It's not "exploiting others' fears" when there is actual evidence that Uber has tracked journalists and other high profile figures, and top execs have brashly threatened to spend millions investigating journalists' personal lives. This is disgusting.
None of those were 'small security holes'. SQL injection on your website? Unnecessary ports open and known vulnerabilities on a public facing server? This is embarrassing for a company that apparently focuses on security.
Get off your high horse and actually read the article - descriptive names should be temporary CNAMEs. There's nothing rigid about an easily changeable pointer. And 'just use different tools' is a naive and reactionary approach.