I accidentally stumbled upon employee admin screens, all by changing a key, isAdmin = true. https://news.ycombinator.com/item?id=9121004
How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
101–110 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#102Earlier quoted context omitted.
We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.
This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#103Earlier quoted context omitted.
> Having to constantly watch your credit because everything an attacker needs to open a new credit card in your name is ruin. This leads to a ruined life? Talk about a first world problem
This leads to a ruined life? Talk about a first world problem Hey now, cancelled auto-payments are no joke. Just imagine you lose your Netflix subscription or (god beware) Amazon Prime over this.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#104Earlier quoted context omitted.
This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#105Earlier quoted context omitted.
Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…
> Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. I don't know about you, but my experience is that Google Maps is far more reliable than a cabbie who purports to know their way around.
Perhaps the US has a different culture for its cab drivers? I can't imagine why, though. We have all the taxi licensing schemes and whatnot that the US does, so it can't be a case of "there's more competition so they're better". Perhaps it literally does just come down to culture?
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#106Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#107Earlier quoted context omitted.
This leads to a ruined life? Talk about a first world problem Hey now, cancelled auto-payments are no joke. Just imagine you lose your Netflix subscription or (god beware) Amazon Prime over this.
Two card changes in quick succession led to my car insurance being cancelled when they couldn't take a payment. The first I knew of it was when the blue lights came on behind me. That is firmly into ruined life territory.
Sounds more like "inconvenience" territory to me, but I hope you and your car are recovering well from this life altering experience.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#108Earlier quoted context omitted.
So what's your point here? Rather than hire a security guy/gal, we should all do... what?
We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.
That said, any company collecting PII (or any type of data a customer believes is protected really) as part of their business has a duty of protecting that information.
Unfortunately, you can't trust joe sixpack to make safe and sound decisions as to whether they should sign up and give their contact/personal info to your new random app, let alone evaluate the level of your opsec practices.
Saying "we take the privacy of our customers very seriously" months after a breach and going back to business as usual is not enough, and I think this is true for both startups and big corporations.
One of the earlier comments said "Stop fucking ruining people's lives.", I think it pretty much sums it up even if it's probably a bit extreme. The first step is to stop considering security as an afterthought when you write any piece of code.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#109Earlier quoted context omitted.
This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…
Will you give your little speech about laws and how it's illegal to hack your website and people shouldn't have done it?
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#110I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…