Man, I don't know if Uber is evil or if most tech companies are evil and Uber just doesn't drop the kind of money on PR strategery that an evil company need to drop in order to seem normal. But either way, holy cow does that company come off as toxic. They've completely revolutionized the drive-for-hire industry and all anyone ever hears about it what a D-bag their CEO is or how toxic and mysogonist their work enviro…
And testing their self driving cars without getting the proper permits. And hiding shit like this from investors so they’ll lose a lot of money later. I would never work as an engineer for a company like that. How can I trust that it will honor any deal I make and not screw me? I have to think about that with every company but this one in particular can’t even spell ”integrity”.
Uber Paid Hackers to Delete Stolen Data on 57M People
441–450 of 606 posts
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#442I am wondering what private Github coding site stands for? If it is GitHub Enterprise, then how those hackers would even access it from outside of the uber network? Does it mean that they had access to Uber's VPN as well?
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#443Earlier quoted context omitted.
What? Uber acted in an unethical manner? Seriously, is anyone surprised? I kinda hope (but not really) that they get hacked again in June 2018 and play the same trick.. us in the EU will have a party on Uber's corpse over GDPR.
And then we can go back to getting ripped off by taxis. I’ve lost more money in taxi rip offs than I ever spent on Uber. Other than the sexist nonsense of the CEO, there really is an irrational hatred of Uber. Are many of us secretly moonlighting as cab drivers? Uber’s nonsense is minuscule compared to generations of taxi corruption. This isn’t me excusing Uber but it does seem like many people, especially Europeans…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#444Earlier quoted context omitted.
And testing their self driving cars without getting the proper permits. And hiding shit like this from investors so they’ll lose a lot of money later. I would never work as an engineer for a company like that. How can I trust that it will honor any deal I make and not screw me? I have to think about that with every company but this one in particular can’t even spell ”integrity”.
That's silly. Uber has a revolving door with Google and Facebook. Nobody is getting screwed, or it would not work to hire people away.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#445Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#446Earlier quoted context omitted.
> To use 2fa on github you need a mobile phone. This is incorrect. You only need the ability to generate TOTP or U2F tokens. This is often done using a smartphone app, but can also be done by a desktop app like 1Password or a hardware device like a Yubikey: https://github.com/blog/2071-github-supports-universal-2nd-f...
You can also record the TOTP secret in your automated login script, next to your password, and generate the token on the fly right there. It's things like that that make me wonder why TOTP tokens are supposed to be conceptually different from passwords. A TOTP scheme involves knowing a master password, and nothing else.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#447Every day we see more evidence that boards of directors and senior management should be personally accountable financially and with respect to their liberty for the company they are managing or overseeing doing foul things that they ought to have known. The "I didn't know, I just took a vast salary to play golf" argument should not be any kind of defence. If there is the real prospect of going to jail, golfers will r…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#448Every day we see more evidence that boards of directors and senior management should be personally accountable financially and with respect to their liberty for the company they are managing or overseeing doing foul things that they ought to have known. The "I didn't know, I just took a vast salary to play golf" argument should not be any kind of defence. If there is the real prospect of going to jail, golfers will r…
I'm in charge of security at a large e-commerce company. I do not play golf. I mostly live in fear. No sensible person would sign up for the CSO position if they risked jail time when their company gets hacked. You can't really control it. A random engineer could make a mistake that gets hackers a step closer. Or it could be a zero-day vulnerability that nobody knows how to protect against. There are millions of moti…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#449Earlier quoted context omitted.
It all started when Google banned all software that can not be used for Evil: http://wonko.com/post/jsmin-isnt-welcome-on-google-code
People keep bringing this link up every time, but obscure the actual reason that was done: it puts the developers depending on the library in legal jeopardy. Licenses like "Do Whatever The Fuck You Want To" [0] are in the same boat. Redhat also stopped including JSMin for the same reason. [1] [0] https://en.wikipedia.org/wiki/WTFPL [1] https://bugzilla.redhat.com/show_bug.cgi?id=455507
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#450Earlier quoted context omitted.
This would have been interesting if GDPR was applied. https://www.gdpr.associates/data-breach-penalties/ "There will be two levels of fines based on the GDPR. The first is up to €10 million or 2% of the company’s global annual turnover of the previous financial year, whichever is higher. The second is up to €20 million or 4% of the company’s global annual turnover of the previous financial year, whichever is higher.…
> The first is up to €10 million or 2% of the company’s global annual turnover of the previous financial year, whichever is higher. Why do big firms get off easier than the smaller firms?
OTOH, consider that the bigger firm is made up of a collection of 10 services, each earning $100 million. The breach is only in one business unit - is the global revenue a fair metric if the breach is not global?
It will be interesting to see how this is enforced against giant corporations when (inevitably) some small piece of data is missed on some small service in a business unit nobody at the c level has ever heard of.