Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

111–120 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#111
post #69

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

I mean they don't say how they accessed the GitHub repo or whether there was a vulnerability in Github itself that allowed access

I assume it was password reuse from one of their engineers or something similar. If you could compromise GitHub itself there would probably be higher value targets (source code for upcoming AAA games, Coinbase, government organizations, etc.)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#112
post #103

Earlier quoted context omitted.

It’s just not possible to be perfectly consistent in all your actions, we’re all hypocrites somewhere if you consider all down to the root. We probably all hate forced child labor, yet we all own smartphones, all of them most likely built with resources mined by children under grueling conditions. (This text Is typed on one) Still, don’t let that stop from doing the right thing once in a while. If we all did the righ…

> We probably all hate forced child labor A false premise. If that were true, just like you stated, we wouldn't support it. Actions speak louder than words, and all that. EDIT: I realize I sound far more judge-y than intended in these posts. My overall point is that people should just do whatever makes 'em happy while doing the best you can (w.r.t. everything else). Trying to emphasize the morality in your actions is…

It’s not a false premise. It’s just not humanly possible to change everything you don’t support. We can’t move all back to self-dug caves and till the land with our bare hands. You need to pick your battles.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#113

Earlier quoted context omitted.

In the disclosure it says that the attack included names, email addresses and phone numbers. It did not contain any passwords or social security numbers, so your passwords must have been compromised in some other way.

It's not related to this particular breach, but given this and Uber's other issues, it's not out of the realm of possibility that at some point they had a more serious breach involving loss of password hashes or interception of credentials at login. (But in all likelihood the poster's account was just compromised through the usual means, otherwise there would be more reports of hacked accounts.)

The article states that this disclosure came out of an board commissioned investigation into the activities of Sullivan’s security team. Do you think that other more serious breaches discovered by this investigation is hidden, or is this more of a general sentiment around how you perceive Uber?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#114

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

Just pigging-backing on your comment. If you did, here's a guide from Github on how to remove it: https://help.github.com/articles/removing-sensitive-data-fro...

They key part is "Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one."

Removing the secrets from the repository is nice to have, but not that necessary - what is mandatory is to ensure that the compromised secrets are no longer useful, since they aren't secret any more and won't be ever again.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#115
post #81

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

uber engineer here, we have 2fa set up for everything. Starting my day takes about 5 different 2fa checks (ssh access, aws, phabricator, team chat, etc)

I know Uber has a strong engineering culture, which is why I was so surprised. I think philsnow's assessment that organization-wide required 2FA wasn't available for GitHub Enterprise at the time of the hack is probably correct.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#116

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

Just pigging-backing on your comment. If you did, here's a guide from Github on how to remove it: https://help.github.com/articles/removing-sensitive-data-fro...

I am rather disappointed in github for publishing this guide. The portion at the top stating

> Warning: Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised. If you committed a password, change it! If you committed a key, generate a new one.

Is a good argument as to why you shouldn't let users erase this data from history, it's already out there so no matter how painful or convoluted your process is for regenerating auth credentials is, you need to do it if you've published them into your SCM. If the process is painful you might want to simplify it because you'll probably need to do it sometime in the future again... yes even you large corporate workers who have no control over credential regeneration, an arduous process leads to credential sharing between projects which is another horrible thing.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#117
post #51

> Uber said it will provide drivers whose licenses were compromised with free credit protection monitoring and identity theft protection This got to be a running joke now. Companies lose the data and offer credit/theft protection than facing the consequences. If Equifax could get away with the giant breach, I am sure Uber will not even feel the heat. smh.

I moved to the US in April was and shocked by the Equifax breach, but more surprised to hear from a coworker how often these “free credit/identity monitoring for a year” situations occur. One co-worker is covered by no less than four groups who failed to look out for him earlier, all for trusting companies to not screw up PII or remember that data is a liability.

Yeah, this happens a lot here. I mean the cheapest and most effective way for companies to get away.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#118

Earlier quoted context omitted.

Less regulation would be better than the system we have now - where large and connected corporations can buy get out of jail free cards.

Please tell me more about how even less regulation would have held Uber accountable.

It wouldn't. But I'd wager that Uber isn't going to be held accountable (or not very accountable) for this, so why not write the rules so that everyone gets to be as cavalier? It'd save a lot of companies the headaches that go along with I.T security.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#119
post #61
post #46

Earlier quoted context omitted.

>Just pay the toll especially when the cost of doing the right thing is higher. i mean look at HSBC - laundered trillions of dollars of mega-organized-crime money. for a decade. 400m dollar fine probably isnt even .01% of what they made off that endeavor

> laundered trillions of dollars of mega-organized-crime money While I agree with your sentiment, there is no need to use such inflated and hilarious numbers.

Edit: Thanks for the corrections. I definitely messed up the magnitudes here. Was doing some other calculation on another topic and somehow I mixed them both. Sorry about that. Please disregard this comment as it it way off :(

While "trillions" is definitely inflated and hyperbole, I don't think it's THAT far off.

According to this The Guardian article [0] "At least $881m in drug trafficking money was laundered throughout the bank's accounts."

So 0.88 Tn. Definitely not "trillions" but definitely much more than I would've expected if they said "billions laundered".

Also, it says "at least", which I take it to say that the investigation was not complete so a final number couldn't be calculated and only a "lower" cap is given. Potentially it could still be "trillions" as in e.g. "1.3 trillions" (if that final figure is ever calculated or even published of course). So inflated, yes. Hilarious... not so sure.

[0] https://www.theguardian.com/business/2012/dec/11/hsbc-bank-u...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#120
post #60

Earlier quoted context omitted.

You'll find that thinking like that will only lead to misery at worst and hypocrisy at best. For example, if you live in the United States (though this logic applies to any country, really), you'll be interested to know that the US holds the world record for the amount innocent civilians killed [1]. [1] https://www.globalresearch.ca/u-s-holds-the-world-record-of-... EDIT: I realize I sound far more judge-y than inten…

Don’t let hypocrisy stop you from doing the right thing. Sometimes you need to climb one tree to cut down another.[1] That’s ok. [1] tbh I don’t think you do, but I like the analogy so I’m keeping it.

> tbh I don’t think you do

I've actually had to climb one tree to cut down another.

Post reply on HN