Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

71–80 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#71
post #13

Earlier quoted context omitted.

I'm not defending them on this because that does seem to be a long enough time to be more proactive about it. You did bring up an interesting point though, Uber is facing opposition from almost every city they are in. Whether it's small town South Carolina where I'm from and even in some of the largest cities in the world. It would be interesting to see how people deal with this on the inside and how it affects the c…

Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.

> every time they play nice it doesn't go well for them.

When have they ever tried playing nice?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#72

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Anthem had security guys.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#73

Earlier quoted context omitted.

> It's not okay to have a breach. It's not. It doesn't matter how much money you saved... If only this were true, they would be hiring security people. Nothing is going to change until companies are held accountable for the damages caused by negligence. If someone in the infosec field wants to make a difference, I'd reckon their best bet is lobbying to make this happen.

We're hiring security engineers at Clever: https://clever.com/about/jobs#engineer-full-stack-security

I think it's safe to say "thank you" on behalf of the students and teachers who won't ever know that you went the extra mile.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#74
post #13

Earlier quoted context omitted.

Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.

> every time they play nice it doesn't go well for them. When have they ever tried playing nice?

I believe they've tried that in Portland and a few other cities. It hasn't gone particularly well for them. Also, there are cautionary tales like Night School, where the industry being disrupted gets the new entrant shut down.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#75
post #33

Earlier quoted context omitted.

> The lesson here is that sometimes, you do much better by breaking all the rules. I guess we'll find out after Uber has exhausted its VC money, if Google doesn't replace them with self-driving cars first.

Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…

> Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around.

I don't know about you, but my experience is that Google Maps is far more reliable than a cabbie who purports to know their way around.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#77

Earlier quoted context omitted.

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

I think you're going to need to define what a ruined life is. I doubt getting a replacement credit card in the mail will ruin someone's life under most definitions.

It can be logistically inconvenient when traveling internationally, a few thousand miles and a few days of shipment delay away from your bank.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#78

Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.

I have no experience in this area so could someone explain how Uber noticed there was a data breach ~4 months after it occurred.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#79
post #11

Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.

How would such legislation ensure companies are able to detect such breaches in the first place? For every Target/PSN/Anthem/Uber how many companies aren't even aware they've been breached?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#80
Under California law, data breach notifications "shall be made in the most expedient time possible and without unreasonable delay".

Civil Code § 1798.82(a): http://leginfo.legislature.ca.gov/faces/codes_displaySection...

I find it hard to square that requirement with Uber waiting 5 months from when it found out.

Post reply on HN