Homepage / Technology / Uber paid 20-year-old Florida man to keep data breach secret, sources said
Menyelami Dunia Slot Thailand: Keseruan dan Peluang Kemenangan Besar Menyelami Dunia Slot Thailand: Pengalaman Bermain yang Tak Terlupakan 1xbet Registration ᐉ 1xbet Sign Up برنامج المراهنات الرياضية تحميل التطبيق العميل Eg 1xbet Com 1xbet Apk 1xbet للموبايل حمل تطبيق 1xbet لأنظمة أيفون و أندرويد 1xbet مصر Eg 1xbet Com قم بتنزيل 1xbet على جهاز الكمبيوتر ، وكيفية تنزيل تطبيق سطح المكتب على جهاز الكمبيوتر Najlepsze kasyna bez depozytu 2025 Promozioni effettive di 22Bet in Italia Отзывы о казино Stake от реальных игроков 2025 о выплатах и игре Cassinos legais no Brasil: novas regras e melhores sites 1xbet 보너스 받는법 및 출금 롤링조건 등 사용법 총정리 온라인카지노 Kr Your Current Reliable Partner Regarding Tent Manufacturing Online Kaszinó Játékok És Élő Kaszinó Játékok En Güvenilir Canlı Bahis Empieza Casino Sitesi Игровые Автоматы На мнимые Деньги Играть Онлайн В Лучшие Слоты Find the right person: tips for effective singles dating over 60 Gamification : la limite entre jeu vidéo et casino en ligne se brouille Ufc 302 Gdzie Oglądać Za Darmo I Na Żywo? 2 06 24 ‎Casino ua online casino club on the App Store 1xbet تسجيل الدخول للجوال قم بتسجيل الدخول إلى حساب 1xbet الخاص بك “원엑스벳1xbet 프로모션 코드 2024: Jbmax Vip! Sweet Bonanza Ücretsiz Demonstration İle Oyun Deneyimi Verde Kaszinó: Új Kaszinó Oldal Rendkívüli Bónuszokkal! Türkiye Casino Sitelerinin Adresi 2024 En Iyi Türk Online Casino En Güncel Ve Güvenilir On Line Casino Ve Bahis Sitelerinin Adresi 2024 Listesi 1xbet 모바일 앱-어플 2024, 버전, 다운로드, 설치, Ios, 안 Diocesan Development Services To The Particular North Karamoja Dds-n Sai Dwaraka In Nessun Caso Tours & Travels Pin-up On Line Casino Türkiye En İyi Canlı Casino Oyunları Ve Slot Makineleri Strategies for making a bisexual woman feel very special and loved Diamond Casino Heist The Big Disadvantage Walkthrough Play 17, 800+ Cost-free Us Online On Line Casino Games No Get” Jouez au casino en ligne numéro un dans le monde 1xbet Login Guide » The Way To Sign Inside To Your 1xbet Account 2024 Better United kingdom Casinos One Undertake Credit card 1вин Бесплатно нет Регистрации Играть и Игровые Автоматы 1win Top Tips For Just How To Beat Slot Machines: Become A New Winner! 원엑스벳 도메인 주소 1xbet 우회접속 가입방법 안내 토크 Deneme Bonusu ile Ücretsiz Oyun Deneyimi Bahis Dünyasında Sıkça Yapılan Hatalar ve Çözümleri 1win Мобильное Приложение На Ios И Android бесплатно Скачать Ücretsiz Slot Oyunları Silvergames’te Çevrimiçi Oynayın ️ Επίσημη Ιστοσελίδα Στην Ελλάδα Casino Bahis Siteleri Ara 2024 Yasal Casinoların Listesi ️” Türkiye’nin En İyi Bahis Şirketi Ve On-line Casino 짱구카지노 공식 평생 도메인 주소 Demo Slot Sweet Bonanza’yı Oynayın: Arkadaşlarınızla Eğlenceli Anlar Yaşayın Meet sexy milfs who’re selecting fun 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации 1вин Игровые Слоты Казино Играть Бесплатно Без Регистрации لماذا يجذب كازينو 1xbet كبار اللاعبين المصريين؟ 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports 1xbet 독점 프로모션 코드 2024년 1월: Xnumxxcompletesports

Taya365 Casino Login⁚ A Comprehensive Guide

Isle Gambling Establishment Hotel Black Hawk Now Under Horseshoe Brand, Changes Label” Top True Money Casino Apps For 2025: Twelve Best Online Casinos Resmi Sitesi Çevrimiçi Oyna, Para İle Oyna 6 Ways To Start An Online Casino تنزيل تطبيق 1xbet قم بتثبيت تطبيق 1xbet للهاتف المحمول Get ready for the ultimate craigslist sex experience Stake Casino Russia официальный Сайт Для Онлайн Игр И Бонусов “bukmacherskie Zakłady Sportowe Najlepsze Oferty W Ggbet Sports Welcome on ultimate dating platform for ssbbw lesbians 1вин Казино ᐉ Вход а Регистрация На 1win Официальный Сайт 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win Encouraged Bonuses As Well As How To Work With Them In Bangladesh 1win: Spor Bahisleri Ve Internet Casino Bonus 500% Glory Casino On-line ️ Play With The Authorized Web Site In Bangladesh Тотал В Ставках На Спорт%3A не Такое И только Рассчитать Ставка Tv Mostbet Türkiye: En Iyi Oranlar Ve Spor Bahisleri Καζίνο Και Στοιχηματική Σε Έναν Ιστότοπο “1xbet App 1xbet Cellular ᐊ تنزيل 1xbet Apk Android و Iphone ᐊ 1xbet Com Get started on mature sex dating sites now “horseshoe Casino Baltimore Wikipedia Judi Online, Kenali Bahaya, Ciri-Ciri Kecanduan, dan Penanganannya Cassino Apresentando Bônus De Boas-vindas: Veja As Opções Disponíveis Casino Mostbet ᐈ Oficiální Stránky Online Kasin V České Republice Casino E Apostas Desportivas No Brasil Bônus 5000 Brl No Depósito Entrar Beginner’s Explained Casino Wagering: Tips & Strategies Beginner’s Explained Casino Wagering: Tips & Strategies Лучшие Букмекерские Конторы Онлайн Рейтинг Бк 2024 “Slot Machine Nedir? Türkiye’deki Çevrimiçi Slot Rehberi Keep Everything You Win At Usa No First Deposit Casinos “roleta Online Jogos De Roleta Virtual » Betfair Casino Лучшие Онлайн Казино Рейтинг Топ 10 Для Игры На 2024 день” 1xbet 보너스 사용법 알아보기 메인 계정과 보너스 계정의 차이 코리아벳 برنامج المراهنات الرياضية تحميل التطبيق العميل Eg 1xbet Com Коэффициенты Букмекеров%3A Что Такое же Как Рассчитать в Ставках На Спорт Лучшие Букмекерские Конторы Рейтинг Букмекеров Топ Бк 2024 Онлайн Ставки на Спорт Лучшие Букмекерские Конторы Рейтинг Букмекеров Топ Бк 2024 Онлайн Ставки на Спорт Mostbet Türkiye Çevrimiçi Kumarhane Mostbet Casino “топ Приложений Для Ставок На Спорт 2024%3A Букмекеры На Android И Ios “How To Play Roulette: Rules & Betting Как 1win Обзор Удовлетворяет Разнообразные Потребности Пользователей Os 15 Melhores Sites De Apostas Esportivas Gates of Olympus’ýn Slot Oyunlarýnda En Büyük ve Çarpýcý Ödüller Gates of Olympus ile En Ýyi, Karlý ve Avantajlý Kazanç Fýrsatlarý Gates of Olympus’ýn En Popüler ve Ödüllü Makineleri Největší Image Hazardu V Evropě: Proslulé Kasino Versus Monte Carlu Láká Na Neobyčejnou Atmosféru” Jak znaleźć legalne kasyno online? Mostbet Tr Resmî Net Sitesinde Giriş Empieza Kayıt Olm Our Cms Play 17, 800+ Totally Free Us Online Online Casino Games No Download” The Benefits of Learning a Second Language “australia’s #1 Online Gambling Establishment Guide 2024 Kde Sony Ericsson Natáčel Film On Line Casino Roya

Technology

Uber paid 20-year-old Florida man to keep data breach secret, sources said

A 20-year-old Florida man was responsible for the large data breach at Uber Technologies last year and was paid by Uber to destroy the data through a so-called “bug bounty” program normally used to identify small code vulnerabilities, three people familiar with the events have told Reuters.

Uber announced on Nov. 21 that the personal data of 57 million passengers and 600,000 drivers were stolen in a breach that occurred in October 2016, and that it paid the hacker $100,000 to destroy the information. But the company did not reveal any information about the hacker or how it paid him the money.

Uber made the payment last year through a program designed to reward security researchers who report flaws in a company’s software, these people said. Uber’s bug bounty service – as such a program is known in the industry – is hosted by a company called HackerOne, which offers its platform to a number of tech companies.

Reuters was unable to establish the identity of the hacker or another person who sources said helped him. Uber spokesman Matt Kallman declined to comment on the matter.

Newly appointed Uber Chief Executive Dara Khosrowshahi fired two of Uber’s top security officials when he announced the breach last month, saying the incident should have been
disclosed to regulators at the time it was discovered, about a year before.

It remains unclear who made the final decision to authorize the payment to the hacker and to keep the breach secret, though the sources said then-CEO Travis Kalanick was aware of the breach and bug bounty payment in November of last year.

Kalanick, who stepped down as Uber CEO in June, declined to comment on the matter, according to his spokesman.

A payment of $100,000 through a bug bounty program would be extremely unusual, with one former HackerOne executive saying it would represent an “all-time record.” Security professionals said rewarding a hacker who had stolen data also would be well outside the normal rules of a bounty program, where payments are typically in the $5,000 to $10,000 range.

HackerOne hosts Uber’s bug bounty program but does not manage it, and plays no role in deciding whether payouts are appropriate or how large they should be.

HackerOne CEO Marten Mickos said he could not discuss an individual customer’s programs. “In all cases when a bug bounty award is processed through HackerOne, we receive identifying information of the recipient in the form of an IRS W-9 or W-8BEN form before payment of the award can be made,” he said, referring to U.S. Internal Revenue Service forms.

According to two of the sources, Uber made the payment to confirm the hacker’s identity and have him sign a nondisclosure agreement to deter further wrongdoing. Uber also conducted a forensic analysis of the hacker’s machine to make sure the data had been purged, the sources said.

One source described the hacker as “living with his mom in a small home trying to help pay the bills,” adding that members of Uber’s security team did not want to pursue prosecution of an individual who did not appear to pose a further threat.

The Florida hacker paid a second person for services that involved accessing GitHub, a site widely used by programmers to store their code, to obtain credentials for access to Uber data
stored elsewhere, one of the sources said.

GitHub said the attack did not involve a failure of its security systems. “Our recommendation is to never store access tokens, passwords, or other authentication or encryption keys in the code,” that company said in a statement.

Uber received an email last year from an anonymous person demanding money in exchange for user data, and the message was forwarded to the company’s bug bounty team in what was described as Uber’s routine practice for such solicitations, according to three sources familiar with the matter.

Bug bounty programs are designed mainly to give security researchers an incentive to report weaknesses they uncover in a company’s software. But complicated scenarios can emerge when dealing with hackers who obtain information illegally or seek a ransom.

Some companies choose not to report more aggressive intrusions to authorities on the grounds that it can be easier and more effective to negotiate directly with hackers in order to limit any harm to customers.

Uber’s $100,000 payout and silence on the matter at the time was extraordinary under such a program, according to Luta Security founder Katie Moussouris, a former HackerOne executive.

“If it had been a legitimate bug bounty, it would have been ideal for everyone involved to shout it from the rooftops,” Moussouris said.

Uber’s failure to report the breach to regulators, even though it may have felt it had dealt with the problem, was an error, according to people inside and outside the company who spoke to Reuters.

“The creation of a bug bounty program doesn’t allow Uber, their bounty service provider, or any other company the ability to decide that breach notification laws don’t apply to them,” Moussouris said.

Uber fired its chief security officer, Joe Sullivan, and a deputy, attorney Craig Clark, over their roles in the incident.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi, said in a blog post announcing the hack last month.

Clark worked directly for Sullivan but also reported to Uber’s legal and privacy team, according to three people familiar with the arrangement. It is unclear whether Clark informed Uber’s legal department, which typically handled disclosure issues.

Sullivan and Clark did not respond to requests for comment.

In an August interview with Reuters, Sullivan, a former prosecutor and Facebook security chief, said he integrated security engineers and developers at Uber “with our lawyers and our public policy team who know what regulators care about.”

Last week, three more top managers in Uber’s security unit resigned. One of them, physical security chief Jeff Jones, later told others he would have left anyway, sources told Reuters.

Another of the three, senior security engineer Prithvi Rai, later agreed to stay in a new role.

Source: Tech CNBC
Uber paid 20-year-old Florida man to keep data breach secret, sources said

Comments are closed.