Former Uber executive charged with paying 'hush money' to conceal breach
npr.org
npr.org
- Hackers downloaded a bunch of PII from Uber
- Uber CISO paid them a 100k bounty with bitcoin to sign an NDA with their hacking handles, but they wouldn't give real names
- Uber staff traced them down, found their real names, then met them in person and got them to sign NDAs with real names
- FTC is mad because CISO tried to make it seem like it wasn't a data breach vs bug report through the bounty program.
- Their 2014 breach was from "an AWS access ID and secret key in software code posted to GitHub"
- In 2016 to FTC "SULLIVAN elaborated that it was common at the time to write access IDs and other secrets directly into code when that code needed to call for information from another service." - oof
- SULLIVAN received an email from “johndoughs@protonmail.com” claiming to have found a “major vulnerability in uber,” and that “I was able to dump uber database and many other things.”
- in 2016 breach, the hackers used to stolen credentials to... get the AWS keys that were still in their github code, but was now private
-"Similarly, Uber argued that the industry at large had become more adept since 2014 at protecting private data in the cloud, and that Uber should not be judged for “what a company did then (back when the company was much smaller and the technology at issue was evolving) according to the standards that the agency thinks are appropriate now (given the current sophistication of the company and current industry best practices).” Uber made these arguments via letter in April 2017, approximately five months after the 2016 Breach."
https://assets.documentcloud.org/documents/7041237/Joseph-Su...
I've been hearing this argument for decades, and every time it's been earnest but transparent blame-shifting. "The industry didn't understand security risks back then." "No one could have predicted this." The risks were well known back then by anyone who cared about risks.
18 U.S. Code § 1505. Obstruction of proceedings before departments, agencies, and committees -- [...] Whoever corruptly, or by threats or force, or by any threatening letter or communication influences, obstructs, or impedes or endeavors to influence, obstruct, or impede the due and proper administration of the law under which any pending proceeding is being had before any department or agency of the United States, or the due and proper exercise of the power of inquiry under which any inquiry or investigation is being had by either House, or any committee of either House or any joint committee of the Congress—
Shall be fined under this title, imprisoned not more than 5 years or, if the offense involves international or domestic terrorism (as defined in section 2331), imprisoned not more than 8 years, or both.
18 U.S. Code § 4. Misprision of felony -- Whoever, having knowledge of the actual commission of a felony cognizable by a court of the United States, conceals and does not as soon as possible make known the same to some judge or other person in civil or military authority under the United States, shall be fined under this title or imprisoned not more than three years, or both.
18 USC § 4 is independent of any federal investigation, unlike § 1505. The complaint itself lists quite damning facts. Have a read, it's quite readable. [0]
[0] https://assets.documentcloud.org/documents/7041237/Joseph-Su...
"The panel affirmed the long-established federal rule that “[t]o establish misprision of a felony,” under 18 U.S.C. § 4, “the government must prove beyond a reasonable doubt: ‘(1) that the principal . . . committed and completed the felony alleged; (2) that the defendant had full knowledge of that fact; (3) that he failed to notify the authorities; and (4) that he took affirmative steps to conceal the crime of the principal.”"
[0] https://www.whitecollarbriefly.com/2017/06/07/9th-circuit-cl...
Edit: I was convinced by the arguments. I was holding onto old idea of him. Clearly things have changed.
It is impressive that he’s avoided any criminal or civil suits. I don’t know that he’s guilty of anything, but with the number of scandals swirling around him it’s surprising that someone hasn’t at least tried to sue him.
Neither person raised their voice or cursed, and I guess you can call it arguing but I did not see anything that was inappropriate behavior.
We are disagreeing right now, and maybe one of us has even been drinking -- does that mean that we are now ineligible to be CEOs?
This is not a forest fire, it's a nuclear reactor breach caused by greedy and irresponsible leaders.
Because the VC's funded Uber precisely because they knew that Kalanick was an asshole?
The people who gave him money did so with the expectation that he would pull out all the stops to become a mega-monopoly.
To top it off, Kalanick had been screwed by VC's before, so he made a particular point to structure stock ownership in such a way that he kept control. It's still not clear what deals were made to actually get him to go away.
Finally, I expect that Kalanick probably knows where all the bodies are buried. So, he probably knows even more shady things that were going on than have been exposed. So, he has leverage.
"Sad to see Joe Sullivan allegations. Joe's had a distinguished career as a US Attorney & exec at eBay, PayPal, Facebook, Uber & Cloudflare. Anytime an opportunity arose, Joe's advocated for us to be as transparent as possible. I hope this is resolved quickly for Joe & his family."
[1]: https://twitter.com/eastdakota/status/1296522269313785862
I just don't understand this sort of detachment.
Optics are not of essence.
If he lies and covers up in the interest of his employer, that's a pretty good recommendation.
Implications that this is an actual breach are large. Does that mean if I hire a red team of independent consultants and they managed to gain access to one of my backups, i have to report it as a breach? Thats the worst case scenario.
The best case scenario is all companies have to pull bug bounty programs because any bug found is now considered a breach. This actually very bad for the industry. Bug bounties are very effective part of a comprehensive strategy to safe guard customer data.
These hackers were not participants in the bugbounty program, and extorted money from Uber. They were not in anyway "consultants", even retroactively.
But that's not the issue at hand here, the issue at hand is the cover-up while Uber was being investigated about a similar breach.
It is also curious that HackerOne was the middleman here. I do wonder how much they knew of what was going on.
https://www.hackerone.com/resources/reporting/the-2020-hacke... says they paid out $40mil in 2019 and undoubtedly would have been much smaller in 2016. This would have been a whale for them and their cut.
Is there a way to determine that your credentials are sufficient to download an S3 object without actually downloading it?
How would you know whether you'd found an information disclosure vulnerability without peeking at the information?
Outside of that, if you're "peeking" at information that doesn't belong to you, you immediately stop, document, and submit the report. You do not download 14,000 files as the Uber hackers did.
This is a non-trivial amount of nuance that clearly shows the hackers were not acting in good faith.
We don't know all of the specifics here, but for the feds to go after it one must assume that there was mens rea for the underlying offense (i.e., the hackers were in fact black hat) and there was actual harm (i.e., the hackers kept the stolen data and either intended to or did in fact use it for criminal purposes).
And in order to go after charges of obstruction and misprision, the DoJ must also believe that Sullivan was clearly aware that this behavior was criminal, and he intentionally sought to cover it up. This isn't much of a stretch because the FTC was probing it, so there was ample opportunity for him to respond incorrectly (and, allegedly, criminally) to FTC's questions during their probe.
I think you’d need a lot more information to draw a reasonable conclusion. That said the prosecutors arguments that $100,000 is so much that it implies criminality, and that NDAs are non-standard (or that they also imply criminality) is complete and utter BS, and instantly makes me incredibly skeptical of the theories they’re operating on.
https://www.justice.gov/usao-ndca/pr/former-chief-security-o...
Doesn't seem like a bug bounty when you're being demanded to pay something, and when you're later asked about it you conceal, deflect and mislead about it.
Plus, I think the messaging between Sullivan and Kalanick more than proves mens rea. It's possible Sullivan does have a "it was someone else's decision" argument, but not that everybody at Uber thought that what they were doing was above board.
IMO, the "real" crime stems from his actions to hide / cover up the hack and payoffs and -- probably more importantly -- explicitly and outright lying to the federal government.
They really don't like that at all.
---
It's possible that this is also, at least in part, an attempt to go after others at Uber (if they have reason to believe there was other criminal behavior taking place).
I cannot imagine how doing business in the US is like given that I feel there are many more laws they can throw at you than where I live, but I know that in my firm have we many meetings on all kinds of levels with supervisors that are frankly quite open. You need good relationships with supervisors and good relationships build on openness. If we were ever to have a serious data breach the first call would be an impact assessment and notification under GDPR, the second call nearly at the same moment would be reaching out to our other (mostly financial) supervisors.
There has to be more to this story. I feel like he was probably railroaded by Uber's legal team/CEO and they did things he may not have been fully aware of. That's the only explanation I can come up with.
I look forward to him having his day in court to vindicate himself.
I don't know whether Uber had a proper bug bounty program setup at the time this happened, nor whether this could be considered one, so I can't comment on the specifics.
In particular, part of Sullivan's cover-up efforts included passing the breach off as a $100,000 bug (their largest at the time) in the bounty program and trying to sign secret NDAs with the hackers. He also paid them a bitcoin ransom.
> Witnesses reported SULLIVAN was visibly shaken by the events.
It's a good read.
1) https://web.archive.org/web/20200414123312/http://www.ubersc...
2) https://arstechnica.com/tech-policy/2017/12/new-letter-top-u...
Puzzling case, as the hackers apparently moved on from Uber to hack other companies. Not something within Uber's control.
What appears to be making this a big deal is that Uber had been hacked several years prior, and was negotiating with the FTC over the breach; the 2016 breach was not timely disclosed to the FTC, despite formal statements being provided after the breach occurred.
Misleading the FTC is pretty clearly something that was under Uber's control.
When we see accounts of someone that strongly conflict with our accounts of that person, our inclination is to believe that our view of that person is the "right" one. This is just an artifact of human's natural sensory self-centrism: you can only see him as the person you have seen him as.
The likely truth, about everyone, is that like a 3D object viewed from a single vantage point, that no one person ever truly knows another.
And obviously, everyone deserves their day in court.
With the hackers' identities known, Uber or Sullivan is able to use the threat of exposing their crime as leverage if they should notice that the PII is being exploited. The 100k doesn't make single-game game-theoretic sense but can guard against people who expect a tit-for-tat.
I've read that if you start to get involved in a legal issue at work like this, you need to get your own lawyer and keep your mouth shut.
That also makes this statement kind of absurd...
"The spokesperson said Uber's legal team, rather than Sullivan, was responsible for deciding whether and to whom the matter should be disclosed."
I never worked with him. That personal anecdote does not exonerate him at all but it does give me second thoughts. Truth is nuanced sometimes.
Same. My initial thought was that Uber threw him under the bus. I still think that.
So the indictment sounds bad, but at this point I'm willing to give the benefit of the doubt and wait to find out the other side of the story.
https://blog.valerieaurora.org/2017/07/18/the-al-capone-theo...
Basically it states that for a long time, sexual harassers were given a blind eye with excuses like "he's good for our bottom line." But it turns out this isn't true. It turns out people who act unethically in one way often act unethically in other ways, that (among other things) hurt the bottom line.
Hopefully eastdakota is preparing a statement about his departure.
I’m saying that is the right thing to do, as opposed to instantly firing someone when there is only an allegation.
Although even in this case, I don’t think it warrants termination (unless he is physically unable to remain in the job because he is in prison, which would be a shame).
There is nothing wrong with paying a ransom, contrary to what the title implies. That’s not his crime. Those less familiar with the ransomware epidemic, and before that, the DDoS extortion/protection racket, might be surprised to hear that paying ransoms is not uncommon.
His alleged crime was essentially failing to disclose the breach. It’s not clear how much of that direction came from above him. Travis obviously knew about it at minimum, and he obviously did not direct him or Uber to disclose it.
It’s not difficult to imagine a complicated scenario where he was essentially in a position to be a whistleblower and forfeit his stock, also potentially damaging his reputation and ability to get a new job (doing the ‘right thing’ can still be career suicide), or just do what he was told.
That doesn’t absolve him of guilt in the eyes of the law, but good people make mistakes too, and this one would not seem to reveal anything that could jeopardize his current company. Again, he did not conceal it from the CEO, so presumably if he made that particular mistake at cloudflare, the CEO would direct him not to cover it up.
There could be other explanations as well. He hasn’t had an opportunity to present a defense. We only have the complaint, which is by design as adversarial and one-sided as possible.
I'm not saying he should be let go at Cloud Flare or not. I'm saying that the suggestion isn't somehow out of bounds.
> Tesla then hired a new senior manager of Global Security named Nick Gicinto. He was told that Gicinto and team were “spying on Tesla employees using devices to monitor emails, cell phones, and data communications from Tesla employees. Hansen expressed concern to his supervisors regarding what he believed was illegal conduct.”
> In fact, Gicinto and his team allegedly used these same tactics at Uber under Jeff Jones, former head of security who was also hired at Tesla with another security employee Jacob Nocon.
> In a lawsuit filed in the United States District Court, District of Northern California, Waymo LLC v. Uber Technologies, Inc., (Case No.:17-cv-00939-WHA). Jones, Gicinto, and Nocon all “allegedly engaged in numerous illegal methods of investigations such as wiretapping and hacking.” These behaviors are all outlined in the “Jacob’s Letter” filed in this case.
https://patriotssoapbox.com/business/tesla-whistle-blower-al...
I would like that to be true, but everything I've read indicates otherwise. Uber, Google, Facebook, banks, and credit bureaus have my personal information, but I am not the owner of that information. I've been told that they own it, at least under U.S. laws. If I do own it, why can't I demand that credit bureaus delete all my personal information?
The quote comes from the prosecutor of the Uber executive. If anyone should know the law regarding who owns your personal information, he should. Is he right or wrong?
[1] https://www.justice.gov/usao-ndca/pr/florida-man-and-canadia... [this was a link in the featured article]
Anonymity does not exist in finance, at least not between you and the institutions warding the money and the authorities they are regulated by. Though they are also (allegedly?) tightly controlled on what they can/cannot do with this personal info.
Frankly it couldn't work if it did because it would be rife with crime (<edgelord>moreso than it already is!</edgelord>)
The better question is: If the CSO was not previously an AUSA, would the prosecutors have charged this conduct?
Hopefully none of them have CISSPs; the CISSP is a joke.
Looks to me like this is why Kalanic was not indicted. If he deferred, said “handle it, keep it legal, and document it for any investigation,” that’s really all you can ask from a CEO.
Whether or not this is REALLY what he meant (or just a way to cover his butt) is up for debate. But it would be a good defense imo.
What control does the FTC have over storage of personal data anyway?
For the misprision offense (18 USC 4), the guidelines are based on the underlying felony, less 9 levels, capped at 19. Assuming CFAA/wire fraud, a 2B.1 offense, that's:
6
+8 for the >$95,000 loss
+2 if involved harvesting email addresses (not charged?)
+2 for evasion across jurisdictions
+2 for exfiltrating trade secrets overseas
+2 for intent to exfiltrate customer PII
That reads to me a worst-case underlying level of 24, or a 15 for the misprision, which is 18-24 months; remove any of those constraints and it's a "Zone C" offense that doesn't require imprisonment at all.The more painful charge appears to be the Obstruction (18 USC 1505), for which the guidelines appear to go:
14
+3 for substantial interference to an investigation
+2 for extensive planning
That worst-cases to 19, 30-37 months. Still not close to 5 years, though, and I'd assume (please correct me!) that these sentences group, since the underlying conduct is the same.(I assume this case settles?)
Happens to the best of us bud.
> The hackers’ ransom was paid in December 2016 via bitcoin, even though the hackers by that time had refused to sign the NDAs in their true names and had not yet been identified by Uber. Uber’s staff continued to work on identifying the hackers and were able to eventually identify them in January 2017, at which point SULLIVAN dispatched security staff to interview both hackers and obtain signed NDAs from them in their true names.
How did they identify them, and is the DOJ going after the hackers too?
edit: finished reading the PDF:
>H. The Hackers Pleaded Guilty to Federal Crimes. >>50. On August 2, 2018, a Grand Jury in the Northern District of California returned an indictment charging Brandon Charles GLOVER and Vasile MEREACRE with crimes related to extortion involving computers under 18 U.S.C. § 1030(a)(7)(B) and 1030(c)(3)(A). The indictment alleged that GLOVER and MEREACRE, between December 2016 and January 2017, conspired to extort a online employment-oriented service (“COMPANY ONE”) by obtaining over 90,000 confidential user accounts and using those accounts as a means to obtain money.
https://www.bloomberg.com/news/features/2019-03-13/when-elon...
https://www.wsj.com/articles/ebay-harassment-campaign-pig-co...
great legacy
They (allegedly) did a whole lot more than that! Everything about that story is absolutely crazy!
I'm not sure what's leading these security folks to believe they can do anything they want and get by with it but I, personally, am glad to see this criminal prosecution taking place -- hopefully it will help to "remind" others that they must "play by the rules" and that "'winning' by any means necessary" is not acceptable.
The complete lack of ethics at Uber, in particular, was appalling. Fortunately, it sounds like Dara was working hard to fix that once they got rid of Kalanik.
This statute doesn't require an active investigation.
> actual commission of a felony cognizable by a court of the United States
Illegal isn't always a cognizable (ie: perceptible; clearly identifiable.) felony by a court. In this case, not only did the two hackers clearly commit a felony, the lack of reporting it lead to the exact same type of breach conducted by the same two individuals against another site Lynda.com.
That suggests they had clear evidence of a felony and knew of intent to commit future felonies. And the two hackers were caught and going through the court stuff now, they even plead guilty. So thats basically a slam dunk on a cognizable felony.
There isn't a clear answer on proactive reporting. Depending on the type of business you have, what data you hold, the scale of the attack, etc. Some specific professions have mandatory reporting laws that may cover individuals that work for you. (see https://www.lw.com/thoughtLeadership/LW-ransomware-attacks-w... for a detailed answer)
The generally accepted best practice is that every ransom attack be reported to the Cybersecurity and Infrastructure Security Agency.
In the specific case of Uber, the incident involved scanned passports. The law is pretty clear that you have to report any compromise of passport data to the State Department.
I could imagine crimes being committed might include securities fraud, money laundering, bribery...
Most states have data breach laws. for California:
>California law requires a business or state agency to notify any California resident whose unencrypted personal information, as defined, was acquired, or reasonably believed to have been acquired, by an unauthorized person.
“ It has been reported that the Congressional Research Service cannot even count the current number of federal crimes. These laws are scattered in over 50 titles of the United States Code, encompassing roughly 27,000 pages. Worse yet, the statutory code sections often incorporate, by reference, the provisions and sanctions of administrative regulations promulgated by various regulatory agencies under congressional authorization. Estimates of how many such regulations exist are even less well settled, but the ABA thinks there are ”nearly 10,000.”
https://www.wired.com/2013/06/why-i-have-nothing-to-hide-is-...
When relevant case-law is taken into account, it appears that is not the case. Courts require active concealment of a known felony for conviction under that statute.
https://en.wikipedia.org/wiki/Misprision_of_felony#cite_note...
In this case, a CISO certainly is aware of the CFAA.
That is a fair counterpoint
I understand that the HN mentality has become very cynical, but if your only contribution to this conversation is a sardonic simile, comparing someone you don't know to a murderer, you should consider biting your tongue.
Because the tendency is overwhelmingly in this vicious and vengeful direction, having HN be the kind of community we want requires that we all make a conscious effort not to go there by default.
https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=24229084.
Why isnt Uber Inc helping him get a “Deferred Prosecution Agreement” so that he can kickback and relax
Other thread: https://news.ycombinator.com/item?id=24227059
Documents are taken down since a court ordered Martin to take them off the public display.
> The database included the drivers’ license numbers for approximately 600,000 people who drove for Uber.
Drivers licenses are deterministic and can be generated by knowing full name and DOB and state. They aren't PII.
> "During this time, two hackers contacted Sullivan by email and demanded a six-figure payment in exchange for silence. The hackers ultimately revealed that they had accessed and downloaded an Uber database containing personally identifying information, or PII, associated with approximately 57 million Uber users and drivers."
The hackers were demanding a ransom from Uber to keep silent about a data breach. Which is a whole lot different than paying a ransom to decrypt valuable, internal data. If a company has been breached, while it will almost certainly cause damage fiscally & to their reputation- they have a responsibility to notify users/customers. I'm unfamiliar with the law on this, but it should be illegal for a company to pay a ransom for malicious actors to keep silent about data they stole.
That those ids are often formed from a transparent function of other PII only makes the issue more extreme. It's like PII^2.
Furthermore, data being derived from something else has no bearing on whether it’s PII or not. ID numbers are personally identifiable information by definition. The whole point of them is to personally identify someone.