Live data from Hacker News

Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

techcrunch.com

161–167 of 167 posts

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#161

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

I completely agree with you, but sadly, this kind of thing will never happen until there is a strong incentive for those companies to hire dedicated security people. Right now it's standard for companies to apologize and give people a year of credit monitoring.

It's become such a common issue there is no incentive to invest in security and that's a bad thing.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#162
post #124

Earlier quoted context omitted.

> It doesn't matter how much money you saved from not having a security guy or the tools they need. It's the only thing that matters. It's capitalism. Those who waste money on unneccessary expenses get outcompeted by those who don't. Unless you find a way to make companies financially responsible for crappy security, they won't care. Right now breaches like these seem to be more like free advertising (a typical user…

> Unless you find a way to make companies financially responsible for crappy security From a market perspective, would be enough if customers cared more about these breaches and take took business elsewhere. Apparently they don't care.

How do you take that argument when huge corporations like Target have been compromised too?

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#163

I work in info sec, and in one of the "Who's Hiring" posts a few months ago (do we still do those? I haven't seen one in a while) I asked "why are startups never hiring security guys?", because I never see a security engineer position open in those topics. I never got a response. To me that indicates the response is "we don't". Listen, guys. I don't care how small you are. If you are handling PII or credit card data…

Matasano security is almost always hiring. Here's their post from this month: https://news.ycombinator.com/item?id=8980464

Matasano (now NCC Group) is always hiring. :)

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#164
post #84

Earlier quoted context omitted.

Matasano security is almost always hiring. Here's their post from this month: https://news.ycombinator.com/item?id=8980464

My POV is kind of limited, but I believe there's a strong argument to be made that security consulting is not an adequate substitute for in-house security. The largest problem that comes to mind is that hiring consultants can lead executives to think they've outsourced security and can not worry about it.

It's good practice to do both.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#165
post #80

Under California law, data breach notifications "shall be made in the most expedient time possible and without unreasonable delay". Civil Code § 1798.82(a): http://leginfo.legislature.ca.gov/faces/codes_displaySection... I find it hard to square that requirement with Uber waiting 5 months from when it found out.

That is a bunch of lawyer words that they can stretch to mean anything. What we need are hard deadlines, say two days after the breakin. Not enough to full find out what happens, but enough to force the companies to act.

It's soft language, but I don't think they can stretch it to mean "anything." 5 months is just way too long.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#166

As much as Uber messed up here and there was a security breach, comparable information is publicly available. For example, the TLC in NYC provides this: http://www.nyc.gov/html/tlc/downloads/excel/current_medallio... This is a spreadsheet containing all the taxi drivers in NYC with their names, license numbers, and license expiration dates. Given that the only information leaked (according to Uber) were names and lic…

Those are medallion numbers or TLC license numbers, but not drivers license numbers. They can't be used for identity theft.

Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms

#167
post #90

Earlier quoted context omitted.

This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.

No, with all due respect, you're bullshit. Hacking my app is illegal. You're saying I shouldn't write a web app in the first place, just because I'm some guy and barely know the framework I'm using. Well, maybe you should go live in Somalia if you don't like a code of laws. I can't do security right. I can do a web app poorly, or nothing at all. You're saying, give the world nothing. I'm saying, sod off. I've had eno…

Yeah, and fuck food safety regulations, because I'm just some schmuck who wants to operate a restaurant but can't be bothered to learn about how to do it properly so everybody who doesn't want to be poisoned shouldn't be such a bitch who'd prefer a steak without a side of e coli, right? And let's abolish drivers licenses too while we're at at, because anyone who wants to have a bare minimum of driving skill from other road users should just go live in Somalia, right?

Well actually, if you think it's OK to expose your user's data because you don't know what you're doing but think you deserve a piece of the startup gold rush pie anyway, it's you who should go live in Somalia and see what becomes of a 'society' of people who just do something with no oversight, skill of knowledge. If the choice is between 'doing it poorly' and 'nothing at all', then you should do 'nothing at all' because your actions affect other people. Basically you say 'screw my users, I can't be bothered to learn things properly but I want money anyway!'. Well, fuck you, you are the cause of all these problems, and you deserve everything that comes to you.

Post reply on HN