Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

101–110 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#101
post #14

I accidentally stumbled upon employee admin screens, all by changing a key, isAdmin = true. https://news.ycombinator.com/item?id=9121004

How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.

How do you know that he got 8 points?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#102
post #90
post #88

Earlier quoted context omitted.

We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had enough of perfectionists like you keeping people from making stuff.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#103
post #98
post #96

Earlier quoted context omitted.

> Having to constantly watch your credit because everything an attacker needs to open a new credit card in your name is ruin. This leads to a ruined life? Talk about a first world problem

This leads to a ruined life? Talk about a first world problem Hey now, cancelled auto-payments are no joke. Just imagine you lose your Netflix subscription or (god beware) Amazon Prime over this.

Two card changes in quick succession led to my car insurance being cancelled when they couldn't take a payment. The first I knew of it was when the blue lights came on behind me. That is firmly into ruined life territory.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#104
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

That's not perfectionism. His comment is an emotional simplification of a complex problem without any consideration of side effects. This is just like being "tough on crime" rhetoric of some politicians.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#105
post #75
post #33

Earlier quoted context omitted.

Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…

> Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. I don't know about you, but my experience is that Google Maps is far more reliable than a cabbie who purports to know their way around.

My experience is the exact opposite in most cities in the UK - Google Maps regularly gets me going insanely stupid routes, while the cabbies always seem to know every street and the best way to get to it.

Perhaps the US has a different culture for its cab drivers? I can't imagine why, though. We have all the taxi licensing schemes and whatnot that the US does, so it can't be a case of "there's more competition so they're better". Perhaps it literally does just come down to culture?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#107
post #98

Earlier quoted context omitted.

This leads to a ruined life? Talk about a first world problem Hey now, cancelled auto-payments are no joke. Just imagine you lose your Netflix subscription or (god beware) Amazon Prime over this.

Two card changes in quick succession led to my car insurance being cancelled when they couldn't take a payment. The first I knew of it was when the blue lights came on behind me. That is firmly into ruined life territory.

That is firmly into ruined life territory.

Sounds more like "inconvenience" territory to me, but I hope you and your car are recovering well from this life altering experience.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#108
post #88
post #82

Earlier quoted context omitted.

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.

Agreed.

That said, any company collecting PII (or any type of data a customer believes is protected really) as part of their business has a duty of protecting that information.

Unfortunately, you can't trust joe sixpack to make safe and sound decisions as to whether they should sign up and give their contact/personal info to your new random app, let alone evaluate the level of your opsec practices.

Saying "we take the privacy of our customers very seriously" months after a breach and going back to business as usual is not enough, and I think this is true for both startups and big corporations.

One of the earlier comments said "Stop fucking ruining people's lives.", I think it pretty much sums it up even if it's probably a bit extreme. The first step is to stop considering security as an afterthought when you write any piece of code.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#109
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

And how about your users? I bet they don't mind their private information stolen, because they support your airbnb for dogs?

Will you give your little speech about laws and how it's illegal to hack your website and people shouldn't have done it?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#110

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

My understanding is that UberX is illegal in Thailand, but they've been doing it anyway as it's too difficult for police to enforce. If I was a Thai UberX driver, I might be thinking my life was significantly worse off...
Post reply on HN