Uber and Lyft unintentionally sent gig workers' SSN numbers to social media companies, researchers report
UberUber(US:UBER) TechXplore·2024-11-18 16:08

Core Insights - Uber and Lyft have been unintentionally sharing sensitive data, including unsalted hashes of Social Security numbers (SSNs), with social media companies Meta and TikTok [2][3][9] Data Privacy Issues - Research indicates that tracking pixels on Uber and Lyft's websites were collecting data from private application forms and sending it to Meta and TikTok [6][7] - The unsalted hashes used for SSNs are considered insecure, raising concerns about data protection [3][10] Company Response - Upon being informed of the vulnerabilities, Uber and Lyft quickly worked to address the issues, indicating that the data sharing was unintentional and related to configuration settings [9][10] Recommendations for Improvement - Companies should implement clearer purpose limitation statements regarding the use of worker data, differentiating it from consumer data [11][12] - There is a call for increased transparency and accountability in how companies handle personal data, with suggestions for legal reforms to protect workers' privacy [15][16]