Live data from Hacker News

Uber employees used the platform to stalk celebrities and their exes

businessinsider.com

241–250 of 250 posts

Re: Uber employees used the platform to stalk celebrities and their exes

#241
post #215

Earlier quoted context omitted.

Most auditors just want to check a box on a sheet, I've never been apart of an audit that was worth anything.

Careful with that brush, Eugene. As someone who has done (extensive) audit, I respectfully submit that the problem is not the audit process but the auditors you hire. The usual process for such a control should be: * Is there a requirement for a log? * Does that log exist? * Can the system(s) that write to the log be prevented from doing so/tampered with? (branch here to system security review) * How are the contents…

Thats broadly correct, although auditing is usually risk based. The first question should be is there a risk that requires a detective control of audit logging to be in place, if the answer is no (because the system is of low risk or value) then you would be unlikely to continue down the checklist.

Re: Uber employees used the platform to stalk celebrities and their exes

#242

Earlier quoted context omitted.

When you lose your credit card and you call your credit card company and them them that you lost it, they issue you a new card with new numbers; this way anybody that had the information on the card would not be able to make further transactions. I would consider the card lost when a company would not delete the credit card information on my request to delete the information.

A new number doesn't necessarily prevent charges from vendors who had the old one. For your convenience the banks actually allow new charges on the old cards after they are cancelled. I assume they whitelist vendors that have good reputations or filter based on patterns of charges against your account which you have not disputed. Verizon was able to charge against my old account for over a year. I kept getting snail…

I have done this. Yes, they initial did keep the subscription going. However, I told the credit card company that I did not authorized any further; they reversed everthing out. I really wonder whether they give the company the new information or whether they just allow authorization using the old numbers; seems like it is pretty screwed up security if they give the new information to the company.

Also, if you say: - Card was lost. - After reviewing all accounts, it was discovered that the CC information couldn't be deleted from the ubuer UI. - I hereby do not authorized uber to make any charges. - tell them in writing or record the conversation.

I don't see any way uber can make any valid charges against your account (assuming no more action on one's part).

I also wonder whether it follows CC guidelines/rules to keep CC information when the customer has explicitly tried to remove and communicated to the company to remove said information.

Re: Uber employees used the platform to stalk celebrities and their exes

#243
post #124

Earlier quoted context omitted.

A new number doesn't necessarily prevent charges from vendors who had the old one. For your convenience the banks actually allow new charges on the old cards after they are cancelled. I assume they whitelist vendors that have good reputations or filter based on patterns of charges against your account which you have not disputed. Verizon was able to charge against my old account for over a year. I kept getting snail…

>In other cases, the bank will actually update the vendor with your new card number so that subscriptions are not interrupted. That's apparently a feature: https://usa.visa.com/dam/VCOM/download/merchants/visa-accoun...

That is pretty screwed up. So, you have a merchant that is stalking one and they get updated information.

I think I will stick with with the new next gen taxi service where one pays with cash.

Re: Uber employees used the platform to stalk celebrities and their exes

#244

Don't forget that Uber now requires you allow them to access your location, even when you aren't using their app [1]. Side note: consider the value to foreign (or domestic) intelligence agencies of this weakly-guarded pot of gold. [1] http://www.theverge.com/2016/11/30/13763714/uber-location-da...

Disclaimer: I work for Uber. However, my opinions are mine. I am also not defending nor attacking in any way Uber gathering location data. With that out of the way - you know your cell phone carrier already has this data right? They have way better data than Uber ever will about all your habits, including establishing relationships based on who you call, which sites you visit, who you are signed up on a plan with, et…

> A much more weakly guarded pot of gold, I would say.

Bigger pot, way more strongly guarded.

Much more frightening is that literally all (4 or 5 I've seen by now) HN accounts that identified as Uber developers tried to ascertain "no it's fine and also I trust Uber" did so by while revealing they either

1. have no idea about Uber's exact privacy and security procedures (you don't need to put all the cards on the table if it's sensitive--though it shouldn't be--but you should be aware of the procedures and be able to ascertain they are in fact in place and implemented)

2. or, like the above poster, have very strange ideas about what constitutes their responsibility of protecting the privacy of their users. Hint: it's NOT "be slightly less bad at it than the next guy" (even though in above example that's arguably not even the case). This may be enough semi-security for your personal WordPress-blog, be slightly harder to hack than most people and if you're not a target, you're probably fine, probably.

Except of course, Uber is a target.

And yes, if I were a bad actor and I wanted data like that, of course I'd try Uber first instead of the (way better protected) cell phone carriers.

Especially now that I've seen all these Uber developers publicly flaunt their ignorance on the subject.

Re: Uber employees used the platform to stalk celebrities and their exes

#245

Earlier quoted context omitted.

Wait, that makes no sense. Your argument is that since there's one (huge) malicious actor we haven't stopped we should not care about any other malicious actors? "Privacy" is not binary. You can have privacy from Uber even while the government spies on you, and the situation when only one of them does is better than the one when both do.

I'm more afraid of the USG than I am of Uber. And while the line you're talking about clearly exists, I consider it such a thin line as to be essentially moot. I guess the analogy I'd use would be this: worrying about Uber in the era of rampant warrant-less nation-state surveillance is like rearranging the deck chairs on the Titanic.

It's not and it doesn't matter. You won't get less state surveillance by only complaining about state surveillance and not about companies that do the same on a smaller scale.

Respect for privacy has to become the normal situation. You can't say what does it matter if the other party does it way worse? No, they both need to step up. Even if it wouldn't make much practical difference if Uber just deleted their databases tomorrow while the NSA goes about their merry nefarious ways, it's also a battle of the public mind. The public doesn't care a lot, in a very large part because they just feel powerless about it, that they have no choice (and people really tend to come up with the stupidest arguments for the status quo if they feel powerless about it). Best way to make people care again (which is a small step towards getting our governments to stop giving our data to the NSA) is to draw a very clear line in the sand, NO you will respect our privacy, even if you're smaller than the big guys, it's not gonna happen, not on my watch.

It's not like people in war-torn areas stopped caring about muggers and looters just because the US army is killing women and children way more effectively using drone-strikes and misinformed soldiers all hyped up on a mission to kill terrrists (oops). No it's wrong and it shouldn't happen.

My opinion is, the data shouldn't be there in the first place. We can't protect it well enough. Especially not from future people who might legally come into possession of this data. Like in the US, privacy statements apparently mean nothing if a company or startup goes bankrupt and its assets are sold to third parties. They don't buy the obligations. This happened to Radioshack a few years ago, IIRC.

Data is the new radioactive waste.

Re: Uber employees used the platform to stalk celebrities and their exes

#246
post #72

Earlier quoted context omitted.

Disclaimer: I work for Uber. However, my opinions are mine. I am also not defending nor attacking in any way Uber gathering location data. With that out of the way - you know your cell phone carrier already has this data right? They have way better data than Uber ever will about all your habits, including establishing relationships based on who you call, which sites you visit, who you are signed up on a plan with, et…

> you know your cell phone carrier already has this data right? "But we already do A, so why shouldn't we do B?" "But we already do B, so why shouldn't we do C?" "But we already do C, so why shouldn't we do D?" ... "But we already do Y, so why shouldn't we do Z?" This is generally how things slowly but surely go down the toilet. From climate change to mass surveillance to fascism, etc.

No no no don't worry, see? It doesn't have to quit at Z. That's just a convention from using letters of the alphabet.

"But we can already has Z, so why shouldn't we do AA?"

"But we already make with the AA going, so why you no AB?"

...

Is no problem we just continue continuing on, standing on the shoulders of somebody else's problems, until the problem becomes the soil and a beautiful flower grows. Is future!

Re: Uber employees used the platform to stalk celebrities and their exes

#247
post #235

Earlier quoted context omitted.

But they may not like it when you have 73 active cards/names - so making this a mandatory thing would affect banks' processes. Also even if you're being literal and can do it in 17 seconds (i.e. after opening a new tab, 30 seconds from now you can have a card in the name of Mary Smith on its way to you) I and I think most people using online banking don't have it so smooth.

I timed it and it took about 25 seconds to go from the Chase login prompt to the "Add authorized user" page where you can get another credit card added to an existing account. So, I admit its not quite as fast as you would like. There is a caveat if you pay an annual fee: you pay the fee for each card. My accounts have no annual fee. I also checked US Bank and American Express and you are correct, the process is not…

I was very impressed with your report of Chase's behavior (and while 25 seconds might be an inconvenience of course it's acceptable.) It sounds like a gold standard. Of course, it's not practical to do that 72 times (for example every time you want to order a dildo from Amazon), due to the wait to get the card (it's not instant), but practically today people could use Chase fine to make companies not follow them. Do you think you can choose a name such as Donttrackme McSpammer? I realize this is pretty much the opposite of the term "John Smith" as for example the Uber driver would see that you went out of your way to call yourseld Donttrackme (there is zero chance it's an actual first name) but the adcantage is that it would not appear fraudulent.

Since you don't have an annual fee, can you order a card in the name of Donttrackme McSpammer (or any other similar name that couldn't be mistaken for a real name) and see if you get it?

Thanks for having taken the time to check the other two sites as well. I appreciate it!

Re: Uber employees used the platform to stalk celebrities and their exes

#248
post #3

This seems like a good place to tell Uber users that the only way of removing your credit card details from your Uber account is to either: a) plead with Uber's customer service to do so or b) add another payment method (like another credit card) This, of course, is horribly bad practice. I can only imagine that they arrived at this very peculiar arrangement after extensive A/B testing - Uber has hired plenty of FB f…

Google Adwords do this, and vultr.com do it as well. I agree it's really user-hostile and a dark pattern to allow users to enter payment details and then refuse to delete them. I don't want to leave my credit card details on the servers of hundreds of companies, or allow them to charge at will, but it's obvious why from the companies point of view why this is attractive.

At least Adwords is a mostly B2B service. Google doesn't do this on their consumer-focused services.

Re: Uber employees used the platform to stalk celebrities and their exes

#249
post #142

Earlier quoted context omitted.

Is it legal to refuse to delete a users account?

I'm seeing a few replies suggesting that it varies between EU/US etc ... but either way it sounds like a REALLY effective way to piss off those customers and guarantee they'll never come back and use your service in future (or share such "horror" stories with their friends and relatives). I don't get why those companies would go out of their way to make things difficult for themselves in the long run

(Sorry, late.)

These companies don't seem to tend to think long-term, at least not at this level. It's all about growth acceleration/hacking.

Re: Uber employees used the platform to stalk celebrities and their exes

#250

Earlier quoted context omitted.

> Despite the bad press it is actually a pretty freaking great place to work. So, how many hours a week do you drive? Oh, I'm sorry... those aren't "workers" -- they're just being nice and sharing their cars in their free time.

Actually I do drive. I drive so I can sympathize with the partners I am serving and better server them by making the product the rely on to make money better, and more reliable.

So now they are making exceptions for employees to drive? Pretty sure that the employee handbook and HR made it crystal clear that employees can't be drivers because then things get real fuzzy legally...
Post reply on HN