Uber told staff to use ‘kill switch’ during raids to stop police seeing data
theguardian.com
theguardian.com
I don't think the lying and the misdirection and the "prediction" based on reading news reports or political rumors are ethical or even particularly smart, but I think you'd be hard-pressed to find a company storing mountains of user data which does not have a lockout plan like this that they will be willing to use against law enforcement in certain scenarios or by default.
btw, this was originally reported in 2018: https://www.theverge.com/2018/1/11/16878284/uber-secret-tool...
No. They must have a system in place to follow local, state and federal laws, to comply with industry regulations, and to allow discovery for lawsuits. Doing otherwise is illegal.
> effort to get a list of people seeking transportation to certain types of healthcare?
Don't collect that data in the first place. Have retention policies to delete data when it's no longer useful (so long as it's legally permissible), so you can demonstrate to the authorities or judge that it wasn't an attempt to evade or obstruct justice.
> I think you'd be hard-pressed to find a company storing mountains of user data which does not have a lockout plan like this that they will be willing to use against law enforcement in certain scenarios or by default.
This is tampering with evidence, which is a crime. Your view appears to be that nearly all such companies have policies to commit a crime.
Moroever, quoting https://corporate.findlaw.com/litigation-disputes/delete-at-...
] However, a number of courts have issued rulings imposing a duty to preserve before litigation begins if a party knows of the existence of a potential claim and can identify relevant evidence. See, e.g., Silvestri v. General Motors Corp., 271 F.3d 583, 590 (4th Cir. 2001) (upholding sanctions for failure to preserve a car involved in an accident, which plaintiff reasonably should have known would be material evidence in anticipated litigation against auto manufacturer). Therefore, as a practical matter, it is our general advice that you should instruct your colleagues and subordinates to retain records of any business activities for which litigation is anticipated, especially when it becomes apparent (through a demand letter or other saber-rattling) that a business relationship is "going south" and may be headed to court.
I'm currently working in LE and I would not be allowed to look at customer data if that was seized during a search related to an investigation of Uber. I would not be able to just grab the ride data of a subject of another investigation because that would be illegal. If I did do that, that evidence would be thrown out and I would be reprimanded.
I understand there are countries where this isn't true though, or where people are worried about the state of legal proceedings in their countries. But that doesn't mean Uber or any other company can just destroy evidence on the premise of securing customer data.
Also, I highly doubt that Uber hosts their customer data on workstations in their offices. At least I hope they don't.
In the majority of countries on Earth, the law is merely a suggestion to a significant portion of the police force.
The point of the raid being to get their hands on the evidence before it can be shredded which Uber have proven is a valid concern.
Physical demolition is much less likely to fail, and more fun to test. Thermite charges are easy enough to make.
I think I'd be too worried about burning my house down, and/or liability in a commercial context. It's also one of the most suspicious sounding things you could possibly do. "There was thermite in the servers" instantly makes people wonder just how much child exploitation material you were storing to even think about doing that. It's not endearing to judges or the media and both of these are likely to be involved in the aftermath.
And as we all know, conspiracy to obstruct justice only started being a crime in 2018, so they're all clear.
It constantly astonishes me the lengths Uber went to in order to build a shitty shitty business.
Yeah, sure we did spend copious amounts of effort to breach every law and regulation around the world, and then even more laws and regulations to cover it up - but look at the results! We have an incredibly unprofitable taxi company, we push our employees into poverty, and we've lost about half the company's value since IPO!
They are not the only industry to have this done to them, takeaway/fastfood outlets are another blindingly obvious example.
Becoming the new middle man, meeting the customers needs goes back hundreds of years.
The US has always allowed a government to get a warrant to search personal records, including the ability to execute that warrant quickly, to prevent someone from destroying those records.
Companies should and do get into legal trouble for destroying records which are required for legal, regulatory, or lawsuit discovery purposes.
I don't think you rank corporate records higher than personal ones.
So I don't understand the moral ambiguity here.
Your moral point is that you think it's okay to block anyone else from accessing your data, but it's not okay to destroy it? Because that's the only way I can make sense of your comment.
Yes.
Why is that even a question?
What is the moral reason for saying that a company can store, use, and profit off of data, with a kill switch that {delete, hides, obscures, encrypts} that data when the government comes with a warrant, or when the courts have authorized discovery for a lawsuit?
Isn't that just rife for abuse? "Sorry, we don't have any records of dumping hexavalent chromium. The file deletion we did 10 second ago must have included them, if we had them." That would make for a very different Erin Brockovich movie.
More to the point, why would encryption be okay, while deletion is not?
Even more to the point, what judge (or jury!) would accept that difference?
I mean it's kind of hard to feel sorry for Uber in this scenario surely?
A kill switch should be standard operating procedure in the event that armed persons enter secured areas unexpectedly. Ideally, the human factor should be avoided too; this makes a good argument for tamper-sensitive systems, anti-forensics, etc.
If I was pulled over and had my car searched by police, I would not expect them to use my keys to then search my home without due process. If I felt that was a risk, I think changing my locks is entirely reasonable, as it doesn't prevent a legitimate search warrant.
I see this as hijacking a companies computers to export confidential data they were not otherwise entitled to from a foreign country.