Earlier quoted context omitted.
Magneto is pretty concerned with ethics and morality, I think Uber is more owned by Tony Stark on a particularly bad binge.
Tony is a changed man! He even voluntarily subjected himself to regulation. We need a new target.
Uber Paid Hackers to Delete Stolen Data on 57M People
521–530 of 606 posts
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#522> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…
Ok, how do you handle a bootstrap problem?
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#523Earlier quoted context omitted.
IANAL, but here is my thinking: The problem with personal phones is they are hard to audit. When a phone belongs to the corp, corp owns the phone, and "probably" can audit it as it wished.
In order to install my work Gmail account on my phone, I had to install a program on my personal phone that let admins wipe it remotely. This is not something that bothers me, because I expect to lose the phone almost anytime, so the contents on it are backed up continously on a system I control.
I'm already answering emails out of office hours which is for my employers benefit and they want to functionaly own my phone because of it?
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#524Earlier quoted context omitted.
It's not just about who knows more about security. It's a trade-off, and you need to account for other factors like cost, availability/uptime, data integrity, total attack surface area and others. Honestly, I'm surprised this is such a controversial point of view, but judging by the downvotes it appears it is. You learn something new every day, I guess.
The point is that the trade-offs usually come down in favor of using GitHub Enterprise (or whatever other well-regarded, trusted enterprise system). The availabilty and uptime are your own, because it’s self-hosted, like git. The data integrity is also your own. The security is better than probably any other VCS interface over git, with the possible exception of GitLab, and almost certainly better than what an organi…
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#525Earlier quoted context omitted.
What makes you think you (or most devs for that matter) know more about security than Github's security team?
It's not just about who knows more about security. It's a trade-off, and you need to account for other factors like cost, availability/uptime, data integrity, total attack surface area and others. Honestly, I'm surprised this is such a controversial point of view, but judging by the downvotes it appears it is. You learn something new every day, I guess.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#526"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.
What? Uber acted in an unethical manner? Seriously, is anyone surprised? I kinda hope (but not really) that they get hacked again in June 2018 and play the same trick.. us in the EU will have a party on Uber's corpse over GDPR.
I get all the other stuff they've done is unethical, but why is this occurrence one of them? They paid to protect their users. Almost plenty of companies get their data breached.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#527Earlier quoted context omitted.
I'm in charge of security at a large e-commerce company. I do not play golf. I mostly live in fear. No sensible person would sign up for the CSO position if they risked jail time when their company gets hacked. You can't really control it. A random engineer could make a mistake that gets hackers a step closer. Or it could be a zero-day vulnerability that nobody knows how to protect against. There are millions of moti…
You raise a difficult issue - how you would honestly resolve it. On one hand, CSOs cannot be personally liable for every hack. On the other, they shouldn't be given a pass on everything either. So how does one draw the lines between bad luck, reasonable security problems, everyday poor performance, civil liability, and criminal negligence? > A random engineer could make a mistake that gets hackers a step closer That…
Sure they can. It is called "insurance". Sort of like malpractice. CSO wants to get paid millions of dollars? Excellent, either be personally on the hook or have an insurance company that would be willing to underwrite your method of dealing with it, be that having your own crack team of people who get to oversee everything, or relying on Jr system admins from your company or whatever else.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#528Earlier quoted context omitted.
Yeah, but hopefully they can't do much if they just have your code base. If the secrecy of your code is the only thing stopping hackers from exploiting you, you're missing some gaping holes in your infrastructure. With that said, nothing wrong with using secrecy as a additional barrier, but shouldn't be the only, and if it's not the only, you're not "so owned at that point".
"If the secrecy of your code is the only thing stopping hackers from exploiting you" I hate these types of arguments. Yeah no one said that ever. Losing your code base is terrible. I view it as losing a journal. What your company tries, tests you run, funny comments, or funny mistakes. I mean they post it on the net, blackmail team members, imposter team members, forge for leaks, sell it, pushes to prod from compromi…
Also "pushes to prod from compromised accounts, CI systems" seems more related to access keys and account security rather than the actual code base.
But hey, in the end I'm no security expert so what do I know.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#529Earlier quoted context omitted.
Yeah, but hopefully they can't do much if they just have your code base. If the secrecy of your code is the only thing stopping hackers from exploiting you, you're missing some gaping holes in your infrastructure. With that said, nothing wrong with using secrecy as a additional barrier, but shouldn't be the only, and if it's not the only, you're not "so owned at that point".
“Just” leaking full source could be enough to destroy a lot of IP-based companies. A lot of companies stay wealthy because their IP is so huge than nobody can afford to develop competitive alternatives anymore (Adobe, Microsoft Office, Salesforce etc). Some of them have actual “secret sauce” that they cannot afford to share (suggestion engines, biotech processes etc). Even a service like Github, which relies on other…
I don't think either of those companies would cease to exist if their code bases leaked online today. Sure, someone might get something to build, but there is surely A LOT of things around the code bases to support all of this, which means the code bases would mostly serve as a study for software in general (and finding holes obviously).
Github is a bit unfair comparision, as their business is literally to make your code private, so if it leaks then of course it would be a hard hit. For the general company, I think leaking access credentials is a much bigger (but easier to fix) problem than leaking the source code itself.
Re: Uber Paid Hackers to Delete Stolen Data on 57M People
#530> Uber said it will provide drivers whose licenses were compromised with free credit protection monitoring and identity theft protection. This happened more than a year ago, and only now that they're planning on offering identity theft protection? That's ridiculous.
"Sorry we left uranium in your house a year ago and didn't bother telling you. Here's a coupon for free cancer screenings."