1. moved from email-based auth to phone-based auth
2. removed all the auth and onboarding logic from the clients and moved it over to server
3. changed the networking from a hacky OpenAPI/Swagger code to Thrift over HTTP
i am not saying it was the most conservative call to do all this at once but it was necessary. the auth logic was basically untenable and no one really knew how it worked. some team in amsterdam could (and did) lock down uber for android users in russia because they changed some code.we also had to move to phone as a primary identifier, because honestly there are many countries people dont even use email. but how do you deal with phone numbers that were validated more than 7+ months ago, if you want to avoid things like this? [1] or how do you deal with promotions that required validating phone numbers not being VoIP that you could do out-of-band before but now have to do in-band?
anyway, i am being scatter minded here but it was probably one of the riskiest things uber did, from my point of view, changing the top of the funnel + also moving users from one auth to another with a download, esp given with apple's rollout mechanism we had no way back.
but it all worked! i should probably write this up one day.
1: https://arstechnica.com/information-technology/2016/02/when-...