Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Ride Carefully
Articles

Ride Carefully

ISBuzz TeamBy ISBuzz TeamMarch 17, 20175 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

New research finds worrisome security issues for anyone who uses the Uber app.

Late last year, Uber launched a major update to its app. One surprising new feature: the ability to track users even when they’re not using the app. Uber claims that the feature is essential to providing a better ride-sharing experience. Maybe so. But excessive location tracking and data sharing potentially comes with a number of unwanted accompaniments, like spear phishing and watering hole attacks and physical security exposure.

In fact, the latest research from Appthority shows that Uber’s new third-party ecosystem enables information sharing with hundreds of other apps – Appthority found over 600 in our database of apps used in enterprises. For instance, Uber is integrating with the Relatient and Medstar apps, which remind users of their doctor appointments and offer a ride there. Uber is also integrating with native calendar apps on your smartphone, giving it access to your meeting schedules and timetables.

Why is this app integration so troubling? Because it opens the door for widespread privacy breaches. For example, location data could reveal that a C-level executive at a large company is visiting a cancer clinic, which could affect the stock price of his or her company if the info were to be leaked. It also has the ability to track other employees – salespeople, developers, etc. – whose location could signal some activities that they don’t want revealed for business reasons.

Employee location becomes even more valuable when other contextual data is added. For example, if users agree to the permission requests, Uber can access not only the location of a meeting, but also the meeting agenda (by accessing calendar) and the meeting attendees and their contact information (by accessing addressbook).

Uber now has access to large volumes of sensitive personal and business information. And while all this additional data sharing might add convenience, it also increases the risk that more of your private data will be shared with unintended or unknown parties, or that sharing will be done without sufficient security protections, like encryption.

The real problem here is that third-party apps may be getting more information than they need and many do not follow Uber’s terms of use. For example, many do not use encryption and that can mean exposing private information. In fact, a new Appthority study found that the vast majority of the 633 third-party apps in enterprise environments that use Uber APIs are transmitting specific information by means that are unencrypted and insecure.

For example, we believe that two tag-along apps—Ride Rates for Uber and Lyft and Fare Check – Instant Uber Price and Arrival Estimates—are supposed to access the Uber API only to check estimated prices and arrival times. However, our analysis showed that these apps are also accessing the history of users’ trips. Uber requires these apps to have publicly available privacy policies by forcing them to submit a URL to these policies during the setup. However, we were unable to find the privacy policies by searching the two apps and the websites of their developers. This means that users who rely on these apps have no idea what data they are sharing, and what these apps will do with that data.

Uber’s business decision to integrate with other apps increases the risk of data leakage and exposure of vital corporate information. For these reasons, making the Uber app itself secure should be Uber’s first priority and, in the meantime, enterprises should be aware of the risks and may want to limit Uber use in their corporate environment. Further, by opening up their API to partners, Uber also bears responsibility to work with their hundreds of partner apps to ensure they too protect and secure the user data they have access too.

Enterprises should take the following actions to address the potential security risks associated with Uber:

  • For enterprises that deem any of the aforementioned risks unacceptable, the Uber app can be blacklisted by their enterprise mobility-management solution.
  • If the enterprise security team choose not to blacklist the Uber app, they can request that employees turn off location services for the app. Uber will still function, the user just has to type in the pickup address. Users may choose to do that anyway to avoid post-ride location tracking.
  • As a general best practice, enterprises should educate their employees that it’s best to say no to apps when they request access to another app unnecessarily. If access has already been given, the user can revoke that access by going to the user’s settings page at the Uber website.
  • Deploying an MTP – Mobile Threat Protection – solution is a great way to automate employee mobile risk education, by providing self-management and self-remediation tools to enable employees to know when it’s safe, and when it’s not, to allow app permissions.

Uber has been making a big play in the enterprise recently with its Uber for Business initiative, which makes it easier for workers to use Uber and expense their rides. Uber’s security practices are, therefore, something that enterprise security departments need to take seriously—before they hit a bump in the road.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}