Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Denver news in your inbox

Catch up on the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Des Moines news in your inbox

Catch up on the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Minneapolis-St. Paul news in your inbox

Catch up on the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tampa Bay news in your inbox

Catch up on the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Charlotte news in your inbox

Catch up on the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Uber CISO John Flynn (foreground) and HackerOne CEO Marten Mickos (rear) testify before the Senate. (Bloomberg)

Marten Mickos, the CEO of security firm HackerOne, said his company might begin advising clients to include proper legal representation when testing the limits of cybersecurity laws after its client Uber's botched response to a 2016 data breach.

"We need to start advising customers about who to have in the room," he told Axios.

Mickos spoke to Axios after testifying at a Tuesday Senate hearing on the Uber breach that also featured Uber Chief Information Security Officer John Flynn.

  • Flynn admitted that Uber concealed the data breach, netting data on more than 50 million people, by paying a hacker to delete stolen data using funds from a so-called bug bounty program run by HackerOne.
  • The problem: Those programs offer rewards for good guy hackers to research security flaws in products and websites and alert the manufacturer, giving the vendor a chance to fix the problem. But the Uber hacker was an extortionist holding data hostage, not a bounty participant. Claiming it was a bug bounty and not a breach, Uber did not notify consumers for more than a year that their data had been stolen.
"There is no justification for that. We should have notified consumers…We did not have the right people in the room," Flynn said at the hearing.

Where HackerOne fits in: HackerOne runs the platform Uber uses for its bounty program. It does not decide whether or not to notify consumers on behalf of Uber and, in this case, did little more than transfer the funds. But Mickos, who also testified Tuesday, recognized that customers may not have been prepared to handle an extortion attack.

Who are the right people? Breach notification laws are complicated. There is no federal standard; 48 states have their own laws, as well as D.C. and the protectorates. Mickos said that the right people must include a specialized lawyer who can navigate the thorny environment.

Go deeper

Updated 12 hours ago - Politics & Policy

Coronavirus dashboard

Illustration: Eniola Odetunde/Axios

  1. Health: Most vulnerable Americans aren't getting enough vaccine information — Fauci says Trump administration's lack of facts on COVID "very likely" cost lives.
  2. Politics: Biden unveils "wartime" COVID strategyBiden's COVID-19 bubble.
  3. Vaccine: Florida requiring proof of residency to get vaccine — CDC extends interval between vaccine doses for exceptional cases.
  4. World: Hong Kong to put tens of thousands on lockdown as cases surge.
  5. Sports: 2021 Tokyo Olympics hang in the balance.
  6. 🎧 Podcast: Carbon Health's CEO on unsticking the vaccine bottleneck.

Trump impeachment trial to start week of Feb. 8, Schumer says

Senate Majority Leader Chuck Schumer. Photo: The Washington Post via Getty

The Senate will begin former President Trump's impeachment trial the week of Feb. 8, Majority Leader Chuck Schumer announced Friday on the Senate floor.

The state of play: Schumer announced the schedule after reaching an agreement with Republicans. The House will transmit the article of impeachment against the former president late Monday.

13 hours ago - Health

CDC extends interval between COVID vaccine doses for exceptional cases

Photo: Joseph Prezioso/AFP via Getty

Patients can space out the two doses of the coronavirus vaccine by up to six weeks if it’s "not feasible" to follow the shorter recommended window, according to updated guidance from the Centers for Disease and Control and Prevention.

Driving the news: With the prospect of vaccine shortages and a low likelihood that supply will expand before April, the latest changes could provide a path to vaccinate more Americans — a top priority for President Biden.