Live data from Hacker News

Former employees say Lyft staffers spied on passengers

techcrunch.com

11–20 of 253 posts

Re: Former employees say Lyft staffers spied on passengers

#11

Whether it’s Uber or the NSA stories of staff spying on people for a variety of reasons... it always comes down to people who seem to have access to things that they probably shouldnt have gotten access to in the first place. Users should be protected by having their data encrypted and anonymized so no other human being (staffers, governments or hackers) can connect an ID to the data. This way they can still access t…

(I work at Google, but these views are my own): This works until you need some kind of ombudsperson. At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up. You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver…

Obviously when you make a support request your record should be displayed for the customer service agent, but this is the other way around where they can seek out people. I don't think that's a valid use case and there's the obvious abuse case.

Re: Former employees say Lyft staffers spied on passengers

#12

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with da…

That sounds like fantastic place to work :), how come you are not locked out for posting on HN? (I am assuming you are doing this during work hours)

Re: Former employees say Lyft staffers spied on passengers

#13

Whether it’s Uber or the NSA stories of staff spying on people for a variety of reasons... it always comes down to people who seem to have access to things that they probably shouldnt have gotten access to in the first place. Users should be protected by having their data encrypted and anonymized so no other human being (staffers, governments or hackers) can connect an ID to the data. This way they can still access t…

(I work at Google, but these views are my own): This works until you need some kind of ombudsperson. At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up. You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver…

You could completely anonymize when certain key variables are met. In your example, when the ride is successfully completed and both parties confirmed this, the data can be anonymized.

Re: Former employees say Lyft staffers spied on passengers

#14

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

> Basically, I think its reasonable to both allow many people access and expect them to not abuse it.

Indeed. The FCRA accounts for bored clerks looking up random peoples' credit history.

Just because you have access to something doesn't mean you're allowed to touch it without a valid business reason.

I'm no fan of regulation but the wild west of PII is long past needing to be tamed. Companies need to be held responsible for their intelligence and how it gets used.

Re: Former employees say Lyft staffers spied on passengers

#15

Earlier quoted context omitted.

I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with da…

That sounds like fantastic place to work :), how come you are not locked out for posting on HN? (I am assuming you are doing this during work hours)

Probably is on the data science team...

Re: Former employees say Lyft staffers spied on passengers

#17
post #2

Someone I know was just commenting that from convos w/ people in other companies, it seems many startups have benefitted from not being under the limelight, and thus had the chance to quietly clean up their own messes while Uber was taking all the heat from the media.

So basically Uber is the Weinstein of startups.

Re: Former employees say Lyft staffers spied on passengers

#18
None of the data that was available sounds like sensitive PII so I'm not sure why anyone would be surprised by this. I would probably think that rider/driver feedback isn't PII at all.

I suppose it might be a bit questionable if Lyft was creating and providing tools to make it easy to look this stuff up and promoting it within the company but that doesn't sound like the case either.

Re: Former employees say Lyft staffers spied on passengers

#20
post #11

Earlier quoted context omitted.

(I work at Google, but these views are my own): This works until you need some kind of ombudsperson. At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up. You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver…

Obviously when you make a support request your record should be displayed for the customer service agent, but this is the other way around where they can seek out people. I don't think that's a valid use case and there's the obvious abuse case.

Right, but the solution to that isn't 'encrypt everything', its 'define reasonable (and this definition may vary, but its certainly not "none") access controls for user data and pii'.
Post reply on HN