Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

91–100 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#91

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

> It's not okay to have a breach. It's not. It doesn't matter how much money you saved... If only this were true, they would be hiring security people. Nothing is going to change until companies are held accountable for the damages caused by negligence. If someone in the infosec field wants to make a difference, I'd reckon their best bet is lobbying to make this happen.

From first hand experience I can tell you that Uber was recruiting to start their information security program at least 18 months ago and when I spoke to their software engineers and SREs they had a decent understanding of modern security issues.

In the 18 months since I assume they have assembled a decent security team and while most likely Uber dropped the ball here at least they recognized the need for security before they got burnt.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#93
post #82
post #70

Earlier quoted context omitted.

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

Only you can prevent forest fires. The aggregate knowledge and concern for security needs to increase. A lot of these security auditors(but not all!) are just running automated tools and generating automated reports. They don't understand your environment like you do. Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security). I was lucky enough to work with/for somebody that was very security concious and involved in the security scene... It changes your thinking. This thinking while staying pragmatic is the key IMHO. Just like the mantra "everyone is responsible for quality" I believe everyone should be responsible for security. If this isn't specific enough well.. Consider some of the hacks mentioned before. It is at the same time completely obvious to some people what went wrong in hindsight, but obviously not apparent to the implementers that it could go wrong at the time. A cultural shift in thinking and better education in security is the way forward IMHO.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#94
post #82
post #70

Earlier quoted context omitted.

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

"You can’t just hire a couple security engineers to shoulder this burden. You wouldn’t hire anyone to just “go deal with that scale issue” you have either."

https://medium.com/@magoo/starting-up-security-87839ab21bae

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#95
post #57

Earlier quoted context omitted.

I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop? And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one. Maybe you don't mean all that, but if I am to take what you p…

I didn't just say PII, I said "PII or credit card data or anything that, if leaked, would harm your business or your customers". If you're not prepared to securely handle PII, you shouldn't be collecting it. Talking about B&M, does Guitar Center or Great Clips really need my phone number? No, they don't. So I don't give it to them. They keep this data because they want it, not because they need it. Insanely irrationa…

You keep bringing up huge examples. Millions of credit cards leaked. Guitar center, a company that has 260 locations across the United States. Great clips has over 3,000 locations. Anthem, a company with multiple billions of dollars in revenue that handles extremely sensitive information for millions of people.

I remember as a kid, there was a family owned comic book shop I would visit. I would let them know what comics I'm interested in, and they would call me if they got something in that they thought I would be interested in. So they had good reason to have our phone number. It was probably even stored really insecurely (on a piece of paper). But it was the early 90's. And if someone stole it it might have included 200 phone numbers.

I buy magic the gathering cards from small card shops across the country. They need my address to ship it. Since most of these single store businesses are fairly low tech, I doubt they do too much to protect it.

Also, your initial statement also said handle, not collect. Most brick and mortar stores handle credit card data, although they don't collect it. There's even been instances of thieves affixing devices to ATMs and credit card machines that will scan your card data as you slide or insert it.

You can collect PII by hosting a static webpage (ip addresses). Leaking that PII can cause harm to users (DDOS). This may seem made up but people who make a living off live streaming are fairly regularly DDOS'd by malicious viewers who figure out their IP.

More generally, any leak of data, whether it includes PII or not, will harm a company's reputation.

This is why I called your post insanely irrational. It's all black and white: hire a dedicated security engineer, or you're doing it wrong. Regardless of size. The majority of businesses in the country would go out of business if they had to abide by your rules.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#96

Earlier quoted context omitted.

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

You're right, "ruin" was poetic license on my part. I was either going all-in with the outrage or I was going to delete the post and move on. I chose the former. But think about the Anthem breech just this year. SSNs, full name, date of birth, employer and yearly income, home address. Everything you need to ruin someone's life for real, and permanently. Having to have a credit card replaced is an inconvenience. Havin…

> Having to constantly watch your credit because everything an attacker needs to open a new credit card in your name is ruin.

This leads to a ruined life? Talk about a first world problem

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#98
post #96

Earlier quoted context omitted.

You're right, "ruin" was poetic license on my part. I was either going all-in with the outrage or I was going to delete the post and move on. I chose the former. But think about the Anthem breech just this year. SSNs, full name, date of birth, employer and yearly income, home address. Everything you need to ruin someone's life for real, and permanently. Having to have a credit card replaced is an inconvenience. Havin…

> Having to constantly watch your credit because everything an attacker needs to open a new credit card in your name is ruin. This leads to a ruined life? Talk about a first world problem

This leads to a ruined life? Talk about a first world problem

Hey now, cancelled auto-payments are no joke. Just imagine you lose your Netflix subscription or (god beware) Amazon Prime over this.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#99
post #93
post #82

Earlier quoted context omitted.

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

Only you can prevent forest fires. The aggregate knowledge and concern for security needs to increase. A lot of these security auditors(but not all!) are just running automated tools and generating automated reports. They don't understand your environment like you do. Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security). I was l…

A lot of these security auditors(but not all!) are just running automated tools and generating automated reports.

Woah... A professional security auditor actually knows what to look for and would be flexible enough to understand (and manipulate) what your software is doing. If you are paying someone to run a script, you're not getting your money's worth.

Even a dedicated security guy at a large company can't be everywhere and doesn't know everything(or even understand, say, hypervisor security).

True, that's why ideally you'd want a team of people on this, not just one security guy to carry the globe.

I agree though, security needs to be thought out from the beginning and throughout the development process. The later you catch something, the harder it is to fix. But you need a fair amount of experience as a developer to see security issues thoroughly (because you often need to understand the platforms you are building on, not just your domain). So if you don't have that knowledge you can either teach yourself or if you don't have the time, let someone else do it.

Having a thorough understanding of what you are actually doing does take care of most of that. I doubt that's where a startup's priorities are, sadly. For most, speed > solid code

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#100
post #14

Earlier quoted context omitted.

How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.

Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.

[deleted]
Post reply on HN