Under California law, data breach notifications "shall be made in the most expedient time possible and without unreasonable delay". Civil Code § 1798.82(a): http://leginfo.legislature.ca.gov/faces/codes_displaySection... I find it hard to square that requirement with Uber waiting 5 months from when it found out.
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
131–140 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#132Earlier quoted context omitted.
> It doesn't matter how much money you saved from not having a security guy or the tools they need. It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user…
> Unless you find a way to make companies financially responsible for crappy security From a market perspective, would be enough if customers cared more about these breaches and take took business elsewhere. Apparently they don't care.
It isn't surprising that they deprioritize security -- the market doesn't demand it.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#133I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
Target paid $1.2 BILLION in dividends on $21.8 BILLION sales for 2014, its data breach only cost it $162 Million. Cost of doing business.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#134Earlier quoted context omitted.
Uber's in a position where they get flak for breaking the rules while also being painfully aware that following the rules is worse for them. They face opposition, but every time they play nice it doesn't go well for them. The lesson here is that sometimes, you do much better by breaking all the rules.
Well, if the only way you can make business is to break laws and be total assholes to everyone, then it kind of strongly suggests you shouldn't be in business in the first place.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#135Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#136Is this what a 40 billion dollar startup looks like?
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#137http://www.nyc.gov/html/tlc/downloads/excel/current_medallio...
This is a spreadsheet containing all the taxi drivers in NYC with their names, license numbers, and license expiration dates. Given that the only information leaked (according to Uber) were names and license numbers, that really isn't much beyond what might otherwise be available publicly.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#138Earlier quoted context omitted.
> Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. I don't know about you, but my experience is that Google Maps is far more reliable than a cabbie who purports to know their way around.
My experience is the exact opposite in most cities in the UK - Google Maps regularly gets me going insanely stupid routes, while the cabbies always seem to know every street and the best way to get to it. Perhaps the US has a different culture for its cab drivers? I can't imagine why, though. We have all the taxi licensing schemes and whatnot that the US does, so it can't be a case of "there's more competition so the…
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#139I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…
This problem might just be a little more complex than we are giving credit for..
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#140Earlier quoted context omitted.
So what's your point here? Rather than hire a security guy/gal, we should all do... what?
"You can’t just hire a couple security engineers to shoulder this burden. You wouldn’t hire anyone to just “go deal with that scale issue” you have either." https://medium.com/@magoo/starting-up-security-87839ab21bae