Live data from Hacker News

Uber CEO Plays with Fire

nytimes.com

481–490 of 529 posts

Re: Uber CEO Plays with Fire

#481
post #474

Earlier quoted context omitted.

I totally agree. But , and this is a very big but: companies would no longer be open to potential acquisition partners during the due diligence phase of an acquisition if professionals in this space would talk publicly (or even at all) about what they find. I'm seriously conflicted about this because I too have seen some extremely horrible stuff in the last couple of years, some of which I'm quite sure would rock the…

Couldn't you leak anonymously?

I don't believe in that. For one, there is no such thing as anonymity to begin with, for another, I think if you do a thing like that you should stand by it.

Re: Uber CEO Plays with Fire

#482
post #466
post #190

Earlier quoted context omitted.

Uber has millions of people who use and love the service. Yanking the app without notice doesn't just punish the company it punishes those users. Working with Uber to get the issue fixed without punishing innocent bystanders is good policy.

i.e. One, weaker, rule for popular apps, one stronger rule for the little people.

It's not about the app developers one way or the other. It's about the end users. What is best for them decides the course of action no matter how it effects app developers of any size.

That's the one rule. For everyone.

Re: Uber CEO Plays with Fire

#483
post #429

Earlier quoted context omitted.

I worked for a company that nearly acquired unroll.me. At the time, which was over three years ago, they had kept a copy of every single email of yours that you sent or received while a part of their service. Those emails were kept in a series of poorly secured S3 buckets. A large part of Slice buying unroll.me was for access to those email archives. Specifically, they wanted to look for keyword trends and for receip…

situations like this is what makes it really hard for others in this space to survive. I run https://clean.email (and we don't store/retain/sell any data, just charge people to use it) and the biggest issue we have is lack of trust because of news like this. although every day someone would still email with a question "why you are not free like unroll.me".. sigh.

Interesting. I can't click your Terms of Use link. Would you happen to have a direct link handy?

Re: Uber CEO Plays with Fire

#484

Earlier quoted context omitted.

I was a little creeped out when--long after I deauthorized the app and enabled 2FA on my Gmail account--I got an email from them saying "We've found 141 new subscriptions". I wonder if that was just marketing spam, or if they have a weird way of accessing my email still.

I believe Google lets you view all apps with access to your account. Check that, change your password, and you should be good.

Oh, that's what I meant by "deauthorized the app". I removed it on the Google side, and shortly after even got an email from Unroll.me saying that it no longer had access. So I was surprised to see an email a couple months later saying they'd found more stuff to unsubscribe from. It could have been a bug or just a message they sent to everyone who'd unplugged their email, but was quite jarring.

Re: Uber CEO Plays with Fire

#485

Earlier quoted context omitted.

Do you only use one device?

Using multiple devices does not preclude one from using a server and end-to-end encryption.

The reason I ask is about private key movement. I'm curious how you share that across devices. It's the biggest issue in e2e encryption imo.

Just curious if you do anything novel there.

Re: Uber CEO Plays with Fire

#486
post #459

Earlier quoted context omitted.

Here's the link to revoke perms: https://myaccount.google.com/permissions I just disconnected from one or two services which had access to my gmail (reasonably so).

Thanks, why the fuck does Swift keyboard need access to all my emails?

The innocuous, benefit-of-the-doubt reason would be to improve their prediction/autocorrect.

Re: Uber CEO Plays with Fire

#487

Buried lede here: "They spent much of their energy one-upping rivals like Lyft. Uber devoted teams to so-called competitive intelligence, purchasing data from an analytics service called Slice Intelligence. Using an email digest service it owns named Unroll.me, Slice collected its customers’ emailed Lyft receipts from their inboxes and sold the anonymized data to Uber. Uber used the data as a proxy for the health of…

I used to recommend unroll.me to people but eventually found that relentlessly unsubscribing from things worked better anyway. I assumed they were making money from ads, but should have known better.

I have a few simple rules I follow to hit inbox zero...works quite well:

1. Unsubscribe Relentlessly 2. Use Keyboard Shortcuts or Gestures 3. Snooze Important Emails 4. Use a To-Do App

(I wrote it up in more detail here: https://shift.infinite.red/how-i-achieve-inbox-zero-every-da...)

Re: Uber CEO Plays with Fire

#488

Buried lede here: "They spent much of their energy one-upping rivals like Lyft. Uber devoted teams to so-called competitive intelligence, purchasing data from an analytics service called Slice Intelligence. Using an email digest service it owns named Unroll.me, Slice collected its customers’ emailed Lyft receipts from their inboxes and sold the anonymized data to Uber. Uber used the data as a proxy for the health of…

Wow I think this unroll.me thing is the real scandal here. I am an unroll.me user, but had no idea they sell user data to companies this way. Their whole value proposition is to help people control their own privacy and now I kind of feel betrayed..

Seems to be a recurring theme for services that scrape your email inbox. For example, see https://context.io which is a popular service for building these kinds of apps. They clearly state that the free version is funded by collecting anonymized data from the end users' email inboxes.

Just another reminder that nothing is free =)

Re: Uber CEO Plays with Fire

#489
post #429

Earlier quoted context omitted.

I worked for a company that nearly acquired unroll.me. At the time, which was over three years ago, they had kept a copy of every single email of yours that you sent or received while a part of their service. Those emails were kept in a series of poorly secured S3 buckets. A large part of Slice buying unroll.me was for access to those email archives. Specifically, they wanted to look for keyword trends and for receip…

situations like this is what makes it really hard for others in this space to survive. I run https://clean.email (and we don't store/retain/sell any data, just charge people to use it) and the biggest issue we have is lack of trust because of news like this. although every day someone would still email with a question "why you are not free like unroll.me".. sigh.

I understand that you don't retain user emails, and that's good, but do I understand that your service has somewhere a database of OAuth bearer tokens that provide direct access to the email archives of everyone who has signed up for your service? How do you protect that? I would be terrified.

Re: Uber CEO Plays with Fire

#490

Earlier quoted context omitted.

Using multiple devices does not preclude one from using a server and end-to-end encryption.

The reason I ask is about private key movement. I'm curious how you share that across devices. It's the biggest issue in e2e encryption imo. Just curious if you do anything novel there.

I don't do anything novel. I have my private key on three devices.
Post reply on HN