Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

121–130 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#121

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

If you look at the actual impact to companies by breaches like this, it's almost the same impact that Google, Apple, and Microsoft faced after the PRISM leak - hardly perceptible to revenue. What does happen though obviously is a lot of opex expenditures to deal with it all, and that's where companies are getting squeezed oftentimes in the usual behemoth dysfunctional megacorp landscape.

I'm gung-ho about security as much as you but the truth is that users hardly stop using a service after data breaches. The ones that do matter though are like the ones that delete all your AWS instances and custom AMIs when holding your company's assets for ransom. That is what startups should be worried about indeed (as well as enterprises that are transitioning more of their IT into cloud environments that can be scripted and automated much easier - makes it easier for attackers in theory too).

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#122
> Uber says it will offer a free one-year membership of Experian’s ProtectMyID Alert

My ID has been breached twice in other, unrelated incidents. Each time these ID protection companies want to know my SS# and all sorts of other stuff. My heart skips a beat imagining them scraping the web for my SS# and CC# in an otherwise well intentioned effort. I've refused their services and insist they only provide the insurance policy associated with this.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#123
post #57

Earlier quoted context omitted.

I generally agree with the main thrust of your argument, but this seems way over the top. I don't know if every brick and mortar business in the world can afford to hire a dedicated security engineer. Should they all just close shop? And if we're going by Wikipedia's definition of PII, probably at least 50% of the websites in the world. Including this one. Maybe you don't mean all that, but if I am to take what you p…

Yes, and basic information security involves weighing the cost of security breaches vs the cost of implementing security measures.

True, but the calculations companies do don't include huge negative externalities they're causing, and this needs to be corrected.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#124

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

> It doesn't matter how much money you saved from not having a security guy or the tools they need. It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user…

> Unless you find a way to make companies financially responsible for crappy security

From a market perspective, would be enough if customers cared more about these breaches and take took business elsewhere. Apparently they don't care.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#125
I see a lot of comments about security, but would be happy to bet this was simple social engineering and "human hacking". It's sobering to see large-ish companies that give full read access (and sometimes write) of customer and financial data to interns, fresh grads and new contractors for expediency. Young people are cheap. $500 is a new computer or weeks of food to an indebted student.

Management usually doesn't care, revenue and convenience trump security; until of course something bad happens, which is why older institutions have draconian access standards, meetings to discuss who has the right to know about the meeting to determine the access list management program (true story) and so on.

Nothing in the press release hints at an actual attack. "An unauthorized third party accessed our database, and we immediately changed the password" sounds like they realized one of their competitors hired an intern to get them a login.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#126
post #13

Earlier quoted context omitted.

I'm not defending them on this because that does seem to be a long enough time to be more proactive about it. You did bring up an interesting point though, Uber is facing opposition from almost every city they are in. Whether it's small town South Carolina where I'm from and even in some of the largest cities in the world. It would be interesting to see how people deal with this on the inside and how it affects the c…

Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.

Well, if the only way you can make business is to break laws and be total assholes to everyone, then it kind of strongly suggests you shouldn't be in business in the first place.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#127
post #65

Earlier quoted context omitted.

I don't think it would require a quantum leap forward in tech to take traffic into account...

It's not just taking traffic into account, which it can (sort of) already do. They need to actually use the accident data. Use a diverse set of routes to get to the same place, so that there isn't one path for every car on the road. Understand stoplight patterns and where it's hard or easy to make a turn. Not focus obsessively on shortest path rather than most tolerable path. Fundamentally what a good cab driver (whi…

You know that you're describing things that machines are inherently better at than humans? And the problems you described stem mostly from the fact that maps also serve informative function (to learn the route in advance), and apparently Google didn't decide yet to compute routes in their navapp based on other active users of said navapp in the neighbourhood. But the data, infrastructure and algorithms are there.

> And if it did, and it controlled a significant portion of the cars, it would no longer be the best route.

Of course it would, because it would be able to run a global route optimization on all the cars simultaneously, thus outperforming even the most experienced human drivers by orders of magnitude. Getting above human level seems like a college-level exercise.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#128
post #124

Earlier quoted context omitted.

> It doesn't matter how much money you saved from not having a security guy or the tools they need. It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user…

> Unless you find a way to make companies financially responsible for crappy security From a market perspective, would be enough if customers cared more about these breaches and take took business elsewhere. Apparently they don't care.

> would be enough if customers cared more about these breaches and take took business elsewhere.

If only they were spherical humans of uniform density...

> Apparently they don't care.

Well, they do, but they can't do anything about it. See, it's a very known problem with real humans - from boycotting Coca Cola for slaughtering people in poor countries, to tantalum capacitor production being based on even worse slaughter of men, women and children in poor countries, to the whole environmental fuckup we enjoy today - "voting with your wallet" doesn't work. People can't coordinate on a large enough scale, so they have to stick with the bad choices. Why should I move my business elsewhere, if the risk is unlikely and my competitor here will save money over me if he stays? And my competitor thinks the same, and neither of us move.

It's the very case regulations exist for - it's much easier (and in reality, actually feasible) to coordinate people to ban all businesses from doing particular classes of shitty things.

But honestly, I thought that's kind of economics 101, that this is market failure mode when it is applied to real, flesh and blood humans.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#129

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

There are top security professionals in companies such as Google, Microsoft, and Facebook. At the end all of them suffer security issues.

The lesson: security is really hard in the real world, even for the best professionals.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#130

Earlier quoted context omitted.

"Stop fucking ruining people's lives" Serious, legit question here. How many lives will be ruined by this breach of 50k? How many lives were ruined when 40 million CCs and 70 million accounts (address, phone number , etc) were stolen in the Target breach? Ruin seems like an awfully strong word here. I hesitate to say that because I don't want to downplay the importance of security. But to take security seriously I th…

My understanding is that UberX is illegal in Thailand, but they've been doing it anyway as it's too difficult for police to enforce. If I was a Thai UberX driver, I might be thinking my life was significantly worse off...

UberX is apparently illegal in parts of Australia as well, and authorities have been using entrapment to identify drivers and fine them [1]. Having access to a database of drivers would make it easier for authorities to fine the drivers, apparently $1700 per offence.

[1] http://www.abc.net.au/7.30/content/2015/s4162393.htm

"NICK MARSDEN, DEPT. OF TRANSPORT AND MAIN ROADS (Aug. 28, 2014, male voiceover): "No covert activity was done today, Uber locked third phone due to penalty infringement notices being issued yesterday. Time was spent purchasing new credit cards, activating Gmail accounts and setting up two more phones. These phones are the last ones, will be ordering additional units.""

Post reply on HN