Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And Uber does not give a damn!

In 2015 my Uber account was hacked and 1k was taken from my bank account. Uber knew/knows about their users getting hacked and their PR was it's the users fault for using a bad password. Also then I tried to cancel my Uber account via their site but there is no option that lets the user do so only can be done by contacting/waiting for a support person to do so. It took them a few days to cancel my account.

Needless to say I loathe then for this reason followed by all their other horrid behavior!



I don't see how it's Uber's fault if someone finds out your password.

I think it's nice of Uber that they refunded OP's trips even though it wasn't their fault that OP's account was compromised. And it makes sense that they just suggested using a strong password. What else could they do?


> even though it wasn't their fault that OP's account was compromised

The article strongly suggests this isn't the case, though. OP had TFA active, but Uber allowed access to his account without without requiring the passcode they texted him. We don't know exactly what happened, because the support rep dodged the TFA question every time, but it doesn't appear to be a proper outcome.


They could fix the security vulnerability that allowed authentication of a new device without the 2nd factor of authentication.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: