Live data from Hacker News

Uber CEO Plays with Fire

nytimes.com

261–270 of 529 posts

Re: Uber CEO Plays with Fire

#261
Uber responds to report that it tracked users who deleted its app [0]. It seems to insist that tracking was done to prevent fraud and account compromise.

  Uber is pushing back on the allegations, saying that the
  tracking is a common industry practice used to prevent fraud
  and account compromise.
[0] https://techcrunch.com/2017/04/23/uber-responds-to-report-th...

Re: Uber CEO Plays with Fire

#262

Earlier quoted context omitted.

Given sufficient data, nothing's really anonymous. That's a bullshit hedge.

Especially if eg Facebook notification emails count as transactional. Group memberships alone massively narrow things down. Throw in a few business notifications and it's game over. Even without that angle, I find it absolutely scandalous that a company is able to do this, even with the T&Cs permission of their users. Surely at some point this is going to bite them in the behind? The possibilities of it going massive…

The problem is likely suable entities. I'd imagine there's a fair number of corporate cut-outs in shady schemes like this. With the expectation that if there are ever lawsuits a sacrificial faux-company goes bankrupt and takes the damages.

Re: Uber CEO Plays with Fire

#263
post #68

Earlier quoted context omitted.

> he might drive for 14-15 hours in one day This, by the way, is probably illegal, as it is extremely dangerous. If I'm taking a taxi, I'd like to know my driver is not on the brink of exhaustion.

It might be unsafe but it's not illegal. It looks like Uber recently sidestepped it with agreeing that drivers not work more than 12 "consecutive" hours. Does a 15-min food break make two 8 blocks "non-consecutive"? I hope not. http://www.politico.com/states/new-york/city-hall/story/2016...

In Israel, food breaks do not make two separate blocks. By law, you can't work more than 12 hours in one work-day, and there must be at least an 8 hour rest period between two work-days.

I remember when I was in the army, you were not allowed to drive if you hadn't slept at least 8 hours the night before. Of course, these rules are never strictly kept.

Re: Uber CEO Plays with Fire

#264

Earlier quoted context omitted.

Perhaps to identify a device from which a fraudulent transaction occurred in the past?

Because you don't want any phone in the world to be allowed to access any bank account in the world by just giving a name and password. Fingerprinting is a form of 2 factor authentication, it's easy to perform and it's relatively efficient against fraud.

If they're doing this on iOS, which is where it's interesting (in that it violates Apple's policies), they have a perfectly good 2-factor solution already present -- your finger.

Re: Uber CEO Plays with Fire

#265

Earlier quoted context omitted.

> "to be clear, a # of companies practice 'fingerprinting,' and it is fully breaking the App Store rules. But also very clever fraud detection." https://twitter.com/MikeIsaac/status/856180005977677825

wonder why Mike Issac gave that clarification immediately to his twitter-base but didn't put it in the relevant section? could it be because the article intentionally glosses over complex details in order to pump a specific narrative ... hmm. \s

Sorry to burst the 'specific narrative' bubble but its probably not that. Just look at the change:

Here's the change in question: http://newsdiffs.org/diff/1383350/1383404/https%3A/www.nytim...

changing "tracking" to "identifying and tagging" and changing "even after its app had been deleted from the devices, violating Apple's..." to "even after its app had been deleted and the devices erased — a fraud detection maneuver that violated Apple's..."

In a really long article like this which is probably under some time pressure to publish, there's almost always things that seem clear to the author aren't to the reader. This is a standard clarification bug fix, and tweets were over an hour after the article was published - enough time to gather feedback and realize the need for clarification.

At least in this instance, the only specific narrative being pumped is the one that journalists are always pumping a specific narrative on touchy subjects.

The tweet responses:

> @MikeIsaac 32 minutes ago > Since the line about fingerprinting is being misinterpreted(though it is explained later in piece) adding language up top to better explain.

> @MikeIsaac 31 minutes ago > appreciate Technical community's concerns about how It is presented. Uber was not tracking location after device wipe (which I never said).

> @dangillmor 30 minutes ago > What exactly were they tracking? Not entirely clear (at least to me).

> @MikeIsaac 29 minutes ago > ID-ing devices. so if I steal a phone and wipe it, they can still determine I had that phone and used it to defraud uber, using other data

Re: Uber CEO Plays with Fire

#266
post #203

Earlier quoted context omitted.

Why would most users care that Uber was slightly evading some privacy rules to prevent drivers from executing fraudulent rides?

They probably don't. Look at my first comment. I said "It'd be nice". It wasn't a comment about what would be good for Apple or bad for Uber or anything like that, it was just a remark about how I see it.

But it wouldn't be nice. It would be terrible for everyone involved, Apple, Uber, Uber/Apple customers.

Re: Uber CEO Plays with Fire

#267
post #36

From the article, explained: At the time, Uber was dealing with widespread account fraud in places like China, where tricksters bought stolen iPhones that were erased of their memory and resold. Some Uber drivers there would then create dozens of fake email addresses to sign up for new Uber rider accounts attached to each phone, and request rides from those phones, which they would then accept. Since Uber was handing…

>" Some Uber drivers there would then create dozens of fake email addresses to sign up for new Uber rider accounts attached to each phone, and request rides from those phones, which they would then accept. Since Uber was handing out incentives to drivers to take more rides, the drivers could earn more money this way." Could someone explain the logic behind how a driver requesting rides benefited them? Did the drivers…

Yes, in the earlier days in each city, they (just pulling numbers from thin air) do something like pay a minimum $20 for each trip if you complete 5 trips within an hour without cancellation. Helps to kickstart the driver supply.

Re: Uber CEO Plays with Fire

#268

It'd be nice if Apple had been less pragmatic and more principled and just yanked any version of the Uber app that broke the rules.

When there's that much VC money on the line, breaking the rules gets you a meeting with Tim Cook.

I would say the fact that the Uber app is installed on millions (or hundreds of millions) of iPhones is what gets you a meeting with Tim Cook.

Re: Uber CEO Plays with Fire

#269
post #36

From the article, explained: At the time, Uber was dealing with widespread account fraud in places like China, where tricksters bought stolen iPhones that were erased of their memory and resold. Some Uber drivers there would then create dozens of fake email addresses to sign up for new Uber rider accounts attached to each phone, and request rides from those phones, which they would then accept. Since Uber was handing…

I think they're referring to Keychain items surviving an app deletion. That quietly stopped working in a recent iOS update.

It was in one of the 10.3 betas but was removed. I don't think it can be deleted reliably without losing data if iCloud keychain is enabled, e.g. another device might still have the same app or share the app group.

Re: Uber CEO Plays with Fire

#270

Earlier quoted context omitted.

wonder why Mike Issac gave that clarification immediately to his twitter-base but didn't put it in the relevant section? could it be because the article intentionally glosses over complex details in order to pump a specific narrative ... hmm. \s

That's a clever media hack. Using provocative headlines and misleading lead to get clicks and shares, but using a separate medium (Twitter) to get away with it. Clever, but it's disappointing that even NYT is turning into this madness.

They've also updated the article text now: "To halt the activity, Uber engineers assigned a persistent identity to iPhones with a small piece of code, a practice called “fingerprinting.” Uber could then identify an iPhone and prevent itself from being fooled even after the device was erased of its contents."

Note that this was at least 4 hours after the outrage on Twitter started. Seems like a very intentional, well-calculated strategy indeed.

Post reply on HN