Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

11/27/2017
04:40 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
100%
0%

Uber's Security Slip-ups: What Went Wrong

The ride-sharing company's decisions leading to a 2016 data breach and its handling of the incident should serve as a cautionary tale for enterprises facing a breach.

Uber is digging out from the wreckage of its latest public relations nightmare, an October 2016 data breach that compromised the information of 57 million riders and drivers.

The company has received backlash not for the size of the breach but how it was handled. Instead of informing those affected, Uber paid attackers $100,000 to delete the stolen data and keep their activity quiet. The hack was disclosed last week, a year after Uber found out about it. The attempted cover-up was one of many mistakes leading up to the breach and the subsequent response.

Former CISO Joe Sullivan, who spearheaded incident response, and his deputy have both been fired for mishandling the hack. Current CEO Dara Khosrowshahi, who took charge in September, says Uber "took immediate steps" to secure affected data, shut down further unauthorized access, and "obtained assurances that the downloaded data had been destroyed."

The CEO may be using the 2016 breach as a catalyst in transforming Uber's approach to security. Khosrowshahi says "we will learn from our mistakes" and "we are changing the way we do business." However, experts across industries have criticized Uber's initial response to a hack that compromised millions of users, as well as the basic security slip-ups that let it happen.

Uber is individually notifying drivers whose license numbers were compromised and offering free credit monitoring and identity theft protection, Khosrowshahi reports. It is also alerting regulatory authorities and affected accounts, which have been flagged for fraud protection.

Where Uber Went Wrong

For starters, the company should have immediately come clean. "Uber undoubtedly violated numerous US and international data breach disclosure laws by failing to inform drivers and users that their personal information had been compromised," says ZScaler CISO Michael Sutton. Several state and federal regulations dictate when such disclosures must be made.

The company should also have had stronger access control for such a large collection of data. Attackers initially accessed a private GitHub coding site for Uber software engineers, where they found credentials for an Amazon Web Services account containing users' information.

This wasn't a sophisticated attack, Imperva CTO Terry Ray points out, questioning Uber's decision to use live production data in an online platform where credentials were stored in GitHub. Developers are frequently allowed to use live production data in testing; unfortunately, this information is "almost never monitored or secured" and often stored in various locations.

Ray points out a few questions that should be considered in the wake of the breach:

  • Why did engineers have access to 57 million records of personally identifiable information?
  • Did they go through an approval workflow to move that data online?
  • Did Uber security have any monitoring in place to alert them when such vast amounts of data were accessed?

"Controls to alert on suspicious data access do exist," says Ray. "But my guess is that they were not used, which is all too typical in today’s enterprises."

Snyk cofounder and CEO Guy Podjarny says credentials should not have been in GitHub in the first place, and that one user's credentials should not have given access to so much data at once. All it took was the compromise of one individual to give attackers the keys.

"The fact that developers have access to GitHub repositories, and the fact that there was access to many customers' data, are both instances of preferring ease-of-use over security," he notes. Uber could have mitigated the damage with preventative measures around data downloads. Once information was compromised, it should have identified the volume of downloaded data.

Experts also say Uber should have encrypted its data before storing it with a third-party service. "It's not a GitHub security issue or an AWS security issue," says McAfee Labs vice president Vincent Weafer. "It really comes down to the user, and not system security issues."

While Uber was wrong not to come forward about the hack, there is less certainty around its decision to pay the attackers, who demanded $100K to delete the stolen data. It's ill-advised and often dangerous to pay hackers, a practice that will continue to drive extortion.

Legal Ramifications

Ken Spinner, vice president of field engineering at Varonis, says "every state attorney general is going to be salivating at the prospect of suing Uber." The lawsuits have already begun to roll in: a class-action lawsuit has been filed against Uber by Wilshire Law Firm on behalf of its client, Flores. Complaints allege Uber violated California constitutional laws and unfair competition laws, engaged in deceptive business practices, and invaded privacy, among other violations.

Uber says it has not seen evidence of fraud or misuse related to the breach, according to Khosrowshahi's statement; however, a press release on the aforementioned lawsuit reports the information stolen by hackers has allegedly ended up on the black market while Uber kept mum about the situation.

At the time of writing, Uber has not responded to Dark Reading's request for comment regarding data shared on the black market.

Related Content:

Join Dark Reading LIVE for two days of practical cyber defense discussions. Learn from the industry’s most knowledgeable IT security experts. Check out the INsecurity agenda here.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ebyjeeby
50%
50%
ebyjeeby,
User Rank: Strategist
12/14/2017 | 5:20:42 PM
scramble data
Uber should have scrambled the data before it went into the test environment.
jdub161
50%
50%
jdub161,
User Rank: Apprentice
11/30/2017 | 11:14:16 PM
What went wrong 'after the incident'
Great article Kelly, but what went wrong after the incident?

Understand that it's critical to understand what went wrong to cause the incident, but I feel it would be very insightful to understand who made the decision not to disclose the incident.  

Where did that decision occur?  At Uber's Board, CEO, Legal team.  Even if that decision was left to the CISO then that's actually a damning indictment on their delegation of authority. 

I understand that Uber want to offer up the CISO as the official 'scapegoat' but wow if the standard response to a major data breach is 'sack the CISO' then in not to long we will be faced with an understaffed industry having to fill strategic leadership positions potentially with highly skilled cyber security people that may not have had the training and experience to work at the strategic C suite level.

Jason 
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
RDP Bug Takes New Approach to Host Compromise
Kelly Sheridan, Staff Editor, Dark Reading,  7/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14248
PUBLISHED: 2019-07-24
In libnasm.a in Netwide Assembler (NASM) 2.14.xx, asm/pragma.c allows a NULL pointer dereference in process_pragma, search_pragma_list, and nasm_set_limit when "%pragma limit" is mishandled.
CVE-2019-14249
PUBLISHED: 2019-07-24
dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHT_GROUP), as demonstrated by dwarfdump.
CVE-2019-14250
PUBLISHED: 2019-07-24
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
CVE-2019-14247
PUBLISHED: 2019-07-24
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
CVE-2019-2873
PUBLISHED: 2019-07-23
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.2.32 and prior to 6.0.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox...