Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"This worked because Uber Eats provides couriers with prepaid cards they can use to purchase up to $700 to complete customers' orders."


Yeah, but were they not suspicious after the previous 1427 prepaid cards?


"Uber continues to invest in robust anti-fraud systems and technology, which allowed our Global Investigations Team to proactively alert law enforcement about this case"

$1,000,000 / 700 = ~1500 trips starting in January last year. 20 months = ~75 trips a month or about twice a day.

I'm not sure Uber understands what the word, "proactive" or "robust" means.


(russellbeattie... I recognize that name... small world. Sorry for digressing. Russell: I've got to thank you for https://www.russellbeattie.com/blog/1008770. We all felt so proud after reading that review! Finally someone who got it. I was the person who led the product design/engineering effort during its first decade.)


The Opera Mini browser was amazing. Did any of the people that worked on it end up working on anything open source making use of the same ideas?

I’m dreaming of having an open source backend that I could run myself on my server, and that would similarly download and compress pages and then send a representation of the page that can be displayed on my iPhone without the app running any JS or anything.

Greater security, and also it would make me able to browse even in bad coverage areas where currently all that happens is I wait an eternity for things to try to load and they just time out.

Basically, I wish there was an open source backend and app that behaved like Opera Mini used to.


(Not that I'm aware of.)

Web pages don't really work without in-page/dynamic javascript any longer.

On the other hand it's now cheaper than ever to just have a full-blown webkit instance in the cloud and just sync/stream the dom tree paints to the client. A bunch of products do that, I think.

Back then we had a moat because

a) Opera's Presto used so much less memory than Webkit - after having gone through so many painful memory optimization efforts, particularly with Japanese mobile browser deliveries, but also with Symbian.

b) We figured out a way of making 90% of the web javascript work be keeping "tabs" around on the server for a few minutes and then just replaying carefully selected input events and capturing the output, with some kinda clever heuristics. That combined with the low memory usage did it.

Webkit used like 10x more memory per tab/window back then, iirc. And RAM was expensive.


Wow! That's a blast from the past! I'm flattered the post meant so much to you and your team that you remember it 17 years later!! The review was well deserved, Opera showed how good browsers could be on mobile, and really presaged how important they would become once smartphones took off. You guys were way ahead of your time.

I still find it interesting how personal blogs could have an impact back then when they were still a relatively new idea. Google gave us preferential placement in searches, and the results for many of us was a boost in our careers and an outsized notoriety. You're not the only one who's contacted me years later about something I wrote back when. I would never have predicted that at the time.

I appreciate you commenting about it!


I used Opera Mini for many, many years on a variety of phones, from "dumb" feature phones to my N-Gage. What an incredible product it was! Thank you for allowing me to read cool stuff in Wikipedia while I was bored in school. It made things a lot more bearable.


To get even more meta, isn't it quite incredible that 17y later not only does the blog still exist, but we have the author and a key subject (or person behind subject) in the same comment section?

Not even like it's particularly niche, 80s arcade games ported to 90s machines forum dot net or something.


It's not like we died or decided to suddenly switch careers and become car salesmen or something. I was just a blogger. I find it even more amazing when someone truly important or influential comments on HN on things they worked on, say in the 1990s. A while ago there was a thread about Sun Microsystems GUI which used PostScript and one of the original developers chimed in and I was astounded.


Sure, sorry, I just thought it was nice. Yes obviously even older is even nicer. A lot of just bloggers 17y ago won't still have their blog (or not that one) up, these things rot. And then just you and someone it had a particular affect on happening to be in the same comment section (about something else) at the same time and noticing... Idk, whatever, I just thought it was nice!


You have a certain "budget" for losses like this. Beneath a certain amount, you just take the loss, as it's more cost effective than spending man-hours on it. Their fraud systems and dedicated fraud teams are better off alerting on the "whales", so to speak. And in these cases, if you're gonna lay accusations and ban people, you'd rather be more certain (i.e. minimize false positives).

All that is to say, it's understandable if they only pounce once it gets to a certain level of badness.


So what you’re suggesting is Uber has an actionable fraud threshold and if an intelligent actor wanted to float beneath that with fake accounts and identities they could extract even more?


Yes. Same for all the big tech companies. I guarantee you people are already doing this in every way you can imagine and many you can't. Source: Worked on bad actor detection at FB.


Reminds me of the guy who scammed Google and Facebook of $123 million via fake invoices.

https://www.cnbc.com/amp/2019/03/28/how-to-avoid-invoice-the...


That article doesn’t make any sense. At big companies like this you can’t just send money to someone who even convincingly looks like a vendor or partner. You need to have a PO created with the vendor as the recipient, and there are entire purchasing departments who vet recipients and make sure things like the legal name of the entity matches the wire instructions and so on.

I’d imagine that medium sized companies without much process might be vulnerable to this, but FAANGs?? No way.

If KNOWN_PARTNER simply emails an invoice and wire instructions to an employee of one of these larger companies, there is no way in hell that’s getting paid without multiple people in the paying company simultaneously screwing up.


Yes. Enforcement action requires cash and man-hours, so its logical that you only go after fraud past a certain threshold.


Uber is so big that they cannot attend to every possible discrepancy .


You mean they are too small compared to their customer base to attend to every discrepancy?


Not having automatic fraud detection that can alert on... (a) new accounts in a (b) geographically-specific area that are (c) failing to balance at a greater than average rate... sounds pretty basic.

You'd assume it would be one of the most common use patterns for structured fraud.


> automatic fraud detection that can alert on... that are (c) failing to balance at a greater than average rate... sounds pretty basic.

What makes you think that it's a greater than average rate?


If they're regularly losing $52,600 every month to fraud from 2 people, then that might explain the $31.5b operating losses they've had since 2014.


I'm positive they have these alerts already and chose not to action on them.


Maybe when you fail at due dilligence so blatantly, you should no longer be able to prosecute or press charges. They deserve to lose their shirts at this point.

I can't shake feeling of disparity - as an ordinary Joe, you are presented with dozens of contracts for loans, mortgages, life insurance. The fine print is incomprehensible to an average person, and yet you could lose your shirt if you get it wrong and law is not on your side.

I know these are different situations, but I am getting these vubes.


yeah, uber is really good at knowing when drivers are not taking less profitable riders, which is generally a no-no, but stuff like this gets through


seems like this is the very definition of “asleep at the switch” - does no manager own P/L for that unit?


Uber has so much $ from VC that this is peanuts, so it's not a priority. Eventually they noticed the theft and contacted authorities and fixed it.

Uber has defied all predictions over the past 13 or so years of running out of money: there is always more $, and stock price keeps going up. It sorta defies reality--like amazon in 2015 in this regard or Tesla in 2013.


Well, it does sound like an area they need to invest in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: