The Courts

Here's the Letter Alleging Uber Spied on Individuals For Competitive Intelligence (recode.net) 37

UPDATE (11/28/2021): While former Uber security officer Richard Jacobs alleged illegal activities, "In June, nearly four years after his claims drew wide attention, he retracted them," the New York Times reports: Testifying in court, Mr. Jacobs seemed to distance himself from some of the claims in the letter. He hadn't had much time to review it before his lawyer sent it, he said, and he wasn't sure if Mr. Gicinto and his other former co-workers had broken the law. "I did not believe it was patently illegal. I had questions about the ethics of it," Mr. Jacobs testified. "It felt overly aggressive and invasive and inappropriate."
Read Slashdot's discussion and coverage of the revelation here.

Below is Slashdot's original 2017 story about Jacobs' now-retracted letter:

The judge in the $1.9 billion civil suit between Google-parent company Alphabet's self-driving car unit Waymo and Uber released the letter of a disgruntled former employee -- former Uber security officer Richard Jacobs -- on Friday, laying bare a number of explosive allegations against the ride-hailing company that include corporate espionage, unlawful surveillance, illegal wiretapping, bribery of foreign officials, and illicit hacking. From a report: The letter read: "This program, formerly known as the Strategic Services Group, under Nick Gicinto, collected intelligence and conducted unauthorized surveillance, including unauthorized recording of private conversations against executives from competitor firms, such as DiDi Chuxing and against its own employees and contractors at the Autonomous Technologies Group in Pittsburgh." Jacobs testified in court and walked back some of the allegations made in the letter, which was written by his attorney, Clayton Halunen. Days later, Uber's new chief legal officer Tony West issued a directive to employees to stop surveilling individuals, which Recode first reported. In a separate note to staff Khosrowshahi (current CEO of Uber) said the letter detailed enough to "merit serious concern." While Jacobs, Padilla (Uber's general counsel) and other employees addressed some of the claims made within the letter -- confirming the use of Wickr for business-related communications -- the letter itself had not been made public before Friday evening. The document prepared by Jacobs' attorney also claimed Uber was using some of these surveillance tactics on Alphabet's self-driving arm, Waymo. However, during his testimony, Jacobs walked that allegation back.
Crime

DOJ Confirms Uber Is Being Investigated For Criminal Behavior (arstechnica.com) 34

A newly released letter from the Department of Justice has formally acknowledged that federal prosecutors have an open criminal investigation into Uber. Ars Technica reports: Late last month, as part of the proceedings in the high-profile and ongoing Waymo v. Uber trade secrets lawsuit, U.S. District Judge William Alsup said that on November 22 he had received a letter from San Francisco-based federal prosecutors. It is very unusual for a judge in a civil case to be apprised of a pending criminal investigation involving one of the litigants. In a separate November 28 letter sent to Judge Alsup, Acting U.S. Attorney Alex Tse asked that the first letter not be made public. The judge unsealed both letters on Wednesday. The first letter was signed by two prosecutors, Matthew Parrella and Amie Rooney. Those attorneys are assigned to the Computer Hacking and Intellectual Property (CHIP) Unit at the United States Attorney's Office in San Jose. [T]he letter could mean Uber and/or its current or former employees may be under investigation for possible crimes under the Computer Fraud and Abuse Act, a longstanding anti-hacking law.
Businesses

Uber's Massive Scraping Program Collected Data About Competitors Around The World (gizmodo.com) 29

Kate Conger, reporting for Gizmodo: For years, Uber systemically scraped data from competing ride-hailing companies all over the world, harvesting information about their technology, drivers, and executives. Uber gathered information from these firms using automated collection systems that ran constantly, amassing millions of records, and sometimes conducted physical surveillance to complement its data collection. Uber's scraping efforts were spearheaded by the company's Marketplace Analytics team, while the Strategic Services Group gathered information for security purposes, Gizmodo learned from three people familiar with the operations of these teams, from court testimony, and from internal Uber documents. Until Uber's data scraping was discontinued this September in the face of mounting litigation and multiple federal investigations, Marketplace Analytics gathered information on Uber's overseas competitors in an attempt to advance Uber's position in those markets. SSG's mission was to protect employees, executives, and drivers from violence, which sometimes involved tracking protesters and other groups that were considered threatening to Uber. An Uber spokesperson declined to comment for this story.
Businesses

Former Uber Employees Have Gone Into Debt To Hang Onto Shares They Can't Sell (qz.com) 72

An anonymous reader quotes a report from Quartz: Uber employees are lining up to sell their stock to Japanese technology giant SoftBank, which will buy up to 17% of outstanding shares for $33 each. The price represents a 30% discount to Uber's last valuation, of nearly $70 billion, but for current and former employees, the SoftBank tender offer is a rare chance to convert paper wealth into actual cash. To qualify for the tender offer, participants must have at least 10,000 Uber shares and be "accredited investors," an SEC designation (pdf) for wealthy individuals. Current Uber employees can't sell more than half of their stake; there are no restrictions on former employees. The deal is on the table until Dec. 28, and could fall through if there aren't enough shares on offer for SoftBank and a small consortium of other investors to purchase at least a 14% stake in the company.

Working at a successful startup is often viewed as a quick path to prosperity, but the reality is more complicated. Startups tend to offer equity packages, typically in the form of stock options, to compensate for below-market salaries. But as companies like Uber have stayed private longer, most employees haven't been able to get rich from those shares. Quite the opposite, some former Uber employees have gone into debt to hang onto shares they still can't sell.

Social Networks

LinkedIn Bro Poetry Pretty Much Sums Up 2017 (thedailybeast.com) 51

An anonymous reader shares an article: It starts out like this: I was homeless. I was fired yesterday. I was walking home. I took an Uber. Someone stopped me on the street. My boss told me not to take a chance on anyone over 50, but I hired him anyway. It was Elon Musk. LinkedIn has become overrun with these types of inspirational tales posted as long status updates. They're characterized by their short sentences and read like E.E. Cummings poems recited from memory by Tony Robbins. They're usually between 15 to 25 lines long, always double spaced. They start with a hook in the first couple sentences that entices the reader to click the "see more" link that's displayed on LinkedIn posts that are longer than three lines. Some refer to this type of post as "the LinkedIn haiku" others call it "broetry" and it has completely cannibalized the LinkedIn newsfeed.
Security

Uber Paid 20-year-old Florida Man To Keep Data Breach Secret (reuters.com) 27

A 20-year-old Florida man was responsible for the large data breach at Uber last year and he was paid by the company to destroy the data through a so-called "bug bounty" program, three people familiar with the events have told Reuters. From the report: Uber announced on Nov. 21 that the personal data of 57 million users, including 600,000 drivers in the United States, were stolen in a breach that occurred in October 2016, and that it paid the hacker $100,000 to destroy the information. But the company did not reveal any information about the hacker or how it paid him the money. Uber made the payment last year through a program designed to reward security researchers who report flaws in a company's software, these people said. Uber's bug bounty service -- as such a program is known in the industry -- is hosted by a company called HackerOne, which offers its platform to a number of tech companies.
Businesses

The Underground Uber Networks Driven by Russian Hackers (thedailybeast.com) 49

Joseph Cox, reporting for DailyBeat: Uber's ride-sharing service has given birth to some of the most creative criminal scams to date, including using a GPS-spoofing app to rip off riders in Nigeria, and even ginning up fake drivers by using stolen identities. Add to those this nefariously genius operation: Cybercriminals, many working in Russia, have created their own illegitimate taxi services for other crooks by piggybacking off Uber's ride-sharing platform, sometimes working in collaboration with corrupt drivers. Based on several Russian-language posts across a number of criminal-world sites, this is how the scam works: The scammer needs an emulator, a piece of software which allows them to run a virtual Android phone on their laptop with the Uber app, as well as a virtual private network (VPN), which routes their computer's traffic through a server in the same city as the rider. The scammer acts, in essence, as a middleman between an Uber driver and the passenger -- ordering trips through the Uber app, but relaying messages outside of it. Typically, this fraudulent dispatcher uses the messaging app Telegram to chat with the passenger, who provides pickup and destination addresses. The scammer orders the trip, and then provides the car brand, driver name, and license plate details back to the passenger through Telegram.
Government

Democrat Senators Introduce National Data Breach Notification Law (cyberscoop.com) 162

New submitter unarmed8 shares a report from CyberScoop: Three Democratic senators introduced legislation on Thursday requiring companies to notify customers of data breaches within thirty days of their discovery and imposing a five year prison sentence on organizations caught concealing data breaches. The new bill, called the Data Security and Breach Notification Act, was introduced in the wake of reports that Uber paid $100,000 to cover up a 2016 data breach that affected 57 million users. The scope of what kind of data breach falls under this is limited. For instance, if only a last name, address or phone number is breached, the law would not apply. If an organization "reasonably concludes that there is no reasonable risk of identity theft, fraud, or other unlawful conduct," the incident is considered exempt from the legislation.

"We need a strong federal law in place to hold companies truly accountable for failing to safeguard data or inform consumers when that information has been stolen by hackers," Sen. Bill Nelson, D-Fla., said in a statement. "Congress can either take action now to pass this long overdue bill or continue to kowtow to special interests who stand in the way of this commonsense proposal. When it comes to doing what's best for consumers, the choice is clear."

Software

Three Quarters of Android Apps Track Users With Third Party Tools, Says Study (theguardian.com) 46

A study by French research organization Exodus Privacy and Yale University's Privacy Lab analyzed the mobile apps for the signatures of 25 known trackers and found that more than three in four Android apps contain at least one third-party "tracker." The Guardian reports: Among the apps found to be using some sort of tracking plugin were some of the most popular apps on the Google Play Store, including Tinder, Spotify, Uber and OKCupid. All four apps use a service owned by Google, called Crashlytics, that primarily tracks app crash reports, but can also provide the ability to "get insight into your users, what they're doing, and inject live social content to delight them." Other less widely-used trackers can go much further. One cited by Yale is FidZup, a French tracking provider with technology that can "detect the presence of mobile phones and therefore their owners" using ultrasonic tones. FidZup says it no-longer uses that technology, however, since tracking users through simple wifi networks works just as well.
Businesses

Uber Trained Employees on How To 'Impede, Obstruct or Influence' Ongoing Legal Investigations, Ex-employee Says (cnbc.com) 62

From a report on CNBC: Uber faced fresh allegations on Tuesday that it deliberately took steps to keep " unlawful schemes from seeing the light of day." Hours of testimony on Tuesday centered around a letter from a former Uber security analyst's attorney to an Uber lawyer. The former analyst, Richard Jacobs, said in the letter there was a directive for Uber employees to use disappearing chat apps like Wickr, and that Uber sent employees to Pittsburgh (where it's developing its autonomous vehicles) to "educate" them on how to prevent "Uber's unlawful schemes from seeing the light of day." He reportedly made other bombshell allegations in the letter, including that employees at Uber were trained to "impede" ongoing investigations, multiple media outlets reported.
Privacy

Researchers Identify 44 Trackers in More Than 300 Android Apps (bleepingcomputer.com) 87

Catalin Cimpanu, reporting for BleepingComputer: A collaborative effort between the Yale Privacy Lab and Exodus Privacy has shed light on dozens of invasive trackers that are embedded within Android apps and record user activity, sometimes without user consent. The results of this study come to show that the practice of collecting user data via third-party tracking code has become rampant among Android app developers and is now on par with what's happening on most of today's popular websites. The two investigative teams found tracking scripts not only in lesser known Android applications, where one might expect app developers to use such practices to monetize their small userbases, but also inside highly popular apps -- such as Uber, Twitter, Tinder, Soundcloud, or Spotify. The Yale and Exodus investigation resulted in the creation of a dedicated website that now lists all apps using tracking code and a list of trackers, used by these apps. In total, researchers said they identified 44 trackers embedded in over 300 Android apps.
Businesses

New Uber CEO Knew of Hack for Months (wsj.com) 27

Greg Bensinger and Robert McMillan, reporting for the WSJ: While the massive data breach at Uber didn't happen under the watch of its new chief executive, more than two months elapsed before he notified affected customers and drivers of the incident (Editor's note: the link may be paywalled), people familiar with the matter said. CEO Dara Khosrowshahi learned of the breach, which Uber said happened in October 2016 and affected some 57 million accounts, about two weeks after he officially took the helm on Sept. 5, one of the people said. Mr. Khosrowshahi said he immediately ordered an investigation, which he wanted to complete before making the matter public. About three weeks ago, though, Uber disclosed the investigation and the broad outlines of the breach to SoftBank, which is considering a multibillion-dollar investment in the ride-hailing company, according to other people familiar with the matter. Uber officials, including its chief security officer, knew at the time of the breach that personal information had been accessed. Uber only informed customers and drivers on Tuesday.
Security

Uber Hackers May Have Been Russian (thetimes.co.uk) 59

Mark Bridge, reporting for The Times: Thousands of Uber customers are believed to have had their accounts hacked by Russians after users of the app (Editor's note: the link is paywalled; alternative source) reported being billed in roubles for taxi journeys they had not taken in Moscow and St Petersburg. More than 800 people in Britain and the United States have complained on Twitter that their accounts were taken over in the past year, The Times found, with the number of reports spiking in April and May. Experts said this number of Twitter reports suggested that the true figure would be much higher.
The Internet

'We Are Disappointed': Tech Companies Speak Up Against the FCC's Plan To Kill Net Neutrality (businessinsider.com) 183

An anonymous reader shares a report from Business Insider: The FCC is planning to kill net neutrality -- and some tech companies are starting to speak out. Pro-net neutrality activists, who argue the principle creates a level playing-field online, are up in arms about the plan. And some tech companies are now speaking out in support of net neutrality as well, from Facebook to Netflix. Business Insider reached out to some of the biggest tech firms in America today to ask for their reaction to the FCC's plan. Their initial responses are below, and we will continue to update this post as more come in.
Privacy

Uber Is Under Investigation By Multiple States Over a 2016 Data Breach (recode.net) 25

Yesterday, it was reported that Uber concealed a massive cyberattack that exposed 57 million people's data. Recode reports that at least five states -- Illinois, Massachusetts, Missouri, New York and Connecticut -- would investigate the matter. From the report: Meanwhile, Uber must contend with the possible threat of a new probe at the Federal Trade Commission. The agency, which acts as the U.S. government's top privacy and security watchdog, penalized Uber for its privacy and security practices just this August. But it may not have known that Uber had suffered a major security breach in 2016, even as they investigated the company at the same time for other, unrelated security missteps. For now, the agency merely said it's "closely evaluating the serious issues raised." And some affected customers are similarly taking action. On Wednesday -- hours after the breach became public -- an Uber user filed a lawsuit accusing the company of negligence and deceptive business practices. The plaintiff, Alejandro Flores, is seeking to represent a class of affected riders and drivers alike.

For one thing, 48 states maintain some version of a law that requires companies that suffer a data breach to communicate what happened to consumers. In most cases, companies must disclose a security incident if hackers steal very sensitive customer data -- such as driver's license numbers, which happened with Uber in late 2016. To that end, the attorneys general in Illinois, Connecticut and New York have said they are probing the breach at Uber -- perhaps with an eye on whether the company skirted state laws. The top prosecutors in other major states, like Pennsylvania and Florida, did not immediately respond to emails on Wednesday seeking comment. California's AG declined to comment.

Transportation

Uber Fined $8.9 Million In Colorado For Allowing Drivers With Felonies, Motor Violations To Work (jalopnik.com) 108

Uber has been fined by a Colorado regulator on Monday for nearly $9 million, after an investigation revealed that 57 people with criminal and motor vehicle offenses were allowed to drive with the ride-hailing company. Jalopnik reports: States across the U.S. have been considering laws to require additional background checks for individuals who drive for Uber and competitors like Lyft. In Colorado, the state's Public Utilities Commission investigated the company's drivers after an incident this past March, reported The Denver Post, when a driver dragged a passenger out of a car and kicked them in the face. The commission said it found 57 drivers had issues that should've disqualified them from driving for Uber, including felony convictions for driving under the influence and reckless driving, while others had revoked, suspended or canceled licenses. A similar investigation was conducted on Lyft, the Post reported, but no violations were revealed. An Uber spokesperson said the situation stems from a "process error" that was "inconsistent with Colorado's ridesharing regulations." The spokesperson said Uber "proactively notified" the commission. "This error affected a small number of drivers and we immediately took corrective action," the company said in a statement to the Post. "Per Uber safety policies and Colorado state regulations, drivers with access to the Uber app must undergo a nationally accredited third-party background screening. We will continue to work closely with the CPUC to enable access to safe, reliable transportation options for all Coloradans."
Privacy

Uber Concealed Cyberattack That Exposed 57 Million People's Data (bloomberg.com) 32

According to Bloomberg, hackers stole the personal data of 57 million customers and drivers from Uber. The massive breach was reportedly concealed by the company for more than a year. From the report: Compromised data from the October 2016 attack included names, email addresses and phone numbers of 50 million Uber riders around the world, the company told Bloomberg on Tuesday. The personal information of about 7 million drivers were accessed as well, including some 600,000 U.S. driver's license numbers. No Social Security numbers, credit card details, trip location info or other data were taken, Uber said. At the time of the incident, Uber was negotiating with U.S. regulators investigating separate claims of privacy violations. Uber now says it had a legal obligation to report the hack to regulators and to drivers whose license numbers were taken. Instead, the company paid hackers $100,000 to delete the data and keep the breach quiet. Uber said it believes the information was never used but declined to disclose the identities of the attackers.

Here's how the hack went down: Two attackers accessed a private GitHub coding site used by Uber software engineers and then used login credentials they obtained there to access data stored on an Amazon Web Services account that handled computing tasks for the company. From there, the hackers discovered an archive of rider and driver information. Later, they emailed Uber asking for money, according to the company.

Transportation

Uber Expands Driverless-Car Push With Deal For 24,000 Volvos (bloomberg.com) 176

Uber agreed to buy 24,000 sport utility vehicles from Volvo to form a fleet of driverless autos. According to Bloomberg, "The XC90s, priced from $46,900 at U.S. dealers, will be delivered from 2019 to 2021 in the first commercial purchase by a ride-hailing provider." Uber will add its own sensors and software to permit pilot-less driving. From the report: Uber's order steps up efforts to replace human drivers, the biggest cost in its on-demand taxi service. The autonomous fleet is small compared with the more than 2 million people who drive for Uber but reflects dedication to the company's strategy of developing self-driving cars. "This new agreement puts us on a path toward mass-produced, self-driving vehicles at scale," Jeff Miller, Uber's head of auto alliances, told Bloomberg News. "The more people working on the problem, we'll get there faster and with better, safer, more reliable systems."
AI

An Inside Look At the First Church of Artificial Intelligence (wired.com) 120

mirandakatz writes: This summer, Backchannel reported that Anthony Levandowski, the controversial engineer at the heart of the Uber/Waymo lawsuit, had filed paperwork for a new religion called the Way of the Future. Today, investigative reporter Mark Harris has all the details on what that AI-based religion actually likes -- and Levandowski granted him his first interview about the new religion and his only public interview since Waymo filed its suit in February. As Levandowski tells him, we can see a hint of how a superhuman intelligence might treat humanity in our current relationships with animals -- and that's why it's so important that we treat AI as a god, not a demon to be warded off. "Do you want to be a pet or livestock?" he asks. "We give pets medical attention, food, grooming, and entertainment. But an animal that's biting you, attacking you, barking and being annoying? I don't want to go there."
The Almighty Buck

Uber Drivers In Lagos Are Using a Fake GPS App To Inflate Rider Fares (qz.com) 86

According to Quartz, some Uber drivers in Lagos have been using a fake GPS itinerary app called Lockito to illicitly bump up fares for local drivers. The app was initially created for developers to "test geofencing-based apps," but has been used by Uber drivers to inflate the cost of their trips. From the report: In some cases, inflated trips can cost riders more than double the rate they should be paying. "It's more like a parasite," says Mohammed, a driver for both Uber and Taxify in Lagos. "It sets the false GPS movement while allowing the phone also to keep track of its actual movement. The Uber app can't tell the difference between both so it just calculates both." When a driver uses Lockito for an Uber trip he or she can have the fake GPS running (and calculating a fake fare) from the pickup point to the drop off location, before the passenger has even got into the car. When the real trip starts, the real GPS starts running and calculating the actual fare. But at the end of the journey the fares from both trips (real and fake) are tallied up as one fare which the unsuspecting rider pays. Some drivers use Lockito to inflate fares by adding 1000 naira to 2000 naira extra (roughly $3 to $6) but some drivers are believed to inflate fares to exorbitant levels.

Slashdot Top Deals