Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

111–120 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#111
post #90
post #88

Earlier quoted context omitted.

We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

Your view doesn't account for the fact that in computer security, offense overwhelmingly beats defense. Target. Sony. Home Depot. Nordstrom. Those are the ones you hear about, but what's scary are the number of company and government breaches that aren't made public. The cost of a zero-day is in the low to mid six figures.[1] If you are a juicy enough target, you will get hacked.

Obviously, this doesn't mean one should disregard security concerns. It's important to engage in good practices, to cultivate a combination of paranoia and attention to detail, to scrutinize suspicious behavior. But even if you do all of these things, modern computer systems have tons of surface area outside of your control. These days, it's unrealistic to demand perfect security from anyone, let alone small businesses.

Instead of being so uncompromising, I think it's better to ask businesses to explain their security policies and practices. Are administrators required to use multi-factor auth? Are backups encrypted, and if so, how? How are passwords hashed? Is data encrypted in transmission, and if so, how? Are server logs shipped to prevent tampering? Answering these questions (and others like them) can give security-conscious customers an idea of the business's expertise, and allow people to use products (or not) accordingly.

1. http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#112
post #107

Earlier quoted context omitted.

Two card changes in quick succession led to my car insurance being cancelled when they couldn't take a payment. The first I knew of it was when the blue lights came on behind me. That is firmly into ruined life territory.

That is firmly into ruined life territory. Sounds more like "inconvenience" territory to me, but I hope you and your car are recovering well from this life altering experience.

No, in the UK being caught like this means a big fine, an long-term endorsement on your license and unpleasant side effects which include raised insurance premiums and not being able to get a hire car for several years afterwards. It IS actually a big deal. And it all has its roots in a bank card number changing unexpectedly.

And the point is, yes, consequences can be rather more damaging than having your Amazon Prime membership lapse.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#113
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

Using this train of thought, you probably don't even have a lock in your door - burglary is illegal!

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#114
This incident - amongst many others - only shows that most companies don't give a rat's ass about our data or privacy.

They are happy enough if their systems actually work and run. That's enough for them.

This incident won't cost Uber anything. It won't matter to them. A few appologies here and there and that will be the end of it.

Maybe, maybe there is some trivial fine to pay, but that will be a rounding error on their balance sheet.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#115

The TechCrunch article says "license plate numbers" but the Uber post[0] says "driver’s license number". [0] http://blog.uber.com/2-27-15

In Massachusetts the driver's license number used to be your social security number. This was changes but are there other states that have not done so?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#116
post #107

Earlier quoted context omitted.

That is firmly into ruined life territory. Sounds more like "inconvenience" territory to me, but I hope you and your car are recovering well from this life altering experience.

No, in the UK being caught like this means a big fine, an long-term endorsement on your license and unpleasant side effects which include raised insurance premiums and not being able to get a hire car for several years afterwards. It IS actually a big deal. And it all has its roots in a bank card number changing unexpectedly. And the point is, yes, consequences can be rather more damaging than having your Amazon Prim…

And they don't do as much as send you a letter first?

Seems hard to believe.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#117
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

[deleted]

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#118
post #116

Earlier quoted context omitted.

No, in the UK being caught like this means a big fine, an long-term endorsement on your license and unpleasant side effects which include raised insurance premiums and not being able to get a hire car for several years afterwards. It IS actually a big deal. And it all has its roots in a bank card number changing unexpectedly. And the point is, yes, consequences can be rather more damaging than having your Amazon Prim…

And they don't do as much as send you a letter first? Seems hard to believe.

Not having insurance is a strict liability offence, and there's now a database (of course) of who has paid up insurance.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#119

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

> It doesn't matter how much money you saved from not having a security guy or the tools they need.

It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user will just read "something something Uber something hacked" and next week will just have a vague sense Uber was mentioned in the news).

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#120
post #118
post #116

Earlier quoted context omitted.

And they don't do as much as send you a letter first? Seems hard to believe.

Not having insurance is a strict liability offence, and there's now a database (of course) of who has paid up insurance.

Not having insurance is a strict liability offence

It's the same in my country.

But if you're late on payments then a normal dunning process begins. Before your insurance turns invalid you have to ignore at least 3 letters over the course of 3 months.

In the UK they just flip the switch when a single payment fails, without prior warning?

Post reply on HN