7 ms·
What's unethical about this? They were doing market research. It's not much different from stalking your competitor on google and going after the users they a
by stass 9y ago
What's unethical about this? They were doing market research. It's not much different from stalking your competitor on google and going after the users they advertise to.
- jsmthrowaway 9y agoIt's completely different, so far different as to be antonyms, opposites, completely diametrically opposed ends, because you just described a passive, orthogonal, ethical activity while Uber actively fooled with Lyft's systems to get the intel they wanted (emphasis mine): > Hell originated after Uber created fake rider accounts on Lyft and used software to trick Lyft’s system into thinking those riders were in certain locations. This allowed Uber to see the eight closest available Lyft drivers to each fake rider. You literally just typed the equivalent of "what's wrong with using an ad unit to deliver a zero day exploit? It's not much different from advertising."
- JustSomeNobody 9y agoAll of which /u/stass would have know had there been an ethics class for them to take. ;)
- stass 9y agoThere isn't the one and only standard for ethics. Perhaps a class would teach a certain version of ethics, but not a universally applicable one. As a somewhat relevant example, a lot of ethical norms in USSR (prosecution of successful individuals, outlawing free speech, destroying dissent, banning "unethical" literature and works of art) would be considered completely unethical in the Western society and vise versa, although the admiration of former became fashionable in tech circles lately.
- _jezell_ 9y agoCreating fake accounts is pretty common for spiders... standard search engine tactics.
- viraptor 9y agoIt's not an exploit. There was no privilege escalation, denial of service, theft of private data, or anything like that. You can take the technology involved and replace it with a human process: multiple people around the city open the app and report back to the HQ the locations they see. Now, would you say this process is illegal? Simplifying it even more: If you had people on the street, looking for cars with a Lyft sticker and reporting back every one you see - would you say that is illegal?
- bencollier49 9y agoNot sure about this in the US, but I'm pretty sure that in the UK, gathering a database of intelligence on competitors' staff earnings would be a violation of the Data Protection Act.
- viraptor 9y agoIt would be interesting if this came to a trial. DPA protects only information that identifies people. If Uber collected information on cars instead which is anonymous and then correlated it with data it already has access to, so it only deanonymises its drivers, that's... I don't know. IANAL, but I read the DPA a few times and I think it's an edge case. If someone has better idea, I'd love to hear it.
- deleted 9y ago[deleted]
- makomk 9y agoThe Data Prrotection Act specifically covers this: "* “personal data” means data which relate to a living individual who can be identified (a) from those data, or (b) from those data and other information which is in the possession of, or is likely to come into the possession of, the data controller" Sorry, but they already thought of that one.
- geocar 9y ago> Simplifying it even more: If you had people on the street, looking for cars with a Lyft sticker and reporting back every one you see - would you say that is illegal? Yes, because trying to "hack" the legal system by finding things that you can argue are "technically legal" is not something that impresses me. I get that beating someone up and throwing a paying customer off a plane, or using a firehose on civil rights marchers, is "legal" if some judge can be persuaded ($$$) to agree, but I'm not going to play that game: I don't want to live someplace where we do what is legal and don't do what is illegal; I want my neighbors to know right from wrong. A Reasonable Person would think that Uber was doing this to wrong Lyft and indeed it turns out, was doing this to wrong Lyft.
- DrJokepu 9y agoIntentionally accessing a protected computer system without authorization and obtaining information from it is a federal criminal offense (18 USC 1030 (a)(2)(C)).
- stass 9y agoThey didn't access any Lyft systems. They ran Lyft software on their own devices and collected and analyzed the data Lyft provides. One can argue that they broke EULA, but it's not necessarily unethical, and I'm ready to bet the majority of this site users broke at least one software EULA in their lifetime.
- tuyguntn 9y agoAssuming they did like you said the main point is > collected and analyzed the data Lyft provides they did it without permission
- deleted 9y ago[deleted]
- pluma 9y agoSure, the fake accounts just violated the ToS. But they then used an enumeration attack to find existing accounts and retrieve information not intended to be available to them. That it's not technologically sophisticated doesn't mean it's not a criminal offense. If someone doesn't lock their front door and you enter their building, you're still trespassing. Especially if it's your competitor's front door and you're repeatedly entering the building to scout the place out for financial gain.
- nikcub 9y agoI don't use any service without having a basic understanding oh how secure and private their systems are - the CFAA makes that all illegal "You wouldn't open an unlocked door" is the "you wouldn't download a car" of infosec. The later redefined theft as not requiring anybody to be deprived of a good while the former has the same flaw, you arent deprived of any good, you aren't harmed, you haven't been coerced or forced - i.e. It meets none of the common law definitions of trespass[0] [0] but it does explain why ddos attacks, spam and stealing user data are trespass because they do meet those definitions
- bitexploder 9y agoLet's explore this from the information security perspective, since that is my thing. If I had performed this research against Lyft and knew about these "information disclosure" issues I would have felt they were significant enough for disclosure to see them remediated. Why? Sweeping privacy concerns. In a world where most people have an Uber or a Lyft app installed security issues like this become spy machines. So it isn't just drivers that lose their privacy, in the long run it touches on everyone's privacy, because location data is notoriously hard to anonymize and machine learning is only getting better. So there is the first ethical argument against this behavior that pops to mind.