Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why would you believe the data was aggregated, and not available in individualized form in the latter case?


Because the blog post was publicly posted (and had been available for 2 years before Uber's recent PR trouble), and the data that was presented was on an aggregate level.

If you are asking if the blog poster had access to the individualized data, I imagine he did as he was a data scientist at Uber - but I don't see how that is something to be alarmed about.


They _published_ the data in an aggregated form, but they have _profiled_ the customers on individual basis.

Now contrast this e.g. to the principles of data protection that Germany has imposed...(http://en.wikipedia.org/wiki/Bundesdatenschutzgesetz)


I'm not sure I quite get what you mean. How do you produce an aggregate without profiling customers on an individual basis?

Secondly, I don't see how a company like Uber can use their data to power something like surge pricing while following the exact letter of the BDSG.


...so maybe they should keep their hands off the aggregates as well?

For the surge pricing, I'm a bit at a loss, because you don't need personally identifiable data for it, just a request counter per area ID, right? Maybe I don't understand it right though...

Also, the reasoning should be the other way around: if I cannot provide a service respecting the basic privacy of my users, I should not be providing a service.


> I'm not sure I quite get what you mean. How do you produce an aggregate without profiling customers on an individual basis?

You can easily calculate the average of a set without keeping every individual member of the set by updating the running average each time a new data point comes in. You still collect individual data, but destroy it as soon as possible.

> Secondly, I don't see how a company like Uber can use their data to power something like surge pricing while following the exact letter of the BDSG.

Then Uber should be banned and its employees and shareholders punished appropriately. I don’t see how “this business model can’t work with this law” could possibly be an excuse to ignore the law. Protection rackets don’t really work with the exact letter of the law, either.


Here's the link: https://web.archive.org/web/20140827195715/http://blog.uber....

The problem that most people have with the article is the creepy tone ("I know which of you are fooling around and where") rather than an actual leak of information on individual users.


The problem many people with Uber is that they leak information, rather than that they actually do creepy stuff...

Whether they brag about it or not, whether they make active use of it or not -- they did invest their time & effort into this type of profiling. Was this altruistic goofing around, with no bad intent? I'd prefer to believe that, but there are no checks in place to ensure this. And I believe most of their customers would be enraged to be subject to such a profiling, even just for the goofing...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: