Security researcher GironSec has pulled Uber's Android app apart and discovered that it's sending a huge amount of personal data back to base – including your call logs, what apps you've got installed, whether your phone is vulnerable to certain malware, whether your phone is rooted, and your SMS and MMS logs, which it explicitly doesn't have permission to do. It's the latest in a series of big-time missteps for a company whose core business model is, frankly, illegal in most of its markets as well.
Taxi-busting ride share app Uber might have an operating model that suits customers better than traditional, regulated taxi services – but the company's aggressively disruptive (and frequently illegal) business practices don't seem to stop at harming the taxi industry.
Its vicious attacks on competitors have included ordering and cancelling more than five and a half thousand rides through its chief competitor Lyft. Its senior Vice President of Business, Emil Michael, casually mentioned at a dinner that maybe Uber could start digging up personal dirt on journalists critical of the company.
These kinds of stories, of course, should be taken with a grain of salt – they're certainly very beneficial to competing services like Lyft.
But there doesn't seem to be a lot of grey area in these latest revelations that Uber is collecting a stack of personal data from users who have its Android app installed, including SMS data that its permissions list doesn't allow.
Security researcher GironSec decompiled the code of the Uber Android app and found it to be collecting and sending the following information back to Uber:
While some people are suggesting it might be an anti-fraud measure to help Uber detect and combat fake accounts set up by its competitors, the fact remains – collecting data without appropriate permission constitutes malware and compromises users' personal data.
It's not yet clear whether the iPhone app does the same level of reporting on its users. As for whether Google will move to pull the Uber app from the Play store, that seems unlikely given that Google's US$258 million dollar stake in Uber represents the biggest deal Google Ventures has ever done.
This is the new world we're living in, folks, and if you think Uber's the only one building fat files out of your personal information, you're mad.
See the stories that matter in your inbox every morning