Uber employees used the platform to stalk celebrities and their exes
businessinsider.com
businessinsider.com
> Individual users' data is very closely guarded internally. It's immensely difficult to look at user data without specific access. Overwhelmingly, this data is queried in aggregate and fed into machine learning systems. The risk of abuse is exceptionally low.
Obviously this doesn't add up. What gives?
That has absolutely nothing to do with preventing insider access. Where there's smoke screen, there's fire.
This bit stood out to me (emphasis mine):
> Uber says employees don't receive across-the-board access to customer data and there are several controls in place to ensure that employees only access that data for work purposes.
The choice of the word "control" in this context I think gives away a little bit here, it's auditor-speak.
This word does not always mean to an auditor what it means to you or I. Having a written policy that says "Don't access X unless it's required for your job" and keeping access logs can satisfy a "control" from an auditor's perspective, depending on the certification.
That's better than nothing, but back to your point, you're right that it doesn't prevent insider access. Which isn't something I worry about normally...
Edit: Typo
The usual process for such a control should be:
* Is there a requirement for a log?
* Does that log exist?
* Can the system(s) that write to the log be prevented from doing so/tampered with? (branch here to system security review)
* How are the contents of that log secured against tampering? (branch here to security review of logs)
* Who is responsible for reviewing it?
* Where is the evidence that such reviews occurred?
* What violations of policy were found during those reviews? (branch here to a review of the follow-up process)
* Can I, the auditor, find violations that were not found during the reviews? (if yes, branch here to figuring out why not)
This is not an especially complex script to follow, and winning at that last step is the kind of thing that gets you nice fat bonuses and happy bosses, because suddenly the auditee needs remediation consulting services. Especially as the cost of "taking a complete sample" (i.e. reviewing every entry in the log) goes down to nearly zero, this kind of review gets easier and easier (and is often automated by the company being audited, which just shifts the focus slightly... with no change to the last step).
The person in the article was terminated before I joined, so I don't know what the systems were like back then, but every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. I haven't actually tested to see what I can get away with because I'm not in the habit of risking my job and career over curiosities.
If you want to defend uber, it's pretty easy, just say there you know people that work on the team that audits the logs of employee access to personal data every quarter, and if those logs aren't justified by a ticket people get fired.
The image of Uber being a brogrammers haven just isn't true anymore. There are thousands of engineers working that care very much about the company and our customers, including drivers and riders.
It's hard to come up with a way to rationalize the above comment, when the comment is in the discussion of an article showing you're, at best, naïve.
I know you want to believe that what you're saying is true, but it sounds like you have no hard evidence to back that up to yourself, let alone evidence you can present to someone outside such as the HN readers reading this thread.
You may trust that Uber takes the security of customer info seriously, but from the outside we have no frame of reference, except for reports of past wrong-doing. A statement to the effect of "it was bad in the past but it's better now" unfortunately isn't all that reassuring, and I hope you can see it from our side of the fence and understand why.
You are calling the OP out for not having hard evidence, yet you are happily accepting the words of other folks in news reports as being true. You can't really have it both ways...you're just picking the side you want to believe is true...
In this case believing a news article over Uber is in our best interest. As a result your the parent poster is justified in requesting Uber for evidence.
You're implying every information available is to be credited with the same amount of trust. A published article from a journalist from a mainstram media outlet has track records, both on the journalist and the editor. The underlying source, is someone testifying in court, which engages more than aliased online posting, as well as cross-check performed by the journalist on other people.
Second point : the person you quote mainly questions whether the experience he described gives us information on Uber's data protection policy. I had the same feeling. This has nothing to do with the guy's integrity.
Maybe -- I don't work there or know anyone who does. But you have to admit that a company that would even think of creating something like "God Mode," then actually do so, then show it off, is seriously twisted and out of touch. AFAIK most of the higher-ups who were around then are still there now. You shouldn't be surprised if "I swear I've changed, baby" is met with a bit of skepticism.
But I trust that Uber takes the security of their customers information very very seriously.
Looking at Uber history and a number of major gaffes that came to light i call bullshit.Trust is something that needs to be earned. I can't speak for others but I don't trust Uber at all.
That judgment is probably even correct until you happen to hire a bad person one day.
So, how many hours a week do you drive? Oh, I'm sorry... those aren't "workers" -- they're just being nice and sharing their cars in their free time.
It's not an insult. It's a statement of fact: it is a different experience than depending on Uber driving for your livelihood. So one should not read much into it regarding the hardships/issues of drivers as professionals.
The same way a NLE developer that "eats his own dog food" by editing his daughter's birthday video doesn't exactly have the same experience/needs/issues of using the software as a professional editor in TV or film.
that's not what I heard from my friends that worked / currently work there.
Giving people a ton of warnings about the dire consequences of accessing data they're not supposed to is really easy. Preventing them from actually doing it is substantially harder.
You do know that this is literally the bare minimum level of user protection that you can legally get away with... right? That this isn't actually reassuring to anyone who has seen user data with any amount of protection?
If you're satisfied with this level of protection, I assume you're satisfied with it at the NSA/GHCQ.
As someone who works at an actual tech company, I can tell you without looking them up at least three layers that actually deny me access to user data. I know the team that actually audits any accesses made by those who can break glass, and I know who does the firing when the rules are broken.
And the products I work on aren't even regulated like those involved in finance/health/safety/etc.
is this built into the application.. at the ssh layer?
That's nice, but it shouldn't be forbidden to violate users' privacy, it should be impossible.
The purported "God-mode" that Uber had years ago, and showed off at parties, was a real problem with their culture. The ability of devs to get read access to some production data is much less of a huge deal.
I know homomorphic encryption is very new, but deploying it for privacy applications like these is a Good Idea.
Work for just about any company, tech or otherwise, in a sysadmin role. There is always going to be some way for a smart, malicious admin to get into things.
Snowden is maybe the best example. If an organization with an insider threat risk profile as high as the NSA's can't get it right, then you can be pretty certain almost no one else is either.
So, the only people with objective knowledge of a company's internal safeguards and hiring practices are those with favorable subjective value judgments of just how hard it is to bypass those safeguards or just how good those hiring practices are at keeping out unethical people.
-A company had a specific dataset that would be worth millions: The kind of things that a wikileaks might want to publish, and would make the papers. I was supposedly unable to access the app that displayed it, but I had access to the tables. For legitimate business reasons, I took the data out, put it in my company laptop, and stuck a search engine on top. There were no logs of my activity, and nobody came to ask why in the world I was doing something like this.
-At another place, they were saving credit cards, encrypted, but their idea of saving encryption keys was to put them in a file that only root could access. Well, everyone had access to create batch jobs (yes, even phone reps), and batch jobs ran as root, so anyone could walk out with the lot. I had to do a lot of work to convince them that yes, this was not PCI compliant.
-Another system had relatively well protected data, only available to people with access. Except they had single sign on, and some of they systems that took credentials did so in the clear. Peek at network traffic, steal credentials, and then do whatever you want as anyone you want! They had a process where you were never supposed to leave your computer unattended, and if you did, team members would go into your computer and send an email to the team promising cake, and you'd have to bring it as punishment for your security problems. Imagine their surprise when people were sending emails promising cake while they were using their computers.
-A phone company having cell call metadata in the clear, in a DB any developer could query. There was another system with billing information, equally accessible. So search for your favorite person in one, and go to the other and see who they call, when they call, and from where. Isn't that convenient?
So I don't believe anyone's claims about their data security unless they come from someone that has some security knowledge and has tried to evaluate the security pretending to be a real attacker. And even in that case, I'll probably want a team of them. Otherwise, I'll assume there are major flaws that nobody has found, just because nobody has cared enough. I have yet to find an employer where this was not the case.
Unfortunately, this is the state of 99% of all software, everywhere, it would appear. And I'm dubious about that extra 1%.
[Edit] and lets not forget, you can care a lot and still have this be the case
If true, that is fantastically ludicrous.
It seems I wasn't paying attention, in 2014 - as this "God view" news passed me by. I will be keeping a closer eye on this as it plays out.
Uber obviously seems to be in a strong position, but going only by this article, Uber might fare poorly in a multi-region privacy-legislation legal battle (war?).
> every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article.
There is probably a small department doing random checks on data access. But with several thousand people (including support staff) accessing data, the chance of being noticed is extremely low.
a) plead with Uber's customer service to do so
or
b) add another payment method (like another credit card)
This, of course, is horribly bad practice. I can only imagine that they arrived at this very peculiar arrangement after extensive A/B testing - Uber has hired plenty of FB folks and those people tend to be really into that kind of thing. I haven't seen this kind of outright customer-hostility from a large Internet company.. well, ever, before.
So, no, I'm not surprised that this company is doing other unethical things - it sort of seems interwoven into their DNA.
But still, this is not something that I expect to have to stoop to when dealing with an Internet company valued at ~$68B.
Btw: This is what you get when you try to delete the first (and last) valid payment method:
Another company, Privacy.com, does on-the-fly numbers as debit cards drafting from your bank account.
https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
You could also ask them to delete your account and certify that all PIO and payment information has been purged. Depending on your state if residence, there may be other things you can ask for.
Grubhub refused to delete my account even after pleading with them to do so many many times. To me seems like a general tech company trend not something specific to uber.
"Thank you for reaching out and providing us with the opportunity to clarify. We welcome and accept employees with all political beliefs at Grubhub, no matter who they voted for in this or any election. We do not discriminate on the basis of someone's principles, or otherwise. The message was intended to advocate for inclusion and tolerance -- regardless of political affiliation -- during this time of transition for our country.
Thank you, Grubhub"
On the one hand, we have the EU's "right to be forgotten" actions against Google, which seem to be gaining ground and are essentially bona fide in their protection of the consumer/society, in the sense that it might be a good idea for other jurisdictions to adopt it as well.
But consider the EU (and worldwide) regulation of banking and transactional accounts. Particularly the prohibitions on money laundering and counter-terrorism funding (AML/CTF laws). You're not allowed to open and close a bunch of bank accounts, which means that you don't really have a "right to be forgotten" in this sense either. Nor, if you are not a "legit" user, should you be.
From a technical standpoint, how do you detect the law abiding citizens that want to close (in the sense of permanently deleting records) their account(s) from the malfeasant actors that want to launder money or fund terrorism by holding many accounts over time in order to obfuscate their transaction patterns.
It's an interesting question that the law -- and to a certain extent, the people -- have not yet got a good answer
But even the EU has exemptions and complications around data that's used to prevent crime.
Upon request we delete accounts but if they have transactional data this is still held in accordance with our legal requirements.
We have to keep address details to prove we have charged VAT correctly.
These companies don't seem to tend to think long-term, at least not at this level. It's all about growth acceleration/hacking.
During the credit card auth they are told whether the expiration, CVV, and ZIP code match and they can choose to accept the charge even if they do not match, although they do so at some additional risk of the charge being flagged/reversed. They can even charge expired and cancelled credit cards as well.
Expiration/CVV/ZIP checking are an additional security layer but they are there for the merchant, not for you. A credit card number is all a merchant actually needs to make a charge.
> Most consumers think their credit card expiration dates -- the month and year in which their cards are supposed to be renewed -- are a sacrosant security feature, without which a business can't process a payment.
> In fact, big players in the U.S. consumer-sales industry have developed informal agreements with credit-card issuers that allow charges to be made to consumers' credit cards without specifying the expiry month and year. This procedure works even after an individual's card has expired and been re-issued with a new expiration date.
http://www.datamation.com/columns/executive_tech/article.php...
Just change it to that and never use it.
"Well, I cannot delete it"
"Oh, well, thanks, good bye"
Verizon was able to charge against my old account for over a year. I kept getting snail mail letters from my bank telling me that the card I was using had been cancelled and that I needed to update it, but I kind of just wanted to see how long they would let it go.
In other cases, the bank will actually update the vendor with your new card number so that subscriptions are not interrupted.
That's apparently a feature: https://usa.visa.com/dam/VCOM/download/merchants/visa-accoun...
Reminds me of what was done in the military (I think it was in a European country). Officers were spending their time writing reports that were never read. They introduced a policy under which for a given time everyone should stop writing reports until someone complained that they were not receiving it. And if that didn't happen this type of report would be scrapped.
And it has been helpful. I mean maybe about 1% of it is read later at some point and helps clarify a situation. 99% of it is never seen again. That 1% of the time it's really helpful to have it.
I think I will stick with with the new next gen taxi service where one pays with cash.
If it expires or you get a new card in a normal flow it can be charged further.
I have not heard this before. My bank certainly doesn't do this and its a major bank. I actually proactively ask for new cards periodically so that the old ones are no longer valid.
Also, if you say: - Card was lost. - After reviewing all accounts, it was discovered that the CC information couldn't be deleted from the ubuer UI. - I hereby do not authorized uber to make any charges. - tell them in writing or record the conversation.
I don't see any way uber can make any valid charges against your account (assuming no more action on one's part).
I also wonder whether it follows CC guidelines/rules to keep CC information when the customer has explicitly tried to remove and communicated to the company to remove said information.
Currently have two Amex cards with different numbers that show up as 1 card on their online portal & get treated as one.
I don't want to leave my credit card details on the servers of hundreds of companies, or allow them to charge at will, but it's obvious why from the companies point of view why this is attractive.
Flat out, it's a credit card- but with their site or app you can generate single use numbers and CV2, or you can generate merchant locked numbers for things like Uber. There's a lot more they offer, but those two things are what I got it for and how I use it.
[1]https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
Side note: consider the value to foreign (or domestic) intelligence agencies of this weakly-guarded pot of gold.
[1] http://www.theverge.com/2016/11/30/13763714/uber-location-da...
With that out of the way - you know your cell phone carrier already has this data right? They have way better data than Uber ever will about all your habits, including establishing relationships based on who you call, which sites you visit, who you are signed up on a plan with, etc etc. A much more weakly guarded pot of gold, I would say.
Citation needed. I have no reason to believe Uber is better at protecting customer data than my phone provider. The latter likely feels a lot more bound by local laws than a US cooperation nearly priding itself in not adhering to them.
Uber has demonstrated that they can't be trusted with personal data, so I'm quite sure the government will be considering implementing some regulation in their industry too. That's a shame really, because I'm sure most of us would prefer companies weren't restricted by regulation and were just sensible and ethical by default, so laws weren't necessary.
Interesting. I prefer regulation by default to be honest. Possibly shows my biases from growing up and living in Europe. I see regulation as something you should start with not something you should end up having to do. Just like I prefer civil laws to be in place by default rather than leaving it to people to be good to each other.
Maybe I'm in the minority here.
That's the Platonic/Napoleonic mindset right there :)
It's one of the Great Philosophical Questions - do we build society from first principles, or do we just react to what people do as they get together? The latter is the current fashion, at least in theory - in practice, the former keeps coming up over and over, because lawmaking is fundamentally a prescriptive action that instinctively moves from first principles (and it's the only way that lawmakers can forever justify their role: if we ever figured out a society working so well that no reaction or correction is necessary, what would lawmakers do? Write law covering behaviour in places where humans could only potentially exist, i.e. prescribe from first principles).
TBH I rarely ever thought about this sort of thing until I moved to the UK, where the average mindset is deeply anti-Napoleonic/anti-Roman.
And the telecom carriers haven't? Please.
Yes, and look what that's gotten us so far.
So the point is moot for telecom carriers because the regulator already swept in. The point is still important to make concerning ongoing practices in unregulated markets, like big data in tech.
If you don't like how little is done to correct the NSA using telecom facilities however, you should see with your government, not simply the companies it coerces.
The point, as I see it, is that your data is never really safe. I don't much care if Uber can be trusted or not, when the State can always step in and hoover up whatever data Uber has.
If you don't like how little is done to correct the NSA using telecom facilities however, you should see with your government, not simply the companies it coerces.
As long as the State can't be trusted, the rest is moot.
I guess the analogy I'd use would be this: worrying about Uber in the era of rampant warrant-less nation-state surveillance is like rearranging the deck chairs on the Titanic.
Suggesting that the threat posed by Uber and by the government are just different points on the same scale is wrong. They're entirely different problems, and they'll need different solutions.
Respect for privacy has to become the normal situation. You can't say what does it matter if the other party does it way worse? No, they both need to step up. Even if it wouldn't make much practical difference if Uber just deleted their databases tomorrow while the NSA goes about their merry nefarious ways, it's also a battle of the public mind. The public doesn't care a lot, in a very large part because they just feel powerless about it, that they have no choice (and people really tend to come up with the stupidest arguments for the status quo if they feel powerless about it). Best way to make people care again (which is a small step towards getting our governments to stop giving our data to the NSA) is to draw a very clear line in the sand, NO you will respect our privacy, even if you're smaller than the big guys, it's not gonna happen, not on my watch.
It's not like people in war-torn areas stopped caring about muggers and looters just because the US army is killing women and children way more effectively using drone-strikes and misinformed soldiers all hyped up on a mission to kill terrrists (oops). No it's wrong and it shouldn't happen.
My opinion is, the data shouldn't be there in the first place. We can't protect it well enough. Especially not from future people who might legally come into possession of this data. Like in the US, privacy statements apparently mean nothing if a company or startup goes bankrupt and its assets are sold to third parties. They don't buy the obligations. This happened to Radioshack a few years ago, IIRC.
Data is the new radioactive waste.
Of course Uber was built on ignoring laws. So there's no reason to believe they'd follow the restrictions even if they were subject to them.
Unfortunately, that doesn't prohibit foreign intelligence agencies just hacking in and taking it anyway. https://theintercept.com/2014/12/13/belgacom-hack-gchq-insid...
(Pity that I can't see any way of having a cellular network that doesn't know which cell you're in)
"But we already do A, so why shouldn't we do B?"
"But we already do B, so why shouldn't we do C?"
"But we already do C, so why shouldn't we do D?"
...
"But we already do Y, so why shouldn't we do Z?"
This is generally how things slowly but surely go down the toilet. From climate change to mass surveillance to fascism, etc.
"But we can already has Z, so why shouldn't we do AA?"
"But we already make with the AA going, so why you no AB?"
...
Is no problem we just continue continuing on, standing on the shoulders of somebody else's problems, until the problem becomes the soil and a beautiful flower grows. Is future!
Oh dear
--edit-- never mind, that turned out to be a different uber employee that posts here.
Its close to fascism when the argument becomes that the government (ie. NSA) already has this data.
> including establishing relationships based on who you call, which sites you visit, who you are signed up on a plan with, etc etc.
Not if you use Signal and Tor.
Also, the phone company supposedly doesn't abuse that data (they certainly don't have my permission for that); Uber supposedly doesn't either, but it is proven time and time again that it is being abused. Just like the NSA watched people on watchlists watching porn.
For evil software practices like the ones from your employer we need two things:
1) FLOSS applications, and legislation against these practices. (Ironically, your employer is already breaking the law in many jurisdictions as we speak.)
2) If that fails, and for the time being we can still work around it by uninstalling your application. We can also still work around it using magic like LD_PRELOAD faking the geolocation. There already exists libfaketime, not sure about geolocation.
Its also already possible to fake this in the browser: http://www.makeuseof.com/tag/disable-fake-location-firefox-i...
No, they don't. My carrier has coarse location data because they know which cell tower served me. Uber has much more precise GPS data. That's the difference between knowing that I'm in the same building as Edward Snowden and knowing that I'm in the same neighborhood.
Bigger pot, way more strongly guarded.
Much more frightening is that literally all (4 or 5 I've seen by now) HN accounts that identified as Uber developers tried to ascertain "no it's fine and also I trust Uber" did so by while revealing they either
1. have no idea about Uber's exact privacy and security procedures (you don't need to put all the cards on the table if it's sensitive--though it shouldn't be--but you should be aware of the procedures and be able to ascertain they are in fact in place and implemented)
2. or, like the above poster, have very strange ideas about what constitutes their responsibility of protecting the privacy of their users. Hint: it's NOT "be slightly less bad at it than the next guy" (even though in above example that's arguably not even the case). This may be enough semi-security for your personal WordPress-blog, be slightly harder to hack than most people and if you're not a target, you're probably fine, probably.
Except of course, Uber is a target.
And yes, if I were a bad actor and I wanted data like that, of course I'd try Uber first instead of the (way better protected) cell phone carriers.
Especially now that I've seen all these Uber developers publicly flaunt their ignorance on the subject.
Doesn't seem to for me. If I disable it in settings, it prompts me to enter an address and suggests that I re-enable the setting.
I can even silo whatever service I want into its own browser to limit tracking, and all location/permissions/etc are all sandboxed by the browser.
A huge bonus is battery life + ad blocking.
Plus, you are now ready to switch your mobile to Linux (Ubuntu), too. And be completely FREED from any proprietary crap prisonware.
Mods should probably change the OP to link there.
Yeah, their prices are a little more than uber's, and their wait times are a bit higher, but these are functions of scale.
Because Lyft is not so widely available. For example, only Uber is available where I live, though I still prefer traditional taxi because of (usually) better price, more reliable service, availability for short rides and privacy.
Now I'm from a third-world country and can't afford to buy a $1000 phone every year, so I have to be careful with the life of my phone.
The turnaround this, I found, is to disallow location to the Uber app when not using the app and allowing access only when I use the app. This, however, is a pain and the Uber app behaves weird if I do so (the previous trip does not end after hours of it actually ending).
Very poor UX from Uber, potentially dangerous, definitely unethical. This is definitely a trend -- startups start with being caring of its customers, but once they grow big, they become callous and even malicious when it comes to users (I don't ask of them to give every customer personal support, but not mis-using customers is the least I can expect).
When I was getting ready to leave for work today, I got out of the shower and grabbed my phone and saw a alert saying Uber has been using my location in the background. I hadn't opened the app since last week, last time I needed a ride. I'm sure it could've just been an errant push notification coming in late and waking the app up in the background, but I'm spooked.
Uber would like to access your location at all times
[Yes, allow in the background]
[Yes, only when open]
[No, deny all together]I think the pop-up is telling me it was using my GPS, especially since the GPS icon on the Settings page where you can retract the permissions was lit up to indicate "Recently used".
I don't want to jump to conspiracy theories but the experience scared me a bit because it was around the exact same time of day I had grabbed an Uber to go to work the last time I had used it.
Perhaps it was an errant random notification meant to scare me, perhaps it was a late delivered push notification opening Uber in the background, perhaps it was Uber seeing if I was home and wanted to commute to work again.
Do they still have "Ride of Glory" detection?
It works for writers, celebrities, etc - why not the rest of us.
EDIT to clarify: this is a serious comment, you can read it literally.
EDIT: to eon - ah, okay. No it was serious, as my other replies here show. I'll add a serious tag.
But I don't think credit card companies will go ahead and send me a new card in a new made-up name just for Uber. (And one for my awazon dildo purchases.. And one for...)
So it's not quite as simple. What I argue is that companies should legally be forced to do just that.
--
EDIT: to dublinben below
Good to know but I likely wouldn't risk doing that today. It would look too much like fraud. (especially if the name doesn't match.) suppose I needed to be in touch with their cust service or billing in the future for example...
If it were known that companies were forced to accept aliases it would be different.
1) go to my online banking and sign in
2) pick a name and request a card for it.
They should be legally forced to send me one.
The point is I can use that for amazon dildo purchases, and no creep at amazon would get to see that I'm (whoever.)
I get that this is possible: it needs to be simple.
I also checked US Bank and American Express and you are correct, the process is not smooth at all. US Bank wants me to print, sign, and mail it! American Express wants to verify identity of the additional user using an SSN. That makes no sense of course, because they might not even have an SSN and the main account holder is still contractually obliged to pay the account balance.
Since you don't have an annual fee, can you order a card in the name of Donttrackme McSpammer (or any other similar name that couldn't be mistaken for a real name) and see if you get it?
Thanks for having taken the time to check the other two sites as well. I appreciate it!
Without locking down such access, you get incidents like these (and this was even when Google purportedly had strong auditing): http://www.pcmag.com/article2/0,2817,2369188,00.asp
> Google this week confirmed that it fired an engineer who accessed the Gmail and Google Voice accounts of several minors and taunted those children with the information he uncovered.
The public sector has its fair share of these too: http://articles.orlandosentinel.com/2013-01-22/news/os-law-e...
Here's a URL to the plaintiff's declaration: https://www.documentcloud.org/documents/3227535-Spangenberg-...
Lots of tidbits there...including how all payroll information is apparently contained in an "unsecure Google spreadsheet"
Won't have a 100% success rate but I guess it could prevent most cases of abuse. It's not that different from what banks do to detect internal fraud.
Menu -> Help -> Account And Payment -> Account Settings and Ratings -> Delete my Uber Account -> Fill in the form.
Oh on iOS you will need to turn on location tracking otherwise the nag screen about how wonderful enabling location services is seems to prevent the app showing the menu button...EDIT: Oh you can still press the Menu Button, its just the nag screen has a strong tint to it and I had my brightness low. Doh.
This is precisely why it makes sense to keep database data encrypted even to admins and why it makes sense for ride-sharing companies to be co-operatives or non-profits.
Profit-seeking companies engage in bad behaviours all the time.
Except Uber now has arbitration clauses in both it's driver and passenger service agreements. It remains to be seen how well it will hold up in court [1], but I wouldn't count my chickens yet.
[1] https://consumerist.com/2016/08/02/judge-shreds-uber-says-co...
- stalk celebrities, as well as the exes of said celebrities
- employees stalk their exes and also some celebrities
It's obviously the latter but couldn't the same sentence imply the former as well? Is their a better way to formulate this sentence in a non-ambiguous way?
Every time you have customer's information, the people responsible for giving access to that data should be held responsible...
1980's: long distance company has employee(s) poking around messaging system and sells to newspaper. Few know. All voice over network is stored "searched" for "key" phrases. Very few know. Moreover there are no blogs or places to tell ones story.
Now one little confessional outing becomes widespread and thus assumed to be happening all the time.
I am sure (without facts) that uber is no worse than AT&T back in the day but now so so so many people can read and tell their stories.
Does anyone really think or expect communication via electricity is truly protected?
There are a million places to talk negative about everyhing. Here, we're trying to build things. We know no one is perfect. Lets make this place a bastion of positivity instead of negativity.
This negative article is no different from the articles posted about Theranos, Amazon, Facebook etc. Uber does not get a free pass.
Uber isn't a YC company.
> Here, we're trying to build things.
Actually, I'm not here to build anything. I'm here to have discussions about tech.
Capitalists who value the free market who are also the bosses and entrepreneurs see opposition to their money making efforts as an affront to their very core values.
In my opinion it's the wrong way to think - and the root cause is unchecked free market capitalism. However, I think it's true that many people think that to succeed as a startup, money comes before morals. We shouldn't hide that, but criticise it and voice our concerns.
It just happens to be hosted on a subdomain of a startup accelerator but the overwhelming majority of people who read it are not involved with startups.
This rule means you can criticise, fiercely and vigorously, any company or product, so long as you're attempting to be civil and constructive.
https://news.ycombinator.com/item?id=9317916
> Critical thinking is good; shallow cynicism, on the other hand, adds nothing of value to the community. It is unpleasant to read and detracts from actual work. If you have something important but negative to say, that’s fine, but say it in a respectful way.
What a useless change just for the sake of being politically correct. Are companies going to start removing "God Mode" from video games and calling it "super mode"? Seems crazy they would muck with naming to be PC even for internal tools
the name was most likely changed because the connotation of a "god view" means its omnipotent or at the very least omniscient. aka, it knows everything about you.
so it was most likely changed because of the backlash of the name being associated with invading your privacy and seeing what you were doing in uber. this again is why everyone is upset about uber forcing their app to be always on.