Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

141–150 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#142
post #33

Earlier quoted context omitted.

> The lesson here is that sometimes, you do much better by breaking all the rules. I guess we'll find out after Uber has exhausted its VC money, if Google doesn't replace them with self-driving cars first.

Uber is already hamstrung by their inexperienced drivers's reliance on Google Maps for navigation. It is in no way equivalent to actually knowing your way around. The difficulty of making an urban self-driving car aside, Google would have to achieve a quantum leap forward in the quality of their navigation platform. Otherwise every auto-taxi in San Francisco will proceed single file down Van Ness, with turns onto Mar…

> inexperienced driver's reliance on Google Maps for navigation

When I lived in Sydney, I used to take the taxi often. And the rule was pretty much: If your address doesn't exist on Google Maps, they don't know how to get there. Even "At the corner of Hyde Park and Oxford St", which is in the CBD, returned a 404 from the driver's vocal API. They were all officially registered drivers, I just think cab's over reliance on Google Maps makes them unaware of the street names.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#144
post #111
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

Your view doesn't account for the fact that in computer security, offense overwhelmingly beats defense. Target. Sony. Home Depot. Nordstrom. Those are the ones you hear about, but what's scary are the number of company and government breaches that aren't made public. The cost of a zero-day is in the low to mid six figures.[1] If you are a juicy enough target, you will get hacked. Obviously, this doesn't mean one shou…

[deleted]

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#145
post #65

Earlier quoted context omitted.

It's not just taking traffic into account, which it can (sort of) already do. They need to actually use the accident data. Use a diverse set of routes to get to the same place, so that there isn't one path for every car on the road. Understand stoplight patterns and where it's hard or easy to make a turn. Not focus obsessively on shortest path rather than most tolerable path. Fundamentally what a good cab driver (whi…

You know that you're describing things that machines are inherently better at than humans? And the problems you described stem mostly from the fact that maps also serve informative function (to learn the route in advance), and apparently Google didn't decide yet to compute routes in their navapp based on other active users of said navapp in the neighbourhood. But the data, infrastructure and algorithms are there. > A…

Well then, I look forward to it happening any day now.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#146
post #136

Is this what a 40 billion dollar startup looks like?

You're officially a billion-dollar corporation, when you start being careless with people's private data. :)

Ok you got me there. :-)

I just think that this is a company with no product, no business model, horrendous business practices and somehow their valuation is still higher than the entire market they operate in. At least their not selling the data to the IRS, right?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#147
post #113

Earlier quoted context omitted.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

Using this train of thought, you probably don't even have a lock in your door - burglary is illegal!

[deleted]

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#148

Earlier quoted context omitted.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

And how about your users? I bet they don't mind their private information stolen, because they support your airbnb for dogs? Will you give your little speech about laws and how it's illegal to hack your website and people shouldn't have done it?

[deleted]

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#149

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Except no one cares, and there are no consequences whatsoever, so WHY BOTHER?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#150
post #82
post #70

Earlier quoted context omitted.

Just like they all need a dedicated network engineer, or a dedicated storage engineer, or a dedicated "whatever" engineer? Losing data is unacceptable too right? I'm not saying security people are not necessary, but there are a lot of not dedicated "whatevers" that can handle "whatever" sufficiently. Coupled with security audits, which in my experience leave a LOT to be desired speaking as a not dedicated "security"…

So what's your point here? Rather than hire a security guy/gal, we should all do... what?

>we should all do... what?

nothing, otherwise you put yourself at a disadvantage against other market players (at least in US).

US has no reasonable industry regulation, its more of a laughable industry written guidelines if anything. There are no consequences, no serious penalties for harming public. Whats more public itself is too clueless to care and incentivize proper behaviour. Only HUGE events are capable of changing (exxon valdez) perception and forcing real regulation.

Post reply on HN