TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Flaw in Uber Protocols Led to Non-Trivial Safety Issue

2 点作者 pain_perdu大约 9 年前
tl;dr a flaw in Uber&#x27;s security protocols can allow an unscreened anonymous driver to pickup passengers.<p>I just spent an hour as a passenger in an UberX driven by someone completely anonymous (with potentially no security screening&#x2F;background check). They somehow managed to upload a stock photo of a generic hand instead of a profile of their face. This is non-trivial breach of Uber&#x27;s system because it meant it was impossible for me to know if the person driving the car was the same as the person who applied for this Uber Driver account. This is not supposed to happen!<p>Checkout a photo from my Uber App: http:&#x2F;&#x2F;imgur.com&#x2F;XTINSpD.png and compare to this stock-photo: http:&#x2F;&#x2F;www.shutterstock.com&#x2F;pic-201949108&#x2F;stock-photo.html<p>There is a vulnerability (or at the very least, lax policies&#x2F;insufficient redundant checks in place) in Uber&#x27;s profile pic screening system that allows unscreened drivers to potentially pickup passengers. I hope they get to the bottom of this soon.<p>I&#x27;ve been in touch with Uber&#x27;s security team who did take the issue seriously and they agreed with my basic conclusion (and confirmed that humans normally screen all profile pics) so I hope there isn&#x27;t a technical vulnerability enabling a photo to be swapped after the manual-check has been done.

暂无评论

暂无评论