Live data from Hacker News

FTC says Uber took a wrong turn with misleading privacy, security promises

ftc.gov

1–10 of 30 posts

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#2
From the article:

For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives.

What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account information and Social Security numbers. The FTC says Uber didn’t discover the breach for almost four months.

The proposed settlement prohibits Uber from misrepresenting its privacy and security practices. It also requires Uber to put a comprehensive privacy program in place and to get independent third-party audits every two years for the next 20 years. You can file a public comment about the settlement until September 15, 2017.

The complaint: https://www.ftc.gov/enforcement/cases-proceedings/152-3054/u...

Links from complaint:

Agreement Containing Consent Order (19.87 KB) https://www.ftc.gov/system/files/documents/cases/1523054_ube...

Decision and Order (57.66 KB) https://www.ftc.gov/system/files/documents/cases/1523054_ube...

Complaint (35.88 KB) https://www.ftc.gov/system/files/documents/cases/1523054_ube...

Complaint Exhibits A and B (1.2 MB) https://www.ftc.gov/system/files/documents/cases/1523054_ube...

Analysis of Proposed Consent Order To Aid Public Comment (56.14 KB) https://www.ftc.gov/system/files/documents/cases/1523054_ube...

Press release: Uber Settles FTC Allegations that It Made Deceptive Privacy and Data Security Claims https://www.ftc.gov/news-events/press-releases/2017/08/uber-...

Settlement agreement quote:

Under its agreement with the Commission, Uber is:

prohibited from misrepresenting how it monitors internal access to consumers’ personal information;

prohibited from misrepresenting how it protects and secures that data;

required to implement a comprehensive privacy program that addresses privacy risks related to new and existing products and services and protects the privacy and confidentiality of personal information collected by the company; and

required to obtain within 180 days, and every two years after that for the next 20 years, independent, third-party audits certifying that it has a privacy program in place that meets or exceeds the requirements of the FTC order.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#3
post #2

From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…

> prohibited from misrepresenting how it monitors internal access to consumers’ personal information;

I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator?

> required to implement a comprehensive privacy program … > required to obtain within 180 days, and every two years after that for the next 20 years, independent, third-party audits certifying that it has a privacy program in place that meets or exceeds the requirements of the FTC order

This is worth noting, it clearly alludes to a need for "privacy champion" (or "privacy engineer/compliance officer/deputy CIO") for any business that deals with sensitive (to regulatory compliance) personal information. It's not enough to write a token "/about/privacy.html" and relegate any and all of the system requirements that arise due to regulatory compliance.

I hope other startups take note of this, and plan to allocate resources to this in their roadmap. I don't care when exactly you plan to do it - make sure it's there in your TODO list of things before the regulator comes knocking on your doors.

Also, I was unable to find any number or estimate of cost of compliance mentioned in the settlement. I would really prefer when a government agency agrees to settle with a business they make it public how much the business was fined as well as the future cost of compliance. This information would hopefully make it clear to future businesses to take privacy issues seriously.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#4
post #2

From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…

Mindboggling huh?

Imagine how deep the hands go or who is on Uber side that the result of FTC settlement is statement tht forbids Uber from... breaking the law. Amazing! Me and you would be heading to jail for the claims they did. Not uber.

It also somehow reminds me of 911 commision. It eventually got so sidetracked that the result of the findings were that pretty much two planes hit towers and then they collapsed. End of investigation.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#5
post #3
post #2

From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…

> prohibited from misrepresenting how it monitors internal access to consumers’ personal information; I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator? > required to implement a comprehensive privacy program … > required to obtain within 180 days, and every two years after that for the n…

> I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator?

Breach of a consent order is a fast track into the court supervising the order, and the terms are usually more specific (and thus easier to demonstrate) than the underlying law, and violating the consent order can risk basically reopening the original litigation with it full potential consequences (not just those for the narrow violation the provision of the order at issue would involve under the bare law), so often consent orders will have restrictions that are special cases of restrictions that already exist in law.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#6
post #4
post #2

From the article: For a particular six-month period, Uber only monitored access to the account information of a select group. Who? Certain high-profile users, including Uber executives. What was the upshot? In May 2014, an intruder used an access key an Uber engineer had publicly posted on a code-sharing site to access the names and driver’s license numbers of 100,000 Uber drivers, as well as some bank account inform…

Mindboggling huh? Imagine how deep the hands go or who is on Uber side that the result of FTC settlement is statement tht forbids Uber from... breaking the law. Amazing! Me and you would be heading to jail for the claims they did. Not uber. It also somehow reminds me of 911 commision. It eventually got so sidetracked that the result of the findings were that pretty much two planes hit towers and then they collapsed.…

I mean, isn't the whole "you gon' get audited for decades" bit about how this usually goes? The audit is the actual teeth here, if the auditor finds issues any time in the next decade, they start assigning fines like in the 10k per infraction per day-not-yet-fixed range or something.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#7
This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say, but very very very few actually do. This is just another minor blip in the otherwise very large system of data available everywhere. Your data is not safe, trust me on that.

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#8
post #3

Earlier quoted context omitted.

> prohibited from misrepresenting how it monitors internal access to consumers’ personal information; I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator? > required to implement a comprehensive privacy program … > required to obtain within 180 days, and every two years after that for the n…

> I don't understand why one would need an agreement between Uber and the FTC explicitly mentioning this. Is it not illegal if a company misrepresents its compliance to the regulator? Breach of a consent order is a fast track into the court supervising the order, and the terms are usually more specific (and thus easier to demonstrate) than the underlying law, and violating the consent order can risk basically reopeni…

Right, this is completely about keeping it within the continuing jurisdiction of the court

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#9
The craziest part to me:

"As a result of the failures described in Paragraph 18, on or about May 12, 2014, an intruder was able to access consumers’ personal information in plain text in Respondent’s Amazon S3 Datastore using an access key that one of Respondent’s engineers had publicly posted to GitHub, a code-sharing website used by software developers. The publicly posted key granted full administrative privileges to all data and documents stored within Respondent’s Amazon S3 Datastore."

https://www.ftc.gov/system/files/documents/cases/1523054_ube... Page 5

Re: FTC says Uber took a wrong turn with misleading privacy, security promises

#10

This isn't an uber problem - it's a startup tech problem - no one wants to take security seriously because it's a cost sink that only averts risk, does not actually make a company revenue. I have seen ssn's store insecurely, open api's with customer data, old frameworks and languages that no longer receive security patches. Nearly every startup says they take security seriously, because that's the right answer to say…

I've done InfoSec for a bunch of startups, none seem to grasp the importance of security by design and how it can play an integral role in the business. It's exhausting to have to battle a neon-haired developer that wants to just write code (rightfully so,) not following a process or standards often engaging in arguments just to be right. Imagine one person going asking an entire engineering org to create security priorities until business gets a hold of those and comes back to yell at you for delaying sprints, yep, that's InfoSec for you. Also, any business that says "We take security seriously" isn't. That's a boilerplate they plucked out of the legalese to CYA.
Post reply on HN