Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

61–70 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#61
post #57

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop? And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one. Maybe you don't mean all that, but if I am to take what you p…

I didn't just say PII, I said "PII or credit card data or anything that, if leaked, would harm your business or your customers". If you're not prepared to securely handle PII, you shouldn't be collecting it. Talking about B&M, does Guitar Center or Great Clips really need my phone number? No, they don't. So I don't give it to them. They keep this data because they want it, not because they need it.

Insanely irrational? If you are comfortable handing your information to companies who do nothing more than the bare minimum to make sure it's safe, that's insanely irrational. I get tired of companies giving my information away. I really do. There's no excuse for it.

Security is by no means a solved problem, nor is it possible to solve at this point. But how often do you hear that the company wasn't hashing, wasn't encrypting, wasn't paying attention to their security tools? Damn near every time. Things like this very, very rarely happen to companies who take security seriously.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#62

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

You're right, "ruin" was poetic license on my part. I was either going all-in with the outrage or I was going to delete the post and move on. I chose the former.

But think about the Anthem breech just this year. SSNs, full name, date of birth, employer and yearly income, home address. Everything you need to ruin someone's life for real, and permanently. Having to have a credit card replaced is an inconvenience. Having to constantly watch your credit because everything an attacker needs to open a new credit card in your name is ruin.

Beyond that though, little inconveniences add up. How many times do you want to have to replace your credit card in a year? And if you have an auto-payment set up but miss changing your card number for that, how much will missing that payment impact your credit score? And how many hours are you spending fighting fraudulent charges? How many years of your life are taken off by the stress of constant breaches?

Life ruining? Probably not. Life-changing? Yeah, it's getting there.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#63

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I mostly agree, but the calculation is different for different businesses. The costs of engineering time and hiring a security professional may be much more expensive than the lost business due to breaches. In this particular case they likely have enough resources to have made it happen, but it remains to be seen whether this will actually cost them much if anything.

That was the case with Home Depot. They made the determination that the cost of implementing proper security would be more than the cost of cleaning up the breach.

However, this is just offloading the negative externalities onto the banks and the customers. That's just shitty. I'm not one to call for government regulation that easily, but this is exactly why we have a federal government. To make sure the citizens are being protected. That's why the FCC declared ISPs to be utilities. To stop them from abusing the customers. That's why the EPA has regulations on chemical and oil spills. If Home Depot got fined $100m for their breach, what would the cost look like then?

The cost of security is more than the impact of the lost business. That needs to be fixed, because until it is, we will continue to have breaches that make our lives terrible.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#64

Earlier quoted context omitted.

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

I think you're going to need to define what a ruined life is. I doubt getting a replacement credit card in the mail will ruin someone's life under most definitions.

One time I got an e-mail from Amex saying my account may have been compromised and to click a link. Fearing a phishing attempt I went direct to their website and logged in. A big red banner said to contact them ASAP. I called a number they gave. They asked if I ordered plane tickets for Turkey. I said no. They said ok, no worries, they auto-blocked the purchase. We went through my history to make sure everything else was correct, it was. The card was cancelled and they mailed a new one overnight. It was under 22 hours from e-mail to new card in hand. I was very impressed.

My sister has info stolen from a fake pad at a gas station. It was a debit card. She got all of her money back but it took close to 6 weeks to fully resolve. If you live paycheck to paycheck, and at the time she wasn't too far off, that can be a very difficult situation. It worked out in the end but it was definitely painful for her.

By and large these are not "ruined life" events. Identity theft and fraud are, unfortunately, common and mainstream enough that hitting "ruined life" level is exceptionally difficult. Back in the 90s when the average person didn't know those terms it might have been more common. But now it's just something that everyone, individuals and corporations, have to deal with.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#65
post #33

Earlier quoted context omitted.

Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…

I don't think it would require a quantum leap forward in tech to take traffic into account...

It's not just taking traffic into account, which it can (sort of) already do.

They need to actually use the accident data. Use a diverse set of routes to get to the same place, so that there isn't one path for every car on the road. Understand stoplight patterns and where it's hard or easy to make a turn. Not focus obsessively on shortest path rather than most tolerable path.

Fundamentally what a good cab driver (which are not that common) offers you is knowledge of the best route to a destination from experience. Google Maps doesn't have that. And if it did, and it controlled a significant portion of the cars, it would no longer be the best route.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#66

Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.

I'm not shocked. I recently found a vulnerability in software used by multiple companies in a specific industry - thousands of names, SSNs, addresses, etc open for the taking. I attempted to disclose to a local company that uses the software and never got a response.

I think often companies just don't respond the first time, or ever. What can you do?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#68

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

> It's not okay to have a breach. It's not. It doesn't matter how much money you saved... If only this were true, they would be hiring security people. Nothing is going to change until companies are held accountable for the damages caused by negligence. If someone in the infosec field wants to make a difference, I'd reckon their best bet is lobbying to make this happen.

We're hiring security engineers at Clever: https://clever.com/about/jobs#engineer-full-stack-security

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#69

Earlier quoted context omitted.

> It's not okay to have a breach. It's not. It doesn't matter how much money you saved... If only this were true, they would be hiring security people. Nothing is going to change until companies are held accountable for the damages caused by negligence. If someone in the infosec field wants to make a difference, I'd reckon their best bet is lobbying to make this happen.

We're hiring security engineers at Clever: https://clever.com/about/jobs#engineer-full-stack-security

That's good! You guys probably have tons of personal data from students who didn't choose to use your service anyway, but their school made that choice for them. Be careful with it!

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#70

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security" engineer(I know of a few areas where I'd like to shore up but they never come up on security audits, hmmm), this is often sufficient. Besides, don't you figure Target, Home Depo, EA, and Sony had dedicated security people?

Again, this is not arguing against security guys.. It's just this post reads a bit like "Well, if they were only hiring people like me maybe this wouldn't have happened".

Post reply on HN