back to article Hackers peer into Uber passenger privates, find and plot trips on maps

Three hackers have found eight holes in Uber that can reveal user e-mail addresses, and found more than 1000 of valid coupon codes including one giving drivers $100 extra in fare rides. The flaws have been reported to Uber which is working through to develop fixes. The team of Vitor Oliveira (@r0t1v), Fábio Pires (@ …

  1. John Smith 19 Gold badge

    Dumb enough to put them in, smart enough to offer a reward to find them.

    Let's hope smart enough to fix them promptly as well.

    Basicall Uber is the first, last and only line of defense to ensure that the total stranger who's giving the ride is "safe" in some sense of the word.

    1. EarthDog

      Re: Dumb enough to put them in, smart enough to offer a reward to find them.

      Dumb enough to push out crappy code (open redirects? really?), then pay to have them found and fix them. Stellar....

  2. Pascal Monett Silver badge

    "applauded Uber for its responsiveness"

    Great, a "disruptive" company thriving on giving a fat middle finger to every local country's laws is on the ball when it risks losing money. I suppose there's little surprise there.

    What I wonder is : how much of these errors are due to buffer overflow scenarios ? And how many are due to non-sanitized inputs ?

    You know, the basic programming errors of last millennium ?

  3. Anonymous Coward
    Anonymous Coward

    Was this actually written in English?

    First paragraph tends to indicate not..

  4. BebopWeBop

    Passenger photographs???????

    1. jtaylor Bronze badge

      BebopWeBop wrote "Passenger photographs???????"

      "We may share your information:

      With Drivers to enable them to provide the Services you request. For example, we share your name, photo (if you provide one), "

  5. EarthDog

    Next time pay cash...of wait.. you can't.

