world of internet security, latest cyber security news,information,updates on technology,it job vacancies,internet security,breaches,and safeguards

Friday 3 April 2015

Uber gets its first chief security officer - Facebook's Joe Sullivan

with 0 Comment

 joe-sullivan-hired-uber-170
 Uber isn't afraid to throw its weight around, and whether it's forcing its will on reluctant cities, or crushing competitors, it usually gets what it wants.Now Uber has poached a top executive from Facebook.Uber wanted a chief security officer (the first ever at the six-year-old company), and got their man - Facebook's Joe Sullivan.Sullivan acted as chief security officer (CSO) at Facebook for five years, and before that in similar roles at eBay and PayPal.
 
In a blog post announcing the hire, Uber CEO Travis Kalanick said Sullivan will oversee the ride-hailing giant's cybersecurity and safety efforts on a global scale.Kalanick set the bar for Sullivan pretty high, saying Uber wants to "redefine what it means to be a world-class, people-centric protector of privacy."A bold statement for sure, especially considering Uber's bad track record around data security and privacy.Let's look at a sampling of Uber's security SNAFUs we've covered at Naked Security in recent months:
  • A database breach in which 50,000 driver identities were stolen, which may have been the result of leaving "secret" login keys in a public posting on GitHub.
  •  Data lost, and found, when customer data was exposed for several hours in an online "lost and found" portal.
  • Stolen customer logins, offered for sale in a dark web marketplace.
 Uber's dedication to privacy hasn't exactly been world-class - an executive at the company confessed to sneaking a peek at a journalist's supposedly private trip information - tracking her movements on two separate occasions.Another Uber executive suggested searching private information to dig up dirt on a journalist who was critical of the company.And Uber data crunchers published a since-deleted blog post about mining data to spot customers who've just had lovers' trysts, which, even if anonymized, is really creepy.
We should give Uber some credit - it has recently stepped up its safety and security efforts.In November 2014, the company hired an outside auditor to check up on its data security practices, and this past March, in response to several lawsuits against it, Uber said it was working on improving customer safety and beefing up background checks on drivers.Uber has learned, slowly, that it has security problems that need addressing - although you have to wonder why Uber didn't have a CSO before now.
 
Maybe it's because start-ups are so busy growing their companies that "security is an afterthought," as Tyler Shields, a senior security analyst at Forrester Research, told the Washington Post.Hiring one of Silicon Valley's top security pros is a positive step in the direction.
But Sullivan, who was a pioneer of cybersecurity investigations at the US Department of Justice before jumping to the private sector, definitely has his work cut out for him.

0 comments:

Post a Comment