I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
81–90 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#82I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#83Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.
Ermahgerd why do you hate bidness and jawbs... ...will be the response by many Congresspersons. Nothing will happen on this until a number of public figures are doxxed to hell and back.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#84I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Matasano security is almost always hiring. Here's their post from this month: https://news.ycombinator.com/item?id=8980464
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#85Congress needs to stop pissing in the wind and make a federal law on breach disclosure. Self evidently companies won't universally do this on their own, and state specific law makes compliance more difficult and expensive.
How would such legislation ensure companies are able to detect such breaches in the first place? For every Target/PSN/Anthem/Uber how many companies aren't even aware they've been breached?
I mean, the average Congresscritter probably has no idea what the typical answer is to "how do you do a password reset?" other than "call daughter/son". They're not good at establishing competency. They are sorta half way decent at bringing out the hammer "disclose what you know within X days, or we're going to fine you... when we do find out when you knew it."
So that brings up the question how the legislation determines whether and exactly when the company knew they were breached. And I'd say they should learn from history which is not to be such dicks like they were with hackers in the 80's and 90's and instantly criminalize disproportionately. We were learning things as a result of all of that, and by repressing it, we learned a lot less. So with companies I'd say up front the disclosure needs to be civil in nature (fines), and if there's willful hiding of what they know, tampering of evidence, destruction of evidence in an attempt to claim they didn't know they were breached or how badly, then it becomes criminal and lay down the hammer. Ultimately though, the worst punishment is up to the states, since the corporate charter is granted by states, not the feds. Off hand I can't think of a case where a corporation was executed in this manner though (revoking it's charter or articles of incorporation).
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#86I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
I would always complain about being 2-5 years behind in terms of technology stacks when I lived in D.C., but we were always a lot more careful about deployment decisions and extremely serious about data security. That mentality is ingrained in me until today so I always think about security. Unfortunately; it's not in the minds of a lot of people.
I don't think these breaches are going to stop until something really serious happens or until there are some serious negative legal consequences for data breaches. Sadly, it's up to consumers to try and sort out which companies have the best practices and that's not always apparent.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#87I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#88Earlier quoted context omitted.
Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…
So what's your point here? Rather than hire a security guy/gal, we should all do... what?
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#89Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.
I have no experience in this area so could someone explain how Uber noticed there was a data breach ~4 months after it occurred.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#90Earlier quoted context omitted.
So what's your point here? Rather than hire a security guy/gal, we should all do... what?
We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.