Featured Article

Ex-Uber CSO Joe Sullivan on why he ‘had to get over’ shock of data breach conviction

Sullivan tells TechCrunch he’s no longer bitter and instead wants to help fix the broken cybersecurity industry

Comment

Joe Sullivan, the former CSO of Uber and Facebook.
Image Credits: Courtesy of Joe Sullivan

Before joining Uber as chief security officer in 2015, Joe Sullivan served for two years as a federal prosecutor with the United States Department of Justice, where he specialized in computer hacking and IP issues. He worked on a number of high-profile cases, from the first case in the U.S. of prosecution under the Digital Millennium Copyright Act to the prosecution of a hacker who breached NASA’s Jet Propulsion Laboratory.

More than 20 years after joining the U.S. government to help organizations defend against the so-called bad guys, Sullivan found himself on the other side of the justice system.

In October 2022, a San Francisco jury found him guilty on charges of obstructing an official proceeding and misprision of a felony (a failure-to-report-wrongdoing offense). In May this year, Sullivan was sentenced to three years probation.

The irony is not lost on Sullivan, who spoke to TechCrunch in London this week prior to his keynote speech at the cybersecurity conference Black Hat Europe.

This precedent-setting case pertains to a breach of Uber’s systems in 2016, where hackers threatened to expose the data of 50 million Uber customers and drivers. The verdict centered primarily around Uber’s decision not to report the breach to the Federal Trade Commission, as the company was mandated to report all breaches after an earlier 2014 hack of its systems exposed the names and driver’s license numbers of 50,000 people.

The case didn’t go as Sullivan, who was fired from Uber in 2017, had expected.

“We thought we were going to win the trial. We barely put on a defense because my lawyers were like, ‘we don’t need to.’ I didn’t testify, so the jury never saw me. They just saw the anonymous Uber executive with a mask on,” Sullivan told TechCrunch during the interview on Wednesday.

The first-of-its-kind verdict hit Sullivan hard initially. “When I lost the trial last October, I was in a funk, I didn’t want to talk to anybody, and I didn’t know what would happen to my life,” he said. “I just wanted to curl up in a ball.”

Sullivan’s case also caused anxiety among fellow CSOs and CISOs, a number of whom wrote letters to the case’s sentencing judge, William Orrick, praising Sullivan’s actions and voicing their fears that they too could face legal penalties for simply doing their jobs.

“Joe’s case has had a huge impact on the cybersecurity community,” one letter, signed by more than 50 CISOs, read. “It has been the subject of frequent executive team conversations and panel discussions at industry seminars, and a significant driver of efforts to change policies and practices to err on the side of disclosure, even when the legal requirement to do so remains unsettled.”

These fears have lasted long beyond Sullivan’s conviction. The former Uber CSO, who now works as CEO at a nonprofit dedicated to providing humanitarian and technology aid to the people of Ukraine, told TechCrunch that he receives calls every week from security professionals asking whether they should stay in the industry and whether they should take interviews for higher-ranking roles that come with greater responsibility — and greater risk.

“What I tell the security executives right now is that they shouldn’t run away from the job — they should run towards it,” Sullivan said, noting that the shared anxiety among cybersecurity professionals, along with the fact that he wanted to be a “better person,” is part of the reason he wanted to start speaking out about the Uber data breach case.

“I realized that sharing what I’ve gone through is better than not, and healthier for me. It’s taken me a year to say that, but that’s the right way to be,” Sullivan told TechCrunch. “I was very bitter, but I want to be a better person. I also want to continue being part of the security world, so I have to get over it.”

Sullivan told TechCrunch that another reason he’s keen to speak out is because of the fact that there have been “100 webinars, by 100 lawyers, saying that ‘you won’t end up like Joe if you have insurance, if you bring legal and PR into the room, or if you have a breach responsibility policy.’”

“We did all of those things [at Uber],” Sullivan said. “We had insurance; there was a data breach response policy; we looped in PR, and the CEO [Travis Kalanick] signed off on everything, including the dollar amount,” he added, referring to the $100,000 payment that was made to the two young men that discovered the vulnerability that led to the 2016 Uber breach.

When asked whether he believed Uber’s then-CEO should have been held responsible, Sullivan said: “I don’t think anybody did anything wrong at the end of the day.”

“Uber wouldn’t exist today — in fact, we would still be taking taxis — if it wasn’t for [Kalanick] and his sheer forcefulness,” Sullivan added. “On the upside, he drove some change in the world. However, on the downside, his philosophy was that the person who threw the first punch wins the fight.”

Fixing a broken industry

In what Sullivan describes as “the greatest irony of his career,” part of his role at the Department of Justice involved him working closely with organizations in Silicon Valley in order to encourage more collaboration with the government. “That’s been the story of my career; trying to get the public and private sectors to work together.”

Sullivan believes that going forward, this public-private sector collaboration, along with strong regulation, is the only way to fix the “broken” cybersecurity industry.

“When I joined, [Uber] had the worst security of any $40 billion company, and that can’t fly in the world anymore. If you’re going to sell a product, your security has to be good enough the day you sell it,” Sullivan said. “I could be very bitter about the idea of government regulation since I was regulated, but I also think we need it for the internet to work well in the future.”

Sullivan praised the U.S. Security and Exchange Commission’s incoming data breach disclosure rules, which come into effect on December 15, noting that while not perfect, it’s much better than having zero guidance. “We can nitpick the details as much as we want, but this is the right way to do it,” he said. “I seem to be the person who’s criticizing the SEC less than everyone else because I think we should praise them for trying to make rules.”

As for CSOs and CISOs, many of whom are still worried that they’ll be held personally liable for security failings at their organization, Sullivan believes that now is the time to speak out in order to shape any future regulation.

“We have to pull ourselves up, we have to learn the policy side of it, and we have to learn how to make our voice heard,” Sullivan told TechCrunch. “I think we have to develop leaders who can be real societal leaders who are experts in our profession.”

Carly Page reporting from Black Hat Europe in London.

More TechCrunch

Zen Educate, an online marketplace that connects schools with teachers, has raised $37 million in a Series B round of funding. The raise comes amid a growing teacher shortage crisis…

Zen Educate raises $37M and acquires Aquinas Education as it tries to address the teacher shortage

“When I heard the released demo, I was shocked, angered and in disbelief that Mr. Altman would pursue a voice that sounded so eerily similar to mine.”

Scarlett Johansson says that OpenAI approached her to use her voice

A new self-driving truck — manufactured by Volvo and loaded with autonomous vehicle tech developed by Aurora Innovation — could be on public highways as early as this summer.  The…

Aurora and Volvo unveil self-driving truck designed for a driverless future

The European venture capital firm raised its fourth fund as fund as climate tech “comes of age.”

ETF Partners raises €284M for climate startups that will be effective quickly — not 20 years down the road

Copilot, Microsoft’s brand of generative AI, will soon be far more deeply integrated into the Windows 11 experience.

Microsoft wants to make Windows an AI operating system, launches Copilot+ PCs

Hello and welcome back to TechCrunch Space. For those who haven’t heard, the first crewed launch of Boeing’s Starliner capsule has been pushed back yet again to no earlier than…

TechCrunch Space: Star(side)liner

When I attended Automate in Chicago a few weeks back, multiple people thanked me for TechCrunch’s semi-regular robotics job report. It’s always edifying to get that feedback in person. While…

These 81 robotics companies are hiring

The top vehicle safety regulator in the U.S. has launched a formal probe into an April crash involving the all-electric VinFast VF8 SUV that claimed the lives of a family…

VinFast crash that killed family of four now under federal investigation

When putting a video portal in a public park in the middle of New York City, some inappropriate behavior will likely occur. The Portal, the vision of Lithuanian artist and…

NYC-Dublin real-time video portal reopens with some fixes to prevent inappropriate behavior

Longtime New York-based seed investor, Contour Venture Partners, is making progress on its latest flagship fund after lowering its target. The firm closed on $42 million, raised from 64 backers,…

Contour Venture Partners, an early investor in Datadog and Movable Ink, lowers the target for its fifth fund

Meta’s Oversight Board has now extended its scope to include the company’s newest platform, Instagram Threads, and has begun hearing cases from Threads.

Meta’s Oversight Board takes its first Threads case

The company says it’s refocusing and prioritizing fewer initiatives that will have the biggest impact on customers and add value to the business.

SeekOut, a recruiting startup last valued at $1.2 billion, lays off 30% of its workforce

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender SoLo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

2 days ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’