Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Placing all of the blame on an individual removes the opportunity to improve things.

It seems to me that there's another option. Describe the problem thusly:

> A Lyft employee grabbed our data storage access keys from Github. He, or someone else then used these keys to grab PII that Uber was legally required to safeguard. Uber management and/or legal actively worked to cover all of this up and mislead the FTC about the nature and size of the breach.

>

> Given these facts, what processes and procedures can we change or create to ensure that the PII we're charged with safeguarding remains safe and guarded, that any threat to or breach of said information is detected as soon as is reasonably possible, and that any attempts of management and/or legal to cover up any such incidents are detected and reported to the appropriate authorities?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: