Uber Doesn’t Want to Give NYC (or Anyone) More Data
bloomberg.com
bloomberg.com
I think it's not unlikely that we will see new legislation soon which will oblige companies to make some of their data available to the public or at least public organizations so that they can be used for public good. In fact this wouldn't be unprecedented, and nothing that would be (IMHO) very detrimental to these companies.
Over regulation kills business; maybe not companies like Uber, but smaller companies that are still trying to get off the ground.
This is a slippery slope.
We obviously wouldn't want the public to have access to personally identifiable data like GPS movements captured by phones, as this kind of data is highly sensitive. But having access to aggregated, (properly) anonymized data would be sufficient for many things, e.g. to see where local traffic hot spots are and how people commute to work. Giving out this data does not compromise privacy (if done right) and has a very little risk of harming the company that generated it.
Almost all information/research would serve a "public good" if it was converted from private to public. If the government forced an investment firm to reveal which companies they thought were the most undervalued in a market, many people would benefit from that knowledge. The question is, what right and what incentive structure promotes the generation of that knowledge. Theft is certainly not a structure that generates it long term.
How so? Sharing this information is a condition of operating in an area. If that is unprofitable, Uber won't operate there.
But they're not doing that work for "free". They're doing in exchange for the privilege of being able to run a large-scale business on one of the most highly-trafficked street grids on the planet. Which in turn certainly doesn't exactly come for "free" (and in fact costs many billions of dollars per year to run, involving thousands and thousands of people who certainly don't work for fee either), now does it.
So Uber says they don't want to pay for that privilege? That they'd rather not have to comply with regulations (like every other business operator in any other damn category you can think of) because they're... special?
That's fine, of course -- they just don't have to do business in NYC, then.
Why should a government be able to coerce a private organization into providing data? How do you define data? At least in the US, I can think of 2 amendments that would be violated by such action (is data speech? can you be forced to self incriminate?).
There are so many things that the government can force an individual or a business to do in the name of public good, but we can agree that many of those things count as government overreach, why not this?
Why should a government be able to coerce a private organization into providing data?
Perhaps when it is benefiting from public infrastructure in the activities that generate that data? Not sure where I come down on this one but it isn't a crazy argument.This does not, however, give the government a blank check on an individual or a business's rights. We don't barter our rights for public benefits - we pay for them through taxation.
If Uber wanted to sell or give away data, properly anonymized and in accordance with their terms of service, that seems fine to me. But it's potentially quite valuable to Uber even in this state, and it doesn't really make sense to require a business to give them this data, any more than it would be to require other data-driven companies to do so. If it's not for public safety or something of that nature, I don't see why the government should really care.
Aside from public safety, there's a whole lot of reasons -- from measuring how efficient these services really are (in a rapidly changing transportation landscape) to ensuring truly open and fair competition among potential providers -- for which regulators (and the public generally) might have an interest in this data.
As a "private organization", Uber of course doesn't have to do anything.
But if it wants to operate a business on NYC's streets on a (massive) scale -- well, that's a privilege, not a right. And if they want access to that privilege, they're gonna have to play by the rules as set forth by the city's voters and their elected representatives. Who have a vested in interest having reliable access to that data for well, a whole bunch of pretty obvious reasons.
It's called "rule of law", a concept which Uber has demonstrated considerable difficult in understanding thus far. Once they do, we can perhaps have a conversation about whether certain regulations are really useful or necessary or not. But it needs to be based on the pragmatic merits (or lack thereof) of those regulations. Arguments on the basis of "they're a private organization; you have not right to tell them what to do" just don't hold a lot of water in these contexts.
This is a slippery slope.
No, it's just life in the big city. And it's about time Uber got used to it.
But as to the principled, absolutist counterargument that was offered: "they're a private organization; you can't tell them what to do! you just can't!" -- well sorry, but that's not how things work.
I get that a business doesn't have the same rights as a person, but do we really want to be crafting a maze of one-off rules for every company just because each of them have something special that we don't want to pay them for?
afaik, Uber makes money selling some of this data to municipalities.
I don't know, and won't pretend to know. Again, it all comes down to the merits. One might very well make the case that companies should be compensated for providing data in some cases.
I was objecting solely to the "business rights" aspect some people were bringing up (and which comes up continuously in discussions about regulation and business ethics generally, here) -- which we seem to be roughly on the same page on.
Forcing an organization to do something is a big deal because, unless you are specific about when and what kind of data you can force a private company to disclose, it can be abused. This is why such arguments are important.
But if it wants to operate a business on NYC's streets on a (massive) scale -- well, that's a privilege, not a right.
It actually is not a privilege, it is a right. Conducting business is a First Amendment right. In fact, this is a dangerous argument: if conducting business is a privilege, couldn't the government decide which businesses it likes and it doesn't like? The use of New York's streets is indeed a privilege, but that is already paid for by road taxes - anything more than that is just double dipping.
It's called "rule of law", a concept which Uber has demonstrated considerable difficult in understanding thus far.
Let's leave the attacks out of this - replace Uber with any other company and you have the same set of issues to discuss. Instead, let's just focus on the merits of the idea of government coercion of a private company to release data.
If this data was truly beneficial to the public, couldn't the government buy it from the company through a voluntary transaction, paid for by taxpayers? The company can decide whether or not they wish to sell that information. The only reason a company would refuse to sell anonymized information is if they think the data is important to their competitive success.
I'm a big fan of the First Amendment, but I'm not following your argument here.
The amendment reads: "Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the government for a redress of grievances."
Furthermore, the framers of the Constitution wrote the Commerce Clause, specifically giving Congress the ability to regulate how businesses conduct themselves (albeit in a limited way).
Do you have a court case in mind that provides more insight here?
This whole discussion could also call into question the idea of corporate personhood, but that's another can of worms. :)
I don't think anybody is disputing that regulation is allowed and useful, but we should also be questioning all regulation to ensure that the government isn't overreaching.
An important decision, for sure. Doesn't have anything to do with the First Amendment, though.
Or, for that matter, setting up a pop-up restaurant in the middle of Central Park somewhere. Because, you know, the foot traffic and all the opportunity.
After all, "conducting business" is your "absolute right", so why not?
That's a pretty peculiar interpretation of the First Amendment, for sure.
The second issue is that there is a nontrivial cost to making data public. And since you are a business most often you might get low quality datasets that either would take real effort to clean or extract knowledge and who is going to do that?
And sure cleaning and publishing this data would take effort, for which one could compensate the companies though. And as there is often just no way for the public hand to generate this kind of data, I think we will definitely see some legislation in this area very soon.
So I think it is not unlikely that people revolt against the progressively erosion of liberties and freedoms.
For example, see this article which talks about how "meaningful use" legislation enables cancer surveillance via provider reporting to cancer data registries: https://www.cdc.gov/cancer/npcr/meaningful_use.htm
This is one of those rare topics where I can make a Modest Proposal style comment that I actually believe in!
In my personal opinion, it's the worst wealth inequality issue we face, as will become more and more apparent in the coming years. As one example, it's far too powerful an advantage as training data for AIs to let one organization control it.
I appreciate the challenges in making it publicly available, but I also believe it's something that will have to be done in the long run.
>Taxis already share all the data the commission is requesting from Uber.
If Taxis are required to give this data why should Uber be different?
Uber is trying to differentiate itself from the standard taxi companies in order to avoid the same level of regulations and issues. To do that, you can't concede on any front no matter how trivial or reasonable it sounds.
Sooner or later somebody is gonna get one of them, and then all the other cities are going to say "Hey, if Los Angeles gets your ride data, then why can't Topeka?"
I can only guess all the reasons why. But it should help them predict supply and demand/gouge you better. It's worth knowing when everybody starts to head for the exits from the Rolling Stones concert. And if you came from there, it's worth knowing to predict what fare you might be willing pay, even if you hail a couple of blocks away from the arena to avoid the crush.
You don't have to elect to have background tracking on. Undoubtedly, most users have elected to keep it on but there is the option to turn it off and just type in the pick up and drop off address.
I just leave in the address that Uber guessed for me, which is always wrong by a couple of street numbers.
> Taxis don't get nearly that much granularity.
The GPS coords in the NYC taxi dataset are accurate enough that in aggregate, you can see precise hot spots at popular trip sources (MSG, GCT, Penn, etc). You should check it out: http://www.nyc.gov/html/tlc/html/about/trip_record_data.shtm...
I think this is the key take away from the article:
> Uber offered to give officials data on how long each trip lasted, without any location information. The regulator rejected this idea, in part because it appears to have more in mind than driver fatigue.
Uber cabs work when you request it at point A and get dropped off at point B. Addresses are recorded and the identity.
Yellow cabs share its data. All journeys along with their start, end coordinates. No identity issues as their platform could not record it.
Say if Uber cabs could share its data. All journeys along with their start, end coordinates. No need to share identity of the person associated with that journey.
Using Yellow cabs data set, if I have an address of my friend's place then I can figure out his journeys pattern when I see a frequency of his apartment address (minus the home number) either by data crunching around his address or the nearest corner intersection where he can potentially hail a cab.
I really don't see what's a huge deal here, unless Uber really does not want to expose its $ amount for a variety of reasons that I don't want to get into. Uber can strip off identity data, they can even strip off building numbers by normalizing pinpointed building numbers to nearest intersections. Sure every place can not have a nearest intersection. In that case, provide macro geo-information for the neighborhood. Trust me, every address has a nearby intersection in the city of New York.
Edit 1: spellings
After all, it is a direct competitor to the US Postal Service.
There are also other municipal needs like collecting utility information from radio systems or pavement management surveys that cities often drive around to collect - Uber could potentially be utilized for data gathering if it was determined that they had sufficient coverage etc.
Every GIS nerd would love a data set like the Uber tracks for analysis and to see what else they could be used for (Uber for mass license plate collection is like something from Black Mirror).
Instead of imagining uses for their data, let's realize it's their data that we have individually given them and we may not want the city - any city - to have.
Remember Uber's (terrible) "Rides of Glory" post describing how they could detect hooksups - http://www.whosdrivingyou.org/blog/ubers-deleted-rides-of-gl... ?
Now imagine that in your local government's hands.
The same argument can be made about Facebook's data. I don't think that justifies making it public.
I think that's the key detail
Besides yellow cabs there are also private livery cabs aka "black cars/car service."
"CURRENT OWNERSHIP: 17 percent of medallions are owned by cab fleets; 54 percent are owned by leasing agents, who delegate management to fleets; and 29 percent are owned by independent drivers"
Additionally, the data is anonymized; the original taxi dataset mentioned in the article had poorly-hashed Taxi ID numbers which is how privacy was compromised. Subsequent TLC datasets lacked that field completely.
> Ride-hailing companies aspire to be something akin to public transportation, but that doesn’t extend to sharing data with governments.
So this is supposedly noteworthy for that reason.
Yes, it's well known that they screwed this up. But that doesn't mean that we should therefore distrust them forever. Although it's tricky, figuring out the right level of granularity for revealing taxi ride data to the public seems doable, and we shouldn't let cynicism prevent all attempts at a compromise.
Better safe than sorry seems like the right heuristic here given that once private data is released in the wild, it will remain public forever [1].
[1] https://www.reddit.com/r/bigquery/comments/28ialf/173_millio...
Private companies have their own issues, obviously, but just because A is bad doesn't mean we should lower our standards for B.
Also, private companies have your data because consumers interact with them directly, so at least there is some implicit consent involved. But I'm less convinced that they should be forced to hand that data over to public agencies that have only a very tangential relationship with the user. If I take an NYC cab ride, why should the city government get to see that, especially if I don't live there?
You are the one saying you want certitude about the security of information held by government; why not propose your preferred standard for how data should be released, maybe get some peer security experts to refine it or agree on a suitable candidate, and then promote its adoption by government with an economic argument?
It seems not to have crossed your mind that government failure is often the result of past policy decisions imposed by representatives or the voters themselves on how things should be done, and that they're often mandatory for the people who work in government. They may know a policy or procedure or person's performance is flawed, but lack the legal or budgetary authority to do anything about it. Sometimes inefficient policies are in place as a political payoff to a corporation, union, or individual - corruption is a problem, and legislatures are essentially political marketplaces, and subject to certain failures of markets. Other times inefficiencies are just unintended consequences of well-intended legislation that was poorly crafted, or outlived its usefulness, or conflicting imperatives that lead to legal race conditions.
Try thinking of government as the operating system (or platform if you prefer) of society. It's buggy, bloated, nominally open but actually with a bunch of closed-source stuff in it, some people mine it for exploits or sneakily implement their own, and so on. You have this huge codebase written in multiple languages running on all sorts of legacy institutional hardware, all strung together in a giant embedded system that is supposed to operate 24-7, often under difficult conditions. Oh, and there's bitter disagreement between two factions of developers with radically different ideas about, well, everything.
Refactoring this isn't an easy undertaking. I suggest to you that the problems of government are similar to the problems of a large software project, and involve many of the same sort of trust problems that operating systems do. Consider that there is a relatively small number of successful operating systems/platforms, none of them were built overnight, and they all suffer from various faults and have interoperability issues - some by design, some by oversight. Your black-box approach to government is of limited utility because it's not like you can easily swap it out for a better one.
I don't know if you've tried to do free work for governments and get them to go along with your initiatives before, but I bet you that it quickly becomes a politicized process and is much more painful than, say, submitting a PR. I don't have the time, energy, or resources to do such a thing, but I do have the ability to vote against policies that I feel are misguided. If you have examples of normal citizens getting municipalities to adopt their initiatives and the process going smoothly, I'm all ears.
Also, the point here is that Uber is not a cab ride; if I take a cab ride I can understand why NYC gets the data directly since cabs are a de facto government-established monopoly, but I don't see why that extends to my business dealings with a private corporation.
As I pointed out in the first place, with a public entity like NYC you can file FOIA requests to find out what they actually did to mitigate the problem and ensure it doesn't recur. Is it enough? Opinions will vary, but reliably ensuring better security practices in the future will require some sort of rule, if only to identify the standard their IT operations need to comply with.
Meanwhile, the city is still expected to respond to complaints from residents about the cab service and to carry out its existing oversight functions which are almost certainly mandated by law. Uber's right to operate a transport service is subject to the same laws as every other transit service, so there's no legal basis for them to have a veto over the city contingent on the city meeting some (undefined) standard of reliable data custody. That would be giving a private entity (Uber) authority over the data security policy of NYC, which is an absurdity.
Certainly their opinion matters, as does yours as a voter, or even (very indirectly) as someone who chooses to drop some of your tourist $ in NYC or not. But having an opinion which you attempt to everage at election time (occasionally alone or more commonly through donating to some lobbying group to do it for you) is very different from a company unilaterally declining to comply with a rule and then claiming to be doing so in order to uphold your interests rather than their own.
Also, the point here is that Uber is not a cab ride
Of course it is. You summon a vehicle to transport you in comfort from A to B and you pay on arrival. Summoning them via an app rather than via a telephone call or a wave down is a mere operational detail. You're still hiring a car, for the time being cars are driven by people, and the law in New York is that commercial drivers can't work more than 60 hours a week (because of the increased risks of accidents due to driver fatigue, which is backed up by a lot of data) and have to be able to provide work logs on request.
The existence of a difference tells you nothing about its degree. From the point of view of the customer and driver, there is virtually no functional difference between Uber or any pre-existing taxi company. The significantly different business, dispatch and billing practices don't alter the fact that it's a ride-for-hire service.
Who still really believes that private companies are any better or have more responsibility to protect your data.
You want to protect your data, don't give it out.
It's easy to get lost in the tech echo chamber where we take security seriously, but many average consumers don't. So we incorrectly associate our priorities with theres.
Just take a look at Chipotle for evidence of this with the average consumer. A number of incidents of e. coli outbreaks led to sales plummeting and wiped away nearly 50% of their equity in the ensuing troubles.
Though same store sales have rebounded considerably they are still off 50% and questions continue to remain.
So trust me, when the consumer is affected directly in a way that they prioritize they take action and the company is definitely affected.
Unfortunately many security related incidents never trickle down to the consumer in the way that an E.coli outbreak did. Just compare what happened to Chipotle for a handful of E.coli cases versus Yahoo being compromised for 1 billion users data.
Evidence shows that in the vast majority of cases (home depot, target, psn, jp morgan etc) they do no such thing.
Chipotle is getting people sick, people don't like to be sick. Uber, the above mentioned breaches, and the GP were talking about their data. People don't care about that, hence companies face no real penalty for not protecting data.
Same rules for everyone.
It's absolutely absurd that it costs over $400,000 for a cab medallion in NYC.