Feb 8, 2018

Uber security contractor discusses lesson from 2016 breach

Uber CISO John Flynn (foreground) and HackerOne CEO Marten Mickos (rear) testify before the Senate. (Bloomberg)

Marten Mickos, the CEO of security firm HackerOne, said his company might begin advising clients to include proper legal representation when testing the limits of cybersecurity laws after its client Uber's botched response to a 2016 data breach.

"We need to start advising customers about who to have in the room," he told Axios.

Mickos spoke to Axios after testifying at a Tuesday Senate hearing on the Uber breach that also featured Uber Chief Information Security Officer John Flynn.

  • Flynn admitted that Uber concealed the data breach, netting data on more than 50 million people, by paying a hacker to delete stolen data using funds from a so-called bug bounty program run by HackerOne.
  • The problem: Those programs offer rewards for good guy hackers to research security flaws in products and websites and alert the manufacturer, giving the vendor a chance to fix the problem. But the Uber hacker was an extortionist holding data hostage, not a bounty participant. Claiming it was a bug bounty and not a breach, Uber did not notify consumers for more than a year that their data had been stolen.
"There is no justification for that. We should have notified consumers…We did not have the right people in the room," Flynn said at the hearing.

Where HackerOne fits in: HackerOne runs the platform Uber uses for its bounty program. It does not decide whether or not to notify consumers on behalf of Uber and, in this case, did little more than transfer the funds. But Mickos, who also testified Tuesday, recognized that customers may not have been prepared to handle an extortion attack.

Who are the right people? Breach notification laws are complicated. There is no federal standard; 48 states have their own laws, as well as D.C. and the protectorates. Mickos said that the right people must include a specialized lawyer who can navigate the thorny environment.

Go deeper

Backed by the Fed, bond investors get bullish

Illustration: Sarah Grillo/Axios

The Fed's massive injections of liquidity have reopened much of the bond market, and after back-to-back weeks in which more than $100 billion flowed out of bond funds, investors have regained their bearings and now see opportunity.

What's happening: But after the hemorrhaging outflows relented last week, bulls may now be sticking their heads out a bit too far. Junk bond funds took in more than $7 billion for the week ended April 1, according to Refinitiv Lipper, setting a new weekly record.

What top CEOs fear telling America about the coronavirus shutdown

Illustration: Eniola Odetunde/Axios

Top CEOs, in private conversations and pleas to President Trump, are warning of economic catastrophe if America doesn't begin planning for a phased return to work as soon as May, corporate leaders tell Axios.

Why it matters: The CEOs say massive numbers of companies, big and small, could go under if business and government don't start urgent talks about ways groups of workers can return.

Health care workers vs. the coronavirus

Photo Illustration: Sarah Grillo/Axios. Photos: ANGELA WEISS/AFP via Getty Images, Bruce Bennett/Getty Images, and Europa Press News/Europa Press via Getty Images

Health care workers are at an especially high risk of catching the coronavirus, because of their prolonged exposure to patients who have it. Making matters worse, the U.S. doesn't have enough of the protective equipment, like masks and gloves, that keeps them safe.

And yet these workers, with loved ones of their own, keep showing up at hospitals across the country, knowing that more Americans than they can possibly care for are depending on them.

Go deeperArrow3 hours ago - Health