News: 1683242414

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ex-Uber CSO gets probation for covering up theft of data on millions of people

(2023/05/05)


Joe Sullivan won't serve any serious time behind bars for his role in covering up Uber's 2016 computer security breach and trying to pass off a ransom payment as a bug bounty.

A San Francisco judge on Thursday sentenced the app maker's now-former chief security officer to three years of probation plus 200 hours of community service, despite prosecutors' pleas to throw Sullivan in the cooler.

Late last month federal officials urged the judge to sentence Sullivan to 15 months in prison for covering up the theft of data from Uber's IT systems and lying to watchdogs about the intrusion.

[1]

"Corporate leaders are called upon to do the right thing even when it is embarrassing, even when it is bad for the company's bottom line," they said

[2]PDF

. "Nobody, neither corporations nor the executives who lead them, is above the law."

[3]

[4]

Sullivan, who previously worked as a cybercrime prosecutor for the US Department of Justice, submitted a letter

[5]PDF

to the judge in which he said he "deeply regrets" his actions in 2016 and urged leniency, to "give me a chance to use what has happened here to give back to my community."

In October, a jury found Sullivan [6]guilty of two felonies related to covering up the theft of Uber drivers and customers' personal information. The conviction followed earlier [7]charges of obstruction of justice and misprision, or concealing a felony from law enforcement.

[8]

The charges, and today's sentencing, stems from an intrusion in 2016 during which crooks broke into the ride-share and food-delivery app developer's network and stole 57 million customer and driver records. Sullivan and Craig Clark, Uber's then legal director of security and law enforcement, were fired as a result.

Travis Kalanick, who was Uber's CEO at the time of the theft, was not charged related to the intrusion, although he allegedly [9]discussed with Sullivan a strategy for handling the breach. Today in court, Judge William Orrick [10]reportedly said he believes Kalanick is "just as culpable" as Sullivan for the cover-up.

These days, Kalanick is worth [11]$4 billion , according to Forbes, and serves as CEO of CloudKitchens, a real estate company that provides kitchens for delivery-only restaurants, that has [12]raised money from the Saudi Arabia Public Investment Fund and Microsoft.

[13]Former Uber CSO convicted for covering up massive 2016 data theft

[14]'Don't be so concerned with your image'... US prosecutor lets rip on Uber for hack cover-up as pair plead guilty

[15]Uber driver info stolen yet again: This time from law firm

[16]Uber explains how it was pwned this month, points finger at Lapsus$ gang

Sullivan, according to court documents

[17]PDF

, learned of the theft in November 2016, about 10 days after providing testimony to the US Federal Trade Commission about a 2014 cyberattack on Uber. Concerned that another data security breach would harm the company, Sullivan tried to cover up that 2016 heist.

"Thereafter, Sullivan engaged in a scheme designed to ensure that the data breach did not become public knowledge, was concealed, and was not disclosed to the FTC," court docs read.

[18]

This scheme involved trying to pass off a total of $100,000 in ransom payments, made to the thieves to recover the stolen data, as a bug bounty award. At the time, Uber's highest reward offered to find and disclose vulnerabilities was $10,000.

Both of the thieves, Brandon Glover and Vasile Mereacre, [19]pleaded guilty in 2019. They haven't yet been sentenced, and Mereacre [20]testified at Sullivan's trial last fall.

Uber, meanwhile, went on to suffer several [21]more data-theft fiascoes. ®

Get our [22]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZFR-YTFO@RXkP3AoXJoj3QAAAAw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://regmedia.co.uk/2023/05/04/us_attys_sentencing_memo_joe_sullivan.pdf

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFR-YTFO@RXkP3AoXJoj3QAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFR-YTFO@RXkP3AoXJoj3QAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://regmedia.co.uk/2023/05/04/joe_sullivan_letter_to_judge.pdf

[6] https://www.theregister.com/2022/10/06/uber_cso_sullivan_guilty/

[7] https://www.theregister.com/2020/08/20/uber_sullivan_concealment_charges/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZFR-YTFO@RXkP3AoXJoj3QAAAAw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.bankinfosecurity.com/blogs/uber-ex-csos-trial-whos-responsible-for-breach-reporting-p-3287

[10] https://twitter.com/MariaDinzeo/status/1654241308733755392

[11] https://www.forbes.com/profile/travis-kalanick/?sh=23762b086199

[12] https://www.crunchbase.com/organization/cloudkitchens/company_financials

[13] https://www.theregister.com/2022/10/06/uber_cso_sullivan_guilty/

[14] https://www.theregister.com/2019/10/30/hackers_guilty_extortion/

[15] https://www.theregister.com/2023/04/03/uber_drivers_info_stolen/

[16] https://www.theregister.com/2022/09/19/uber_admits_breach/

[17] https://regmedia.co.uk/2023/05/04/joe_sullivan_indictment.pdf

[18] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZFR-YTFO@RXkP3AoXJoj3QAAAAw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[19] https://www.theregister.com/2019/10/30/hackers_guilty_extortion/

[20] https://www.courthousenews.com/hacker-details-plot-to-breach-ubers-data-servers-at-trial/

[21] https://www.theregister.com/2023/04/03/uber_drivers_info_stolen/

[22] https://whitepapers.theregister.com/



aerogems

Kind of torn on this one. On the one hand, the fact that PII was exfiltrated should be taken very seriously. The sentence seems a bit light on this one. Though, at the same time, his being in prison isn't going to change anything for the people who had their PII compromised and at least he was charged and convicted. That alone is a big step forward for the US legal system where normally these sorts of crimes end with the company raiding the CEO's hookers and blow petty cash box to pay the fine and that's the end of it. I know... won't someone think of the executives!?

The "bug bounty" bit... meh. I suppose it could technically be seen as some kind of market manipulation or other fraud, and while he should have known better, there's a very good chance he wasn't some rogue actor who took it upon themselves to take this action alone. It was likely cleared with others like the CFO and CEO. On that one, probation and community service seems on the light, but fair side. Probation isn't as easy as a lot of people think. You have to regularly check in with your PO, live by a bunch of arbitrary rules set by your PO, you can be in violation of your parole if you don't have a job and getting a job with a felony conviction can be difficult, plus it's often times ridiculously expensive. His community service should be having to work for some credit monitoring outfit or something that is largely related to what he was convicted of, not just picking up trash on the side of the road or something.

I think we've spotted the problem

MachDiamond

There's very little downside to exposing people's PII so there's no point in putting much money and effort into it. Uber is still around and people still think of them first when they need a taxi (I exclude myself). If execs were likely to be spending time behind bars and relieved of their expense home, fancy cars and extensive wine cellars, maybe more care would be taken. The fines should be steep and that means the possibility of company ending steep. It would be too bad that rank and file employees would lose their jobs, but that's nothing in comparison to all of the people who's sensitive information is made public. I don't accept the preservation of a few hundred jobs being that important.

in what country?

very angry man

"Corporate leaders are called upon to do the right thing even when it is embarrassing, even when it is bad for the company's bottom line," they said [PDF]. "Nobody, neither corporations nor the executives who lead them, is above the law."

If voting could change the system, it would be illegal. If not voting
could change the system, it would be illegal.