Live data from Hacker News

Uber employees used the platform to stalk celebrities and their exes

businessinsider.com

201–210 of 250 posts

Re: Uber employees used the platform to stalk celebrities and their exes

#203
post #6

A few days ago (on the discussion of the Uber app tracking users' movements after the end of their ride) an Uber employee commented on their data handling: [0] > Individual users' data is very closely guarded internally. It's immensely difficult to look at user data without specific access. Overwhelmingly, this data is queried in aggregate and fed into machine learning systems. The risk of abuse is exceptionally low.…

I don't know about Uber, but I've worked at a lot of places that had sensitive data. A common patterns is to fail to treat employees like attackers, and protect data in ways that are very beatable by a motivated employee. Some examples that hopefully have been fixed:

-A company had a specific dataset that would be worth millions: The kind of things that a wikileaks might want to publish, and would make the papers. I was supposedly unable to access the app that displayed it, but I had access to the tables. For legitimate business reasons, I took the data out, put it in my company laptop, and stuck a search engine on top. There were no logs of my activity, and nobody came to ask why in the world I was doing something like this.

-At another place, they were saving credit cards, encrypted, but their idea of saving encryption keys was to put them in a file that only root could access. Well, everyone had access to create batch jobs (yes, even phone reps), and batch jobs ran as root, so anyone could walk out with the lot. I had to do a lot of work to convince them that yes, this was not PCI compliant.

-Another system had relatively well protected data, only available to people with access. Except they had single sign on, and some of they systems that took credentials did so in the clear. Peek at network traffic, steal credentials, and then do whatever you want as anyone you want! They had a process where you were never supposed to leave your computer unattended, and if you did, team members would go into your computer and send an email to the team promising cake, and you'd have to bring it as punishment for your security problems. Imagine their surprise when people were sending emails promising cake while they were using their computers.

-A phone company having cell call metadata in the clear, in a DB any developer could query. There was another system with billing information, equally accessible. So search for your favorite person in one, and go to the other and see who they call, when they call, and from where. Isn't that convenient?

So I don't believe anyone's claims about their data security unless they come from someone that has some security knowledge and has tried to evaluate the security pretending to be a real attacker. And even in that case, I'll probably want a team of them. Otherwise, I'll assume there are major flaws that nobody has found, just because nobody has cared enough. I have yet to find an employer where this was not the case.

Re: Uber employees used the platform to stalk celebrities and their exes

#204

Earlier quoted context omitted.

So, you occasionally drive Uber as an experiment/hobby, not as a job, which is not the same experience as relying on it for your next meal.

That's uncalled for. How many software developers ever bother to use the software they develop, or work with (or even talk to) the people who use the software as part of their job? Actually doing the job that your users do, even part time, is fantastic dedication. Doing it full-time is absurd; when would he make use of what he's learned?

>That's uncalled for.

It's not an insult. It's a statement of fact: it is a different experience than depending on Uber driving for your livelihood. So one should not read much into it regarding the hardships/issues of drivers as professionals.

The same way a NLE developer that "eats his own dog food" by editing his daughter's birthday video doesn't exactly have the same experience/needs/issues of using the software as a professional editor in TV or film.

Re: Uber employees used the platform to stalk celebrities and their exes

#205

Earlier quoted context omitted.

This quote from another employee also looks naive now (and I'm not trying to offend him): https://news.ycombinator.com/item?id=13086454

No, I'm not naive, and I, proudly, stand behind everything I wrote. The person in the article was terminated before I joined, so I don't know what the systems were like back then, but every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. I haven't actually tested to see what I…

>every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article.

That's nice, but it shouldn't be forbidden to violate users' privacy, it should be impossible.

Re: Uber employees used the platform to stalk celebrities and their exes

#206

Earlier quoted context omitted.

No, I'm not naive, and I, proudly, stand behind everything I wrote. The person in the article was terminated before I joined, so I don't know what the systems were like back then, but every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. I haven't actually tested to see what I…

>every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. That's nice, but it shouldn't be forbidden to violate users' privacy, it should be impossible .

I mean... it should be, but every business I've ever worked at has had difficulty cleaving between "the kind of access that developers need in order to do their jobs" and "the kind of access that would be abusable." It's legitimately difficult to do, and there's no way to make your system proof against insider abuse without serious trade-offs.

The purported "God-mode" that Uber had years ago, and showed off at parties, was a real problem with their culture. The ability of devs to get read access to some production data is much less of a huge deal.

Re: Uber employees used the platform to stalk celebrities and their exes

#207

Earlier quoted context omitted.

No, I'm not naive, and I, proudly, stand behind everything I wrote. The person in the article was terminated before I joined, so I don't know what the systems were like back then, but every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. I haven't actually tested to see what I…

>every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. That's nice, but it shouldn't be forbidden to violate users' privacy, it should be impossible .

>That's nice, but it shouldn't be forbidden to violate users' privacy, it should be impossible.

Work for just about any company, tech or otherwise, in a sysadmin role. There is always going to be some way for a smart, malicious admin to get into things.

Snowden is maybe the best example. If an organization with an insider threat risk profile as high as the NSA's can't get it right, then you can be pretty certain almost no one else is either.

Re: Uber employees used the platform to stalk celebrities and their exes

#208
post #134

Earlier quoted context omitted.

You missed the point: the telecom carriers haven't either, however they are regulated, which is not the case for Uber. So the point is moot for telecom carriers because the regulator already swept in. The point is still important to make concerning ongoing practices in unregulated markets, like big data in tech. If you don't like how little is done to correct the NSA using telecom facilities however, you should see w…

You missed the point: The point, as I see it, is that your data is never really safe. I don't much care if Uber can be trusted or not, when the State can always step in and hoover up whatever data Uber has. If you don't like how little is done to correct the NSA using telecom facilities however, you should see with your government, not simply the companies it coerces. As long as the State can't be trusted, the rest i…

Wait, that makes no sense. Your argument is that since there's one (huge) malicious actor we haven't stopped we should not care about any other malicious actors? "Privacy" is not binary. You can have privacy from Uber even while the government spies on you, and the situation when only one of them does is better than the one when both do.

Re: Uber employees used the platform to stalk celebrities and their exes

#209
post #6

A few days ago (on the discussion of the Uber app tracking users' movements after the end of their ride) an Uber employee commented on their data handling: [0] > Individual users' data is very closely guarded internally. It's immensely difficult to look at user data without specific access. Overwhelmingly, this data is queried in aggregate and fed into machine learning systems. The risk of abuse is exceptionally low.…

I don't know about Uber, but I've worked at a lot of places that had sensitive data. A common patterns is to fail to treat employees like attackers, and protect data in ways that are very beatable by a motivated employee. Some examples that hopefully have been fixed: -A company had a specific dataset that would be worth millions: The kind of things that a wikileaks might want to publish, and would make the papers. I…

[deleted]

Re: Uber employees used the platform to stalk celebrities and their exes

#210

Earlier quoted context omitted.

No, I'm not naive, and I, proudly, stand behind everything I wrote. The person in the article was terminated before I joined, so I don't know what the systems were like back then, but every time I access production systems, I have a ton of messages telling me that our access is being completely tracked and we are prohibited from doing anything that was mentioned in the article. I haven't actually tested to see what I…

Uber employee here too. Would never ever check any data of anyone not related to debugging crashes, race conditions, unexpected app behavior etc etc, its just not worth losing my job. Despite the bad press it is actually a pretty freaking great place to work. Also wanna +1 the warnings about data access and only looking at PII for legitimate purposes are all over the place.

> Despite the bad press it is actually a pretty freaking great place to work.

that's not what I heard from my friends that worked / currently work there.

Post reply on HN