Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

181–190 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#181

Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…

You're watching too much CNN.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#182

> Joe Sullivan, the outgoing security chief, spearheaded the response to the hack last year, a spokesman told Bloomberg. Sullivan, a onetime federal prosecutor who joined Uber in 2015 from Facebook Inc.... Why on earth would a software-based company like Uber that stores a boatload of confidential employee and customer information on its servers put a non-technical person of any sort, lawyer or not, in charge of its…

Put a lawyer in charge when your strategy is to defend lawsuits against issues and mitigate the fallout of issues, rather than to, you know, prevent the security issues

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#183

> Joe Sullivan, the outgoing security chief, spearheaded the response to the hack last year, a spokesman told Bloomberg. Sullivan, a onetime federal prosecutor who joined Uber in 2015 from Facebook Inc.... Why on earth would a software-based company like Uber that stores a boatload of confidential employee and customer information on its servers put a non-technical person of any sort, lawyer or not, in charge of its…

Welcome to lobbying ver, 2.0.

Instead of giving cash bribe, bribe with cushy jobs with high salary and no real responsibility, since no one would expect a lawyer to understand what even to delegate to members of IT security team.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#184

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

git-secrets is a pre-commit hook that regexp's out secrets and blocks commits

https://github.com/awslabs/git-secrets

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#185

> Joe Sullivan, the outgoing security chief, spearheaded the response to the hack last year, a spokesman told Bloomberg. Sullivan, a onetime federal prosecutor who joined Uber in 2015 from Facebook Inc.... Why on earth would a software-based company like Uber that stores a boatload of confidential employee and customer information on its servers put a non-technical person of any sort, lawyer or not, in charge of its…

Security, as far as a corporate entity is concerned, is fundamentally a way to reduce business and legal risk. A lawyer at the top, making those decisions with the input of technologists, seems like it should be reasonable when things are working correctly. This isn't a failure of skillset or knowledge, it's a failure of ethics and leadership. (Which should, to be clear, be punished far more severely than skill-related incompetence.)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#186
post #158

Earlier quoted context omitted.

The way you fix this is by making each 5m late cost 2 gallon of milk. If you are late for 15m that's 6 gallons of milk, an operational burden has been passed to the late parent. It's embarrassing to bring in 6 gallons of milk, an inconvenience to buy and deliver it, and an effective deterrent.

> If the parents were fined a day's daycare fee for being ten minutes late you can bet their attitude would change. I think upping the pain works better. What's a daycare going to do with so many gallons of milk?

The very last late parent of the day has to dispose of all the milk.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#187
post #175

Earlier quoted context omitted.

> If the parents were fined a day's daycare fee for being ten minutes late you can bet their attitude would change. I think upping the pain works better. What's a daycare going to do with so many gallons of milk?

That amount of milk would last a couple days if snack is included in tuition. 20-40 glasses of milk, twice a day. If for some reason you have too many gallons of milk, you can also use toilet paper, 10 rolls per 5 minutes. You can never have too much toilet paper, some late parents even buy the soft stuff too! lol A huge fine isn't always the best deterrent and it makes people generally mad at your child care center.…

It's not so great for the staff either. Instead of waiting an extra 10 minutes for a parent that's 10 minutes late, they now have to wait 30 minutes because the parent had to make a 20 minute detour to the grocery store to buy milk.

> A huge fine isn't always the best deterrent and it makes people generally mad at your child care center.

EDIT: You can make this revenue neutral. Give parents a discount at the end of every month out of the money they collect in late fines. People on time at a better-than-average rate will come out ahead.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#188
post #44

Earlier quoted context omitted.

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

To use 2fa on github you need a mobile phone. Do you give every enployee a mobile phone, or do you ask your employees to use their own personal phones? Asking them to use their personal phones seems like a very bad solution. Many software companies do not routinely give developers mobile phones...

It works with u2f as well.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#189
post #44

Earlier quoted context omitted.

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

To use 2fa on github you need a mobile phone. Do you give every enployee a mobile phone, or do you ask your employees to use their own personal phones? Asking them to use their personal phones seems like a very bad solution. Many software companies do not routinely give developers mobile phones...

> To use 2fa on github you need a mobile phone.

This is incorrect.

You only need the ability to generate TOTP or U2F tokens. This is often done using a smartphone app, but can also be done by a desktop app like 1Password or a hardware device like a Yubikey: https://github.com/blog/2071-github-supports-universal-2nd-f...

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#190

Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…

>and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work environment is or how hard they work to spy on their employees and customers

I don't think the average Joe is up to date with this news, or even care about.

Post reply on HN