Earlier quoted context omitted.
How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.
Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.
Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
21–30 of 167 posts
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#22the number of f*cks i can give for the company is so low. just feel sorry for all the drivers with the leaked information...
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#23Earlier quoted context omitted.
How in the world did you only get 8 points for that? I've upvoted yours. That seems almost as bad as the incident reported in this thread.
Because it's just the UI, you can't actually use it without an admin account. It's really not an issue at all.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#24Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.
I could see it taking a while to find one bad request in the entire history of the API's lifespan -- presuming that they had to find the logs, weed out false positives, different sites and versions that behaved differently, etc.
That still doesn't explain a 5 month gap. The only (charitable) explanation that makes sense to me is that they discovered the API was exposed, thought they had proven it was never improperly accessed, and then only much later realized that it had been after all.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#25Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#26Data accessed on 5/13/2014, uber noticed on 9/17/2014, and then notifies affected on 2/27/2015. Thankfully it was only names and plate numbers, but still... All I see from uber is bad publicity and poor management decisions. I wonder what it's like to work there from an insiders perspective, cause from the outside it doesn't look good.
[0] https://news.ycombinator.com/item?id=9122369 [1] http://blog.uber.com/2-27-15
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#27Uber really needs to have a public data retention policy stating that they anonymize or delete all data older than a couple weeks. I'm just waiting for them to be hacked and have to reveal that people's trip data for years has been released.
Not just Uber. Obama's proposing data privacy regulations. I think it's worth considering what you'd like to see involved in same.
Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#28Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#29Re: Uber Database Breach Exposed Information of 50,000 Drivers, Company Confirms
#30Between this breach, and the impending classification as a cab company by more and more major cities. I think that we can consider Uber to be either the walking dead or something very close to it at this point.
If they get classified as a cab company in a particular market, they'll sue. If they don't get their way, they'll exit the market. They could also move into other businesses which are clearly not cabs, as shown by their dabblings in courier and delivery services. Consider how many startups are paying people to drive things from point A to point B -- that entire industry could be outsourced to Uber.
If they do exit a market, they won't lose anything besides face -- it's the drivers who will carry all of the capital investment and most of the operating costs, they're the ones who will be hurt.