Attacks/Breaches

4/12/2018
01:20 PM
50%
50%

Uber Agrees to New FTC Settlement Over 2016 Breach Disclosure

Uber has agreed to an updated settlement with the FTC after news of its massive 2016 data breach.

Uber has agreed to an expanded settlement with the Federal Trade Commission, which last year charged the ride-sharing company for deceiving customers with its privacy and data security practices. The new settlement takes into account Uber's massive 2016 data breach.

In the original settlement, proposed in August 2017, the FTC reported Uber failed to live up to claims that it closely monitored employees' access to rider and driver data, and that it implemented measures to secure personal data on third-party cloud servers.

The FTC later learned Uber had failed to disclose a significant breach of user data that occurred in 2016 while it was investigating this settlement. As a result, it has updated its complaint to note that Uber knew about the 2016 breach and paid the attackers $100,000 through a "bug bounty program" to keep quiet. The breach was disclosed a year after it occurred, in Nov. 2017.

In the new agreement, Uber is compelled to disclose future incidents involving consumer data and submit all reports from required third-party audits of its privacy program. It must retain certain records related to bug bounty reports of flaws that could compromise users' data. Uber could be subject to civil penalties if fails to share future incidents with the FTC.

Read more details here.

Interop ITX 2018

Join Dark Reading LIVE for two cybersecurity summits at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the security track here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-13106
PUBLISHED: 2018-08-15
Cheetahmobile CM Launcher 3D - Theme, wallpaper, Secure, Efficient, 5.0.3, 2017-09-19, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13107
PUBLISHED: 2018-08-15
Live.me - live stream video chat, 3.7.20, 2017-11-06, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13108
PUBLISHED: 2018-08-15
DFNDR Security Antivirus, Anti-hacking & Cleaner, 5.0.9, 2017-11-01, Android application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13100
PUBLISHED: 2018-08-15
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
CVE-2017-13101
PUBLISHED: 2018-08-15
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.