The admission arrived on 21 November 2017, in a written statement from a chief executive who had held the job for less than three months. Dara Khosrowshahi disclosed that in October 2016 two attackers had downloaded the names, email addresses and mobile phone numbers of some 57 million Uber riders and drivers worldwide — roughly 50 million riders and 7 million drivers — along with around 600,000 driver's licence numbers belonging to drivers in the United States. "None of this should have happened, and I will not make excuses for it," he wrote. Bloomberg, which broke the story the same day, supplied what the statement circled around: Uber had known for over a year, had paid the attackers, and had told nobody — not the drivers, not the riders, not the regulators already investigating its previous breach.
The mechanics were ordinary. The attackers had found credentials in a private GitHub repository used by Uber engineers, and those credentials opened an Amazon Web Services account where an archive of rider and driver data sat. On 14 November 2016 an email reached Joe Sullivan, Uber's chief security officer, announcing that a vulnerability had been found and demanding a six-figure payment for the data's destruction. Court records would later fix the timing with some cruelty: the message arrived ten days after Sullivan had given sworn testimony to the US Federal Trade Commission about Uber's handling of a smaller 2014 breach — an investigation that was still open as he read the new demand.
What followed is the part the industry has argued about ever since. Within two days Uber agreed to pay $100,000, and in December 2016 it sent the two men $50,000 each in bitcoin through HackerOne, the platform that ran its bug-bounty programme — a scheme built to reward researchers who report flaws, not intruders who take data and set a price for deleting it. The two men signed non-disclosure agreements under pseudonyms, promising the data was gone. Uber's security team then traced them — Brandon Glover in Florida, Vasile Mereacre in Toronto — and in January 2017 had them sign again, in person, under their real names. The breach stayed secret for another ten months.
The dismissals came with the disclosure: Sullivan and a senior lawyer, Craig Clark, were out by the time the statement was published. Everything else took years, and this archive holds the chapters. Attorneys general and regulators on both sides of the Atlantic opened inquiries within days; the reckoning ran to a $148 million settlement with all fifty US states in September 2018. Glover and Mereacre pleaded guilty to extortion conspiracy in October 2019. Sullivan was charged in August 2020, convicted by a San Francisco jury in October 2022 of obstructing the FTC and concealing a felony, and sentenced in May 2023 to three years' probation — the first security chief convicted over the handling of a breach.
Intel confirms flaws in the Management Engine
On 20 November 2017 Intel published security advisory SA-00086 and confirmed what outside researchers had been arguing for months: the Management Engine — a small computer inside the chipset that runs its own operating system, below anything the owner installs — contained serious vulnerabilities. The review had been prompted by Mark Ermolov and Maxim Goryachy of Positive Technologies, who had found ways to run unsigned code on the subsystem; Intel's own audit then turned up further flaws across the Management Engine, its Server Platform Services and its Trusted Execution Engine. The affected list covered sixth, seventh and eighth generation Core processors, several Xeon families, and Atom, Pentium and Celeron parts — millions of machines, from laptops to servers. An attacker who got in could execute code invisible to the operating system and to every security product running on it. Intel shipped a detection tool and left the firmware itself to the computer makers, whose update schedules stretched into 2018. In December the two researchers presented the work at Black Hat Europe in London, under a title that summarised the anxiety: how to hack a turned-off computer.
Imgur answers on Thanksgiving
The month's counter-example took a single day. On 23 November 2017 — Thanksgiving in the United States — the researcher Troy Hunt sent Imgur, the image-hosting service, a file that had been passed to him: email addresses and passwords for about 1.7 million accounts, taken in a breach dating to 2014 that the company had never detected. Imgur confirmed the data over the holiday, began forcing password resets, and published its disclosure on the afternoon of 24 November, noting that the stolen passwords had been protected with the SHA-256 algorithm it used at the time and that it had moved to the stronger bcrypt in 2016. Hunt praised the company's "exemplary handling" and did the arithmetic himself: twenty-five hours and ten minutes from his first email to public disclosure. The contrast with the cover story was the point, and everyone made it — organisations were no longer being judged for having a breach, but for what they did in the hours after learning of one.
210 websites, none of them UIDAI's
The admission surfaced through a Right to Information request. In a reply reported on 19 November 2017, the Unique Identification Authority of India said that around 210 websites of central and state government departments, educational institutions among them, had displayed lists of welfare beneficiaries — names, addresses, other details and Aadhaar numbers — for public view. The authority said it had taken note and had the data removed, but not when the publication had begun or how long it had lasted. Its statement drew the line it would hold for years afterwards: the details had "never been made public from/by UIDAI", and the Aadhaar database itself remained safe and fully secure. The distinction was accurate and, for the people whose numbers had been listed, beside the point.
The programme's legal front moved the same month. On 3 November a Supreme Court bench of Justices A.K. Sikri and Ashok Bhushan declined to stay the mandatory linking of Aadhaar to bank accounts and mobile numbers, leaving the deadlines of 31 December 2017 and 6 February 2018 standing — but ordered banks and telecom operators to state those dates plainly in their warning messages, rather than the open-ended threats of frozen accounts and dead SIMs then arriving on millions of phones. The constitution bench meant to settle the question kept receding, and in December the deadlines slipped to March. Within six weeks a reporter in Chandigarh would buy access to the demographic database for ₹500 — the January 2018 edition of this archive — and the linking mandates for banks and telecoms did not survive the court's final verdict the following September. A comprehensive data protection law took until 2023.
Slaughterbots plays Geneva
The film ran seven minutes and needed no jargon. Slaughterbots, released on 12 November 2017 by the Future of Life Institute with the Berkeley computer scientist Stuart Russell, dramatised swarms of cheap microdrones using facial recognition to find and kill their targets, and was screened in Geneva as governmental experts convened under the UN Convention on Certain Conventional Weapons for their first formal talks on lethal autonomous weapons. It drew millions of views within days and put the case for a ban more vividly than any position paper; the ban has still not arrived, and small drones with a measure of autonomy moved from speculation to the battlefields of Ukraine. The rest of the month was quieter machinery. On 7 November Waymo said its minivans were driving public roads in Chandler, Arizona with nobody at the wheel, the trials that grew into its robotaxi service, and at the month's end a Stanford-led team published the first AI Index, an accounting of the field's progress — active AI startups up fourteen-fold since 2000 — that has measured the boom annually ever since.
Newly single, McAfee buys Skyhigh
The industry's news led with a purchase. On 27 November 2017 McAfee, spun out of Intel that April, announced its first acquisition as an independent company: Skyhigh Networks, a broker of security for cloud services, for an undisclosed sum, with Skyhigh's chief executive Rajiv Gupta joining to run a new cloud unit. The bet — that protecting the endpoint meant following its data into other people's servers — aged well, and the name better: after McAfee's enterprise arm merged into Trellix, the cloud business re-emerged in 2022 as Skyhigh Security. The month's other lesson was less flattering. On 10 November the researcher Florian Bogner published AVGater, a technique abusing the quarantine-restore function of antivirus products from Trend Micro, Kaspersky, Malwarebytes, Emsisoft, Check Point and Ikarus to drop a malicious file into folders ordinary users cannot touch — a route from a standard account to full control of the machine. The vendors patched, but in the month of Intel's Management Engine advisory the moral was plain: the layers built to protect the computer kept turning out to be ways in.
⏳ Time capsule — November 2017
- Leonardo da Vinci's Salvator Mundi sold at Christie's in New York on 15 November for $450.3 million after nearly twenty minutes of bidding — the most expensive work of art ever auctioned.
- Robert Mugabe resigned as president of Zimbabwe on 21 November, a week after the army took control; his letter was read out midway through the parliamentary session convened to impeach him, ending 37 years in power.
- Bitcoin passed $10,000 for the first time on 28 November, having started the year below $1,000 — the run that made cryptocurrency a dinner-table subject.
- Prince Harry and the American actress Meghan Markle announced their engagement on 27 November from Kensington Palace, with a wedding set for the following spring.
What silence costs now
The Uber affair became the industry's reference case, cited in every argument about what a security chief owes the public when the news is bad. The judge who spared Sullivan prison in 2023 said plainly that the next defendant in his position should expect otherwise, and the years since have built the machinery to find one: the US Securities and Exchange Commission now requires listed companies to disclose a material incident within four business days, and sued SolarWinds' security chief the same year Sullivan was sentenced; India's CERT-In allows six hours. Bug-bounty platforms drew brighter lines between a reward for research and a payment for silence. The working assumption of 2016 — that a breach concealed is a breach survived — did not itself survive.
The rest of the month's ledger reads the same way. The Management Engine flaws made the computer below the computer a permanent line item: firmware attacks moved from conference stages to real intrusions within a year, and the question of what runs beneath the operating system stopped being exotic. Imgur's twenty-five hours remains the number quoted when a board asks what good looks like. And the Aadhaar stories of November — the 210 websites, the texted deadlines — were early entries in a file that ran through the constitution bench, the ₹500 portal and, six years later, a data protection act. The Vault's restoration of 2017 continues around this edition, from the three days of WannaCry in May to the months still returning.