Homepage / Technology / Uber paid 20-year-old Florida man to keep data breach secret, sources said
Le Jeu en Ligne en France: Casinos en Ligne et leur Rфle dans l’Industrie Moderne des Jeux d’Argent Mostbet App A Convenient And Reliable Way To Place Bets Masjid Al-Huda Mranggen Demak Lemon Casino recenzja nowego polskiego kasyna Atrakcyjne bonusy i wysoki RTP! MostBet Bangladesh BD ᐉ Official Site Most Bet Casino and Sport Betting Lil Nas X calls out the BET Awards in his new single He has a point : NPR Most readily useful Adult Internet Dating Sites | FreeHookupsSites Unlocking the secrets of craigslist m4m green bay dating Just what comes in 66 sizes and vegan latex? Brand new generation of condoms | Sex | 8 Brands & Generics Human Growth Hormone HGH Injections Find local black hookups near you what’s ssbbw chat? About Japanese Dating society and also the west Guy who would like to Date a Japanese woman – MeetKing Blog 9 Guidelines On How To Hook-up On College Gameday (At Any College) Leading Live Casino Games Provider Leading Live Casino Games Provider Pin Up Slotlarýyla Eðlence ve Para Kazanma Bir Arada The core concept of digital entertainment hub AbeBet: signature points and groups Live-сессии с дилерами в онлайн-казино azino777 How Online Gambling Enterprises Operate Around the World Meet compatible single mothers and exchange ideas official site Play airplane online Ritalin: Jak legálně zakoupit bez receptu v České republice Connect with suitable asian singles in your area How-to Date A Pornstar While Making It Operate (The Ultimate Guide) Buy Bitcoin with Credit Card or Debit Card Instantly Buy Bitcoin How to buy BTC Finding trans girls near you – the simplest way to hookup Connect with like-minded singles on a mennonite dating website Assortment of in-demand games respected casino platform abe bet casino in cyberspace Connect with girls from round the world Alexander Gambling establishment: Dйcouvrez une Nouvelle Expйrience de Jeu en Ligne Le meilleur Extra casino en ligne pour jouer BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING The simplest way to get a local hookup what’s millionairess dating? Get prepared to connect to latinas whom share your interests Estonian Chat place – an ideal Place for Dating Estonian Singles Join our bisexual chat room now and commence connecting Discover the advantages of dating a mature mom latina How to discover the best bbw hookup app for you Title: Juega en 1Win Casino Argentina Bonos y Apuestas 5 Best BBW Lesbian Dating Apps/Sites In 2022 Online Gambling Review submissions dia govt.nz Разыгрываемые джекпоты в виртуальном клубе Вулкан казино 30 Of The Greatest Adult Sex Toys For Males | Men’s Room Health Mag Australian Continent Cazino 7 slots cyberspace: conditions and rules for betting with real cash 1Win: ¡el mejor lugar de casino y apuestas deportivas de Argentina! Aufcasino ????Mature Dating Evaluation 2023 – Whatever You Need To Know About It! ???? Take the first step towards fulfilling your ebony lesbian bbw match now Ideas on how to come-out: Tips to keep in mind > Taimi Meet your perfect match – granny hookup site Türkiye-Çin İşbirliği Derinleşiyor GuGi Mobil Yükleme Seçenekleri Hizmet İçi Eğitim Sona Erdi Dooball tv ดูบอล ออนไลน์ สด 66 ลิงค์ บนมือถือ ฟรี ภาพชัด HD ทั่วโลก Find your rich cougar date in the most useful dating site Find your dream fat girl hookup today Slot Thailand Daftar Link Situs Slot Gacor Maxwin x500 Terbaru Hari Ini Resmi Auto Jackpot! Konsultasi ke Dewan Pers, Komisi I DPRD Jambi Pertanyakan Indeks Kemerdekaan Pers Jambi yang Turun Akses News Cerita Korban Judol di Balikpapan yang Nekat Gelapkan Uang How to get local horney women in your area 3 Cara Hapus Akun Judi Online Slot : Okezone Economy SITUS TOTO > Sering Kalah Main Di Situs Slot Gacor Terbaru Mudah Maxwin Situs Slot Gacor Maxwin Main Tanpa Pola Modal 5ribu Terbaik Melhores cassinos online de Novembro 2024: Confira o top 10! Enjoy amazing gay sex experiences using the top sites on the web Make the absolute most of one’s big butt dating adventure here 9 circumstances this means when a person avoids eye contact with a lady – Hack Spirit Top Greatest M4M Personals Sites in 2022 ◉ BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING Лотерейные розыгрыши в kasino on-line Лев казино: условия осуществления и доступа Main features of playing in machines at online-club Karavan Connect with like-minded females making new friends Comment accéder à des jeux gratuits avec Space fortuna bonus ? PUCUK4D⭐ Bandar Toto Togel Online & Situs Toto 4d Terpercaya #1 Betting site Karavan bet Gates of Olympus internet-based: benefits of playing for real money Discover an environment of opportunities with lesbian and bisexual dating Aprovecha Los Códigos Promocionales De Bbrbet ¡más Bonos, Más Juegos 1xbet Giriş Yeni Adresi 2024 ⭐️ 1xbahis Güncel Adres » 1x Guess Mobil Casino How to get started with sext room BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING La Application De Bbrbet: Juegos Y Apuestas Approach Alcance De Tu Man Start your love story now – join our talk to gay strangers source today BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING Find regional bbw hookups inside area BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING BLACK SEO LINKS, BACKLINKS, SOFTWARE FOR MASS BACKLINKING The Brazilian Bum Bum Lotion: Introducing the Keys of its Elegance Advantages

Technology

Uber paid 20-year-old Florida man to keep data breach secret, sources said

A 20-year-old Florida man was responsible for the large data breach at Uber Technologies last year and was paid by Uber to destroy the data through a so-called “bug bounty” program normally used to identify small code vulnerabilities, three people familiar with the events have told Reuters.

Uber announced on Nov. 21 that the personal data of 57 million passengers and 600,000 drivers were stolen in a breach that occurred in October 2016, and that it paid the hacker $100,000 to destroy the information. But the company did not reveal any information about the hacker or how it paid him the money.

Uber made the payment last year through a program designed to reward security researchers who report flaws in a company’s software, these people said. Uber’s bug bounty service – as such a program is known in the industry – is hosted by a company called HackerOne, which offers its platform to a number of tech companies.

Reuters was unable to establish the identity of the hacker or another person who sources said helped him. Uber spokesman Matt Kallman declined to comment on the matter.

Newly appointed Uber Chief Executive Dara Khosrowshahi fired two of Uber’s top security officials when he announced the breach last month, saying the incident should have been
disclosed to regulators at the time it was discovered, about a year before.

It remains unclear who made the final decision to authorize the payment to the hacker and to keep the breach secret, though the sources said then-CEO Travis Kalanick was aware of the breach and bug bounty payment in November of last year.

Kalanick, who stepped down as Uber CEO in June, declined to comment on the matter, according to his spokesman.

A payment of $100,000 through a bug bounty program would be extremely unusual, with one former HackerOne executive saying it would represent an “all-time record.” Security professionals said rewarding a hacker who had stolen data also would be well outside the normal rules of a bounty program, where payments are typically in the $5,000 to $10,000 range.

HackerOne hosts Uber’s bug bounty program but does not manage it, and plays no role in deciding whether payouts are appropriate or how large they should be.

HackerOne CEO Marten Mickos said he could not discuss an individual customer’s programs. “In all cases when a bug bounty award is processed through HackerOne, we receive identifying information of the recipient in the form of an IRS W-9 or W-8BEN form before payment of the award can be made,” he said, referring to U.S. Internal Revenue Service forms.

According to two of the sources, Uber made the payment to confirm the hacker’s identity and have him sign a nondisclosure agreement to deter further wrongdoing. Uber also conducted a forensic analysis of the hacker’s machine to make sure the data had been purged, the sources said.

One source described the hacker as “living with his mom in a small home trying to help pay the bills,” adding that members of Uber’s security team did not want to pursue prosecution of an individual who did not appear to pose a further threat.

The Florida hacker paid a second person for services that involved accessing GitHub, a site widely used by programmers to store their code, to obtain credentials for access to Uber data
stored elsewhere, one of the sources said.

GitHub said the attack did not involve a failure of its security systems. “Our recommendation is to never store access tokens, passwords, or other authentication or encryption keys in the code,” that company said in a statement.

Uber received an email last year from an anonymous person demanding money in exchange for user data, and the message was forwarded to the company’s bug bounty team in what was described as Uber’s routine practice for such solicitations, according to three sources familiar with the matter.

Bug bounty programs are designed mainly to give security researchers an incentive to report weaknesses they uncover in a company’s software. But complicated scenarios can emerge when dealing with hackers who obtain information illegally or seek a ransom.

Some companies choose not to report more aggressive intrusions to authorities on the grounds that it can be easier and more effective to negotiate directly with hackers in order to limit any harm to customers.

Uber’s $100,000 payout and silence on the matter at the time was extraordinary under such a program, according to Luta Security founder Katie Moussouris, a former HackerOne executive.

“If it had been a legitimate bug bounty, it would have been ideal for everyone involved to shout it from the rooftops,” Moussouris said.

Uber’s failure to report the breach to regulators, even though it may have felt it had dealt with the problem, was an error, according to people inside and outside the company who spoke to Reuters.

“The creation of a bug bounty program doesn’t allow Uber, their bounty service provider, or any other company the ability to decide that breach notification laws don’t apply to them,” Moussouris said.

Uber fired its chief security officer, Joe Sullivan, and a deputy, attorney Craig Clark, over their roles in the incident.

“None of this should have happened, and I will not make excuses for it,” Khosrowshahi, said in a blog post announcing the hack last month.

Clark worked directly for Sullivan but also reported to Uber’s legal and privacy team, according to three people familiar with the arrangement. It is unclear whether Clark informed Uber’s legal department, which typically handled disclosure issues.

Sullivan and Clark did not respond to requests for comment.

In an August interview with Reuters, Sullivan, a former prosecutor and Facebook security chief, said he integrated security engineers and developers at Uber “with our lawyers and our public policy team who know what regulators care about.”

Last week, three more top managers in Uber’s security unit resigned. One of them, physical security chief Jeff Jones, later told others he would have left anyway, sources told Reuters.

Another of the three, senior security engineer Prithvi Rai, later agreed to stay in a new role.

Source: Tech CNBC
Uber paid 20-year-old Florida man to keep data breach secret, sources said

Comments are closed.