Financial Poise
Uber app

The Biggest Cybersecurity Lesson from the Uber Hack

Cybersecurity was once more in the headlines this week as a massive hack of ridesharing company Uber was made public. According to the New York Times:

Uber discovered its computer network had been breached on Thursday, leading the company to take several of its internal communications and engineering systems offline as it investigated the extent of the hack.

The breach appeared to have compromised many of Uber’s internal systems, and a person claiming responsibility for the hack sent images of email, cloud storage and code repositories to cybersecurity researchers and The New York Times.

“They pretty much have full access to Uber,” said Sam Curry, a security engineer at Yuga Labs who corresponded with the person who claimed to be responsible for the breach. “This is a total compromise, from what it looks like.”

Well, that’s not alarming or anything. It’s not like an estimated 119 million people use Uber to get from point A to point B using their credit card details, or that between 4 and 5 million drivers have their own personal information stored by the tech giant. Nothing could go wrong if the movements of private citizens were made available for public consumption. No big deal, right?

So far, the hack does not appear to be rooted in overt malice, but protest over driver pay. The culprit seems to have been enjoying themselves, announcing the hack on the company’s Slack channel before redirecting that URL to a page featuring pornographic images and commenting on all open tickets about their accomplishment.

As the New York Times article pointed out, though, this was no basic breach of cybersecurity. The hacker was able to gain access to the company’s source code, email, HackerOne bug reports, AWS admin, G Suite admin, and domain admin.

If all that sounds like Greek to you, it’s more simply put this way: for a moment time, Uber was not owned by Uber.

Fortunately, the purported teen who was able to grab the keys to the kingdom doesn’t seem to have done much with them, and Uber released a statement on Friday stating that no user data had been compromised. They don’t exactly have a great track record on transparency with hacks, but that’s not really the point.

Whether or not the hacker did anything nefarious, they could have. It’s a scary proposition for any company, to be sure. What’s even scarier, though, is that the hack was executed using a tactic that almost any company could be vulnerable to on any given day.

Technology Confounded by Exasperation

It wasn’t a fancy new piece of technology or a particularly ingenious string of code that got the hacker inside Uber’s gates. It was instead akin to the never-ending tantrum your toddler throws to try and wear you down. This was the text sent by the purported hacker to the New York Times.

Uber Cybersecurity Hack Explanation Text

To translate for those who have never had to deal with “push auth”, it’s a shortening of the term “push authentication”. As digital security company HYPR explains:

Push authentication is a mobile-centric authentication whereby the service provider sends the user a notification over the most secure available communication channel. The user responds to the challenge by performing an action to verify their identity and access the service. Push authentication relies on device possession as the dominant factor.

So, essentially, to get around Uber’s cybersecurity, this hacker barraged an employee with a whole lot of these push requests in order to access their device. If you’ve ever seen your phone blow up with notifications, you know that – even when you like the application they’re coming from – it can be irritating beyond words. Banking on that feeling of frustration, the hacker then reached out to the employee directly using the free messaging tool Whatsapp, framing the situation as an IT problem that would go away if the employee just accepted the request.

Seem improbable? Think again. Whatsapp became all but ubiquitous during the pandemic due to its versatile messaging capabilities and the low price of $0 for use. At the same time, it was relatively popular among those wanting to fly under the radar, with lax requirements for participation and a bevy of guides available on how to hide who you are.

So if you’re an employee at a sprawling company experiencing technical difficulties, and someone messages you using a common alternative messaging system to let you know they’re aware of the issue and can help if you do what they say, you might not blink. After all, if there are tech problems in play, of course they’re going to have to contact you outside of the tech that’s currently malfunctioning.

That’s all it took. For all the money and access to technology in the world, Uber was felled, at least temporarily, by a kid who knew something anyone who has ever had a computer mess up on them does.

Sometimes you just don’t want to be told to turn it off and on again. Sometimes you just want the headache to be done.

Cybersecurity in the Age of Psychological Warfare

Much has been made of the importance of digital security in the modern age, and with good reason. From the Melissa Virus of the 90’s to Stuxnet taking out Iran’s Nuclear program, NASA and the DOD getting bested by a high school student, and the Equifax FTC settlement over compromised data, there is no shortage of stories out there about hacks big and small, playful and nefarious. Nervous corporations began investing heavily in battening down the hatches against the advances of unknown assailants wielding keyboards, Red Bull, and an insatiable desire to beat the big dogs at their own game.

Cybersecurity has come a long way since John McAfee convinced the world that anti-virus software was the cure to all that might ail them in an increasingly digital world. The industry is projected to reach more than $400 billion in size by 2027, and that estimate might be conservative. With threats seemingly coming from every direction, is that really so surprising?

What is surprising is that, despite the sheer size of the industry and the critical role cybersecurity plays in protecting a company’s well-being, they still haven’t figured out the problem with their approach. The lesson they keep missing – which feels impossibly obvious given the history of cyberattacks over the years – is that our cybersecurity is only strong when people know how to use it and are willing to do so.

Modern cybersecurity is, in some ways, lightyears ahead of where we were a decade ago. It seems like only yesterday that CAPTCHA codes to verify that whoever was trying to access a system or account was at least human was height of innovation. However, while the processes and technology we use to secure our systems today may be more advanced and difficult to get around, the people who use it are still just people. They are still just human beings trying to navigate a system that was built for a purpose, but not necessarily a person. To this end, the security gap is less about technology than it is the way users are forced to interact with it.

This is where UX – or user experience – design becomes crucial. Yes, some of the apps associated with these processes look pretty enough, but an experience is about more than meets the eye. That’s where modern cybersecurity falls flat. It forgets about the person on the other side of the code.

Generally speaking, people are lazy. If we can find a faster or easier way to do something, we do. If something is confusing or cumbersome, we will just as soon abandon it or move around it than we will invest time in figuring out. In some cases, that’s not a bad thing, what with necessity being the mother of all invention. When it comes to cybersecurity, though, a system that makes the user not want to follow protocol is a liability. It means that the wall you’ve built has missing bricks that leave your company vulnerable to attack, and the wrong hit can bring your whole operation tumbling down. Odds are you won’t even realize the wall isn’t strong enough until it’s too late.

If cybersecurity measures are to be reliable, they have to be designed to not only keep attacks out but keep people in the workflow. This means considering elements like training quality and simplicity, time burden associated with compliance, memory constraints, navigability of a system, availability of support, and more. And it means that companies need to determine which sorts of processes are necessary and workable for their particular needs and team.

This is not the age of McAfee and standard phishing attacks. The stakes are higher. The technology is there to protect you and your interests. You just have to make sure you’re choosing a solution that will actually get put to effective use.


[Editors’ Note: To learn more about this and related topics, you may want to attend the following on-demand webinars (which you can listen to at your leisure and each includes a comprehensive customer PowerPoint about the topic):

Additional Reading:

©All Rights Reserved. November, 2021.  DailyDACTM, LLC d/b/a/ Financial PoiseTM

Share this page:

About The Financial Poise Editors

Financial Poise helps trusted advisors (accountants, attorneys, business brokers, consultants, financial advisors, investment bankers, etc.) by providing a meritocracy-based platform on which to demonstrate their thought leadership. The thought leadership of these advisors is expressed in the form of educational articles, so we can provide our readers high-quality, unbiased education about investing, owning a business…

Read Full Bio »

Follow The Financial Poise Editors on: