Chairman Moran Issues Statement at Hearing on Data Security, Bug Bounty Programs - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
February 8, 2018 Newswires
Share
Share
Post
Email

Chairman Moran Issues Statement at Hearing on Data Security, Bug Bounty Programs

Targeted News Service

WASHINGTON, Feb. 6 -- The Senate Commerce, Science and Transportation subcommittee on Consumer Protection, Product Safety, Insurance and Data Security issued the following statement by Chairman Jerry Moran, R-Kansas, at a hearing entitled "Data Security and Bug Bounty Programs: Lessons Learned from the Uber Breach and Security Researchers":

"Good afternoon. Welcome to the Consumer Protection, Product Safety, Insurance, and Data Security Subcommittee's hearing on "Data Security and Bug Bounty Programs: Lessons Learned from the Uber Breach and Security Researchers." The Subcommittee will come to order.

"Thank you all for being here today to discuss the October 2016 Uber data breach and the allegations against the company regarding impermissible payments to conceal a security incident through its bug bounty program. A bug bounty is a reward offered to someone outside of the company who identifies an error or vulnerability in a computer program or system in connection with a coordinated vulnerability disclosure program. The committee plans to examine the value of these innovative programs and other coordinated approaches to identify cyber vulnerabilities and prevent these types of incidents.

"In late 2016, Uber was notified by anonymous sources that certain archived copies of its databases had been compromised. According to a letter in response to an inquiry made by this committee in partnership with the Senate Finance Committee, Uber's security team "took immediate steps to respond to and limit the impact of the incident," including identifying the parties responsible and paying $100,000 to them in exchange for assurances that the compromised data would be deleted.

"An independent forensic analysis found that the exposed data included information pertaining to approximately 57 million users in total, from both drivers and riders. 25 million of those affected users were from the United States, and the driver's license numbers of about 600,000 drivers were compromised in the breach.

"The fact that the company took approximately a year to notify impacted users raises red flags within this Committee as to what systemic issues prevented such time-sensitive information from being made available to those left vulnerable. Additionally, my colleagues and I seek specific clarification as to what policy safeguards are currently in place to prevent bug bounty programs from being used as extortion pay-out mechanisms in the future.

"These substantive concerns, however, should not completely outweigh the overall utility of this innovative, crowd-sourced approach that many industry actors have taken to proactively identify "chinks in their technological armor" through effectively administered bug bounty programs and other cyber vulnerability disclosure efforts.

"As the American public becomes more and more dependent on innovative technologies to complete everyday tasks, cybersecurity vulnerabilities pose a direct threat, whether it be through a critical telehealth monitoring system, an autonomous vehicle transporting your family, or access to personally identifiable information. Cyber threats are continuously evolving with the technology we rely on.

"My goal for this hearing is to find out exactly what prevented Uber from immediately notifying its users who were impacted by the 2016 breach, the specifics of the related payments and what steps Uber is taking internally to improve its notification protocols. I also want to have a larger discussion on how vulnerability disclosure programs, like bug bounties, can be used effectively to deter cyber threats from harming consumers.

"It is my pleasure to introduce our panel today. Thank you all for being here.

"Mr. John "Four" Flynn is the Chief Information Security Officer for Uber Technologies, Inc. He is an expert in information security with over 10 years of experience in the field, including leading infrastructure security at Facebook and managing security operations at Google.

"Mr. Martin Mickos is the Chief Executive Officer of HackerOne, which is a leading bug bounty firm in the country serving a variety of government and private sector clients, including Uber, in administering their crowd-sourced vulnerability disclosure programs.

"Ms. Katie Moussouris is the Founder and CEO of Luta Security, Inc., which advises its clients on vulnerability coordination programs and applicable internal company policies.

"Mr. Justin Brookman is the Director for Consumer and Technology Policy for the Consumers Union, which is an independent nonprofit consumer organization. In his role, he focuses on policies related to consumer data privacy and security.

"I look forward to hearing the testimonies of this expert witness panel. I now turn to my colleague Ranking Member Blumenthal for his opening remarks."

Older

Sen. Casey Issues Statement at Hearing on Rheumatoid Arthritis Therapies

Newer

Senate Environment & Public Works Committee Issues Testimony From National Cattlemen’s Beef Association

Advisor News

  • Americans aren’t turning retirement plans into action, LIMRA finds
  • Ashley Hinson ‘death tax’ story collides with truth
  • How advisors can prepare clients for an uncertain retirement landscape
  • Investors aren’t waiting out uncertainty
  • Transamerica and Advo(k)ate Advisors launch pooled employer plan
More Advisor News

Annuity News

  • Jackson Financial CEO caps 40-year career with blockbuster Q2
  • Lumos Insurance introduces the Immediate Care Plan to help families fund long-term care
  • NAIC regulators begin consensus phase on annuity illustration overhaul
  • AM Best Revises Outlooks to Negative for Subsidiaries of Group 1001 Insurance Holdings, LLC
  • Market-value adjusted annuities: Key considerations for advisors
More Annuity News

Health/Employee Benefits News

  • Vote delayed on school employee health plan NJ school employees' health care plan vote delayed amid 34% rate hike
  • Financial planning could solve the looming Medicaid disaster
  • Industry groups urge caution in the wake of CMS action against ACA agents
  • Health care regulator should stay the course
  • DAVIE COUNTY WOMAN ACCUSED OF FILING MULTIPLE FALSE MEDICAL INSURANCE CLAIMS
More Health/Employee Benefits News

Life Insurance News

  • Don't keep checks with clerical errors
  • The insurance distributor that builds its own software will win the next decade
  • iA Financial Group Reports Second Quarter Results
  • Supporting small businesses starts with smarter benefits conversations
  • Judge again tosses Penn Mutual whole life lawsuit alleging tax scam
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Press Releases

  • Royal Neighbors Unveils Its 2026 Scholarship Recipients 2026 Royal Neighbors Scholars Making a Difference Across the Country
  • Ibexis Announces Expanded Bank Relationships and New Index Options for FIA Plus® and WealthDefender® Series
  • Agent Review Launches Video AI Identity Verification to Help Protect Insurance Professionals, Consumers and Public Trust
  • Prosperity Life GroupSM Launches Prosperity PathWaySM Series, Bringing Greater Choice and Flexibility to Retirement Income Planning
  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet