Live data from Hacker News

Uber CEO Plays with Fire

nytimes.com

461–470 of 529 posts

Re: Uber CEO Plays with Fire

#461
post #454

Earlier quoted context omitted.

Well there is, but it's not cheap. You get a trusted third party to Audit you and publish the result of their Audit, something similar to a SAS70. It's not a perfect solution but it's an option to consider

fair point – this is something we consider doing before expanding to b2b market. but: my day job is in ecommerce (I work as a product manager at FastSpring) and I used to work on CleanMyMac at MacPaw – had to work with trust in both. it's somewhat unexpected but people who are buying software for themselves usually don't care about PCI compliance, audits, and other artifacts of "institutional validation". they care a…

When dealing with sites where high trust is required I think people would much rather see an independent audit or compliance with a (legit) security accreditation than a Norton badge, however, most of the time this is not offered, so we make do with the crappy badge, a recommendation, or gut instinct.

Having said that, I deal with independent audits in my job, and they're not all that reassuring.

Re: Uber CEO Plays with Fire

#462
post #429

Earlier quoted context omitted.

I worked for a company that nearly acquired unroll.me. At the time, which was over three years ago, they had kept a copy of every single email of yours that you sent or received while a part of their service. Those emails were kept in a series of poorly secured S3 buckets. A large part of Slice buying unroll.me was for access to those email archives. Specifically, they wanted to look for keyword trends and for receip…

situations like this is what makes it really hard for others in this space to survive. I run https://clean.email (and we don't store/retain/sell any data, just charge people to use it) and the biggest issue we have is lack of trust because of news like this. although every day someone would still email with a question "why you are not free like unroll.me".. sigh.

> the biggest issue we have is lack of trust because of news like this.

This gives you something fundamental to compete on.

Re: Uber CEO Plays with Fire

#463
post #373

Earlier quoted context omitted.

Is talking about an achievable political goal instead of whatever you think would be ideal really the same sort of thing as gaslighting?

No. But Pence was definitely not talking about achievable political goals. He was just flatly denying that certain things happened. Clinton wasn't gaslighting; she was just espousing the (correct, as far as I can tell) idea that in order to be a successful leader, you have to convince different sides that you believe different things, even if those sides are talking to each other to figure out what you believe. That…

>Clinton wasn't gaslighting; she was just espousing the (correct, as far as I can tell) idea that in order to be a successful leader, you have to convince different sides that you believe different things

Not sure how well that worked for her. See "Poll: Just 12 percent of Dems see Clinton as 'honest and trustworthy'" and similar headlines. Plus losing to a pretty bad opponent.

Re: Uber CEO Plays with Fire

#464

Serious question. How can I short this $70B stock?

Sadly there doesn't seem any way to short it on an organised stock or spread betting market. The best you could probably do would be a private bet or forward contract if you can find someone who wants to be long.

Re: Uber CEO Plays with Fire

#465

Random Question: Why doesn't Apple do clean uninstalls once you remove an app? Every time I re-add Uber (I usually delete it since I live in Austin and it's useless... but then when I travel I re-add it when I want a ride) it already has my account and password saved. I'd be a lot happier if it did a clean install. Not just Uber, but every app... any idea how I can do a true clean uninstall when I remove an app from…

Try Settings > General > Profile > Delete Profile?

https://support.apple.com/en-gb/HT205347

Re: Uber CEO Plays with Fire

#466
post #190

It'd be nice if Apple had been less pragmatic and more principled and just yanked any version of the Uber app that broke the rules.

Uber has millions of people who use and love the service. Yanking the app without notice doesn't just punish the company it punishes those users. Working with Uber to get the issue fixed without punishing innocent bystanders is good policy.

i.e. One, weaker, rule for popular apps, one stronger rule for the little people.

Re: Uber CEO Plays with Fire

#467
post #355

Earlier quoted context omitted.

Who knows? Maybe at one point people will realize the value of local mail storage and end to end cryptography.

Do you only use one device?

Using multiple devices does not preclude one from using a server and end-to-end encryption.

Re: Uber CEO Plays with Fire

#468
post #454

Earlier quoted context omitted.

fair point – this is something we consider doing before expanding to b2b market. but: my day job is in ecommerce (I work as a product manager at FastSpring) and I used to work on CleanMyMac at MacPaw – had to work with trust in both. it's somewhat unexpected but people who are buying software for themselves usually don't care about PCI compliance, audits, and other artifacts of "institutional validation". they care a…

When dealing with sites where high trust is required I think people would much rather see an independent audit or compliance with a (legit) security accreditation than a Norton badge, however, most of the time this is not offered, so we make do with the crappy badge, a recommendation, or gut instinct. Having said that, I deal with independent audits in my job, and they're not all that reassuring.

Pardon my ignorance or perhaps its just that I've become jaded, but outside of circumstances with dire/sever consequence such as laws, regulations, etc how does an independent audit (legit accreditation or not) verify what happens after the audit is done and the auditors long gone?

How does an independent audit detect out of band taps (swapping binaries, re purposing archives/backups, mirroring, etc) on infrastructure the auditor wasn't monitoring before the audit? logs? but more importantly amortized or not the customer eventually pays for all this activity that at the end of the day is more fluff than substance (in terms of what the customer can actually verify) In the end doesn't all this come down to just another form marketing?

Please note, that I recognize that there are many scenarios where an independent audit would add value. I just don't think it adds anything that social validation doesn't already add when considered from the perspective of a consumer to whom the infrastructure behind the service is unavoidably opaque.

Re: Uber CEO Plays with Fire

#469

Earlier quoted context omitted.

All the companies subsidize rides, including Lyft and Didi. No company would willingly do it if the others didn't do it as well, except maybe to increase market liquidity as the market maker. Why single out Uber when all the companies in this space are doing the exact same?

Because Uber is the market leader, with the most investment, and with the largest subsidies. Given your short posting history's unusual interest in Uber stories you probably know about that already.

Largest subsidies by volume or per ride?

From what I've seen based on leaked financials, Lyft is outspending Uber by more than 2x in terms of subsidy dollars per ride [0]. Subsidies do not scale, and Uber is subsidizing less per ride than its competitors so it's surprising to me that it receives the bulk of the criticism when it's actually far the most thrifty of the ridesharing companies. If anyone should be criticized for buying their growth, it should be Lyft, not Uber.

[0] https://news.ycombinator.com/item?id=13772168

Re: Uber CEO Plays with Fire

#470

Earlier quoted context omitted.

Wow I think this unroll.me thing is the real scandal here. I am an unroll.me user, but had no idea they sell user data to companies this way. Their whole value proposition is to help people control their own privacy and now I kind of feel betrayed..

I worked for a company that nearly acquired unroll.me. At the time, which was over three years ago, they had kept a copy of every single email of yours that you sent or received while a part of their service. Those emails were kept in a series of poorly secured S3 buckets. A large part of Slice buying unroll.me was for access to those email archives. Specifically, they wanted to look for keyword trends and for receip…

Am I correct in thinking this is class-action lawsuit-able?
Post reply on HN