Live data from Hacker News

Uber hauls GitHub into court to find who hacked database of 50,000 drivers

theregister.co.uk

11–20 of 47 posts

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#12
post #2

Uber publishes secret key. Uber ignores security breach for half a year. Uber sues third party while trying to repair damage caused by their own failings. At this point the identity of the hacker is irrelevant. The data is in the wild, Uber is exposed as incompetent (again). But hey, anyone want to invest another billion at a 40 billion valuation? This company is going places.

To be clear, GitHub is not being sued. GitHub is being served a subpoena. Big difference.

The third party being sued is the (as yet unidentified) person who used the key to obtain & leak the data.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#13
post #12
post #2

Uber publishes secret key. Uber ignores security breach for half a year. Uber sues third party while trying to repair damage caused by their own failings. At this point the identity of the hacker is irrelevant. The data is in the wild, Uber is exposed as incompetent (again). But hey, anyone want to invest another billion at a 40 billion valuation? This company is going places.

To be clear, GitHub is not being sued. GitHub is being served a subpoena. Big difference. The third party being sued is the (as yet unidentified) person who used the key to obtain & leak the data.

I for one am just glad to see that GitHub refused to turn the data over without a subpoena.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#14
post #2

Uber publishes secret key. Uber ignores security breach for half a year. Uber sues third party while trying to repair damage caused by their own failings. At this point the identity of the hacker is irrelevant. The data is in the wild, Uber is exposed as incompetent (again). But hey, anyone want to invest another billion at a 40 billion valuation? This company is going places.

At this point the identity of the hacker is irrelevant No. Even if I leave my door unlocked, someone who comes in and steals my stereo should still be punished.

[deleted]

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#15

So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/

So how is the IP address of someone that has viewed or crawled said secret Gist relevant anyways? Someone crawling a website is not probable cause (even if there is a single IP address which can be traced to specific machine, which is highly unlikely).

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#16
Nitpick: the title implies that Uber is suing Github, but that's not the case. Uber has a civil suit pending in N.D. Cal., and has issued Uber a third-party subpoena: http://regmedia.co.uk/2015/02/28/ubergithubexhibit.pdf. Such subpoenas are used when a third party might have information relevant to a pending lawsuit. They do not imply any allegations of wrongdoing against the third party.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#17

So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/

How do we know it was a gist published by Uber, and not a third party?

I couldn't find that information in the article or the subpoena.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#18
post #2

Uber publishes secret key. Uber ignores security breach for half a year. Uber sues third party while trying to repair damage caused by their own failings. At this point the identity of the hacker is irrelevant. The data is in the wild, Uber is exposed as incompetent (again). But hey, anyone want to invest another billion at a 40 billion valuation? This company is going places.

At this point the identity of the hacker is irrelevant No. Even if I leave my door unlocked, someone who comes in and steals my stereo should still be punished.

This is different than someone stealing a stereo. This is you tape the security code for your front door onto the door and then your mad at the manufacturer of the door's lock. You want the manufacturer to give any information about the person who broke into your house.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#19

So let me get this straight - They're publishing a secret key on a Gist, and then getting whiny when it somehow gets leaked. Github very clearly states that "secret" gists are NOT private: https://help.github.com/articles/about-gists/

> and then getting whiny when it somehow gets leaked

How did you come away with that? They're trying to subpoena GitHub to gather information on who may have been responsible for the hack.

Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers

#20
post #2

Uber publishes secret key. Uber ignores security breach for half a year. Uber sues third party while trying to repair damage caused by their own failings. At this point the identity of the hacker is irrelevant. The data is in the wild, Uber is exposed as incompetent (again). But hey, anyone want to invest another billion at a 40 billion valuation? This company is going places.

At this point the identity of the hacker is irrelevant No. Even if I leave my door unlocked, someone who comes in and steals my stereo should still be punished.

The victim here is not Uber, but the Uber drivers whose data was lost. Uber is partly guilty here, because of their negligence.

Your analogy is wrong. It's more like asking someone to protect the key of your locked door. And they make copies and leave them in random places with the address attached.

Post reply on HN