Perhaps they just don't care about security?
Perhaps they just don't care about security?
For decades I've been told that security through obscurity is no security at all, but in the back of my mind, I think it might be the best thing I've got going for me working at a small place. Though I should say, that's far from being our only security - we do work at it too.
If I'm thinking about it, I can be assured that someone with differing motivations likely already has, or soon will be thinking about the same.
Small startups and businesses can absolutely get it right. It's usually much easier, with a small number of people and systems involved. You just have to approach it knowing it will take work every day. Some things will be harder than you want them to be. It will be worth it to avoid this kind of stuff.
In a well run organization it takes a lot more than that. There were a dozen steps in this exploit chain where it could have been detected and blocked. Likely Uber didn't care about security and their security team lacked both political power and resources.
Just don't rely on only that layer, and watch out for oddly quiet individuals named Sam Sepiol.
Developers do not give a shit. Security is not something they're trained in, interested in, or competent in (though they often think they are).
Security is a couple of people trying to bucket out the water as fast as they can from every sinking ship while developers are taking a piss on the floor and poking holes in the hull.
I think the bar for devs is extraordinarily low and we'll keep seeing this sort of thing until it we collectively raise it. Thankfully it seems like, very recently, this is starting to maybe happen. Packages requiring 2FA is the first thing I've seen that seems to indicate that developers are going to have to do the bare minimum for security in order to participate.
Believe it or not, it's much easier to successfully phish a big company where you have unlimited pool of emails to tap into.