driver signup form that saves to some database table on their site.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#57

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop?

And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one.

Maybe you don't mean all that, but if I am to take what you posted at face value, it seems insanely irrational.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#58
post #7

I find it unlikely they have a database explicitly for driver names/license plates. Unless it was some flat-file dump compromised. I'm curious how much data was really obtained. If only 50k were truly stolen, it could be a shard too. The lack of technical details is sketchy to me

I also find it unlikely it's just the name and license number. They used to return all of a driver's information (name, phone, address, drivers license, license plate, etc) from the rest endpoint they were using on their website. They closed that hole it after it we disclosed it to them.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#59

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

I think you're going to need to define what a ruined life is. I doubt getting a replacement credit card in the mail will ruin someone's life under most definitions.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#60
post #57

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop? And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one. Maybe you don't mean all that, but if I am to take what you p…

Yes, and basic information security involves weighing the cost of security breaches vs the cost of implementing security measures.
Post reply on HN