Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

81–90 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#81

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Matasano security is almost always hiring. Here's their post from this month: https://news.ycombinator.com/item?id=8980464

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#82
post #70

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#83
post #11

Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.

Ermahgerd why do you hate bidness and jawbs... ...will be the response by many Congresspersons. Nothing will happen on this until a number of public figures are doxxed to hell and back.

Companies are asking Congress to do this because already states are doing it, and it's totally haphazard. If Congresscritters were to get doxxed maybe it'd go faster.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#84

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Matasano security is almost always hiring. Here's their post from this month: https://news.ycombinator.com/item?id=8980464

My POV is kind of limited, but I believe there's a strong argument to be made that security consulting is not an adequate substitute for in-house security. The largest problem that comes to mind is that hiring consultants can lead executives to think they've outsourced security and can not worry about it.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#85
post #11

Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.

How would such legislation ensure companies are able to detect such breaches in the first place? For every Target/PSN/Anthem/Uber how many companies aren't even aware they've been breached?

Withholding knowledge of a breach is self-rewarding which is why there needs to be a law stating the time frame for disclosure, and either penalties or liablity (per affected customer, employee, contractor, vendor). Lack of skill in detection is a problem, but I don't know whether Congress is well equipped to legislate that, and also companies aren't exactly incentivized to just let themselves get completely owned. They're just ignorant. There's no question this behavior is changing, even if we're dissatisfied with how slow it's happening.

I mean, the average Congresscritter probably has no idea what the typical answer is to "how do you do a password reset?" other than "call daughter/son". They're not good at establishing competency. They are sorta half way decent at bringing out the hammer "disclose what you know within X days, or we're going to fine you... when we do find out when you knew it."

So that brings up the question how the legislation determines whether and exactly when the company knew they were breached. And I'd say they should learn from history which is not to be such dicks like they were with hackers in the 80's and 90's and instantly criminalize disproportionately. We were learning things as a result of all of that, and by repressing it, we learned a lot less. So with companies I'd say up front the disclosure needs to be civil in nature (fines), and if there's willful hiding of what they know, tampering of evidence, destruction of evidence in an attempt to claim they didn't know they were breached or how badly, then it becomes criminal and lay down the hammer. Ultimately though, the worst punishment is up to the states, since the corporate charter is granted by states, not the feds. Off hand I can't think of a case where a corporation was executed in this manner though (revoking it's charter or articles of incorporation).

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#86

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I totally agree. I used to work in Info-sec back in D.C. before I moved out to San Francisco and I would always joke with my D.C. buddies that San Francisco cares about product first, security later. Most people in SF are so wrapped up around which framework is the coolest hottest thing and have no idea about anything related to security until it's too late.

I would always complain about being 2-5 years behind in terms of technology stacks when I lived in D.C., but we were always a lot more careful about deployment decisions and extremely serious about data security. That mentality is ingrained in me until today so I always think about security. Unfortunately; it's not in the minds of a lot of people.

I don't think these breaches are going to stop until something really serious happens or until there are some serious negative legal consequences for data breaches. Sadly, it's up to consumers to try and sort out which companies have the best practices and that's not always apparent.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#87

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

This is anti-competitive, and regressive, it helps the big guns. Imagine big companies shutting down small ones because they don't have dedicated security staff. We need companies with working security to outsource this service, for example for storing records.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#88
post #82
post #70

Earlier quoted context omitted.

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#89
post #78

Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.

I have no experience in this area so could someone explain how Uber noticed there was a data breach ~4 months after it occurred.

I don't know what happened here, but presumably they keep fairly detailed request logs. If they were notified of a security vulnerability like this, they would probably sweep logs for suspicious requests. This way they would become aware of all breaches using that vulnerability, but not until they found the vulnerability, which could be any amount of time after the breaches occurred.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#90
post #88
post #82

Earlier quoted context omitted.

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
Post reply on HN