Uber to Update 'Bug Bounty' Policies After 2016 Data Breach: Executive

Advertisement
By Reuters | Updated: 26 April 2018 18:24 IST

Uber on Thursday plans to announce changes to how it rewards cyber researchers who report flaws in its software, a company executive told Reuters, as part of the ride-hailing firm's response to concerns raised about the way it handled a data breach in 2016.

Among the changes to Uber Technologies's so-called bug bounty program are new terms that more clearly define what Uber does and does not consider "good faith" vulnerability research, John Flynn, the company's chief information security officer, said in an interview.

"We're clarifying the difference between researchers that act in good faith and people who don't," Flynn said. "We're doing a better job about being explicit about what those things are, because it's important these programs have high integrity."

Advertisement

Uber will also update its policies to specifically state that it will not pursue or recommend legal action against good-faith hackers who submit flaws through its "bug bounty" portal. It will provide support to those who may face litigation from others as a result of a bug submission.

Advertisement

The changes are the first made to Uber's bug bounty platform since the company revealed last November the 2016 data breach of 57 million user credentials, including names, phone numbers and email addresses.

Reuters reported in December that a 20-year-old man was primarily behind the breach, and that he was paid by Uber to destroy the data through the bounty platform after receiving an email from anonymous person demanding money in exchange for user data.

Advertisement

The large size of the payment and Uber's use of the bounty system led some security researchers to criticize the company and suggest it had sought to conceal a criminal breach.

"An unfortunate reaction to all this was the doubt cast by some people on whether companies should run bug bounty programs at all," Flynn said.

Advertisement

Uber apologized for how it handled the breach months after new Chief Executive Dara Khosrowshahi was installed following founder Travis Kalanick's ouster. The company fired its chief security officer, Joe Sullivan, and a deputy, attorney Craig Clark.

As part of the changes, Uber will test an option allowing researchers to donate their bounties to charity, which the company will match. The company will also update its submission form to include a question that asks whether personal consumer information may be exposed through the discovered flaw.

Flynn said the added question is intended to more quickly trigger review internally as to whether regulators may need to be notified, a change intended to avoid repeating mistakes made during its response to the 2016 breach. A European data privacy law taking effect next month will require companies to disclose within 72 hours whether user data has been compromised.

Marten Mickos, the chief executive of HackerOne, which hosts Uber's bug bounty program and provided input on its updates, welcomed the changes but said they alone would not guarantee Uber would avoid its previous mistakes.

"It's not the main thing that was missing in 2016," said HackerOne Chief Executive Marten Mickos. "The main failure in 2016 was not notifying the authorities."

© Thomson Reuters 2018

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apps, Internet, Uber, Uber Bug Bounty
Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Fusion Renders Leaked Again: See Design and Colourways
  2. Anaganaga Oka Raju Now Streaming on OTT: What You Need to Know
  3. Samsung Galaxy S26 Series Will Be Available via These E-Commerce Platforms
  4. Samsung Galaxy S26 Series Pricing, Specs Leak As Galaxy Unpacked Nears
  5. Sony WF-1000XM6 Spotted in Comparison Images With These Design Changes
  6. Zeiss Aatma Lenses With Retro Design Unveiled in India: See Availability
  7. Microsoft Says AI Tools With Too Many Privileges Can Become 'Double Agents'
  8. Realme Narzo 90x 5G Gets a New Colour Option Ahead of Valentine's Day
  9. Samsung Announces Galaxy S26 Series Launch Date as Pre-Reservations Begin
  10. EA Teases Battlefield 6 Season 2 Content Ahead of February 17 Launch
  1. James Webb Telescope Finds Galaxies Nearly as Old as the Early Universe
  2. SPHEREx Captures Dramatic Outburst of Interstellar Comet 3I/ATLAS
  3. Microsoft Warns AI Tools With Excessive Privileges Could Act as ‘Double Agents’
  4. Sony WF‑1000XM6 Leak Reveals Size Differences With WF‑1000XM5 and WF‑1000XM4
  5. Android 17 Beta 1 Expected to Roll Out to Eligible Pixel Devices Soon: Expected UI Changes, Features
  6. Lumio Vision TVs to Receive Android 14 Update With Performance Improvements; Arc Projector to Follow
  7. Maruva Tarama OTT Release Date: When and Where to Watch it Online?
  8. Hackers Use ClickFix Scam to Target Crypto Executive via Fake Zoom Meetings
  9. Heated Rivalry OTT Release Date Revealed: Know When and Where to Watch it Online
  10. The Maadhar Streaming Now on OTTPlus: Know Everything About This Tamil Short Thriller Film
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.