Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

71–80 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#71
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

When I deactivated my account it was a huge pain, I had to reply to 2 emails, and in the end it took 5 days to complete. That alone annoyed me enough to never go back.

The current deletion process is smooth and can be completed in-app.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#72

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

From what I hear it's pretty common...

It's very common, but there are lots of ways of addressing it.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#73
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

This is mentioned in Dan Ariely's Predictably Irrational.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#74
post #46
post #40

Earlier quoted context omitted.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

>Just pay the toll especially when the cost of doing the right thing is higher. i mean look at HSBC - laundered trillions of dollars of mega-organized-crime money. for a decade. 400m dollar fine probably isnt even .01% of what they made off that endeavor

HSBC did not make trillions from those transactions and they were fined $1.9bn in 2012.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#75
post #60

Earlier quoted context omitted.

You'll find that thinking like that will only lead to misery at worst and hypocrisy at best. For example, if you live in the United States (though this logic applies to any country, really), you'll be interested to know that the US holds the world record for the amount innocent civilians killed [1]. [1] https://www.globalresearch.ca/u-s-holds-the-world-record-of-... EDIT: I realize I sound far more judge-y than inten…

Don’t let hypocrisy stop you from doing the right thing. Sometimes you need to climb one tree to cut down another.[1] That’s ok. [1] tbh I don’t think you do, but I like the analogy so I’m keeping it.

I disagree. One needs to be consistent in their actions, otherwise, what's the point? Two wrongs don't make a right, after all.

EDIT: Er, I agree that hypocrisy shouldn't stop you from doing the right thing.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#76
post #60
post #4

Ever since Susan Fowler told her story about what happened to her at Uber, I have only used Lyft, and have encouraged all my friends to do the same. I plan to never use Uber again.

You'll find that thinking like that will only lead to misery at worst and hypocrisy at best. For example, if you live in the United States (though this logic applies to any country, really), you'll be interested to know that the US holds the world record for the amount innocent civilians killed [1]. [1] https://www.globalresearch.ca/u-s-holds-the-world-record-of-... EDIT: I realize I sound far more judge-y than inten…

We can vote for people who don't want the US to kill civilians while not using Uber. I don't see the conflict here.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#77
post #60

Earlier quoted context omitted.

You'll find that thinking like that will only lead to misery at worst and hypocrisy at best. For example, if you live in the United States (though this logic applies to any country, really), you'll be interested to know that the US holds the world record for the amount innocent civilians killed [1]. [1] https://www.globalresearch.ca/u-s-holds-the-world-record-of-... EDIT: I realize I sound far more judge-y than inten…

We can vote for people who don't want the US to kill civilians while not using Uber. I don't see the conflict here.

The point is that if you know that the US kills civilians yet you stay in the US, giving them money through tax, the majority of which is used to fund the very same military that kills civilians, yet claim to do the right thing, that's hypocritical, no?

In any case, you're right. There is no conflict. Just hypocrisy.

EDIT: I realize I sound far more judge-y than intended in these posts. My overall point is that people should just do whatever makes 'em happy while doing the best you can (w.r.t. everything else). Trying to emphasize the morality in your actions is just wrong, imo.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#78
post #44

Earlier quoted context omitted.

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

This is so gob-smackingly uncommon I started asking "do you require 2fa for your github accounts" as part of my interview questions when I was looking for jobs (i.e. I'd ask my interviewers). I don't know how to feel knowing that there is even one software-focused company out there that doesn't enforce 2fa on its github accounts. Like... how?! Why?!

2fa is just another hurdle. Good to have, but by no means a silver bullet.

Just one of the many ways to bypass it in this case: hack a developer machine and look at the local checkout.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#80

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

The most I've ever personally seen a company do is require a VPN for their privately-hosted repos. For others using GitHub or Bitbucket? Never anything beyond a standard login.
Post reply on HN