Uber Spying on People?

Although marketed on its simplicity, convenience and economy, your Uber ride may still cost you more than you planned or wanted. Similarly, as an Uber driver, you may end up sharing more than your vehicle when you respond to their app. Uber’s appeal to both driver and rider derives from their remarkable technological advancements. Poised to deliver even more advanced technology through its new Uber A.I. Labs, those achievements may ultimately be undercut, and their appeal diminished, by an inability to prevent internal and external data breaches.

THE “GOD VIEW”

Uber was designed with a real-time aerial view geolocation dubbed the “God View.” Uber cars in a city, along with details of who was inside the vehicles, were automatically tracked by their internal system. Vehicles locations could be identified and followed by pulling up a map of the city which identified every Uber vehicle. Unfortunately, the Uber employees could also access “The God View” and few security constraints were placed on the system to protect the privacy of the vehicle occupants.

2014 BREACHES

In 2014, formal complaints arose from allegations by a BuzzFeed reporter that an Uber executive had used the “God View” to track her. Other allegations arose that Uber employees were using the “God-View” as entertainment, and even allowing non-employee party guests to view live data. As a result, the NY Attorney General (NYAG) initiated an investigation into their privacy practices.

In 2015, Uber belatedly revealed they had also been hacked in 2014. The data breach the prior year included both the names of the drivers and their driver’s license numbers. Resulting from the compromise of an encryption key, data for over 50,000 drivers may have been downloaded.

A settlement was announced in the NYAG investigation in January 2016. The investigation concluded that Uber had updated “God-View” to remove all personal identifiable data from the geo tool and even changed the name of the reworked tool to “Heaven View.” Uber also signed a document reassuring the and had tightened enforcement of their internal privacy policy. In addition, Uber agreed to pay $20,000 to the state for its failure to disclose the data breach to impacted drivers in a timely manner.

2016 BREACH ALLEGATIONS OF “HEAVEN VIEW”

In 2016, new allegations that Uber employees violated the privacy of clients surfaced during the lawsuit of a former Uber forensic investigator, Ward Spangenberg. In his suit involving allegations of wrongful termination and age discrimination, Spangenberg claimed he had been aware of employees tracking personal acquaintances, ex-girlfriends/boyfriends/spouses and celebrities. He claimed he was fired in retaliation for bringing those privacy violations to light. Perhaps the most significant aspect of his testimony is that these violations continued well after Uber had indicated to the NY Attorney General that they had enhanced and were effectively enforcing stringent privacy policy practices internally.

However, the greater concern is that while has arguably demonstrated neither the ability nor the inclination to protect personal data of their users, they are increasing the information they gather. In addition to data that has historically been gathered on drivers while the app was active, the app update now continues to gather information while you consider it turned off.

Uber also appears to be accumulating broader information on their drivers through their “Vehicle Solutions” and other partnership programs. Uber notes partnerships with health insurance companies, auto rental companies, auto dealerships and finance companies on their website. As a result, their driver database could now incorporate information ranging from your banking and investment accounts which was gathered as part of the financial advice they offer you to details about your auto title loan.

Technology advances like those pursued by Uber are undeniably encouraged and embraced by all components of society – corporations, government and everyday consumers. But responsibility and accountability are integral requirements of such advancements. Uber has yet to convince their critics that they understand that reality and are willing to fully implement the necessary safeguards.

Leave a comment

Your email address will not be published.


*