6 ms·
Your haughty attitude toward privacy is really chilling. If Uber hasn't received a NSL [1] I would be astounded, and your employer doesn't have a great track re
by stirner 10y ago
Your haughty attitude toward privacy is really chilling. If Uber hasn't received a NSL [1] I would be astounded, and your employer doesn't have a great track record [2]. Please think hard about the world you are helping to create.
[1] https://en.m.wikipedia.org/wiki/National_security_letter https://en.m.wikipedia.org/wiki/National_security_letter
[2] http://www.buzzfeed.com/johanabhuiyan/uber-is-investigating-its-top-new-york-executive-for-privacy http://www.buzzfeed.com/johanabhuiyan/uber-is-investigating-...
- bastawhiz 10y agoYou missed my point. I said that if we accidentally started collecting all user locations, you wouldn't have to worry about us getting an NSL because our servers would have crashed and burned and no data would have managed to have been collected. Uber's infrastructure is completely incapable of handling that volume of data, because it was never designed to handle it. As far as software bugs go, accidentally collecting all user locations always would be a disastrous one for Uber, not for user privacy. Have we gotten an NSL? I don't know, but I'd guess we probably have. It would be foolish to think otherwise.
- kevin_thibedeau 10y ago> Uber's infrastructure is completely incapable of handling that volume of data, because it was never designed to handle it. That is completely irrelevant. The powers that be can siphon off the data as it comes in. The danger is in receiving excess data in the first place, making yourself a more enticing target for collection activities.
- bastawhiz 10y agoThat Uber could have a bug that sends all location data is irrelevant. Google, Apple, Lyft, Yelp, Foursquare, Microsoft, or any other company that has any app that accesses and transmits location data could have an identical bug that presents an identical problem, and Google and Apple already regularly collect and transmit that data all the time without it being a bug. And being a bug of biblical proportions, it'll get resolved very, very quickly because it would be causing a hugely expensive outage. Uber also only uses strong TLS for connections, so "the powers that be" will have a heck of a time taking a real heap of gigabits (terabits?) per second of encrypted data and doing anything particularly useful with it.
- brokenmachine 10y agoI'm convinced! Does uber offer a password/bank information storage service? With such great security and unhackable storage, those are the next logical upgrade and would make a really great one-stop service for your customers.
- HappyTypist 10y agoNo, Uber internally uses OneLogin with mandatory 2FA.
- rm999 10y ago> Uber's infrastructure is completely incapable of handling that volume of data, The data volume isn't very big. Let's assume Uber records locations for 20 million users and pings each user every 5 minutes. We're talking about 20 million users * 12 events per hour * 24 hours * 16 bytes (my generous assumption of how much it would cost to store a user id, timestamp, and precise long/lat data) = ~100 GB a day or 3 TB a month. And 20 million / (5 * 60) = 67k events per second. I could probably build out the infrastructure to process and store a year's worth of user location data for 20k a year on AWS.
- bastawhiz 10y agoBeing a bug, though, it would record with the fidelity of the Uber app. Which is a lot more than every five minutes.
- rm999 10y agoIt's not a bug I'm concerned about, it's this part of the privacy policy "if you permit the Uber app to access location services through the permission system used by your mobile operating system (“platform”), we may also collect the precise location of your device when the app is running in the foreground or background" What I'm getting at is that it's pretty straightforward and easy for Uber to maintain a database of every user's locations at all times, even if they aren't active users. This kind of data is valuable. Assuming Uber isn't already doing it, all it takes is one mid-level product manager to initiate a small project to kickstart it.
- swyman 10y agoYou're not doing yourself any favors here. People say they don't trust your company because of past behavior of the company itself and history of even ethical companies being bought or changing priorities, and you just keep pushing me further and further toward Lyft or my bike.
- xapata 10y agoOnly 12 events per hour? I'd guess you're off by an order of magnitude.
- dannyobrien 10y agoIf NSLs are included under its "national security" category, Uber said it has not received any such requests at the time of its last Transparency Report. https://transparencyreport.uber.com https://transparencyreport.uber.com