Taxi Driver Online

UK cab trade debate and advice
It is currently Mon May 04, 2026 8:55 am

All times are UTC [ DST ]




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Fri Aug 21, 2020 7:36 pm 
Offline
User avatar

Joined: Wed Sep 03, 2003 7:30 pm
Posts: 57358
Location: 1066 Country
Uber ex-security boss accused of covering up hack attack

Uber's former chief security officer Joseph Sullivan has been charged with obstruction of justice in the US.

The 52-year-old is accused of trying to cover up a data breach in 2016 that exposed the details of 57 million Uber drivers and passengers.

The company has previously admitted to paying a group of hackers a $100,000 (£75,000) ransom to delete the data they had stolen.

Mr Sullivan was fired in 2017 when the data breach was revealed.

The charges filed by the US Department of Justice said Mr Sullivan had taken "deliberate steps" to stop the Federal Trade Commission (FTC) from finding out about the hack.

He is accused of approving the $100,000 payment to the hackers, which was made in bitcoin.

The payment was disguised as a "bug bounty" reward, used to pay cyber-security researchers who disclose vulnerabilities so they can be fixed.

The charges allege that he asked the hackers to sign non-disclosure agreements, falsely stating they had not stolen any Uber data.

"Silicon Valley is not the Wild West," said US lawyer David Anderson. "We expect good corporate citizenship. We expect prompt reporting of criminal conduct. We expect co-operation with our investigations. We will not tolerate corporate cover-ups."

A spokesman for Mr Sullivan said he denied the charges.

"If not for Mr Sullivan's and his team's efforts, it's likely that the individuals responsible for this incident never would have been identified at all," said spokesman Brad Williams.

Mr Sullivan currently works as chief information security officer at cyber-security firm Cloudflare.

Uber chief executive Dara Khosrowshahi disclosed the data breach in 2017. The company eventually paid $148m to settle legal claims by all 50 US states and Washington DC.

Analysis

When is a breach a breach?

This could be the key question facing the court in this case which will be watched closely by hackers and security experts around the world.

Mr Sullivan says he did nothing wrong and was simply rewarding the hackers a "bug bounty" for discovering a security flaw in Uber's system.

Many large companies have open bug bounty schemes that invite hackers - under strict conditions - to test their computer systems for flaws.

If they find one, they get paid and the company can fix it without needing to alert the authorities.

But these hackers did not approach Uber as part of a scheme. They broke into the systems anonymously, stole data and held the company to ransom.

Effectively, Mr Sullivan is being accused of turning a serious hack into a routine bug bounty, which was therefore not worth notifying the authorities or his company about.

The fact that the hackers themselves have already pleaded guilty to the cyber-attack may not help Mr Sullivan's case.

_________________
IDFIMH


Top
 Profile  
 
PostPosted: Mon Aug 24, 2020 8:04 am 
Offline
User avatar

Joined: Mon Mar 21, 2005 8:44 pm
Posts: 10591
Location: Scotland
Pity the hackers didnt turn their system off permanently.


Top
 Profile  
 
PostPosted: Mon Aug 24, 2020 11:58 am 
Offline
User avatar

Joined: Sat Apr 01, 2006 11:47 pm
Posts: 20863
Location: Stamford Britains prettiest town till SKDC ruined it
sounds about right for Uber but they are one of those Teflon coated organisations no matter how much muck you sling at them none of it sticks ! :wink:

_________________
lack of modern legislation is the iceberg sinking the titanic of the transport sector


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC [ DST ]


Who is online

Users browsing this forum: No registered users and 805 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group