Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

41–50 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#42

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

Working at another large tech company, this does not surprise me.

Edit: I mean it would surprise me if it wasn't recommended practice, but it would also surprise me if it was somehow strictly enforced.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#44

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers).

I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#46
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

>Just pay the toll

especially when the cost of doing the right thing is higher.

i mean look at HSBC - laundered trillions of dollars of mega-organized-crime money. for a decade. 400m dollar fine probably isnt even .01% of what they made off that endeavor

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#47
Yep.

About that time my Uber account was 'hacked' and someone kept requesting rides in Florida and I had to cancel them as fast as they made them.

I emailed Uber support and they got back to my 3 days later.

Then someone proceeded to try to gain access to every account I had with that email and password (yeah, yeah, I know). The next worse was someone getting into my DigitalOcean account and launching an instance.

It has finally settled down, I occasionally get alerts from people trying to break into something but lots of 2FA and no shared passwords anymore.

I am not sure if this was Uber's fault or another site's but the timeframe of Oct 2016 lines up.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#49
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

> The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willing to pay.

The real question in this story is this: If you find that you have customers who are willing to pay you more for providing more service ... why not provide that service? You get more money, your staff gets paid overtime, parents get peace of mind, everyone's happy.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#50
post #9

Earlier quoted context omitted.

Never underestimate the power of marketing. My mother for instance would use Uber over any ride-sharing system due to its insane exposure and the fact that these stories remain relatively unheard of in comparison.

It's already way more common to use "Uber" as a verb, or even a noun, that doesn't necessarily even mean Uber the company itself. People have asked me before if I'm about "to uber" or "take an uber" someplace and they say it in an obvious way that implies "any ridesharing company" (or lyft in my case since most people know I only lyft nowadays). Uber just as a word for ride-sharing has become ingrained and won't be e…

At this rate, Uber may be the first company to have a generic name and go out of business so soon afterward.
Post reply on HN