Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

321–330 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#321
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

Uber employee chiming in - while I entirely sympathize with HN's frustrations around our ethics and can't really justify our actions around this data breach, it is very much worth noting that Lyft would not exist were it not for Uber's extremely aggressive practices. There were/are far too many protectionist policies at play at most locales that -- not out of pure coincidence -- needed a company as aggressive as Uber…

I don't buy your view of what transpired. "In an ideal world", "making a near perfect switch like that is probably unlikely", "took a hit on our reputation", etc. None of these truly recognize the actual weight of what Uber has done as an organization.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#322

Amazon's access control and authorization system is the current most important broken thing in the industry. The Joe Sullivan details are the lurid stuff that propels news story copy, but the important takeaway is that almost nobody, including companies with serious investments in security, can safely get a large-scale dev team deploying onto AWS. This story keeps getting re-told, and has been for something like 5 ye…

Full disclosure: I'm the founder of CloudSploit[1] which aims to reduce these risks.

You're definitely on to something here. While I wouldn't call AWS security "broken," it is next to impossible to implement it correctly in any medium to large size business. There are 30+ services that AWS provides, each with an infinite number of security controls, JSON-based policies, etc. Cross-service access is even worse. Almost every service has some form of sub control that extends or complements the main security tool (IAM). KMS has key policies, ECR has registry policies, SNS has delivery policies, etc. S3 has perhaps the most confusing permission policy in existence, which has led to scores of high profile hacks this year alone.

There are 12+ public regions now, with more coming every few months, each fully enabled, yet segregated within the UI and API (which makes detecting attackers who have embedded themselves in unused regions more difficult).

All it takes is literally one typo in a single user's policy and leaked credentials and you're environment is completely compromised. Recovery is next to impossible without basically starting from scratch because you'll never find every tiny hole the attacker left as a backdoor for later without combing through GB of CloudTrail logs.

Now take all that, put it in an organization with 500+ engineers and you can see how easy it is for this to happen. Think you're safe by putting each team in their own account? Well AWS supports cross account role provisioning and engineers can easily set that up within their accounts. The spider web of issues is endless.

[1] https://cloudsploit.com

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#323

If these 'hackers' were white hat and signed a contract saying they responsibly handled and deleted the data, and then uber checked the access logs of the data and verified that nobody else accessed it, then IMO it is not a data breach. It was a potential breach. A white hat hacker you have an agreement with on how the data should be handled is the same as an employee who has access to the same data, where you also h…

These are absolutely not white-hat hackers. In order for a breach of this nature to be white-hat, they would have to be acting openly, and within the parameters of Uber's bug bounty program (https://hackerone.com/uber). I have yet to see a bug bounty program that would allow the pen-testers to access private user data en-masse (I don't even think a company could legally allow this).

Anonymously extorting a company after stealing its data is a black-hat activity any way you look at it.

If Uber didn't have a bounty program or responsible disclosure policy, and the hackers didn't download the user data, but reported it in a manner consistent with other responsible disclosures after discovering a means to access, then it would be grey-hat at best.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#324
post #234

Earlier quoted context omitted.

Taking money away from a bad company helps stop that company from doing bad. Similarly, voting for a politician who will try not to kill civilians helps prevent civilians from being killed. Both of these are correct actions to take. Moving out of the country is comparatively less effective, and continuing to give money to the bad company is not effective at all.

I agree with you in general, but unfortunately things are never that simple. Most companies do good too, otherwise they wouldn't exist.

"things are never that simple" says the guy who is implying that you shouldn't think about whether a company is moral/not if you live in a country that does horrible things?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#325

Earlier quoted context omitted.

Just yesterday, I got some serious flak for suggesting that changing one person in leadership wasn't enough to make them not evil. I'm sad to see just how bad this is/was, but I'm not one bit surprised.

This happened last year.

But the coverup persisted until just now. Kalanick has been gone for almost half a year.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#326

Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…

I haven't heard stories about how Uber employees are getting screwed. (Presumably financially?) Are you referring to Uber drivers in this comment?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#328

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm not even mad, thats a good bug bounty

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#329

Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…

I haven't heard stories about how Uber employees are getting screwed. (Presumably financially?) Are you referring to Uber drivers in this comment?

Protip: Uber's own bullshit aside, their drivers are employees.

Who are getting screwed.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#330

Earlier quoted context omitted.

I'm not sure if that's an accurate analogy. Few politicians would want to find themselves working in the climate Trump has found in Washington, (if anything, he has proven that a groundswell of popular support can't unseat a party establishment). Also, it simply would be inaccurate to describe Uber's actions as impotent . Edit: allow me to replace the word "found" with "created." I was just using a figure of speech.

>Few politicians would want to find themselves working in the climate Trump has found in Washington I can think of a few: https://en.wikipedia.org/wiki/United_States_presidential_ele... If you think the current sitting POTUS is an innocent victim of politics, then I have a bridge to sell you. Uber has used similar PR tactics in the past to deflect/detract from their actions.

> If you think the current sitting POTUS is an innocent victim of politics, then I have a bridge to sell you. Uber has used similar PR tactics in the past to deflect/detract from their actions.

I think the point that the great great? grandparent top post was making is that whoever is in charge of dealing with the media at Uber is doing a horrible job.

Also, I am sad that we don't talk about the policies and rather focus on the personal flaws. I think there would be a chance of a compromise if we debated on policy. I mean if we talk about just personality, what makes our Honorable Governor of New Jersey eligible for office? Not a fan of 45 but really I think politics has become too polarized.

Post reply on HN