Also super shady they don't bother to explain why it took them almost 5 months after they discovered it to notify anyone.
Uber hauls GitHub into court to find who hacked database of 50,000 drivers
31–40 of 47 posts
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#32Earlier quoted context omitted.
So how is the IP address of someone that has viewed or crawled said secret Gist relevant anyways? Someone crawling a website is not probable cause (even if there is a single IP address which can be traced to specific machine, which is highly unlikely).
Secret gists are not published publicly, and thus are not crawled. You would need to have a direct link to the gist to have accessed it. Having the link either means you had access to it as an internal employee, it was shared by an internal employee, or an internal employee's system or email was accessed by someone else.
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#33Earlier quoted context omitted.
The manufacturer digitally stores the fingerprints of anyone who uses the lock. You want the manufacturer to give you a copy of the fingerprints to help you identify the person who broke into your house. > ...and then your [sic] mad at the manufacturer of the door's lock. There is no evidence that Uber is mad at Github.
No,Uber is fishing for data they don't need. They have an IP address of the intruder. Instead of demanding all the access logs for a months long period, why not compel Github to answer the question "Did this IP address access the Gist in question? If so, what are the timestamps?" Instead Uber wants all github's access log data for the gist in question which sounds like more incompetence and desperation on Uber's part…
Which is why we have courts.
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#34> In keeping with its image as a gas tank of ethics running on empty (...) This is the best one-sentence summary of Uber I've ever seen.
Peter Sagal on NPR's "Wait Wait...Don't Tell Me!" had a good one liner something along the lines of Uber heard Google's "Don't be evil" motto and thought "They are leaving an open market niche for us!".
BTW. After watching all episodes of John Oliver's "Last Week Tonight" I'm looking for interesting shows. Is that podcast worth listening to? Anything else you'd recommend?
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#35Earlier quoted context omitted.
The manufacturer digitally stores the fingerprints of anyone who uses the lock. You want the manufacturer to give you a copy of the fingerprints to help you identify the person who broke into your house. > ...and then your [sic] mad at the manufacturer of the door's lock. There is no evidence that Uber is mad at Github.
No,Uber is fishing for data they don't need. They have an IP address of the intruder. Instead of demanding all the access logs for a months long period, why not compel Github to answer the question "Did this IP address access the Gist in question? If so, what are the timestamps?" Instead Uber wants all github's access log data for the gist in question which sounds like more incompetence and desperation on Uber's part…
which could be the audience they're most concerned about.
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#36Nitpick: the title implies that Uber is suing Github, but that's not the case. Uber has a civil suit pending in N.D. Cal., and has issued Uber a third-party subpoena: http://regmedia.co.uk/2015/02/28/ubergithubexhibit.pdf . Such subpoenas are used when a third party might have information relevant to a pending lawsuit. They do not imply any allegations of wrongdoing against the third party.
Actual headline: "FORK ME! Uber hauls GitHub into court to find who hacked database of 50,000 drivers"
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#37Earlier quoted context omitted.
> getting whiny Actually, they're subpoenaing. This is necessary to identify who may have accessed it; i don't think this is a suit over the privacy of gists.
> This is necessary to identify who may have accessed it Actually, it's not. If Github's TOS (and their legal argument in response to the subpoena) is strong enough, Uber can go fly a kite.
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#38https://www.eff.org/issues/mandatory-data-retention/us
Neocities currently scrambles stored IP addresses with scrypt, and (soon) after 30 days, we intend to delete those IP hashes. It's legal. Consider doing it.
Here's the code we used to do it: https://github.com/neocities/neocities/commit/4983a9b24eac00...
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#39Earlier quoted context omitted.
No,Uber is fishing for data they don't need. They have an IP address of the intruder. Instead of demanding all the access logs for a months long period, why not compel Github to answer the question "Did this IP address access the Gist in question? If so, what are the timestamps?" Instead Uber wants all github's access log data for the gist in question which sounds like more incompetence and desperation on Uber's part…
incompetence, desperation, and a great way to shift some blame onto GitHub, in the eyes of people who know absolutely nothing about how this stuff works. which could be the audience they're most concerned about.
Re: Uber hauls GitHub into court to find who hacked database of 50,000 drivers
#40Earlier quoted context omitted.
Peter Sagal on NPR's "Wait Wait...Don't Tell Me!" had a good one liner something along the lines of Uber heard Google's "Don't be evil" motto and thought "They are leaving an open market niche for us!".
Haha, that's excellent as well! I think I'll just note both of them in my quotes file. BTW. After watching all episodes of John Oliver's "Last Week Tonight" I'm looking for interesting shows. Is that podcast worth listening to? Anything else you'd recommend?