5 ms·
"This worked because Uber Eats provides couriers with prepaid cards they can use to purchase up to $700 to complete customers' orders."
by tpmx 3y ago
"This worked because Uber Eats provides couriers with prepaid cards they can use to purchase up to $700 to complete customers' orders."
- russellbeattie 3y ago"Uber continues to invest in robust anti-fraud systems and technology, which allowed our Global Investigations Team to proactively alert law enforcement about this case" $1,000,000 / 700 = ~1500 trips starting in January last year. 20 months = ~75 trips a month or about twice a day. I'm not sure Uber understands what the word, "proactive" or "robust" means.
- lozenge 3y agoWell, it does sound like an area they need to invest in.
- personjerry 3y agoYou have a certain "budget" for losses like this. Beneath a certain amount, you just take the loss, as it's more cost effective than spending man-hours on it. Their fraud systems and dedicated fraud teams are better off alerting on the "whales", so to speak. And in these cases, if you're gonna lay accusations and ban people, you'd rather be more certain (i.e. minimize false positives). All that is to say, it's understandable if they only pounce once it gets to a certain level of badness.
- ethbr1 3y agoNot having automatic fraud detection that can alert on... (a) new accounts in a (b) geographically-specific area that are (c) failing to balance at a greater than average rate... sounds pretty basic. You'd assume it would be one of the most common use patterns for structured fraud.
- personjerry 3y agoI'm positive they have these alerts already and chose not to action on them.
- deleted 3y ago[deleted]
- inetknght 3y ago> automatic fraud detection that can alert on... that are (c) failing to balance at a greater than average rate... sounds pretty basic. What makes you think that it's a greater than average rate?
- ethbr1 3y agoIf they're regularly losing $52,600 every month to fraud from 2 people, then that might explain the $31.5b operating losses they've had since 2014.
- almost_usual 3y agoSo what you’re suggesting is Uber has an actionable fraud threshold and if an intelligent actor wanted to float beneath that with fake accounts and identities they could extract even more?
- paulpauper 3y agoUber is so big that they cannot attend to every possible discrepancy .
- remram 3y agoYou mean they are too small compared to their customer base to attend to every discrepancy?
- personjerry 3y agoYes. Same for all the big tech companies. I guarantee you people are already doing this in every way you can imagine and many you can't. Source: Worked on bad actor detection at FB.
- boeingUH60 3y agoReminds me of the guy who scammed Google and Facebook of $123 million via fake invoices. https://www.cnbc.com/amp/2019/03/28/how-to-avoid-invoice-theft-scam-that-cost-google-facebook-123m.html https://www.cnbc.com/amp/2019/03/28/how-to-avoid-invoice-the...
- ryandrake 3y agoThat article doesn’t make any sense. At big companies like this you can’t just send money to someone who even convincingly looks like a vendor or partner. You need to have a PO created with the vendor as the recipient, and there are entire purchasing departments who vet recipients and make sure things like the legal name of the entity matches the wire instructions and so on. I’d imagine that medium sized companies without much process might be vulnerable to this, but FAANGs?? No way. If KNOWN_PARTNER simply emails an invoice and wire instructions to an employee of one of these larger companies, there is no way in hell that’s getting paid without multiple people in the paying company simultaneously screwing up.
- tpmx 3y ago(russellbeattie... I recognize that name... small world. Sorry for digressing. Russell: I've got to thank you for https://www.russellbeattie.com/blog/1008770 https://www.russellbeattie.com/blog/1008770. We all felt so proud after reading that review! Finally someone who got it. I was the person who led the product design/engineering effort during its first decade.)
- codetrotter 3y agoThe Opera Mini browser was amazing. Did any of the people that worked on it end up working on anything open source making use of the same ideas? I’m dreaming of having an open source backend that I could run myself on my server, and that would similarly download and compress pages and then send a representation of the page that can be displayed on my iPhone without the app running any JS or anything. Greater security, and also it would make me able to browse even in bad coverage areas where currently all that happens is I wait an eternity for things to try to load and they just time out. Basically, I wish there was an open source backend and app that behaved like Opera Mini used to.
- tpmx 3y ago(Not that I'm aware of.) Web pages don't really work without in-page/dynamic javascript any longer. On the other hand it's now cheaper than ever to just have a full-blown webkit instance in the cloud and just sync/stream the dom tree paints to the client. A bunch of products do that, I think. Back then we had a moat because a) Opera's Presto used so much less memory than Webkit - after having gone through so many painful memory optimization efforts, particularly with Japanese mobile browser deliveries, but also with Symbian. b) We figured out a way of making 90% of the web javascript work be keeping "tabs" around on the server for a few minutes and then just replaying carefully selected input events and capturing the output, with some kinda clever heuristics. That combined with the low memory usage did it. Webkit used like 10x more memory per tab/window back then, iirc. And RAM was expensive.
- OJFord 3y agoTo get even more meta, isn't it quite incredible that 17y later not only does the blog still exist, but we have the author and a key subject (or person behind subject) in the same comment section? Not even like it's particularly niche, 80s arcade games ported to 90s machines forum dot net or something.
- someguydave 3y agoseems like this is the very definition of “asleep at the switch” - does no manager own P/L for that unit?
- paulpauper 3y agoUber has so much $ from VC that this is peanuts, so it's not a priority. Eventually they noticed the theft and contacted authorities and fixed it. Uber has defied all predictions over the past 13 or so years of running out of money: there is always more $, and stock price keeps going up. It sorta defies reality--like amazon in 2015 in this regard or Tesla in 2013.
- paulpauper 3y agoyeah, uber is really good at knowing when drivers are not taking less profitable riders, which is generally a no-no, but stuff like this gets through
- ClumsyPilot 3y agoMaybe when you fail at due dilligence so blatantly, you should no longer be able to prosecute or press charges. They deserve to lose their shirts at this point. I can't shake feeling of disparity - as an ordinary Joe, you are presented with dozens of contracts for loans, mortgages, life insurance. The fine print is incomprehensible to an average person, and yet you could lose your shirt if you get it wrong and law is not on your side. I know these are different situations, but I am getting these vubes.
- loeg 3y agoYeah, but were they not suspicious after the previous 1427 prepaid cards?