- Hackers downloaded a bunch of PII from Uber
- Uber CISO paid them a 100k bounty with bitcoin to sign an NDA with their hacking handles, but they wouldn't give real names
- Uber staff traced them down, found their real names, then met them in person and got them to sign NDAs with real names
- FTC is mad because CISO tried to make it seem like it wasn't a data breach vs bug report through the bounty program.
- Their 2014 breach was from "an AWS access ID and secret key in software code posted to GitHub"
- In 2016 to FTC "SULLIVAN elaborated that it was common at the time to write access IDs and other secrets directly into code when that code needed to call for information from another service." - oof
- SULLIVAN received an email from “johndoughs@protonmail.com” claiming to have found a “major vulnerability in uber,” and that “I was able to dump uber database and many other things.”
- in 2016 breach, the hackers used to stolen credentials to... get the AWS keys that were still in their github code, but was now private
-"Similarly, Uber argued that the industry at large had become more adept since 2014 at protecting private data in the cloud, and that Uber should not be judged for “what a company did then (back when the company was much smaller and the technology at issue was evolving) according to the standards that the agency thinks are appropriate now (given the current sophistication of the company and current industry best practices).” Uber made these arguments via letter in April 2017, approximately five months after the 2016 Breach."
https://assets.documentcloud.org/documents/7041237/Joseph-Su...