news.volyx.in

Uber investigating breach of its computer systems (nytimes.com)

591 points by arkadiyt · 1455 days ago · 313 comments on HN

Article summary

Uber is investigating a breach of its computer systems, with reports suggesting that an attacker gained access to the company's VPN and then scanned the intranet to find a network share containing admin credentials. The breach may have been preventable with stronger security measures, such as webauthn or hardware 2FA. The incident highlights the importance of robust security practices, including defense in depth and zero-trust networks. The exact details of the breach are not yet publicly available.

Main themes

  • Uber breach
  • zero-trust networks
  • MFA security
  • cloud security
  • defense in depth
  • security best practices

What commenters say

  • The breach was likely caused by a combination of social engineering and inadequate security measures, such as a lack of webauthn or hardware 2FA.
  • Zero-trust networks are a crucial security measure, but their implementation can be complex and may be hindered by vendor buzzword garbage.
  • The use of MFA that is not based on Webauthn should be considered insecure, as it can be proxied by a sufficiently skilled attacker.
  • Implementing robust security measures, such as YubiKeys or Google Titan FIDO2 keys, can be challenging and requires significant retraining and resources.
  • Some companies may be overly reliant on cloud services and lack a clear plan for recovering from a breach.
  • The effectiveness of zero-trust networks depends on their proper implementation, which can be difficult to achieve in practice.
  • The breach highlights the need for companies to assume a breach will occur and have a plan in place for responding to it.