I've said it here before, and I'll say it again: ValleyWag/Gawker Media are scum. This is just another entry in a long list of terrible things they do to get pageviews.
I've said it here before, and I'll say it again: ValleyWag/Gawker Media are scum. This is just another entry in a long list of terrible things they do to get pageviews.
Editor John Cook told us that the screenshots did not, in fact, have any identifying information.
“We didn't publish any identifying information about the source of the screengrab,” Cook says. “We don't know who sent us that shot, and neither does Uber.
Now, I can't say which one of the two is telling the truth, but at least give both sides of the story. Looking at the shots, I'm not sure what is personally identifiable, though the bookmarks bar could give some clues.
And Travis's threat of legal action might just be hot air from him (which isn't exactly unprecedented). After all, these numbers look very good for Uber. I wouldn't want to be one of their competitors trying to raise a round of funding right now.
> It's a shame when tech journalists don't understand tech. Of course, they outed their source. With the time stamp Uber can check which employees looked at that page at a particular time. They can then ask these employees [likely just one] whose computer they were using at that time to figure out who grabbed the screenshot and sold it to ValleyWag.
So it's either VW didn't realize this, or fully realized it and still outed their source because they don't give a shit. Given their history of outing their sources, even after specifically being asked not to, I think the latter is much more likely.
I think it's a bit of a leap to assume that the Uber admin system logs every user pageview. It may well do, but many home-grown systems (and it certainly looks homegrown) don't bother with that level of detail. Certainly, if they were that security conscious you'd think they'd also avoid allowing any employee to see overall revenue figures.
I doubt Uber was secure/paranoid enough that the timestamp will immediately yield the leaker - but between webserver logs, VPN logs, etc etc, there's probably enough information there to deduce the culprit, especially if this occurred outside business hours.
grep /log-in server.log
to find the admin user id which logged in around that time and viewed that page from an external IP. I'm sure if they really want to they could find the IP at least, and track which user accessed the resource, which other pages were accessed, which will probably lead them to the leaker. Quite a lot is logged by default by the web server usually, and then on top of that their app will do more logging, maybe even associating page views with user ids.Presumably if the time stamp is identifiable, the leak comes from an entry level employee.
On the other hand, this makes for a nice PR stunt.
After you login to Uber.com it instantly does a GET to /api/clients/[PERSUMABLY_USER_ID]?parameters which would be in the logs or they might have logs of user logins on their side (to show users a 'you've recently logged in from...' list somewhere)
What's weird is the editor hairsplitting between the source and the employee that happily helped the source access the data. I guess Uber might care about the intermediary, but I'm pretty sure they will be concerned about the actions of the employee.
Privacy is like a game of 20 Questions where the adversary intends to hone in on the full identity. Regardless of whether the source is identified, it is still unfathomably sloppy on ValleyWag's part in protecting their sources.
It could also be the last-updated time, or particular numbers in a column... which would have only been served to a single account in a logged transaction.
A company that cares about its proprietary information can easily log and/or watermark everything served via internal tools.
Jokes on them cause AOL successfully hijacked their story anyway.
The press doesn't exist to cheerlead (in most cases). There's no arguing that Uber's numbers are newsworthy, so I don't see anything wrong with Valleywag's coverage in this instance.