Live data from Hacker News

Ask HN: Have you taken action regarding the Uber hack?

news.ycombinator.com

41–50 of 69 posts

Re: Ask HN: Have you taken action regarding the Uber hack?

#41
post #13

I never drove for Uber nor worked as a corporate employee (no risk for SSN leak). Have only used them as a customer. I only paid for their services using Apple Pay. Even if that number was compromised, the CVV would no longer be valid. I think most banks would automatically re-issue the account number (not the physical card number) if they detect fraudulent use. The only time I saved a card to Uber was before the NFC…

With apple pay your card number is never even sent to uber. Apple generates a unique virtual card number every time you use it.

Re: Ask HN: Have you taken action regarding the Uber hack?

#42
> [From the end of the article] Lawyers for Mr. Sullivan have argued that other employees were responsible for regulatory disclosures and said the company had scapegoated Mr. Sullivan.

Unless and until CEOs are held personally responsible for such security breaches there will be no solution to the problem. A Chief Security Officer job looks more and more as a designated scape-goat for hire.

Re: Ask HN: Have you taken action regarding the Uber hack?

#43
post #18

Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option. Previous jihads against hardcoded credentials (use Vault or equivalent). Next target after this will probably be Slack.

I get the spirit of your conversation but I urge you to not normalize a term like jihad. It’s sole purpose is to exterminate people by means of brutal violence who don’t fall in line in the name of religion.

Re: Ask HN: Have you taken action regarding the Uber hack?

#45
post #18

Going to wage jihad on everything less than FIDO2/WebAuthn in any org where I'm affiliated; previously people were pushing for using push-auth shit (e.g. Microsoft Authenticator) as an option. Previous jihads against hardcoded credentials (use Vault or equivalent). Next target after this will probably be Slack.

I get the spirit of your conversation but I urge you to not normalize a term like jihad. It’s sole purpose is to exterminate people by means of brutal violence who don’t fall in line in the name of religion.

Pretty weird since in the original language it just means Struggle. Cleaner connotation than the western equivalent 'Crusade' which is used secularly all the time tbh.

Re: Ask HN: Have you taken action regarding the Uber hack?

#47
post #14

Well now that you mention it, I enabled 2FA :awkward:

Good, but the attacker spammed 2FA requests at an employee until they convinced them to accept one. Other than FIDO I think, most forms of 2FA are vulnerable to this.

You can obviously rate limit the requests, and there are other tricks as well. I tend to think FIDO is better than push notifications for other (related) reasons, but it's not impossible to mitigate this kind of attack.

Re: Ask HN: Have you taken action regarding the Uber hack?

#48

The vibe I get is this is an internal compromise. Disgruntled employee, maybe looking for evidence of upcoming layoffs, doesn't find them, now makes it look like "a hacker".

Currently there is an 18 year old hacker bragging everywhere on the internet and seems he/she has no clue what to do with his/her newfound god mode.

Yeah I heard that. I read on Techcrunch. Do you have any links to this person?

Re: Ask HN: Have you taken action regarding the Uber hack?

#50

Sitting here pleased I continually refused to open an Uber account or have anything to do with them.

Yes, because I’m sure none of the places you do business with have ever been compromised.

That's true. But like the parent poster, I'm likewise glad I had avoided using them.

What I hated about Uber and why I never ended up using it was that their app wanted so much info from my phone for no discernibly good reason. And Lyft didn't seem to be much better. I just wanted a ride man, I didn't want a 500 MB app that sucked all the data out of my phone and sent it to god knows where.

So I've just ended up calling taxis.

It's not that your data won't get compromised by someone else, it's just about mitigating the exposure.

I acknowledge my tradeoffs wouldn't make sense for a frequent traveller.

Post reply on HN