Previous jihads against hardcoded credentials (use Vault or equivalent).
Next target after this will probably be Slack.
1 - https://slack.com/help/articles/360019110974-Slack-Enterpris...
Unless and until CEOs are held personally responsible for such security breaches there will be no solution to the problem. A Chief Security Officer job looks more and more as a designated scape-goat for hire.
You have to realize that a CEO is just an employee. An important employee, but like any other employee, he is paid to do a job, and can be fired if his employers are not satisfied with his work.
If we want to punish the people who have the ultimate responsibility, that would be the shareholders. And it may include you if you have stock in that company. The CEO could also be punished as a shareholder (CEOs usually are), but not as a CEO unless he commit fraud against the shareholders.
We could imagine prison sentences for the most important shareholders, but really, financial sanctions are the most fair. Shareholders will lose money proportional to their share. And if the CEO really is the problem, shareholders will be very unhappy and he won't last long and may even get sued.
So yeah not great, but also too much effort to pre-emptively revoke anything so I'll just hope that the fallout isn't too bad.
What I hated about Uber and why I never ended up using it was that their app wanted so much info from my phone for no discernibly good reason. And Lyft didn't seem to be much better. I just wanted a ride man, I didn't want a 500 MB app that sucked all the data out of my phone and sent it to god knows where.
So I've just ended up calling taxis.
It's not that your data won't get compromised by someone else, it's just about mitigating the exposure.
I acknowledge my tradeoffs wouldn't make sense for a frequent traveller.
Not to mention with Uber/Lyft, I know exactly where my driver is, I don’t have to flag down a taxi, I know the price before I sit in the car, etc.
And in the apple appstore it says 363MB size.
I don't know if apple calculates the unpacked and installed size or if it is the "download size" too.
Drivers seem to be hit with a PII breach though, and I’d have concerns if pickup and drop off locations were exposed, particularly for those where that information might be sensitive (e.g. journalists in some jurisdictions).
It sucks for my phone number but it won't be the first hack/leak where it is shown next to my name.
Not sure about the scope of the hack so I won't be canceling my card yet.
Is my credit card information compromised in a way that allows attackers stealing my money?
I only paid for their services using Apple Pay. Even if that number was compromised, the CVV would no longer be valid. I think most banks would automatically re-issue the account number (not the physical card number) if they detect fraudulent use.
The only time I saved a card to Uber was before the NFC era (pre-2015/2016). Those cards have long been removed from the account and have expired.
I am not too worried. Worst case scenario, they have my address and name. Which are both publicly available anyways.
Although maybe I shouldn’t be too complacent. If the data is sold, then it will make me more vulnerable to social engineering attacks. Albeit knowing Uber has been hacked I will be much more aware.
https://theguardian.com/technology/2022/sep/15/uber-computer...
Canceling cards preemptively is a nuclear option.
Uber is infamous for not following the law¹. There is at least one other known case of them not disclosing a data leak²:
> In 2016, hackers stole information from 57 million driver and rider accounts and then approached Uber and demanded $100,000 to delete their copy of the data. Uber arranged the payment but kept the breach a secret for more than a year.
¹ https://www.theguardian.com/news/2022/jul/10/uber-files-leak...
² https://www.nytimes.com/2022/09/15/technology/uber-hacking-b...
So, some people just accept whatever pushes they get.