Live data from Hacker News

Uber Paid Hackers to Delete Stolen Data on 57M People

bloomberg.com

81–90 of 606 posts

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#81

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

uber engineer here, we have 2fa set up for everything. Starting my day takes about 5 different 2fa checks (ssh access, aws, phabricator, team chat, etc)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#83
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

It's in the book Freakonomics, when talking about economic, social, and moral incentives.

The day care changed what was a social incentive for an economic one, and then couldn't reverse the consequences: Not fining the parents anymore didn't reduce the number of late ones to previous levels.

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#84
post #49
post #40

Earlier quoted context omitted.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

> The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willing to pay. The real question in this story is this: If you find that you have customers who are willing to pay you more for providing more service ... why not provide that service? You get more money, your staff gets paid overtime, parents get peace of mind, everyone's happy.

[deleted]

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#85

Yep. About that time my Uber account was 'hacked' and someone kept requesting rides in Florida and I had to cancel them as fast as they made them. I emailed Uber support and they got back to my 3 days later. Then someone proceeded to try to gain access to every account I had with that email and password (yeah, yeah, I know). The next worse was someone getting into my DigitalOcean account and launching an instance. It…

In the disclosure it says that the attack included names, email addresses and phone numbers. It did not contain any passwords or social security numbers, so your passwords must have been compromised in some other way.

It's not related to this particular breach, but given this and Uber's other issues, it's not out of the realm of possibility that at some point they had a more serious breach involving loss of password hashes or interception of credentials at login.

(But in all likelihood the poster's account was just compromised through the usual means, otherwise there would be more reports of hacked accounts.)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#87
post #40
post #10

"In January 2016, the New York attorney general fined Uber $20,000 for failing to promptly disclose an earlier data breach in 2014." Because you know...20k really really hurts for a company like Uber.

I recall a story (that I'll probably recount incorrectly) about a daycare business deciding that too many parents were arriving late to pick up their children (meaning that staff had to stay late with the kids), so they instituted a fine for late pickups. The result was that more parents were late. The reason being that the parents effectively considered the fine a "late pickup fee", and one they were more than willi…

I know about day care in Bay Area which is charging $20 per 5 minutes delay. I guess that's the reason:)

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#88

> Here’s how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company. D…

I'm surprised Uber doesn't have their engineers set up 2FA for GitHub. Super simple to implement and require organization-wide[1] and would have prevented this. Then again, not storing credentials in GitHub would also have prevented this . . . [1] https://help.github.com/articles/requiring-two-factor-authen...

You couldn't enforce 2FA on GHE for the longest time. GHE version 2.8.0 lists [0] "Enforce two-factor authentication" as a feature. 2.8.0 was released November 2016. According to the article,

> Kalanick, Uber’s co-founder and former CEO, learned of the hack in November 2016, a month after it took place, the company said.

I don't know if they were using GHE. If they were, at the time it did not come with a good way for them to enforce 2FA for users.

[0] https://enterprise.github.com/releases/2.8.0

Re: Uber Paid Hackers to Delete Stolen Data on 57M People

#89
post #75

Earlier quoted context omitted.

Don’t let hypocrisy stop you from doing the right thing. Sometimes you need to climb one tree to cut down another.[1] That’s ok. [1] tbh I don’t think you do, but I like the analogy so I’m keeping it.

I disagree. One needs to be consistent in their actions, otherwise, what's the point? Two wrongs don't make a right, after all. EDIT: Er, I agree that hypocrisy shouldn't stop you from doing the right thing.

Consistency is absolutely impossible, as you already alluded to. It’s not a bad move to assess the current position, accept it for what it is, and improve it bit by bit. Pick your battles.

Two wrongs don’t make a right when you try to sum them, I.e. combine them. My point is: don’t compare them at all. Don’t change the subject. Uber is one, other things are another. Being a hypocrite doesn’t make you wrong, it just makes you a hypocrite. Don’t even pull in the other wrong to begin with.

Otherwise, how do you ever justify standing up for anything you believe in? I was born a hypocrite, surely a life of mute acquiescence can’t be my destiny?

Post reply on HN