Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

151–160 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#151
post #95

Earlier quoted context omitted.

The current deletion process is smooth and can be completed in-app.

Why bother? I just deleted the app and forgot about it. Is there something I should know?

IIRC you can't remove all payment methods from the app, so just deleting the app will leave your credit card information in their hands. Also all your previous ride data will still be on their servers. Both of these things could be lost in a data breach, and presumably account deletion deletes this data.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#152
post #75

Earlier quoted context omitted.

Don’t let hypocrisy stop you from doing the right thing. Sometimes you need to climb one tree to cut down another.[1] That’s ok. [1] tbh I don’t think you do, but I like the analogy so I’m keeping it.

I disagree. One needs to be consistent in their actions, otherwise, what's the point? Two wrongs don't make a right, after all. EDIT: Er, I agree that hypocrisy shouldn't stop you from doing the right thing.

> Two wrongs don't make a right, after all.

That saying... doesn't even apply here.

Being consistent in all you do is hard. Doing 5 "bad" things instead of 10 "bad" things is certainly better.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#153
post #138

Earlier quoted context omitted.

Github 2FA has been part of the first-day training/laptop setup for a while now (I joined in may) and there's security-related training in place as well. I was told there are also scanners in place now that check repos, gists, etc for secrets for exactly this type of mistake. One snippet of the email the article didn't mention was that Sullivan's firing happened pretty much right after Dara learned of the breach and…

its possible and even likely that this happened post hack.

True, I just wanted to shed some light into the current state of affairs in here.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#154
post #61

Earlier quoted context omitted.

> laundered trillions of dollars of mega-organized-crime money While I agree with your sentiment, there is no need to use such inflated and hilarious numbers.

Edit: Thanks for the corrections. I definitely messed up the magnitudes here. Was doing some other calculation on another topic and somehow I mixed them both. Sorry about that. Please disregard this comment as it it way off :( While "trillions" is definitely inflated and hyperbole, I don't think it's THAT far off. According to this The Guardian article [0] "At least $881m in drug trafficking money was laundered throu…

Parent might be conflating the amount actually found to be laundered with HSBC's failure to monitor over $200 trillion [1] in suspicious transactions.

[1] https://www.theglobeandmail.com/incoming/article6209613.ece/...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#155
post #92

Earlier quoted context omitted.

Consistency is absolutely impossible, as you already alluded to. It’s not a bad move to assess the current position, accept it for what it is, and improve it bit by bit. Pick your battles. Two wrongs don’t make a right when you try to sum them, I.e. combine them. My point is: don’t compare them at all. Don’t change the subject. Uber is one, other things are another. Being a hypocrite doesn’t make you wrong, it just m…

My overall point is that people don't actually care. It's just virtue signaling. If people cared they'd have consistency in their actions. For example, you probably are very consistent in the fact that you probably will never cause physical harm to someone. Consistency isn't impossible at all. People are already very consistent in doing what simply is convenient for them. In the case of Uber vs. Lyft, if you live in…

> My overall point is that people don't actually care. It's just virtue signaling.

That's just, like, your opinion, man.

I care up to certain thresholds. Last year my Uber use was probably 90%, Lyft 10%. Now that's flipped. I only use Uber if I'm outside the US and there's no comparable local alternative.

Uber is demonstrably making less money than it used to because I do this, and Lyft is making more. I'm personally happy with that arrangement, and honestly my feelings here are the only ones that matter. I don't particularly care if you think I'm just "virtue signaling" or if I'm "not doing enough" or whatever.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#156
post #62

Earlier quoted context omitted.

It's already way more common to use "Uber" as a verb, or even a noun, that doesn't necessarily even mean Uber the company itself. People have asked me before if I'm about "to uber" or "take an uber" someplace and they say it in an obvious way that implies "any ridesharing company" (or lyft in my case since most people know I only lyft nowadays). Uber just as a word for ride-sharing has become ingrained and won't be e…

Same as `googling` will long remain the synonym for `searching the internet`.

> Same as `googling` will long remain the synonym for `searching the internet`.

That's more due to the ubiquity and dominance of Google itself.

It's rare to hear someone say "I Googled it on Bing" or even "Let me Google my email" when they're using Outlook. Maybe not unheard-of, but definitely nowhere near the threshold needed for genericization.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#157
post #122

Earlier quoted context omitted.

It's not about changing things you support, it's just about consistency in your actions. Taking the child labor thing into account, never being brand new electronics again would pretty much take care of that. One could make an argument that buying used goods is still supporting child labor, but I'd argue it's a sunk cost.

> brand new electronics Why choose this example? Child labour is rife in many sectors, particularly textiles. It's also rampant in electronics recycling[0]. So even if you never buy any new electronics, you're complicit when you dispose of your old electronics. The point is you shouldn't allow an impossible quest for perfect ideological consistency and moral purity to prevent you from doing good on a imperfect, incon…

Oh I completely agree.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#158
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

The way you fix this is by making each 5m late cost 2 gallon of milk. If you are late for 15m that's 6 gallons of milk, an operational burden has been passed to the late parent. It's embarrassing to bring in 6 gallons of milk, an inconvenience to buy and deliver it, and an effective deterrent.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#159

I woke up an Silicon Valley has really become an Evil place. What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"? We really need to change.

> What ever happened to our mantra (really Google's but it reflected the whole valley) "Don't be evil"?

The kool-aid wore off and everyone realized it never had any meaning to begin with.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#160
> Joe Sullivan, the outgoing security chief, spearheaded the response to the hack last year, a spokesman told Bloomberg. Sullivan, a onetime federal prosecutor who joined Uber in 2015 from Facebook Inc....

Why on earth would a software-based company like Uber that stores a boatload of confidential employee and customer information on its servers put a non-technical person of any sort, lawyer or not, in charge of its security team?

Post reply on HN