Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

21–30 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#21

Earlier quoted context omitted.

Money.

how does this stop being the case? money > all else.

Start communities that use solar/wind energy, grow their own food (maybe using this in urban areas: https://www.media.mit.edu/groups/open-agriculture-openag/ove...), use WiFi mesh networking, maybe launch their own satellites (for inter-community links: https://newatlas.com/tubesat-personal-satellite/22211/), build their own things with multi-material 3D printers (maybe even print semiconductor components, who knows...) and employ barter rather than artificially scarce magical paper or e-coins. Also, employ "DIY Bio" in ethical life enhancing way, open production (open source everything etc) The technology and paradigms exist today or will fully exist soon.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#24
> Uber said it will provide drivers whose licenses were compromised with free credit protection monitoring and identity theft protection

This got to be a running joke now. Companies lose the data and offer credit/theft protection than facing the consequences. If Equifax could get away with the giant breach, I am sure Uber will not even feel the heat. smh.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#25
post #12

At the time of the incident, Uber was negotiating with U.S. regulators investigating separate claims of privacy violations. Uber now says it had a legal obligation to report the hack to regulators and to drivers whose license numbers were taken. Instead, the company paid hackers $100,000 to delete the data and keep the breach quiet.

Only $100k? They really should have tried for more... not that I support stealing PII.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#26
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

When I deactivated my account it was a huge pain, I had to reply to 2 emails, and in the end it took 5 days to complete. That alone annoyed me enough to never go back.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#27
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

Same here. That and that video from the driver that bought a black car to drive it for Uber and ended up in massive debt.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#28
post #9
post #2

I am amazed at the things Uber gets through and is still standing after...

Never underestimate the power of marketing. My mother for instance would use Uber over any ride-sharing system due to its insane exposure and the fact that these stories remain relatively unheard of in comparison.

She used uber because the service is fantastic.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#29
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

Even larger fines seem to draw weak behavior change. The U.S. corporate structure is remarkable in that sense. It shields employees (especially executives who often don't carry out orders) from criminal and financial responsibility for their actions.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#30
"Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company."

Seems to suggest they committed AWS credentials into source control?

Post reply on HN