Live data from Hacker News

Uber CEO Plays with Fire

nytimes.com

231–240 of 529 posts

Re: Uber CEO Plays with Fire

#231
Although the article says they stopped using fingerprinting after getting caught by Apple, that's not actually the case. They're still doing it. I have an iphone that no matter how many times you wipe it, or how many sim cards you use, it will get instantly banned if you try and create an account on Uber.

Re: Uber CEO Plays with Fire

#232

Earlier quoted context omitted.

100% sure that all decent banking app use device fingerprinting. 100% sure that it is not breaking the rules and it is really important that they keep doing it.

Why would a banking app need to use device fingerprinting?

Perhaps to identify a device from which a fraudulent transaction occurred in the past?

Re: Uber CEO Plays with Fire

#233

Earlier quoted context omitted.

While it's generally true, I'm not sure that's really an excuse for deceptive behavior.

The saying isn't meant to be an excuse for companies, it's a reminder to end users to pay attention what they're signing up for. Situations like this one are exactly why the saying became popular.

Like i said below, the most obvious expectation was thinking that they would monetize with ads, which is why people didn't think twice about this.

There's a difference between ad supported businesses and business that actually directly sell user data behind the scenes.

Equating all the ad-supported businesses with this case is not really fair because the types of businesses you're talking about here are not actually literally selling you out. They are simply pushing you ads on THEIR platform which YOU agreed to use. Sure there are lots of shady things going on in this department as well, but it's a completely different game than what this looks like.

Based on this article it looks like they took your data and actually sold it to a third party, this is different from simply displaying ads on their platform. They literally sold you. And it happened OFF of the platform you signed up for.

Re: Uber CEO Plays with Fire

#234

Earlier quoted context omitted.

While it's generally true, I'm not sure that's really an excuse for deceptive behavior.

The saying isn't meant to be an excuse for companies, it's a reminder to end users to pay attention what they're signing up for. Situations like this one are exactly why the saying became popular.

It's trite, and aside from belonging in the big dustbin of Hacker News cliches like linking to XKCD Standards, 'Just because you can doesn't mean you should' and 'Conflating Causation and Correlation' in this case it obscures more than it illuminates.

A product may be free - and you may still be happy to be the product if you think your attention is being sold, or that they plan to upsell you onto a premium plan.

'If you're not a paying user' doesn't immediately lead you to 'They're going to scan my email and sell the data to fucking Uber' and shouldn't require the user to scan the ToS / rack their brains for every nefarious bit of fuckery the company might conceivably use the data for.

Re: Uber CEO Plays with Fire

#235

Earlier quoted context omitted.

Was the keychain item surviving app deletion a feature that was dropped or an undocumented feature?

If it "quietly stopped working" I'd have to assume the latter.

Thanks, I just remember that when I stored the items the documentation recommended that one put in the keychain list, then deleted the app off of an actual device for testing purposes and reinstalled the app on that same device, all those items would still be there so I (wrongly in hindsight ) assumed it was the desired behavior by Apple otherwise other developers would have complained.

Re: Uber CEO Plays with Fire

#236
post #210
post #110

Earlier quoted context omitted.

This really doesn't match up with how the conversation/outrage is playing out on Twitter right now. People seem to be interpreting this as "Uber continues to track your location after you have deleted the app," when what really happened seemed to be "If you delete Uber and then reinstall it on the same phone, Uber knows that it's the same phone." See for example this Tweet, with hundreds of retweets and lots of verif…

Uber was tracking people after they left their rides, and it's unsure if they ever stopped. http://www.npr.org/sections/alltechconsidered/2016/12/01/503...

OK, but that's different from tracking people after they've deleted the app.

Re: Uber CEO Plays with Fire

#237
I don't know but Uber has proven to be a shinny example of a ponzy scheme within a larger ponzy scheme. They will never be profitable, Burning billions, so is the case with Careem whom I met, and their staff was at loss to tell how this is a viable business to run. They disrupted taxi drivers, making good earnings. They benefited a lot to consumers eliminating overcharging by common taxi drivers. But as an entrepreneur I am still failing to understand how far they can go before they run out of fuel $ eventually.

Re: Uber CEO Plays with Fire

#238
post #45

For all the criticism he is getting, this would never have happened without him. Taxi companies are too strong, and the US needed someone like him to break barriers. Lyft would never have existed without Uber. Now that Uber broke through the path (and is getting destroyed for it) the way is open for lots of other companies. It happens all the time that the company that invents or creates something new, does not actua…

Your optimism is refreshing. The only way Uber makes sense is if they get a monopoly. Uber has been trying to make sure no other company can be profitable by subsidizing rides to unsustainably low prices, in the hope they are the last company standing.

All the companies subsidize rides, including Lyft and Didi. No company would willingly do it if the others didn't do it as well, except maybe to increase market liquidity as the market maker.

Why single out Uber when all the companies in this space are doing the exact same?

Re: Uber CEO Plays with Fire

#239

Earlier quoted context omitted.

No, they fingerprint the phone like browser fingerprinting. Unique settings, apps installed etc. Very hard to have a non-unique set up with enough data points.

No? Did you work on this code and know for sure? Let's look at roughly what's available: iPhone model (2 orders of magnitude of possibilities) Device storage -- increases entropy with iPhone model but still not that much Device name -- easily changeable by scammer, so not enough iOS version -- changes over time, not great for a long term fingerprint but might help short term IP address -- short term attribution ok, b…

Each variable you mentioned is not unique, but put them all together and now you are talking. And then apply a heavy dose of statistics and machine learning on top of THAT.

Especially since the behavior/activity of the phone could be suspicious as well.

You also don't need to be 100% accurate all the time. The point is to minimize the damages done to you by scammers, not reduce it to 0 which is impossible.

Re: Uber CEO Plays with Fire

#240
post #167

Earlier quoted context omitted.

100% sure that all decent banking app use device fingerprinting. 100% sure that it is not breaking the rules and it is really important that they keep doing it.

While you're right that a lot of FinTech applications do use fingerprinting, it is absolutely against the rules. It's rather annoying from a mobile security perspective but given the rampant abuse of persistent device identifiers on Android, I understand and appreciate Apple's stance here.

> While you're right that a lot of FinTech applications do use fingerprinting

Do they really? [Citation needed] very much here. Which fintech app fingerprints devices? What would even be the point of doing that. You can persist a token in the keychain for that which is enough unless you are devious.

Post reply on HN