Specal iPhone permission let Uber app see iPhone screen even when app not running

Security researcher Will Strafach found Uber’s app enjoying an unusual Apple iOS security permission not used by any other app. Called com.apple.private.allow-explicit-graphics-priority, this permission allowed Uber’s app to see what was on the user’s screen even if the Uber app was not active.

An Uber spokesperson explained the purpose of this security permission: “It was used for an old version of the Apple Watch app, specifically to run the heavy lifting of rendering maps on your phone & then send the rendering to the Watch app.” The spokesperson continued: “Apple gave us this permission years because Apple Watch couldn’t handle our maps rendering.”

Uber indicated that it used the entitlement only in version 8.2 of its app, and that a subsequent update from Apple fixed the memory issue for Apple Watch and made this workaround unnecessary.

London Employment Tribunal determined that Uber unlawfully denied basic workers’ rights

Having determined that Uber drivers are employees, the London Employment Tribunal further determined that Uber unlawfully denied drivers certain basic rights guaranteed to all employees.

Among other rights, GMB alleged that Uber drivers were entitled to holiday pay, a guaranteed minimum wage, and breaks.

GMB specifically challenged the amount that drivers are paid. After deducting costs and fees, GMB found that members could make as little as 5 GBP per hour, well below the national minimum wage of 7.20 GBP. They also challenged Uber’s practice of deducting sums from drivers’ pay including in response to customer complaints.

LET also found that, contrary to Uber’s insistence that Netherlands law governs the relationship between Uber and its London drivers, in fact British law governs because the relationship “relevant to the situation” was the UK.

Uber appealed the decision. A judgment of the appeal is expected in late 2017.

Fuel Card duplicate charges

Uber provided some drivers with “fuel cards” usable for gasoline, carwashes, and other services, at a discount, with charges deducted from future Uber earnings. Multiple drivers reported duplicate charges. Representative quotes:

“Double charged for gas with Uber card. Same transaction. Exact same time and date stamp. You took double from my earnings…The rep last night said they have had multiple calls for this same issue. That it would be cleared up by midnight. Today it’s still not fixed and the rep said he couldn’t do anything about it! Uber this is unacceptable” (September 6, Facebook, Florida driver).

“Gas card is very funny…Something is fishy about how this card works. Once I was triple charged and no one caught on until I bought it to Uber attention and the fixed it. I no longer want to use card” (September 2017, YouTube, Curtis J.).

“I was looking over my transaction history and there is two gas card purchases. Same amounts/ days. I was charged twice for 1” (June 28, Twitter).

“Hey my uber gas card was charge 3 times at the same time and day, but different days each” (June 28, Twitter, Oregon driver).

“It’s been 4 days since I wrote to customer care to review my fuel card charges, there were duplicate charges on it and I was overcharged, I have sent screenshots of duplicate charges but so far I got only one reply yesterday with copy pasted text that has nothing to do with what I asked for.” (April 4, Facebook, New York driver).

Drivers reported heightened difficulty resolving the problems because Uber told them to contact FleetCor, which operated the fuel card program. FleetCor in turn told them to contact Uber.

Drivers also reported that Uber and FleetCor suggested that the drivers conduct their own investigations into the disputed transactions such as interviewing merchants and requesting refunds from merchants. Most drivers found these approaches untenable, particularly because the fraudulent charges could occur at distant merchants far from where the drivers lived.

A further challenge for drivers is that many did not know how to contact FleetCor. The Uber-provided FleetCor card does not include a customer service phone number. Drivers would need to find the number in the original card materials that provided in an envelope along with the card — easily overlooked or discarded.

An October 5, 2017 report from The Capitol Forum (paid subscription required) analyzed these concerns and tabulated these and numerous additional driver complaints.

Uber investors challenged board decision

In October 2017, Uber’s board voted to end the benefit that let early employees and investors get 10 votes per share, a benefit which had given those groups disproportionate control. In response, early Uber investors Shervin Pishevar and Steve Russell said they would sue to block the change. Their statement:

Today’s action by the board was the culmination of a blatant bait and switch, essentially robbing loyal employees, including the more than 200 early founding Uber employees and advisors, of their hard earned shareholder rights.

Former CEO Travis Kalanick unilaterally appointed two board members

Former Uber CEO Travis Kalanick appointed two new members to the Uber board. Kalanick explained in a statement:

“I am appointing these seats now in light of a recent Board proposal to dramatically restructure the Board and significantly alter the company’s voting rights. … It is therefore essential that the full Board be in place for proper deliberation to occur.”

Kalanick was responding to a proposal from Benchmark Capital, a large shareholder in Uber, seeking to eliminate super-voting power of shares held by Kalanick, other early executives, and investors. With two more board members receptive to Kalanick’s perspective, Benchmark’s proposal is correspondingly less likely to proceed. (Forbes called the appointees “presumed allies” to Kalanick.)

An Uber spokesperson indicated that Kalanick’s appointment of two new board members “came as a complete surprise to Uber and its board.” The New York Times reported that new Uber CEO Dara Khosrowshahi called Kalanick’s move “disappointing” in an internal memo to employees. Bloomberg reported that the appointment was contrary to a prior agreement associated with Kalanick’s resignation.

The New York Times called Kalanick’s approach a “power move.” Former Uber adviser David Plouffe indicated that events at Uber were crazy and that the Trump white house “seems sane by comparison.”

Portland “Regulation Evasion Audit” of Uber Greyball

In response to Uber’s Greyball blocking of government investigations, the Portland Bureau of Transportation (PBOT) prepared a 56-page audit report. Their summary:

In using Greyball, Uber has sullied its own reputation and cast a cloud over the TNC industry generally. The use of Greyball has only strengthened PBOT’s resolve to operate a robust and effective system of protections for Portland’s TNC customers.

PBOT continued:

As the agency responsible for ensuring the safety of TNC customers and the integrity of the TNC market, PBOT views Uber’s failure to comply with deep concern. This failure calls into question Uber’s commitment to comply in general with the City of Portland’s regulatory framework. It also raises questions about Uber’s ability to be a trustworthy partner in PBOT’s efforts to ensure that Portland’s TNC customers receive safe and reliable service.

PBOT searched for evidence of Uber continuing to use Greyball, or of Lyft doing so. They found no such evidence, though they noted that “It is inherently difficult to prove a negative.”

London Police said Uber “aware of criminal activity and yet haven’t informed the police”

In an April 2017 letter, the London Metropolitan Police questioned why Uber had not notified the police about criminal offenses known to Uber. The Police reported Uber refusing to provide information within its custody unless the police submit a formal request, and also refusing to report crime to the police because such reports may breach rights of a passenger. The Police questioned Uber’s approach, saying that Uber is “allowing situations to develop” that affect public safety, and noting also that the extra steps Uber calls for can impede prompt prosecution and ultimately lead perpetrators to go free.

The letter’s conclusion:

The significant concern I am raising is that Uber have been made aware of criminal activity and yet haven’t informed the police. Uber are however proactive in reporting lower level document frauds to both the MPS and LTPH. My concern is twofold, firstly it seems they are deciding what to report (less serious matters / less damaging to reputation over serious offences) and secondly by not reporting to police promptly they are allowing situations to develop that clearly affect the safety and security of the public.