3 ms·
Shouldn't a company which could collect location data of sensitive populations, opposition politicians, etc, not have a standard operating procedure to make sur
by rrix2 4y ago
Shouldn't a company which could collect location data of sensitive populations, opposition politicians, etc, not have a standard operating procedure to make sure un-audited+un-reviewed access is not possible? Shouldn't companies with user-generated "content" have a way to remotely lock down and wipe laptops which are seized or stolen? even when law enforcement or state actors involved: what will we say when uber's florida or texas office is raided in an effort to get a list of people seeking transportation to certain types of healthcare? what about in states where "aiding and abetting" certain types of healthcare is itself treated as a criminal act? what about in places which imprison or persecute queer people?
I don't think the lying and the misdirection and the "prediction" based on reading news reports or political rumors are ethical or even particularly smart, but I think you'd be hard-pressed to find a company storing mountains of user data which does not have a lockout plan like this that they will be willing to use against law enforcement in certain scenarios or by default.
btw, this was originally reported in 2018: https://www.theverge.com/2018/1/11/16878284/uber-secret-tool-block-data-law-enforcement-ripley https://www.theverge.com/2018/1/11/16878284/uber-secret-tool...
- deleted 4y ago[deleted]
- eesmith 4y ago> to make sure un-audited+un-reviewed access is not possible? No. They must have a system in place to follow local, state and federal laws, to comply with industry regulations, and to allow discovery for lawsuits. Doing otherwise is illegal. > effort to get a list of people seeking transportation to certain types of healthcare? Don't collect that data in the first place. Have retention policies to delete data when it's no longer useful (so long as it's legally permissible), so you can demonstrate to the authorities or judge that it wasn't an attempt to evade or obstruct justice. > I think you'd be hard-pressed to find a company storing mountains of user data which does not have a lockout plan like this that they will be willing to use against law enforcement in certain scenarios or by default. This is tampering with evidence, which is a crime. Your view appears to be that nearly all such companies have policies to commit a crime. Moroever, quoting https://corporate.findlaw.com/litigation-disputes/delete-at-your-peril-preserving-electronic-evidence-during-the.html https://corporate.findlaw.com/litigation-disputes/delete-at-... ] However, a number of courts have issued rulings imposing a duty to preserve before litigation begins if a party knows of the existence of a potential claim and can identify relevant evidence. See, e.g., Silvestri v. General Motors Corp., 271 F.3d 583, 590 (4th Cir. 2001) (upholding sanctions for failure to preserve a car involved in an accident, which plaintiff reasonably should have known would be material evidence in anticipated litigation against auto manufacturer). Therefore, as a practical matter, it is our general advice that you should instruct your colleagues and subordinates to retain records of any business activities for which litigation is anticipated, especially when it becomes apparent (through a demand letter or other saber-rattling) that a business relationship is "going south" and may be headed to court.
- donkeyd 4y agoI understand where these questions are coming from, but many Western countries have decent legal systems where data unrelated to a case cannot be used by law enforcement and this will be tested by both prosecutors and judges. I'm currently working in LE and I would not be allowed to look at customer data if that was seized during a search related to an investigation of Uber. I would not be able to just grab the ride data of a subject of another investigation because that would be illegal. If I did do that, that evidence would be thrown out and I would be reprimanded. I understand there are countries where this isn't true though, or where people are worried about the state of legal proceedings in their countries. But that doesn't mean Uber or any other company can just destroy evidence on the premise of securing customer data. Also, I highly doubt that Uber hosts their customer data on workstations in their offices. At least I hope they don't.
- FrenchDevRemote 4y ago>. I would not be able to just grab the ride data of a subject of another investigation because that would be illegal. If I did do that, that evidence would be thrown out and I would be reprimanded. In the majority of countries on Earth, the law is merely a suggestion to a significant portion of the police force.
- donkeyd 4y agoI understand, but Uber used these practices everywhere. And, like I mentioned, they used it on their company machines, not the servers where their customer data would probably be stored. So the hypothesis of doing this to protect customers is doubtful at best.