SAN FRANCISCO — A former chief safety officer for Uber was convicted Wednesday of federal fees stemming from funds he quietly approved to hackers who breached the ride-hailing firm in 2016.
Washington
Former Uber security chief convicted of covering up 2016 data breach
The decision ended a dramatic case that pitted Sullivan, a outstanding safety professional who was an early prosecutor of cybercrimes for the San Francisco U.S. legal professional’s workplace, in opposition to his former authorities workplace. In between prosecuting hackers and being prosecuted, Sullivan served as the highest safety govt at Fb, Uber and Cloudflare.
Choose William H. Orrick didn’t set a date for sentencing. Sullivan might enchantment if post-trial motions fail to set the decision apart.
“Mr. Sullivan’s sole focus — on this incident and all through his distinguished profession — has been guaranteeing the protection of individuals’s private knowledge on the web,” Sullivan legal professional David Angeli mentioned after the 12-member jury rendered its unanimous verdict on the fourth day of deliberations.
Even with out Sullivan’s job historical past, the trial would have been carefully watched as the primary main felony case introduced in opposition to a company govt over a breach by outsiders.
It additionally could also be one of many final: Within the 5 years since Sullivan was fired, payoffs to extortionists, together with those that steal delicate knowledge, have turn out to be so routine that some safety companies and insurance coverage corporations concentrate on dealing with the transactions.
“Paying out the ransom I believe is extra widespread than we’re led to imagine. There’s an angle that’s just like a fender bender,” mentioned Michael Hamilton, founding father of safety agency Crucial Perception.
FBI leaders, whereas formally discouraging the observe, have mentioned they won’t pursue the individuals and firms that pay ransoms in the event that they don’t violate sanctions prohibiting funds to named felony teams particularly near the Russian authorities.
“This case will definitely make executives, incident responders and anyone else linked with deciding whether or not to pay or disclose ransom funds suppose somewhat more durable about their authorized obligations. And that’s not a nasty factor,” mentioned Brett Callow, who researches ransomware at safety agency Emsisoft. “As is, an excessive amount of occurs in shadows, and that lack of transparency can undermine cybersecurity efforts.”
Most safety professionals had been anticipating Sullivan’s acquittal, noting that he had stored the CEO and others who weren’t charged knowledgeable of what was occurring.
“Private legal responsibility for company selections with govt stakeholder enter is a brand new territory that’s considerably uncharted for safety executives,” mentioned Dave Shackleford, proprietor of Voodoo Safety. “I concern it’ll result in an absence of curiosity in our area, and elevated skepticism about infosec general.”
John Johnson, a “digital” chief info safety officer for a number of corporations, agreed. “Your organization management may make decisions that may have very private repercussions to you and your life-style,” he mentioned. “Not saying all the pieces Joe did was proper or excellent, however we will’t bury our head and say it’ll by no means occur to us.”
Prosecutors argued in Sullivan’s case that his use of a nondisclosure settlement with the hackers was proof that he participated in a coverup. They mentioned the break-in was a hack that was adopted by extortion because the hackers threatened to publish the information they took, and so it shouldn’t have certified for Uber’s bug bounty program to reward pleasant safety researchers.
However the actuality is that because the hacking of companies has gotten worse, the best way corporations have handled it has moved far previous the letter of the legislation when Sullivan was accused of breaking it.
Bug bounties normally require nondisclosure offers, a few of which final without end.
“Bug bounty applications are being misused to cover vulnerability info. Within the case of Uber, they had been used to cowl up a breach,” Katie Moussouris, who established a bug bounty program at Microsoft and now runs her personal vulnerability decision firm, mentioned in an interview.
The case in opposition to Sullivan began when a hacker emailed Uber anonymously and described a safety lapse that allowed him and a accomplice to obtain knowledge from one of many firm’s Amazon repositories. It emerged that that they had used a stray digital key Uber had left uncovered to get into the Amazon account, the place they discovered and extracted an unencrypted backup of knowledge on greater than 50 million Uber riders and 600,000 drivers.
Sullivan’s staff steered them towards Uber’s bounty program and famous that the highest payout underneath it was $10,000. The hackers mentioned they would wish six figures and threatened to launch the information.
A protracted negotiation ensued that ended with a $100,000 fee and a promise from the hackers that that they had destroyed the information and wouldn’t disclose what that they had completed. Whereas that appears like a coverup, testimony confirmed that Sullivan’s workers used the method to get clues that will make them the actual identities of the perpetrators, which they felt was mandatory leverage to carry them to their phrase. The 2 had been later arrested and pleaded responsible to hacking fees, and one testified for the prosecution in Sullivan’s trial.
The obstruction cost drew energy from the truth that Uber on the time was nearing the tip of a Federal Commerce Fee investigation following a serious 2014 breach.
A cost of actively hiding a felony, or misprision, may additionally apply to most of the company chiefs who ship bitcoin to abroad hackers with out telling anybody else what occurred. Whereas the variety of these hush-ups is unattainable to get, it’s clearly a big determine. In any other case, federal officers wouldn’t have pressed for latest laws that may require ransomware notifications from essential infrastructure victims to the Cybersecurity and Infrastructure Safety Company.
The Securities and Alternate Fee can be pushing for extra disclosure. The conviction surprised company safety and compliance leaders and can rivet their consideration on the main points of these guidelines.
The case in opposition to Sullivan was weaker in some respects than one may anticipate from a trial geared toward setting a precedent.
Whereas he directed the response to the 2 hackers, many others on the firm had been within the loop, together with a lawyer on Sullivan’s staff, Craig Clark. Proof confirmed that Sullivan informed Uber’s then-chief govt, Travis Kalanick, inside hours of studying concerning the risk himself, and that Kalanick accredited Sullivan’s technique. The corporate’s chief privateness lawyer, who was overseeing the response to the FTC, was knowledgeable, and the pinnacle of the corporate’s communications staff had particulars as nicely.
Clark, the designated authorized lead on breaches, was given immunity to testify in opposition to his former boss. On cross-examination, he acknowledged advising the staff that the assault wouldn’t need to be disclosed if the hackers had been recognized, agreed to delete what that they had taken and will persuade the corporate that that they had not unfold the information additional, all of which ultimately got here to move.
Prosecutors had been left to problem “whether or not Joe Sullivan may have presumably believed that,” as certainly one of them put it in closing arguments Friday.
Sullivan’s legal professional Angeli mentioned that the actual world functioned in a different way from bug bounty beliefs and the insurance policies specified by firm manuals.
“On the finish of the day, Mr. Sullivan led a staff that labored tirelessly to guard Uber’s clients,” Angeli informed the jury.
After Kalanick was compelled out of the corporate for unrelated scandals, his successor, Dara Khosrowshahi, got here in and realized of the breach. Sullivan depicted it to him as a routine payoff, prosecutors mentioned, modifying from one electronic mail the quantity of the payoff and the truth that the hackers had obtained unencrypted knowledge, together with telephone numbers, on tens of hundreds of thousands of riders. After a later investigation turned up the total story, Khosrowshahi testified, he fired Sullivan for not telling him extra, sooner.
Keen to point out that it was working in a brand new period, the corporate helped the U.S. legal professional’s workplace construct a case in opposition to Sullivan. And the prosecutors in flip unsuccessfully pressed Sullivan to implicate Kalanick, who would have been a far greater prize however was not damned by the surviving written proof, based on individuals conversant in the method.
Bug bounties had been by no means meant to supply as a lot cash to hackers as criminals or governments would pay. As an alternative, they had been designed to supply some money to these already inclined to remain above board.
However the corporations are those paying the invoice even when the applications are run by outdoors distributors corresponding to HackerOne and Bugcrowd. Disputes between the researchers reporting the safety holes and the businesses with the holes at the moment are widespread.
The 2 sides differ over whether or not a bug was “in scope,” that means contained in the areas the place the corporate mentioned it wished assist. They differ over how a lot a bug is value, or whether it is nugatory as a result of others had already discovered it. They usually differ over how, or even when, the researcher can disclose the work after the bug has been mounted or the corporate opts to not change something.
The bounty platforms have arbitration procedures for these disputes, however because the corporations are footing the invoice, many hackers see bias. An excessive amount of protesting, and so they get booted from the platform completely.
“When you’re hacking on a bug bounty program for the love of hacking and making safety higher, that is the unsuitable cause, as a result of you haven’t any management over whether or not an organization decides to patch in a well timed matter or not,” mentioned John Jackson, a researcher who in the reduction of on his bounty work and now sells vulnerability info when he can.
Casey Ellis, founding father of Bugcrowd, acknowledged that some corporations use bounty applications to hush up issues that ought to have been disclosed underneath state or federal guidelines.
“That’s positively a factor that occurs,” Ellis mentioned.
Ransomware assaults had been uncommon when Sullivan was charged, rising dramatically within the years that adopted to turn out to be a risk to U.S. nationwide safety.
The methods in these assaults have additionally shifted.
Firstly of 2020, most ransomware merely encrypted information and demanded cash for the important thing to unlock them. By the tip of that 12 months, most ransom assaults included the outright theft of information, establishing a second ransom demand to forestall their public launch, based on a 2021 report by the Ransomware Activity Power, an industry-led group that features representatives from the U.S. Cybersecurity and Infrastructure Safety Company, the FBI, and the Secret Service.
Extra just lately, cryptocurrency exchanges have been robbed after which negotiated to offer large funds to get these funds again, a freewheeling observe bearing little resemblance to conventional bounties.
“Particularly over the previous six months within the crypto area, the mannequin is ‘construct it till we get hacked, and we’ll determine it out from there,’ ” mentioned Ellis.
As common payouts zoomed previous Sullivan’s, into the tons of of hundreds of {dollars}, extra companies turned to insurance coverage corporations for predictability.
However usually, the insurance coverage corporations reasoned it was cheaper to pay than to cowl the injury from misplaced information. Some paid repeatedly, guaranteeing regular earnings for the gangs.
Making funds unlawful, as some have proposed, wouldn’t truly cease them, the FBI has mentioned. It will as an alternative give the extortionists yet one more membership to carry over their victims after fee is made.
No less than to this point, Congress has agreed, declining to ban the transactions. Which implies that offers like Sullivan’s will proceed to occur each week.
Will all of them be disclosed when required underneath state legal guidelines or federal consent decrees? Most likely not.
However don’t anticipate those that hush issues as much as find yourself in handcuffs.
Washington
BIZ BUZZ: Antonios go to Washington
Donald Trump is scheduled to be inaugurated—again—as the president of the United States on Jan. 20 in Washington.
Among those who will witness his return to power as the 47th president of the world’s largest economy are some of his old friends from the Philippines.
We’re talking about Century Properties Group founder and chair Jose EB Antonio and his wife, Hilda.
Going with them is their third son, Jose Roberto, who had just been appointed managing director of the J. Antonio Group Inc. in charge of resort-related projects.
It may be recalled that the Trumps and the Antonios struck up a friendship decades ago in New York when Trump was more known as a property developer, just like the Antonios. Some of their children also went to business school together.
And then, the Antonios also brought the Trump brand into one of the office buildings in its Century City development in Makati City.
Article continues after this advertisement
But the elder Antonio will be there not just as a personal friend invited by the Trumps to attend the inauguration but also to represent President Marcos as his ambassador-at-large tasked with inviting more investments into the Philippines.
Article continues after this advertisement
With a friend in the White House, the Antonios are confident that more investments as well as visitors will flow toward the Philippines. —Tina Arceo-Dumlao
Clark hits the Belle’s eye
In July 2024, Belle Corp. gave us a teaser about applying for a gaming license from “government regulators.”
Despite the rumor mill running wild that the gaming-focused investment firms of delisted subsidiary Premium Leisure Corp. had plans to conquer Clark, Belle opted to keep quiet.
Nearly half a year later, Belle hailed Clark as “the next gaming and tourism hub” and confirmed that they had, indeed, applied for a gaming license specifically to develop an integrated resort in the former American air base.
Belle president and CEO Armin Raquel Santos likewise expressed optimism on his company’s growth prospects, “and bullish on the Philippine gaming market and its resilience despite industry headwinds.”
”Belle, through its gaming subsidiaries, continues to explore and pursue related ventures and high-growth opportunities in the gaming space that will enhance shareholder value while delivering its commitments to all stakeholders,” the company quoted Santos as saying.
Though much still remains unsaid about Belle’s plans for Clark, it is clear that the gaming industry is still attractive despite some weakness and hiccups—Bloomberry Corp.’s earnings, for instance, and Davao-based businessman Dennis Uy’s long-stalled Cebu casino project.
Let’s see if Belle will go against the odds. —Meg J. Adonis
Washington
What Washington State’s head coach said after Gonzaga game
Washington State men’s basketball head coach David Riley could point to a few factors that led to Gonzaga pulling away from the Cougars during the second half of Saturday night’s showdown at the McCarthey Athletic Center.
For starters, the Bulldogs’ 15-5 scoring run to start the second half certainly didn’t help the Cougs’ cause. Neither did Ryan Nembhard, who came out of the halftime break even more refreshed after sitting on the bench for the final 9:34 of the first half due to foul trouble. Turnovers and miscues on the defensive end of the floor also started to pile up for WSU, which led by six points in the first half only to trail by three at the break and fall behind by 21 in the second half while the Zags nailed 10 3-pointers and scored 20 points off 16 turnovers.
Consider Saturday night, then, a perfect storm for the Bulldogs (14-4, 5-0 WCC). Led by Graham Ike’s 21 points, Gonzaga pulled away for an 88-75 victory over its in-state rival in a thriller from the Kennel.
Here’s what Riley had to say after the game.
On what changed for WSU in the second half:
“It was a hard-fought game, and I feel like we had it slip away from us early in that second half where we didn’t stay connected as much, and I personally didn’t do a good enough job of having us ready for the fight. They got some 50-50 balls. They got a couple offensive rebounds, just some toughness plays that second half that hurt us. And that comes down to, we have game plan stuff, we’re gonna have X’s and O’s, we’re gonna have great plays from different players and bad plays from different players, but that fight for 40 minutes, I think, was the difference, and they came out with a little more fire than us.”
On Ryan Nembhard’s impact in the second half after sitting most of the first half:
“He did a good job with their pace. I think he gets them up the floor really well. I felt like it was a lot of factors that second half, and he played a part in that and started isolating some of our bigs when we made a couple of adjustments. [Nembhard is a] good player.”
On WSU’s defensive breakdowns that led to 10 3-pointers for Gonzaga:
“A couple of execution errors. I think one of them we didn’t have a ball screen right, one of them we didn’t order our post defense right. Kind of going into the half that was our thing, when things get tough, or they throw in a 25-second possession, we got to execute all 30 seconds of the shot clock. And I think it was more just cover stuff. We didn’t have that many space cadet errors. I think it was more just kind of one guy doing something that wasn’t exactly right in coverage.”
MORE GONZAGA NEWS & ANALYSIS
FOLLOW US ON SOCIAL MEDIA
Continue to follow our Gonzaga coverage on social media by liking us on Facebook and following us on Instagram and Twitter.
Washington
What Gonzaga’s Mark Few said after win vs. Washington State
The Gonzaga men’s basketball team pulled away from Washington State for an 88-75 victory in the first meeting between the in-state rivals in over a decade.
Graham Ike led the way with 21 points on 8-for-11 from the field, Nolan Hickman added 19 points and the Bulldogs (14-4, 5-0 WCC) earned their fifth straight win to open league play by putting the Cougars (13-5, 3-2 WCC) away early in the second half. After ending the first half on an 8-2 scoring run, the Zags came out of the second half with a sense of urgency on both ends, sparking a 15-5 scoring run to make it a double-digit margin.
Here’s what Gonzaga head coach Mark Few had to say after the game.
On what he told the team at halftime that led to the strong start to the second half:
“I just told them, ‘hey, we’re in a we’re in a battle. It’s a great game. Both teams are competing really hard, and we’re at our best when we’re in attack mode.’ And they did a great job of taking the message and I thought we really went out and turned defense into offense, and we knew that was going to be a big key for us. [The Cougars] are hard to guard, they’re big and they’re physical, and [WSU coach David Riley] does a really lot of nice stuff on on offense that exploits mismatches. But our guys battled tonight, so I was really proud of them.”
On the team’s performance while Ryan Nembhard was on the bench for the final 9 minutes of the first half:
“They played great. I told them that in the locker room that that was huge. We haven’t really had to do that all year. And this guy [Nolan Hickman] stepped up. He was amazing tonight. I mean, seven boards … defensively in there, battling in the post. I mean, he did a lot of stuff that, as I said, he’s now, he set a high standard, so kind of be counting on that moving forward, but he and Dusty [Stromer] both really helped during that stretch and [Khalif Battle] and obviously having Ben [Gregg] and then Graham was rock solid all night.”
On the team’s effort on the defensive end of the floor in the second half:
“I thought our effort and our making plays, I thought it was definitely up there [with the best of the season], and just the physicality that it took. Because, again, they’re so much bigger than us at several of those spots. And again, you just don’t see the post-up thing like this, where your guards are getting constantly posted. But so in that way, we fought, we were physical and kind of had to navigate our way through a lot of different actions. There’s staggers and some curls and some switches and all that. For the most part, we did pretty good.”
-
Politics1 week ago
Carter's judicial picks reshaped the federal bench across the country
-
Politics1 week ago
Who Are the Recipients of the Presidential Medal of Freedom?
-
Health1 week ago
Ozempic ‘microdosing’ is the new weight-loss trend: Should you try it?
-
World1 week ago
South Korea extends Boeing 737-800 inspections as Jeju Air wreckage lifted
-
Technology4 days ago
Meta is highlighting a splintering global approach to online speech
-
News1 week ago
Seeking to heal the country, Jimmy Carter pardoned men who evaded the Vietnam War draft
-
Science1 day ago
Metro will offer free rides in L.A. through Sunday due to fires
-
News1 week ago
Trump Has Reeled in More Than $200 Million Since Election Day