{"id":685,"date":"2017-11-27T19:00:33","date_gmt":"2017-11-27T19:00:33","guid":{"rendered":"https:\/\/securitycurve.com\/?p=685"},"modified":"2017-11-27T19:00:33","modified_gmt":"2017-11-27T19:00:33","slug":"the-uber-incident","status":"publish","type":"post","link":"https:\/\/securitycurve.com\/?p=685","title":{"rendered":"The Uber incident"},"content":{"rendered":"<p><a href=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/11\/lqpx04TUSaSqEUG6sWUt_Uber-Review1.jpg\"><img decoding=\"async\" class=\"alignright wp-image-686 lazyload\" data-src=\"https:\/\/securitycurve.com\/wp-content\/uploads\/2017\/11\/lqpx04TUSaSqEUG6sWUt_Uber-Review1.jpg\" alt=\"\" width=\"331\" height=\"241\" src=\"data:image\/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==\" style=\"--smush-placeholder-width: 331px; --smush-placeholder-aspect-ratio: 331\/241;\" \/><\/a>Uber, amirite?<\/p>\n<p>Here&#8217;s the quick thirty-second post-vacation catch up for those (like me) that have been out of the loop because vacation.\u00a0 First,\u00a0<a href=\"https:\/\/futurism.com\/uber-reveals-long-kept-hacking-jeopardized-data-57-million-people\/\">Uber got hacked<\/a>, potentially exposing data from up to 57 million people. The data in play included driver license numbers, names, phone numbers, and email addresses.<\/p>\n<p>Is that the most surprising thing in the world?\u00a0 Probably not.\u00a0 The breach is on the large-ish side, but certainly not the biggest one ever.\u00a0 Likewise, the data involved isn&#8217;t &#8220;super worst case scenario&#8221; like say, the Equifax breach.\u00a0 No, in this case the surprising parts are the timing and their reaction.\u00a0 Because first, it happened in 2016.\u00a0 Second, they apparently <a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/uber-paid-hackers-$100k-to-conceal-2016-data-breach\/d\/d-id\/1330487\">paid the hackers $100,000 to keep quiet<\/a> about it.<\/p>\n<p>To put icing on the already-ridiculous cake, its&#8217; worth reading the <a href=\"https:\/\/www.uber.com\/newsroom\/2016-data-incident\/\">blog post about the issue from Uber CEO\u00a0Dara Khosrowshahi<\/a>.\u00a0 Let&#8217;s walk through some of the high points.\u00a0 Why?\u00a0 As a cautionary tale.\u00a0 The level of ineptitude (note that I&#8217;m being generous in saying &#8220;inept&#8221; because the alternative is &#8220;legit evil&#8221;) is epic in scale.\u00a0 It&#8217;s also not likely to go away quickly (or cleanly) and will likely wind up resulting in long-term financial impact for Uber.<\/p>\n<p>The statement starts out by saying that &#8220;<em>I recently learned that in late 2016 we became aware that two individuals outside the company had inappropriately accessed user data stored on a third-party cloud-based service that we use.<\/em>&#8221;\u00a0 Let&#8217;s stop right there.<\/p>\n<p>My questions about just this sentence are legion.\u00a0 First, &#8220;recently learned&#8221;?\u00a0 \u00a0He&#8217;s been CEO of Uber since August.\u00a0 The fact that they lost 57 million records and then paid to cover it up just came up recently?\u00a0 I&#8217;m sure he&#8217;s being honest here&#8230; he probably is just hearing about it now.\u00a0 That&#8217;s not a good thing though.\u00a0 Like, if you were head of compliance or security for Uber, wouldn&#8217;t this be one of the first things on your docket to discuss with the incoming CEO?\u00a0 Yeah, me too.\u00a0 Which suggests to me one of a few things are true; either: <strong>A)<\/strong> security is so jacked at Uber that this didn&#8217;t rate as a top-tier issue, <strong>B)<\/strong> there&#8217;s high turnover and little recordkeeping (so everybody pretty much forgot it happened) or <strong>C)<\/strong> the CEO isn&#8217;t meeting directly with security or compliance teams.\u00a0 My suspicion is it&#8217;s a combination of all three.\u00a0 \u00a0Someone suggested to me this morning that maybe internal Uber teams did know about it, but didn&#8217;t inform the CEO.\u00a0 That&#8217;s possible too.\u00a0 If that&#8217;s the case, its still really, really not good.<\/p>\n<p>Second, who cares where the data was?\u00a0 The post mentions the cloud provider and then goes on to say, &#8220;<em>The incident did not breach our corporate systems or infrastructure.<\/em>&#8221;\u00a0 But really, who cares?<\/p>\n<p>This fails what I like to call &#8220;the cat test&#8221;.\u00a0 Imagine you ask me to take care of your cat while you&#8217;re away on a trip.\u00a0 You come back and the cat died.\u00a0 Is my excuse one where you punch me in the face, one where I get arrested, or one where we&#8217;re still friends?\u00a0 I find that many issues can be understood by thinking through how it would play out in the cat-sitting scenario above. For example:<\/p>\n<ul>\n<li>Example one: I couldn&#8217;t feed the cat because I was in a coma from a brain aneurysm.\u00a0 You probably don&#8217;t love the consequences, but maybe we could stay friends. It&#8217;s force majeur&#8230; pretty much unavoidable even though the outcome is so terrible.<\/li>\n<li>Example 2: I was too lazy to do it, so I gave my cousin a bag of meth in exchange for him looking after your cat&#8230; he was high (because meth) so forgot to put out food.\u00a0 In this case, my actions were clearly illegal so the appropriate response is that I be arrested.<\/li>\n<li>Example 3: I accidentally pour tuna juice into the jar of rat poison I left open on your counter.\u00a0 That&#8217;s a face punch scenario: it&#8217;s not exactly <em>illegal<\/em> per se (negligent animal cruelty maybe?) but it&#8217;s absolutely my fault: my carelessness caused it.<\/li>\n<\/ul>\n<p>In the case of Uber, it sounds to me like a &#8220;face punch&#8221; scenario.\u00a0 They apparently put their AWS credentials into code that they uploaded to GitHub.\u00a0 So the analogy to run through the cat test would be: I tied your apartment key to a string and left it tied around your doorknob; a band of local kids got in your apartment, trashed the place, and killed your cat.\u00a0 Were my actions illegal?\u00a0 No.\u00a0 But there wasn&#8217;t force majeur either.\u00a0 There&#8217;s exactly one entity at fault and one reason the situation occurred: willful carelessness.<\/p>\n<p>Next, they go on to say:<\/p>\n<blockquote><p>At the time of the incident, we took immediate steps to secure the data and shut down further unauthorized access by the individuals. We subsequently identified the individuals and obtained assurances that the downloaded data had been destroyed&#8230;<\/p><\/blockquote>\n<p>Bah.\u00a0 Paying the bad guys money to destroy the data isn&#8217;t acceptable.\u00a0 Ever.\u00a0 \u00a0This response is cavalier at best.\u00a0 What were the assurances they received?\u00a0 How do they know the data was destroyed?\u00a0 How were they able to trust these assurances?\u00a0 This is absolutely not the right way to go about this.\u00a0 And, as a steward of people&#8217;s data, this is exactly what breach disclosure notification laws are for.<\/p>\n<p>The tone of the concluding paragraph is the right one though.\u00a0 They say:<\/p>\n<blockquote><p>None of this should have happened, and I will not make excuses for it. While I can\u2019t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes. We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.<\/p><\/blockquote>\n<p>I&#8217;m really glad they are not making excuses.\u00a0 The tone of this sentence is the right one.\u00a0 However, the cleanup of this mess is going to be a long row to hoe.\u00a0 I also question what the response of regulators is going to be and whether there will be legal action against them.\u00a0 I&#8217;m thinking there&#8217;s more to come on this.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Uber, amirite? Here&#8217;s the quick thirty-second post-vacation catch up for those (like me) that have been out of the loop because vacation.\u00a0 First,\u00a0Uber got hacked, potentially exposing data from up to 57 million people. The data in play included driver license numbers, names, phone numbers, and email addresses. Is that the most surprising thing in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4],"tags":[122],"class_list":["post-685","post","type-post","status-publish","format-standard","hentry","category-security","tag-uber"],"_links":{"self":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/685","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=685"}],"version-history":[{"count":0,"href":"https:\/\/securitycurve.com\/index.php?rest_route=\/wp\/v2\/posts\/685\/revisions"}],"wp:attachment":[{"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=685"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=685"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/securitycurve.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=685"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}