Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

391–400 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#391
post #137

They stored AWS storage credentials in clear, in a (private) Github repo... This is so baffling coming from one of the largest tech companies in the world. Among other things, this shows that they do not have proper access policies to user data (e.g anybody working at Uber can get access to any user's data), which in my opinion is a larger issue than this individual hacking case.

We already knew that -- viz Uber showing off their ability to track famous users at a party. see https://www.forbes.com/sites/kashmirhill/2014/10/03/god-view... https://www.cnet.com/news/god-view-under-spotlight-as-uber-i... and https://www.cnet.com/news/uber-lawsuit-alleges-startup-track...

Yes, and this is from 2014! They really did not learn anything, and Kalanick's apologies and statements about "becoming more mature" were all just bullshit.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#392
post #106

Every day we see more evidence that boards of directors and senior management should be personally accountable financially and with respect to their liberty for the company they are managing or overseeing doing foul things that they ought to have known. The "I didn't know, I just took a vast salary to play golf" argument should not be any kind of defence. If there is the real prospect of going to jail, golfers will r…

I'm in charge of security at a large e-commerce company. I do not play golf. I mostly live in fear. No sensible person would sign up for the CSO position if they risked jail time when their company gets hacked. You can't really control it. A random engineer could make a mistake that gets hackers a step closer. Or it could be a zero-day vulnerability that nobody knows how to protect against. There are millions of moti…

You raise a difficult issue - how you would honestly resolve it. On one hand, CSOs cannot be personally liable for every hack. On the other, they shouldn't be given a pass on everything either.

So how does one draw the lines between bad luck, reasonable security problems, everyday poor performance, civil liability, and criminal negligence?

> A random engineer could make a mistake that gets hackers a step closer

That could be prevented, to a large extent, with much tighter controls. Of course, those controls would greatly increases the cost of operations and other things.

Is it possible we're all accustomed to the wrong model, that our standard of IT security is like the standard of car safety in the early auto industry (and maybe until the 1970s) - far too lenient? Maybe we should be facing the potential fact that the normal cost of IT should include those controls and other security expenses.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#393

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

You can use tools like Talisman which registers a Git hook to check if you are checking in anything that looks like secret. https://github.com/thoughtworks/talisman

It's not foolproof but this tool needs to be more widely-known - it would've saved me on countless occasions.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#394
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I bet the statutes define fines the same for any party with some maximum. States could charge a percentage of revenue, cash on hand, valuation, but those are easily fudged to minimize liability.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#395
post #121
post #98

Earlier quoted context omitted.

I really don't think using 2FA and the direct hacking of an individual developer's machine are all that comparable here. Who cares about access to individual dev's machines if the credentials to access code on github are obtained - 2FA at least offers some degree of protection in this scenario. The scope for attack is extremely different.

The hackers wanted access to the code to look for Amazon keys. For them it doesn't matter if they get the code from the internal GitHub or from a developer machine. If you have an ultra-secure door, the thiefs will just enter through your regular window.

How do you know they "wanted" access to look for Amazon keys? Do you know it wasn't from a blanket scan of github?

Sure, there are only 13 projects on https://uber.github.io/, but there are 169 on https://github.com/uber, and it only takes a short while to scan for access keys. There are plenty of open tools that will scan github for keys.

This may not have been targeted at Uber but a net for all of github with Uber being just one company that was hit up for cash. Unless you're saying that you know the motivations of the attackers.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#396
post #138

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

Github 2FA has been part of the first-day training/laptop setup for a while now (I joined in may) and there's security-related training in place as well. I was told there are also scanners in place now that check repos, gists, etc for secrets for exactly this type of mistake. One snippet of the email the article didn't mention was that Sullivan's firing happened pretty much right after Dara learned of the breach and…

Uber will not tolerate unethical behavior, you got to be joking!?!?

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#397
post #77

Earlier quoted context omitted.

We can vote for people who don't want the US to kill civilians while not using Uber. I don't see the conflict here.

The point is that if you know that the US kills civilians yet you stay in the US, giving them money through tax, the majority of which is used to fund the very same military that kills civilians, yet claim to do the right thing, that's hypocritical, no? In any case, you're right. There is no conflict. Just hypocrisy. EDIT: I realize I sound far more judge-y than intended in these posts. My overall point is that peopl…

Why should I tidy my room when we don't have world peace?

It's a ridiculous comparison. Leaving the country is a lot more difficult than changing ride share apps. It's not hypocritical to take the low-hanging ethical fruit, even if you don't do the harder stuff. In any case, living in a country doesn't imply that you support everything its government does. If anything, the ethical course of action is to stay and try to change things.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#398

Earlier quoted context omitted.

That is exactly my point ;) The irony is lost. User starik36's comment was in a downvoted state. Which is what prompted me to write that comment. I didn't think what he said deemed a down vote because from general observation what he stated seems true.

There isn't any irony. Freedom of speech is about preventing government censorship of citizens and has absolutely nothing to do with shielding people from the social consequences of saying unpopular things. It's about being legally allowed to say unpopular things, not about stopping people from disliking what you say.

I agree. That's all I meant too. Stating the obvious - As in, if you say anything in support of this Trump fellow, you will be down voted. And this is true as exemplified by the "down votes".

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#399
post #303

Earlier quoted context omitted.

Is conservative media berating Musk? I thought progressive media was souring on him?

I think it's more the "anti-fact" wing of the media (which does mostly overlap "conservative" on the Venn diagram). Unabashed alt-right agitprop outlets like Breitbart news, for instance, or climate change deniers. There are a couple different things at play. First, one plank in their infowar strategy is to combat anything that even indirectly propagates any understanding of climate change among the proles. They take…

I personally mostly don't agree with conservative media either, and I even mostly agree with you here, but to be fair the left also has their anti-fact narratives & outlets, and wrongthink, just the same as the right--just on different issues.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#400
This has been blown out of proportion.

- This is not Equifax, which leaked hundreds of millions SSN; or LinkedIn, which leaked hashed password of millions[1]; or Yahoo, which leaked personal information of billions, including security questions and hashed passwords [2]; or Target, which affected 40MM credit cards [3].

"Compromised data [..] included names, email addresses and phone numbers of 50 million Uber riders around the world, [..] including some 600,000 U.S. driver’s license numbers. No Social Security numbers, credit card information, trip location details or other data were taken"

- There is no gross incompetence. The breach was due to an AWS access key in a private github repo. I bet you can find enough developers in this forum who store sensitive information in private GitHub repos without git encryption, and who may or may not feel guilty, because of the (false) sense of safety given by 1) the guarantee of github private repo and 2) the fact that access keys can be revoked and are generally handled with less care.

- The response by the new CEO is decisive and timely. The CSO was fired on the same day the CEO learned about the incident. There is also internal review, new advisor, and reasonable protection offered to the drivers affected, even though there is no indication the data is leaked beyond the thief, and driver license numbers are not the best for identify theft.

[1] https://en.wikipedia.org/wiki/2012_LinkedIn_hack

[2] https://en.wikipedia.org/wiki/Yahoo!_data_breaches

[3] https://www.huffingtonpost.com/eric-dezenhall/a-look-back-at...

Post reply on HN