Is Uber’s rider database a sitting duck for hackers?
washingtonpost.com
washingtonpost.com
I guarantee there are state intelligence agencies (both US and non-US) with "assets" at Uber with access to this information. This is bread and butter espionage - plant or recruit employees at private companies with access to the information you need.
> Wouldn’t detailed data on such rides be handy for a foreign power eager to map the relationships among various Washington players? It could potentially show both a history of contact and real-time movements as meetings are convening.
And then what? Let's say China knows that Senator A and Senator B both took an Uber to the same restaurant at the same time. What do they do with that information? It doesn't tell them what, if anything was discussed. Maybe they didn't talk politics at all. Maybe they had a big fight and swore never to speak to each other again. Who knows? How does the ride information help? I'm hardly an expert on espionage, but I don't see what advantage this gives anyone.
Ask any cab driver about drugs and prostitution in their locale and they'll be able to give you quite a lot of information (you might have to buy them a beer or three first). Uber's records could reveal substantially similar things, like "Person X from escort agency Y visited address Z twice a month for a year".
If you know who lives at Z, you know a lot. Again: not from one trip, but from the pattern. And not with certainty (obviously: knowledge is not certain) but with high enough plausibility to target a deeper investigation.
All that without doing anything illegal. It's just a matter of matching pick-up locations and timestamps to people of interest. Which should be easy in case of public officials and companies with known headquarters.
Another big difference: taxi destination is only in lat/lng. For Uber data, it's possible that much of the data is exact address (or at least corner) of the destination...because it's just easier to enter it in the address you want as a user rather than obfuscate it (obviously, people trying to cover their tracks would try to obfuscate, but why would the use Uber in the first place if they were that self-conscious?)
I don't think the media is going to stop targeting Uber for a while...
I am always happy when the topic of security and data-privacy is discussed in the broader media. I wish there was an easy 'goto' option for agile/startup/lean/hacker teams with little time for security policies are focused on speed so early on.
"Regulation--SOX, HIPAA, GLBA, the credit-card industry's PCI, the various disclosure laws, the European Data Protection Act, whatever--has been the best stick the industry has found to beat companies over the head with. And it works. Regulation forces companies to take security more seriously, and sells more products and services." - Bruce Schneier[1]
[1] https://www.schneier.com/news/archives/2008/01/bruce_schneie...
Obviously, that kind of alleged discussion is not going to win the hearts of the journalistic class, but Uber's problem is that it had a reported history of using user data for unexpected purposes, like to use the God View as decoration at a company party.
One of the key points in the OP that I hadn't seen before is an anonymous Uber interviewee who claimed that he/she had total access to the Uber customer database as part of the interview...and for hours after the interview.
I agree with some people here, that this seems like an overblown story because Uber isn't any more an attractive data center than Google/Facebook/Github/etc...the problem is that what we know of how Uber has disseminated the data within the company indicates an almost certain lack of prioritization of access control. And many of the employees at Uber being human, it's only a matter of time before someone gets phished and something like an attachable Excel file of intranet-passwords is found (or other manifestation of sloppy IT-security practices/work-arounds).
And I'd say Uber deserves a little additional scrutiny...its data may not be as valuable as Google or Facebook's, but it could very well have the lowest focus on operational-security compared to companies in its tier of valuations.
While I agree that given the nature of the data they capture, it makes sense that they receive a little additional scrutiny -- this more feels like someone had the idea of how the data could be misused, then discussed the idea with a various security folks who (unsurprisingly) said, "Well.. yeah, now that you mention it, this COULD be a problem." In other words, feels like the writer was making the news here and not reporting it.
And to an extent that's legitimate. I question the need to approach it in this way though - making a one-sided story of it instead of working with Uber to see if they're aware of this as a potential issue, determining what steps they're taking to prevent it, etc...
As far as how Uber is using the data they've acquired - it seems they've hit that painful point that every long-term startup does. They've evolved past the point of a small group of folks with an idea, and need to adjust to a new reality. That includes reining in some of their "ooh, pretty data! let's play with it!" impulses, because of the privacy implications and because of the implicit trust their users place in them. I would expect a couple of high profile hires and some policy statements to be forthcoming as they mature.
There are billions of dollars in play here, and this isn't the anywhere close to the first time people are fighting dirty.
"Is the Washington Post the Most Unethical Publication in the Nation?"
Opening up innocent people to hacking is one of the most important reasons that this new school of data gathering is being discussed.
Is it unethical when it appears as if the answer is almost certinly "YES!"?
edit: I'm specifically thinking of Uber gathering which customers have phones with vulnerabilities.
Every company sits on troves of data re: your personal habits and comings and goings - and they all get hacked, all the time. Even ones run by the "grown ups" that - according to the narrative - Uber so desperately needs if they ever want to be seen as a member of decent society.
Not to mention, this type of reasoning could be applied to almost any technology company. Every company is theoretically an attractive target for personal information.