Uber CEO Plays with Fire
nytimes.com
nytimes.com
"They spent much of their energy one-upping rivals like Lyft. Uber devoted teams to so-called competitive intelligence, purchasing data from an analytics service called Slice Intelligence. Using an email digest service it owns named Unroll.me, Slice collected its customers’ emailed Lyft receipts from their inboxes and sold the anonymized data to Uber. Uber used the data as a proxy for the health of Lyft’s business. (Lyft, too, operates a competitive intelligence team.)"
I am an unroll.me user, but had no idea they sell user data to companies this way.
Their whole value proposition is to help people control their own privacy and now I kind of feel betrayed..
If it's free for you, you're the product.
Situations like this one are exactly why the saying became popular.
There's a difference between ad supported businesses and business that actually directly sell user data behind the scenes.
Equating all the ad-supported businesses with this case is not really fair because the types of businesses you're talking about here are not actually literally selling you out. They are simply pushing you ads on THEIR platform which YOU agreed to use. Sure there are lots of shady things going on in this department as well, but it's a completely different game than what this looks like.
Based on this article it looks like they took your data and actually sold it to a third party, this is different from simply displaying ads on their platform. They literally sold you. And it happened OFF of the platform you signed up for.
A product may be free - and you may still be happy to be the product if you think your attention is being sold, or that they plan to upsell you onto a premium plan.
'If you're not a paying user' doesn't immediately lead you to 'They're going to scan my email and sell the data to fucking Uber' and shouldn't require the user to scan the ToS / rack their brains for every nefarious bit of fuckery the company might conceivably use the data for.
1. Emails with subject [xxx] are opened more often than emails with subject [yyy].
2. Lyft does more business in Scottsdale than we expected.
3. 25% of people who use ridesharing use multiple services and 75% are loyal to one service.
4. 33% of people who don't use ridesharing services also don't use traditional taxi services.
"Nefarious" is a strong word.
I agree with the first half of what you said and disagree with the second. That's precisely the value of the original saying: it's not there to be an excuse for a company, it's there to spread awareness and remind people that they should get informed about just _how_ they're being productized _before_ they have cause to regret using the service.
If more of us scanned the ToS carefully, we might catch the nefarious bits of fuckery on time and pressure the company to change.
Does the privacy policy say your data will be sold to third parties? Great, find out what data, to what third parties and questions like that.
It's still unethical.
People who go to loan shark know exactly what they're getting into--borrowing money.
People who signed up for unroll.me signed up because they got sick of all the the spammers and wanted to get away from all that easily.
Most people including me, thought they would somehow monetize with ads or something like that, but never thought they would sell our info to 3rd parties like this. So No, it wasn't at all obvious what to expect.
The saying "power corrupts" is more correctly expressed as "power attracts the corruptible".
So hypothetically, if you paid $5 a month for this service, you would be confident they were NOT selling your information?
Since the answer is obviously no (and in fact, purchasing behavior is the juiciest stuff to sell, be it Comcast, Target, etc), then this tired trope is meaningless.
It's moot anyway because the answer is out there publicly and no heuristic is needed to resolve it.
Now it's obvious why I've got people calling me asking about my recent loan that may have had PPI or that traumatic car crash I was in a few years ago, even though I've never in my life on both fronts. It's my bloody carrier!
If you use Google, shop in a supermarket, use a mobile phone, have the internet, your data is being collected and, in most cases, being sold to "chosen partners for marketing purposes". Everyone's doing it because they can make money from it.
No. A statement's truth doesn't imply its inverse [1].
It simply means if a company has employees, and they're receiving paychecks, and the money is not coming from you, then it's definitely coming from someone else.
If you are giving them money, it doesn't mean they're not also getting money from somewhere else. But they're less likely to need to do that, especially if it would upset their paying customers.
How is it a scandal? Competitive intel is a normal and widespread thing and it's not a scandal that people don't read a privacy policy that says, "We may collect, use, transfer, sell, and disclose non-personal information for any purpose."
That companies are allowed to have such a non-privacy policy damned well should be. The number of privacy policies I'd have to read on a daily basis to function on the Internet is ludicrous and it is only because of my job working for companies like that that I know that those privacy policies exist in the first place.
Really? I never got that. While I'm also a little unsettled by the selling data part, the value prop was always pretty clearly simplifying unsubscribing en masse, which necessarily involved handing over access to the contents of your emails.
The irony is that Rakuten also owns a significant (12 percent?) stake in Lyft. Pretty funny that one Rakuten property was selling data to Uber who used it to hurt a second Rakuten property.
The founders of unroll.me were pretty dishonest, which is a large part of why the company I worked for declined to purchase the company. As an example, one of the problems was how the founders had valued and then diluted equity shares that employees held. To make a long story short, there weren't any circumstances in which employees who held options or an equity stake would see any money.
I hope you weren't emailed any legal documents or passwords written in the clear.
It's ok that we pay you sub market salary because you get great ipo and equity.
Yeaaaah no.
When you bump into your colleagues in the morning you have an extra talking point.
Granted, I tend to think the people who run Gmail are more honest than that, but if someday the wrong people retired and others took over or what have you, I wonder just how suddenly that could change?
Just curious if you do anything novel there.
With an HSM, it would have to be marked as exportable (bad for security), or to happen via some proprietary HSM to HSM cloning method endorsed by the vendor.
That said, I don't see that much HSM usage outside of the government or their contractors.
Your main problem is going to be getting everyone to use it. If you converted 25% of the people using email today to an end to end encryption system it means that they can either only email anyone else in that 25% or anytime they send or receive an email from the other 75% it's not going to be encrypted the entire way.
In fact it would be a stupid idea for them to sell any of that data directly to a 3rd party. Instead they package them in user friendly (marketer/advertiser friendly) ways to capitalize. Some of these are shady and I'm not a fan but overall I think this approach is fine.
The problem happens when you sell user data to a 3rd party.
Here's an example: Let's say you start an email newsletter about travel. You get millions of subscribers. Then you start putting ads on your email. Maybe sometimes even send sponsored messages. This is kind of annoying but not "unethical".
On the other hand, the same company could take all the email list and sell it to bunch of travel agencies. Then all the million users who subscribed suddenly start receiving spam emails from these travel agencies. This is unethical because they literally "sold" your email address.
Of course this is more of an extreme example, but the pattern is the same.
Yes, it is called Gmail Sponsored Promotions or "GSPs." Depending on the audience they can apparently be quite effective. [1]
[1] http://marketingland.com/gmail-sponsored-promotions-everythi...
Seed money is the first to take the risk and deserves the majority share of profit
VC (series A,B,C) are putting in the most money and brining big hitters for the board and advisors. They clearly deserve the majority share.
Founders do all the work and it's their idea so they deserve all the money.
The second generation leaders productive, operationalize, and bring legitimacy to the company, so they deserve all the money.
Whichever group has the leverage forces the table to tilt their direction.
It doesn't matter how good the potential is, how sure the victory is, how close the first breakthrough customer is, if you don't trust someone, or there's a slimy/smarmy vibe then just walk away. It's not worth putting in years of effort to have to resort to contract lawyers to get paid.
Somewhere in the past few decades we've conflated the two - and a larger portion of our population believe that Capitalism is the goal. It's not, it's a way to achieve our goals. It is efficient, it is effective, it will always have little to no morals and consolidate in the hands of the few. That is not a judgement of the system it is an assessment. No different than stating a hammer will will work well with nails and poorly with screws.
We as a world society (and particularly an American socienty) need to refocus on what our goals of society are. And actively decided when to use and when to rein in specific tools to achieve our goals.
Absent of focusing on goals, our tools become our goals and we get the results we're seeing today.
I'll avoid getting into an internet argument, and just leave this quote here.
> tech has become a cesspool of slimy founders + and unbridled capitalism - this needs to stop for the greater good
This was the thread the comment was posted in and it's entirely the topic of discussion.
In the future try to choose more productive ways of describing people's views and engaging in discussion than as 'rabble-rousing' 'rants'.
If you want to understand what the implications are you need to spend time not with technologists but with ecologists. In nature there is a reason the apex predator doesn't evolve predatory advantages at a faster rate than its prey evolves defensive advantages. These rates grow or shrink in lockstep depending on resource availability. If they don't the ecosystem collapses.
On top of that, it should be very clear that everything I said is hearsay at best. If I had known the attention this would receive, I would have been clearer about it.
> I haven't been a part of that company for several years now, and did not have any legal agreements or first party relationship with either of the companies named above, and since the deal closed since with Slice it would be difficult for anyone to allege damages.
And if all this disappears, then yes, someone did attack me legally over it. I don't like the business culture that has built up around this kind of thing -- reputation is important, so let's defend it with lots of lawyers and NDAs, but it's too much effort to be up front about business practices that might give us a bad reputation. That's bullshit.
I'm seriously conflicted about this because I too have seen some extremely horrible stuff in the last couple of years, some of which I'm quite sure would rock the world orders of magnitude worse than what unroll.me has been up to and that was secured roughly in the same way (or maybe even worse) and with data best qualified as 'radioactive'. I do sign NDAs and I stick to them religiously but it is very hard at times to do that. Even so I understand that I'd make life miserable for those that employ me if I'd ever break an NDA.
My boundary, and the legal boundary that NDAs (even despite what is written in them) are generally held to is "trade secrets." I would hope that everything in my post is three or more years out of date, and would no longer qualify as such.
I say not doing evil to the rest of mankind trumps protecting the evil few.
Leaking systems that work seem like the moral road?
https://unrollme.zendesk.com/hc/en-us/articles/200243036-If-...
> we don't store any of your emails on our servers.
Either way, I just deleted my Unroll.me account and revoked access to my Gmail account. I don't think there's anything the company can do to ever get me back as a user.
That might also be a case of an article that's written from the point of view of one feature ("what happens if I delete") and not what's going on under the hood. There are other references to deleting data stored with unroll.me, e.g. When you go through the delete steps you need to do it in a particular order so that data on their side is removed, as discussed in another comment thread.
although every day someone would still email with a question "why you are not free like unroll.me".. sigh.
Also, it's only been 30 minutes since your first post, and 50 is a small sample size.
now, whether it's valuable enough to justify the price – depends a lot on how you use your email. we've got users managing 3-5 accounts with hundreds of thousands of emails each and they use our labeling/organization more than removal. think of it as of a way to act upon a group of emails no matter what the size of the group is.
(and I kinda think our website is not really good at communicating this – our traffic is mostly coming from android app right now and we've been putting website work off. who knew!).
You offer plain and simply ask for 8€ per month per account.
That's simply a ridiculous amount of money for 99% of the people, what you have but we can't see is part of the problem, not the trust, the price is just not worth for what you offer, so, don't complain about "not a single new customer from 50 clicks".
and it's even scarier with iCloud for example – they don't have oAuth and people need to enter their passwords to scan/clean. (they do have "app-specific" passwords though but looks like people have hard time figuring those out.)
It's not a perfect solution but it's an option to consider
my day job is in ecommerce (I work as a product manager at FastSpring) and I used to work on CleanMyMac at MacPaw – had to work with trust in both. it's somewhat unexpected but people who are buying software for themselves usually don't care about PCI compliance, audits, and other artifacts of "institutional validation". they care about a "norton secured" badge, proper language, recommendation from a person they know, a review at the website they read, "that green thing with the lock in my browser".. we're now at the phase where we are trying to find the right combination.
just to be clear – it's very different from project to project and depends on the audience. what I'm saying is that we're making decisions emotionally mostly based on our prior experience and rely on internal "thermometer" to tell us if what we're seeing is trustworhty.
Having said that, I deal with independent audits in my job, and they're not all that reassuring.
How does an independent audit detect out of band taps (swapping binaries, re purposing archives/backups, mirroring, etc) on infrastructure the auditor wasn't monitoring before the audit? logs? but more importantly amortized or not the customer eventually pays for all this activity that at the end of the day is more fluff than substance (in terms of what the customer can actually verify) In the end doesn't all this come down to just another form marketing?
Please note, that I recognize that there are many scenarios where an independent audit would add value. I just don't think it adds anything that social validation doesn't already add when considered from the perspective of a consumer to whom the infrastructure behind the service is unavoidably opaque.
This gives you something fundamental to compete on.
they are encrypted and can only be decrypted by "scan" and "action" (delete, trash, etc) jobs, job servers are not exposed to the outside and can only be accessed via the private network via ssh using access keys and only from a specific node which has those keys. keys are password protected. access to that specific node is restricted to a set of known public ip addresses. database and job servers are different servers of course. database servers are also only accessible within the private network.
the only thing that's publicly exposed is a load balancer. to access anything else we log in to the "gateway" instance which we access by ip only and it does not have any domain name associated with it.
with all that – I am very open to ideas about protecting that further.
Too often, it's used to shut down all conversations around corporate malfeasance re:privacy, so the industry doesn't get better, we all just move on to the next big story. And victims are blamed and shamed. "Your fault for using a free service, what did you expect?" vs. "This is unacceptable behavior, let's force a change."
Not to mention so many don't understand free vs. non-free. Are there ads? Are there optional purchases that keep the company going? As someone else mentioned here, unroll.me showed ads, which would lead users to believe their usage was being subsidized by those ads - and Slice's About page on its web site says nothing about using unroll.me as a data source, it claims to use its own shopping app.
Also spreading unfounded rumors about data storage practices you know zero about is really irresponsible.
If unrollme made it clear they were making their money by selling every one of your emails in plaintext they'd never have signed up anyone.
I just disconnected from one or two services which had access to my gmail (reasonably so).
Just another reminder that nothing is free =)
> [...] Mixmax may securely access or store your name, your Gmail email address, your Gmail emails and other conversations, and your Gmail contact list [...] We may anonymize your Personal Information so that you are not individually identified, and provide that information to our partners.
https://mixmax.com/privacy.html https://mixpanel.com/privacy/
Paribus is another of such services that I am aware that require you open your inbox access to them (the pull model).
There is nothing wrong with reading your emails with your explicit consent but I believe a push model like TripIt/Kayak's previous push model (send email receipts to trips@tripit/kayak.com) is a safer way to avoid privacy being violated and abused.
Clean up your inbox
Instantly see a list of all your subscription emails.
Unsubscribe easily from whatever you don’t want.
It's not clear at all that they are reading people's emails and selling the data.We may collect and use your commercial transactional messages and associated data to build anonymous market research products and services with trusted business partners. If we combine non-personal information with personal information, the combined information will be treated as personal information for as long as it remains combined.
Aggregated data is considered non-personal information for the purposes of this Privacy Notice."
That just happen, at last.
Slide deck 1 of 44: "Learn how your competitors are doing."
They don't think it's any of the customer's business to know that, and it's counter to the company's interests to publicize it.
It would be much bigger news if they were selling data that could be used against the consumers on an individual basis.
Even without that angle, I find it absolutely scandalous that a company is able to do this, even with the T&Cs permission of their users. Surely at some point this is going to bite them in the behind? The possibilities of it going massively wrong seem endless. Then again - common sense and the law rarely seem to intersect.
You can find out a lot of personal information about someone by tracking where they go on a regular basis.
[1]: https://unrollme.zendesk.com/hc/en-us/articles/200165526-How...
Now we know what they are doing it and how. I hope they get shutdown within the aftermath of this story.
> 'consenting adults'
Are you consenting if you don't know what you're consenting to.
> anonymized data
Widely understood that anonymized data is bullshit, which is why the term "de-anonymized" exists. It's especially bullshit when there are no 'standards' as to what constitutes it.
> shared in a compliant way
What does that even mean.
The beef industry would also collapse if all the meat-eaters who thought killing animals wasn't ideal in principle had to watch the cow get killed before every meal.
It may be of interest to you, but it isn't the lede of the story. The lede is a pattern of behavior by the CEO, of which that is one element.
OP is implying the "real story" (i.e. the most important part of the article) is not what the article begins with
That headline "Your inbox security is our top priority" sure seems hilarious now. Also, I wonder why the article refers to it as Slice Intelligence? Is that their official company name on the paperwork? Is it to portray this shadowy intelligence gathering agency for hire? Both?
Please delete my account and all my data.
I have a few simple rules I follow to hit inbox zero...works quite well:
1. Unsubscribe Relentlessly 2. Use Keyboard Shortcuts or Gestures 3. Snooze Important Emails 4. Use a To-Do App
(I wrote it up in more detail here: https://shift.infinite.red/how-i-achieve-inbox-zero-every-da...)
At the time, Uber was dealing with widespread account fraud in places like China, where tricksters bought stolen iPhones that were erased of their memory and resold. Some Uber drivers there would then create dozens of fake email addresses to sign up for new Uber rider accounts attached to each phone, and request rides from those phones, which they would then accept. Since Uber was handing out incentives to drivers to take more rides, the drivers could earn more money this way.
To halt the activity, Uber engineers assigned a persistent identity to iPhones with a small piece of code, a practice called “fingerprinting.” Uber could then identify an iPhone and prevent itself from being fooled even after the device was erased of its contents.
I imagine that they wouldn't really have much difficulty tracking you through ad tech, another APP, or some other Cult Of Free system that is willing to sell database access.
Basically, they created a unique 'fingerprint' of the iPhone. It was unique enough that even if you reinstalled the app, the fingerprint would still be the same. This was done, ostensibly, to prevent people from scamming them by reinstalling the app and coming over as new users? But they already have the phone number, so I don't understand the point.
In the article this is in the context of fraudsters buying used phones to fake rides in China and take advantage of incentive programs to make money. So they want to track these devices as they change hands.
So I think their goal is not so much about identifying people, but identifying devices in order to prevent this loophole.
I believe I tried long long ago on iOS and couldn't get it to work, but I don't know if I'm remembering correctly.
To halt the activity, Uber engineers assigned a persistent identity to iPhones with a small piece of code, a practice called “fingerprinting.” Uber could then identify an iPhone and prevent itself from being fooled even after the device was erased of its contents.
I also interpreted "track" as "report geolocation data," but that's not what the reporter means, and honestly the reporter's meaning is more consistent with, e.g., "this website is tracking users" or "Do-Not-Track".
It's not clear if such code would work today on the latest iOS version but maybe. They probably used a private API to do so, and that itself was obfuscated in the compiled binary such that apples automatic analysis would fail to catch it.
Unique settings, apps installed etc.
Very hard to have a non-unique set up with enough data points.
Let's look at roughly what's available:
iPhone model (2 orders of magnitude of possibilities)
Device storage -- increases entropy with iPhone model but still not that much
Device name -- easily changeable by scammer, so not enough
iOS version -- changes over time, not great for a long term fingerprint but might help short term
IP address -- short term attribution ok, but not against scammers. People in china have multiple sims very often so even relying on carrier isn't enough
Cell phone carrier -- same as above
Other apps installed -- as of iOS 9 you have to pre-declare what you want to be able to query, and that's subject to App Store review. It does help give a fair bit entropy. This also can change at any moment. But if you're wiping the device constantly, they might not be installing any apps.
In advertising / web, you want to attribute across sites / installs on a short time basis. You have plugins and their unique version numbers, OS versions and all their attributes, browsers version, fonts installed, etc. Way more variation than iPhones.
To defeat scammers erasing their phone constantly it's actually much harder, and likely needs something a bit more unique.
Especially since the behavior/activity of the phone could be suspicious as well.
You also don't need to be 100% accurate all the time. The point is to minimize the damages done to you by scammers, not reduce it to 0 which is impossible.
I'd assume the miners just wipe a phone clean, reinstall Uber & create a new account.
There are no special settings & variability in installed apps in that case.
My understanding was that Apple made those APIs return garbage anyway, so more hacky methods were required.
Pretty sure this is about persisting data after the entire device has been wiped. Not just the app removed and re-installed.
could it be because the article intentionally glosses over complex details in order to pump a specific narrative ... hmm. \s
Clever, but it's disappointing that even NYT is turning into this madness.
The correction bounces around but never takes hold the way the initial claim does and people quietly go on believing their initial interpretation. Sad.
Note that this was at least 4 hours after the outrage on Twitter started. Seems like a very intentional, well-calculated strategy indeed.
That comment seems a bit disingenuous. i.e. it's entirely possible it takes a journo 20 seconds to post a correct to a twitter account he/she controls and 4 hours/days/weeks to get his/her editors to sign off on the same correct and the change pushed to the news website.
Here's the change in question: http://newsdiffs.org/diff/1383350/1383404/https%3A/www.nytim...
changing "tracking" to "identifying and tagging" and changing "even after its app had been deleted from the devices, violating Apple's..." to "even after its app had been deleted and the devices erased — a fraud detection maneuver that violated Apple's..."
In a really long article like this which is probably under some time pressure to publish, there's almost always things that seem clear to the author aren't to the reader. This is a standard clarification bug fix, and tweets were over an hour after the article was published - enough time to gather feedback and realize the need for clarification.
At least in this instance, the only specific narrative being pumped is the one that journalists are always pumping a specific narrative on touchy subjects.
The tweet responses:
> @MikeIsaac 32 minutes ago > Since the line about fingerprinting is being misinterpreted(though it is explained later in piece) adding language up top to better explain.
> @MikeIsaac 31 minutes ago > appreciate Technical community's concerns about how It is presented. Uber was not tracking location after device wipe (which I never said).
> @dangillmor 30 minutes ago > What exactly were they tracking? Not entirely clear (at least to me).
> @MikeIsaac 29 minutes ago > ID-ing devices. so if I steal a phone and wipe it, they can still determine I had that phone and used it to defraud uber, using other data
Do they really? [Citation needed] very much here. Which fintech app fingerprints devices? What would even be the point of doing that. You can persist a token in the keychain for that which is enough unless you are devious.
Fingerprinting is a form of 2 factor authentication, it's easy to perform and it's relatively efficient against fraud.
The first time you use an app you have to enter your user name and password and that is stored in the secure enclave that not even the operating system had access to.
When the banking app request validation, you use your fingerprint to authenticate and the secure enclave sends the username and password to the app. The fingerprint scanner is connected directly to the secure enclave.
When you sell your phone, you go through the process of erasing your phone, the encryption key is destroyed and your fingerprint is no longer valid.
See for example this Tweet, with hundreds of retweets and lots of verified replies:
https://twitter.com/dnvolz/status/856166875511894016
"This is like a holy trinity of privacy disaster: 1) secret tracking that 2) persists after users delete app 3) in knowing violation of rules"
C.H. Spurgeon, Gems from Spurgeon (1859)
But in the direct interest of capitalism, and indirectly consumers, it's terrible to restrict important businesses.
http://www.npr.org/sections/alltechconsidered/2016/12/01/503...
Edit: Read up a bit more on it. Turns out it was the practice of fingerprinting and tracking after re-installs, not after an uninstall. TechCrunch provided a better technical description: https://techcrunch.com/2017/04/23/uber-responds-to-report-th...
So for all means continue to investigate the seemingly terrible and anti-women culture and the fraudulent stealing of Technology from Google. But like you said, don't mischaracterize other facts to make them sound more terrible than what they really are.
The problem for Uber is that they /are/ scummy. They proudly bend every possible rule to their advantage. It's easy to believe the worst about them.
Could someone explain the logic behind how a driver requesting rides benefited them? Did the drivers fake the ride and pay for it themselves? Was there a cash incentive where they were reaping enough to offset paying for the fake rides themselves and profit hanseomely? Is that correct?
Interesting and somewhat ironic to think that Uber had to put countermeasures in place against drivers engaging in their own questionable version of "growth hacking."
Rider and drivers are randomly assigned. I am not sure if you can choose your driver. Not sure if all these drivers in China made a huge group to benefit each other
I just hope Lyft plays the game with a social conscious and makes positive decisions and continues to treat drivers well (most Lyft drivers I talk to say they like driving for Lyft way better than Uber).
I'm not so sure that as a society we should be rewarding people with drive like this "Mr. Kalanick, 40, is driven to the point that he must win at whatever he puts his mind to and at whatever cost".
I fail to see what one has to do with the other. Can you explain?
Seems to me the opposite is the case - as a contractor the driver has full control, but as an employee how hard he works has little to do with how much he gets paid.
I don't understand why not. I have a total of five friends who have each chosen to drive for various ridesharing companies, and in the conversations I've had with them, it seems pretty clear that none of them would be drivers if they couldn't set their own schedules, or if they were otherwise treated as actual employees.
To be fair, only one of them is driving as their main source of income; the other four are driving to supplement their day jobs for side money. The flexible schedule is crucial to that. The fifth prefers flexible scheduling as well. Though he might otherwise be considered a 'full time' employee, he working a schedule around a non-standard custodial agreement with his ex-wife, which means he might drive for 14-15 hours in one day, and none in another.
Re the base comment, it's almost not worth replying to as any:
"you can't do X and consider yourself Y" comments are in themselves silly, because answering in the general case - I have a different definition of Y to you - you can think of our internal definitions as an ordering of <things related to Y> by <how efficient it is for me to do thing in advancing the cause of Y>.
For example, I care a lot about humanity being happier and more equal but I think that in the long term this is something which will have to be provided by the state and not employers, so I'm ambivalent towards laws trying to push employers into a paternal role.
https://www.oregon.gov/ODA/shared/Documents/Publications/Nat...
From https://www.irs.gov/businesses/small-businesses-self-employe... : "In determining whether the person providing service is an employee or an independent contractor, all information that provides evidence of the degree of control and independence must be considered."
One of the categories of control and independence is behavioral, which is described here: https://www.irs.gov/businesses/small-businesses-self-employe...
It says: "An employee is generally subject to the business’s instructions about when, where, and how to work."
Uber, Lyft, etc. leave the driver to decide which car they drive, where they buy gas, which jobs they take, and when they work or don't work. This is a big part of what goes into justifying their legal status as contractors rather than employees.
EX: Using their app counts as their equipment even if you use your car. Much like using your shoes is required to work fast food not not sufficient equipment. However, it's a more balanced arrangement.
This, by the way, is probably illegal, as it is extremely dangerous. If I'm taking a taxi, I'd like to know my driver is not on the brink of exhaustion.
http://www.politico.com/states/new-york/city-hall/story/2016...
I remember when I was in the army, you were not allowed to drive if you hadn't slept at least 8 hours the night before. Of course, these rules are never strictly kept.
Whether the drivers are employees, contractors, or volunteers is an implementation detail. If laws, public opinion, or economics change, the fundamental business still seems reasonable and useful.
You state that like it's a proven fact, when it's anything but. I personally think it's farcical to treat Uber drivers as employees. They have no set schedule, location, or expectations. They're constantly making ad-hoc decisions on which rides to accept.
The closest analogue is traditional taxi drivers, who also aren't employees.
I hope he loses big. Losing everything because of a sociopathic drive to win? That's the stuff of classical tragedy.
The idea that the taxis are corrupt and despicable is 100% Uber/Lyft propaganda.
The idea that a bunch of immigrants driving 12 hours a day to support a meager income for their families are a cabal of special interests is ridiculous.
Uber and Lyft are better than taxis because of the on demand nature and they are cheaper because of better utilization. But there is no need to make taxi drivers out to be evil.
That's not the (only) reason why they're cheaper.
They're cheaper because they offer drivers less downtime, therefore the drivers can end up earning more money since they're driving more of the time and earning fares.
They're also cheaper because services like uber pool and lyft line allow riders to spilt the fare among themselves.
I also think that Uber and Lyft will be cheaper than taxis for many more years to come. They're just more efficient as business models than taxis'.
Kalanick's moral compass may or may not be aligned, but the service his company offers is awesome.
And on the consumer side, consumers are afraid of being cheated, they deal with more payment uncertainty, and the prices are inflated.
And the taxi drivers can't get out of a crappy taxi company and start their own because of the expensive taxi medallions, so they're stuck with it as much as we are.
You can ignore that distinction, but you're just going to be arguing against a straw man, which might feel satisfying, but will get you nowhere.
There should be enough, but there is a point where there are too many people driving through the streets of NYC looking to pick up riders.
Secondly, even if there's a good reason why that's bad, it's a problem that would sort itself out. The supply (drivers) will decrease until it meets demand (riders).
Maybe that's a good reason now, but it's unfair to say it's the only reason.
> The supply (drivers) will decrease until it meets demand (riders).
Maybe? Economics is rarely perfect like this. See the government subsidies of many industries, farming for example.
Maybe in the middle of the ebb-and-flow lifecycle you'll have something that works really great: but at the extremes you'll have something that hurts a lot of people for a good amount of time.
in general if a state want's to limit concession to a scarce resource (whether riders, coal, fishes) it's best to make them time limited and non transferable, with the current owner having a preferred option for renewal and a bid for reassignment.
> There should be enough
And who gets to decide how many is "enough" or "too many"?
Shouldn't it be the voluntary actions of individuals coordinated by the price system, rather than a centralized planning board? When ride prices are very high, new competitors come in to serve the demand. When prices are low, the least efficient cars stop giving rides, and the supply shrinks. The price system coordinates the actions of countless individuals without the need for a central planner.
Note: I'm not defending Uber / Lyft in any way, as I'm not familiar enough with the latest drama.
Cars impose negative externalities on others in that they take up space on the road and increase traffic congestion. This is not factored into any pricing system.
Too many taxis is potentially bad in that they increase traffic congestion and make public transit less efficient. This can result in worse transportation options for low income persons, especially in the case where the taxis are Lyft/Uber type ride shares that are only hailable with a smart phone and may be more expensive due to surge pricing.
A potential solution is to introduce comprehensive road pricing such that a car pays for its amount of road use.
You are correct the solution to congestion is to use tolls in some manner, whether on parking or entry to freeway/city. But they have to apply to all vehicles, not just cabs.
There are good reasons to limit cars.
There is zero good reasons to limit cabs. Cabs reduce congestion. Apply limits to cabs and not private cars just means more people driving instead of sharing rides.
Limiting cabs is anti-competitive behavior to benefit cab companies, pure and simple.
Add to that the issue that every taxi ride I've taken in recent memory involved the driver spending the entire ride complaining about the low fare (which is 2x the UberX fare). The first time it was an interesting conversation but by the 10th it's just annoying and one more reason to dread taking a yellow cab.
To be fair most of the conversations I've had with Lyft drivers quickly turned to fair price and their own financial issues too. (I've never ridden Uber so I don't have any data points to compare.)
Maybe they're just trying to develop a context for any tip you might give?
> the driver spending the entire ride complaining about the low fare (which is 2x the UberX fare).
My understanding is that UberX fares seen by riders are ridiculously low (significantly below the cost of the ride) and are actually subsidized by Uber so I'm not sure if that's a great price comparison point.
https://motherboard.vice.com/en_us/article/uber-true-cost-uh...
I just can't see how that could be said with any seriousness unless you've never used a taxi. I'm not saying Uber/Lyft are without their own faults. I've never really had /that/ much experience with taxis, but on my few interactions encountered in the US:
* (after arriving at the destination) Sorry, my credit card machine is broken. I can drive you to an ATM if you'd like? This is a common taxi scam and many places have laws to protect against it. After arguing they pull out the old slide machine.
* When traveling only the minimum fare distance, "These trips really aren't allowed."
* Use their website to schedule a few days before my flight--nobody shows. Call their dispatch phone number, "Oh, the website never really works. Someone will be there in 40 minutes." A taxi shows up over an hour later.
There's a difference between saying taxi drivers are evil, and saying that the taxi system is a corrupt special interest.
The 'system' is not just drivers, in most large US Cities it's a few concentrated medallion owners, strongly motivated to lobby against diluting their share of the taxi market. Dilution could come from regulatory changes, or just allowing more medallions.
What is a 'special interest' anyway? Medallion owners represented a concentrated minority of the population with strong motivation to push for policies that are neutral or harmful to the majority. But since the harm is spread among the many, and the benefit is concentrated in the few, the few are more organized and willing to expend time and money to achieve their goal. And yup now ride sharing apps are a new special interest.
That's just the political economy. There's also the fact that in many cities the cab titans were operating like corrupt slumlords, while local law enforcement long seemed willfully ignorant.
https://www.bostonglobe.com/metro/2016/08/03/fallen-taxi-kin...
You have a different kind of safety with Uber. There are always tradeoffs.
Also, I don't miss the days of walking an hour through the city on a Friday night because every passing cab was taken. I remember how bad things were before 2010
This happened so much that Bloomberg said screw it and was basically turned a blind eye to what they were doing and let them operate. The NYC Taxi Union got pissed and complained. But while complaining they still basically said in so many words that they still weren't going to service the area. They just didn't want anyone else to.
I had a cab driver pick up my ex girlfriend and her coworkers and pull something shady along the lines of this. They were being dropped in mid town. She was being dropped off uptown. When he dropped her coworkers off, he drove a few more blocks and stopped the cab and told her she had to get out. He wasn't going to drive all the way to Uptown.
So yeah I was glad when Uber gave them competition. Now when I go to NYC I have no problems out of the cab drivers like I used to.
Here's links to stories of investigations into taxi bureaus and dispatchers for bribery and other schemes in 3 states:
http://www.nola.com/crime/index.ssf/2011/06/federal_investig... http://astoriapost.com/taxi-dispatchers-arrested-for-alleged... https://nypost.com/2014/03/19/16-jfk-taxi-dispatchers-busted...
Perhaps there's a city where Taxis are a good, clean business, but there are enough bad ones to support the generalization.
> The idea that a bunch of immigrants driving 12 hours a day to support a meager income for their families are a cabal of special interests is ridiculous.
There's a distinction between the drivers and the taxi regulatory agencies and dispatchers in the above stories. In this case, Uber/Lyft are replacing the agencies and dispatchers that are the bad actors, not the drivers. Your point about not making drivers out to be evil is well taken, but I don't think that's what anyone refers when they talk about "the evil taxi industry."
Maybe not 'evil', but I'm curious about these amazing experiences people have with cabs (US-centric here).
In NYC, cab drivers would refuse to drive to areas they deemed undesirable. I'm not even talking someone taking non-Manhattan rides, I would occasionally have cab drivers refuse to take me to Harlem from lower Manhattan. Cabs refusing to pick up non-white passengers is a common thing. Hell, even basic things like trying to get a dispatched cab to pick one up for an airport could be a disaster (during my time in Portland, I think I tried getting a Radio Cab to the airport three times, they never showed up).
> Uber and Lyft are better than taxis because of the on demand nature and they are cheaper because of better utilization.
Hell, I would pay more for an Uber of Lyft just because of the reliability of the service.
Have you ever actually used a taxi?
It's incredibly common for taxi drivers to refuse to pick you up because you don't look desirable, or aren't going to the right place, or want to use a credit card, or any other reason (all of which are totally illegal). They flout the rules regularly, it's by no means propaganda.
I've been kicked out of cabs more than once when the driver learned I'm deaf and I would give them the address of my destination on paper. Got kicked out because I was signing with my friend in the back. Etc.
Lyft would never have existed without Uber. Now that Uber broke through the path (and is getting destroyed for it) the way is open for lots of other companies.
It happens all the time that the company that invents or creates something new, does not actually reap the rewards because the cost of creating it was so high they die in the process - but leave the way open for other companies.
How can you be so sure of this? The person who came up with the concept behind Uber was not Kalanick, it was Garrett Camp.
http://www.businessinsider.com/uber-travis-kalanick-bio-2014...
Uber's innovation was financial (fleecing investors), not technical.
But who knows? Do the riders and the drivers really need Uber or Lyft?
Why single out Uber when all the companies in this space are doing the exact same?
From what I've seen based on leaked financials, Lyft is outspending Uber by more than 2x in terms of subsidy dollars per ride [0]. Subsidies do not scale, and Uber is subsidizing less per ride than its competitors so it's surprising to me that it receives the bulk of the criticism when it's actually far the most thrifty of the ridesharing companies. If anyone should be criticized for buying their growth, it should be Lyft, not Uber.
Lyft rolled out in many cities before Uber. It certainly can / did exist without Uber's aggressive approach in several cities.
It's also not that black and white as the Lyft team built Zimride (2007) prior to starting Lyft before Uber existed (2009). Even with that Uber focused on the high end market at the start while Lyft focused on the budget market.
It's always easy to point out the things they did and criticize them, but it is harder to realize the work that they put in and the choices they make to keep their company (and most of the time, the industry they're in prosper). If he would've played by all the rules, Uber would've had to put up a Goodbye page on their homepage a while ago. Taxi industry would've tried to decimate it, and what ever would've happened, wouldn't be good for the transportation ecosystem as a whole. Self driving taxis are even being talked about because of Uber. I think Uber moved the arrival of self driving taxis from the concept to the street a decade earlier (although I have to say it might've taken longer if Levandowski was never at Uber; lets wait for the outcome of the lawsuit)
Makes me think of Steve Jobs in the same way. Steve Jobs was (and still is in parts of the internet) intensely hated for his contributions. But he made a change in the computing industry which made computers (electronics in general) much more beautiful and a pleasure to use. Bringing about that kind of change is very difficult in my opinion, and we need brazen people like Jobs and Kalanick. They are sometimes immoral with their choices, but people tend to forget the world we live in often is too.
One consistent feature of Kalanick's tactics appears to be a proclivity for gaslighting on an industrial scale - geofencing Apple, regulators, etc.
Among (many) other things, I would never trust any data sourced solely to anything under his control.
See, for instance, Mike Pence's behavior during the VP debate, saying with a straight face that certain things never happened that did happen (it's a very different experience watching it once you understand that gaslighting is a thing that exists), or Hillary Clinton talking approvingly of Abe Lincoln having a public and private position - duplicity is good leadership. If you want to get something done, and you have two constituencies that disagree about how to do it, go to each constituency and say that you agree with them. Anyone who thinks of calling you out on it is going to doubt their own recollection of events.
I think it's good for our culture that people are starting to question that, but it will be a very long and difficult battle.
Clinton wasn't gaslighting; she was just espousing the (correct, as far as I can tell) idea that in order to be a successful leader, you have to convince different sides that you believe different things, even if those sides are talking to each other to figure out what you believe. That seems at least a little bit gaslighty if you never admit your duplicity. (In Clinton's favor, the speech in question was effectively admitting the duplicity - and the backlash made it clear how bad an idea that is if you want to remain in positions of leadership.)
I think it's certainly possible to tell everyone you meet, "In an ideal world, I'd support X, but for the following reasons I think only X' is achievable right now; these are the ways in which I'd be convinced that X is in fact achievable." And you could be effective doing that. But probably you'd not be as effective in the American value system as someone who says "No, I genuinely support X and will fight for X" to one person and "Of course I don't support X, that's unrealistic" to another.
Not sure how well that worked for her. See "Poll: Just 12 percent of Dems see Clinton as 'honest and trustworthy'" and similar headlines. Plus losing to a pretty bad opponent.
Meanwhile, her opponent is almost a parody of the stereotype of the politician who lies about everything to get votes, and people just assume he's playing 11-dimensional poker and his actual goal is whatever they want to think his actual goal is (and this includes both people who agree with him and people who disagree).
Read plainly, I'd call my comment a criticism of Apple and people that might be congratulating them for working the issue out behind the scenes.
The thing you leave out is that inflicting the inconvenience on the users would have increased the chances of the users understanding what Uber had been doing.
Look at my first comment. I said "It'd be nice". It wasn't a comment about what would be good for Apple or bad for Uber or anything like that, it was just a remark about how I see it.
Longer term I think it is harder to say.
That's the one rule. For everyone.
A good amount of people would stop using / buying iphones if their device stopped using facebook, uber, or some other central app in their lives. It would also disuade a bunch more customers from buying from that platform again, because they don't know what else would be yanked from them.
Platforms live and die on what they can provide, if one platform is missing a bunch of central apps, it's not going to succeed as one.
Spine implants are hard to get, even for Tim Cook.
It look more like an hack more than "a lack of boundaries" to me...
this article is talking about something else it seems.
I'm not going to defend Kalanick, but I'm through with getting emotionally worked up by news articles.
To halt the activity, Uber engineers assigned a persistent identity to iPhones with a small piece of code, a practice called “fingerprinting.” Uber could then identify an iPhone and prevent itself from being fooled even after the device was erased of its contents.
There was one problem: Fingerprinting iPhones broke Apple’s rules. Mr. Cook believed that wiping an iPhone should ensure customers that no trace of the owner’s identity remained on the device.
Uber engineers assigned a persistent identity to iPhones with a small piece of code, a practice called “fingerprinting.” Uber could then identify an iPhone and prevent itself from being fooled even after the device was erased of its contents.
There was one problem: Fingerprinting iPhones broke Apple’s rules. Mr. Cook believed that wiping an iPhone should ensure customers that no trace of the owner’s identity remained on the device.
I expect what they do is fingerprint the device to detect fraudulent use later. Typically this is done by combining a bunch of identifiers and details on the device and then hashing the result. The output is a unique identifier for that specific device.
While technically this doesn't store any "identity" information on the device itself, if done correctly, the device could be identified and tracked across wipes (hence Cook's comment).
Of course, the article does a piss poor job explaining this, but for many readers the nuance doesn't matter... They capture the spirit well enough, even if the details are pretty misleading.
Furthermore, that code wasn't triggered, somehow, in devices near Cupertino, indicating that they were trying to hide the code from App Store reviwers.
I think I feel that this is very qualitatively different from gathering location data on users who have deleted the app (if such a thing were possible), but nevertheless a serious ethical lapse.
In my opinion Apple should have suspended their app from the iTunes App Store until they fixed the app. Because isn't that what they do to other small players? I would say there is a bit of hypocrisy on Apple's part here.
Can someone explain to me the mechanics of how this happens? I use Lyft, which emails me a receipt. How does Slice get a hold of this? Does Lyft sell it to Slice?
It purports to be a convenient tool for end users. But sells them out for revenue.
Edit: I'm sure it's in the terms somewhere. But to me, something this intrusive should be stated up front if it's not obvious.
Honest question (not trolling, I swear), is Gmail any different? I guess (I'm guessing though?) google doesn't sell users' info to third parties? (But I guess it does use the info within alphabet companies??) Does anyone know this for sure?
Instantly see a list of all your subscription emails. Unsubscribe easily from whatever you don’t want.
Unroll.Me is a free service
So they analyse an inbox, and siphon the data in the process.
[1] quote from article: Using an email digest service it owns named Unroll.me, Slice collected its customers’ emailed Lyft receipts from their inboxes and sold the anonymized data to Uber
So they had access to the inboxes of people who happened to be Lyft customers, without any business relationship with Lyft.
From their privacy policy at https://unroll.me/legal/privacy/ :
We also collect non-personal information − data in a form that does not permit direct association with any specific individual. We may collect, use, transfer, sell, and disclose non-personal information for any purpose. For example, when you use our services, we may collect data from and about the “commercial electronic mail messages” and “transactional or relationship messages” (as such terms are defined in the CAN-SPAM Act (15 U.S.C. 7702 et. seq.) that are sent to your email accounts. We collect such commercial transactional messages so that we can better understand the behavior of the senders of such messages, and better understand our customer behavior and improve our products, services, and advertising. We may disclose, distribute, transfer, and sell such messages and the data that we collect from or in connection with such messages; provided, however, if we do disclose such messages or data, all personal information contained in such messages will be removed prior to any such disclosure.
We may collect and use your commercial transactional messages and associated data to build anonymous market research products and services with trusted business partners. If we combine non-personal information with personal information, the combined information will be treated as personal information for as long as it remains combined.
Aggregated data is considered non-personal information for the purposes of this Privacy Notice.
Apparently, if you're not paying for it, you're, yet again, the product.
I've also left Uber for Lyft.
Tons of apps use their platform to identify unique devices, and I'm curious what makes it legal and what makes it not.
https://dev.branch.io/getting-started/matching-accuracy/over...
That's kind of surprising.
can somebody explain this?
McDonalds fits those criteria as well.
Not by me. No affiliation. Found it after this news.
[edit: typo]
Uber is pushing back on the allegations, saying that the
tracking is a common industry practice used to prevent fraud
and account compromise.
[0] https://techcrunch.com/2017/04/23/uber-responds-to-report-th...Truly blind justice.
Not just Uber, but every app... any idea how I can do a true clean uninstall when I remove an app from my iPhone?
http://www.cnbc.com/2017/04/23/new-york-times-digital-uberas...
If the answer is they need to raise prices and/or reduce the drivers' cut, how will they be better than the taxi services they're replacing? Many taxi services up here in Canada already have apps that are close to on par with what Uber offers.
pssst!! it's not a 'angelic ride sharing' service period. it's hiring taxi drivers and in this case mostly entrepreneurial taxi drivers having multiple cars and running it as a business.
https://static01.nyt.com/images/2017/04/22/business/24travis...
If so, I don't see how anyone can get any serious work done there.
I work on one of these two floors, and have worked at all three SF engineering offices on three different teams since joining 3 years ago. I would say those are not typical conditions for most engineering teams, but are more common if you work on a team that needs to be close to the non-technical areas in the company.
That all said, you can work wherever you want. Sometimes I work at my desk with headphones and sometimes I find a quiet place on that floor or one of the other floors. There are no lack of quiet spaces. It's also easy to work from home one to two days a week if you want. My team has our own no meetings day and some team members work from home that day (but typically do so to save themselves the commute).
I won't go into any details on what I work to maintain my anonymity but I have no problem getting serious work done and I work on one of the largest scale and most critical pieces of infrastructure.
https://static01.nyt.com/images/2017/04/19/technology/24trav...
I chuckled a little bit reading this.
"Savant" is very specific term. "Some" is very unusual reference to describe sources for good journalism.
For a moment I wondered why Travis Kalanick playing with matches was on the front page.
I also find the fact that their new logo looks like an asshole very fitting
Did they laugh at him to his face, cause if it was just the two of them...
Maybe you meant they knowingly allowed Uber to do on iOS what any app can commonly do on Android? Apple works very hard to protect users privacy, it doesn't guarantee it. Android doesn't guarantee it either, and doesn't try very hard to protect it.
Keep truckin, Travis.
This is classic malignant narcissism[1]. The irony of the story is that it describes a confrontation with Apple, which became successful through the machinations of another malignant narcissist, Steve Jobs.
But: Narcissistic Personality Disorder: DSM-5 301.81
Also mentioned but not properly defined in ICD (F60.8)