Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

101–110 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#101
post #44

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

The ones that care about the security of their code base host it internally anyway.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#102

"Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company." S…

81% of all breaches now originate from compromised credentials mainly acquired from 3rd party data breaches or data leaks. Most organizations believe that 2FA and SSO are the answer but this proves that 2FA/SSO are not enough.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#103
post #75

Earlier quoted context omitted.

I disagree. One needs to be consistent in their actions, otherwise, what's the point? Two wrongs don't make a right, after all. EDIT: Er, I agree that hypocrisy shouldn't stop you from doing the right thing.

It’s just not possible to be perfectly consistent in all your actions, we’re all hypocrites somewhere if you consider all down to the root. We probably all hate forced child labor, yet we all own smartphones, all of them most likely built with resources mined by children under grueling conditions. (This text Is typed on one) Still, don’t let that stop from doing the right thing once in a while. If we all did the righ…

> We probably all hate forced child labor

A false premise. If that were true, just like you stated, we wouldn't support it. Actions speak louder than words, and all that.

EDIT: I realize I sound far more judge-y than intended in these posts. My overall point is that people should just do whatever makes 'em happy while doing the best you can (w.r.t. everything else). Trying to emphasize the morality in your actions is just wrong, imo.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#104
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

Wait until the EU GDPR kicks and in fines of up to 4% of annual turnover or 20 million kick in...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#105
post #92

Earlier quoted context omitted.

Consistency is absolutely impossible, as you already alluded to. It’s not a bad move to assess the current position, accept it for what it is, and improve it bit by bit. Pick your battles. Two wrongs don’t make a right when you try to sum them, I.e. combine them. My point is: don’t compare them at all. Don’t change the subject. Uber is one, other things are another. Being a hypocrite doesn’t make you wrong, it just m…

My overall point is that people don't actually care. It's just virtue signaling. If people cared they'd have consistency in their actions. For example, you probably are very consistent in the fact that you probably will never cause physical harm to someone. Consistency isn't impossible at all. People are already very consistent in doing what simply is convenient for them. In the case of Uber vs. Lyft, if you live in…

Today's SMBC comic is relevant to your argument: http://smbc-comics.com/comic/wait-a-sec

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#106
Every day we see more evidence that boards of directors and senior management should be personally accountable financially and with respect to their liberty for the company they are managing or overseeing doing foul things that they ought to have known.

The "I didn't know, I just took a vast salary to play golf" argument should not be any kind of defence. If there is the real prospect of going to jail, golfers will resign, those who take the job would actually take an interest and have the ability to do so.

An idea whose time has come.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#107

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

that doesn't protect you from GitHub employees snooping around.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#108
post #77

Earlier quoted context omitted.

We can vote for people who don't want the US to kill civilians while not using Uber. I don't see the conflict here.

The point is that if you know that the US kills civilians yet you stay in the US, giving them money through tax, the majority of which is used to fund the very same military that kills civilians, yet claim to do the right thing, that's hypocritical, no? In any case, you're right. There is no conflict. Just hypocrisy. EDIT: I realize I sound far more judge-y than intended in these posts. My overall point is that peopl…

So one should absolve themselves of any way they could stop it in a peaceful and legal manner?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#109

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

Just pigging-backing on your comment. If you did, here's a guide from Github on how to remove it: https://help.github.com/articles/removing-sensitive-data-fro...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#110
post #70

Earlier quoted context omitted.

And they say we need less regulation of corporate behavior.

Less regulation would be better than the system we have now - where large and connected corporations can buy get out of jail free cards.

Please tell me more about how even less regulation would have held Uber accountable.
Post reply on HN