Live data from Hacker News

Former employees say Lyft staffers spied on passengers

techcrunch.com

41–50 of 253 posts

Re: Former employees say Lyft staffers spied on passengers

#41

Earlier quoted context omitted.

(I work at Google, but these views are my own): This works until you need some kind of ombudsperson. At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up. You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver…

> if my driver just drops me off at a different place than where I asked... "Hey, this isn't the right place. Take me where you said you would please." > ...or doesn't pick me up. "Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there." > otherwise how can they charge me if I ruin their car They will prevent you from departing,…

>"Hey, this isn't the right place. Take me where you said you would please."

The app still charges you. You need a way to get a refund from Lyft, not from the driver.

>"Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there."

The app still charges you. You need a way to get a refund from Lyft, or alternatively, to refute the loss in rating.

Is your issue with Lyft's business model, or my comments about encryption?

Re: Former employees say Lyft staffers spied on passengers

#42
post #8

What circumstance would be needed to have a view where an employee can find riders by name and look at their whole history? If there is a complaint it should allow the customer service agent to see the ride and perhaps some history (ratings make sense, but including full locations/times seems unwise), but I can't think of a reason why this would ever need to be a process started by a Lyft agent and not the customer o…

I used to be in the habit of taking my cat to the vet in a regular taxi, with a local company. I always got the same guy and the same car as they always 'knew' where I was going. The guy I got liked cats, didn't mind waiting around and made sure everything was looked after. Others were allergic to cats or only doing airport trips, so I had no problem with them looking at my history and doing their best for me.

Re: Former employees say Lyft staffers spied on passengers

#43

Earlier quoted context omitted.

> if my driver just drops me off at a different place than where I asked... "Hey, this isn't the right place. Take me where you said you would please." > ...or doesn't pick me up. "Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there." > otherwise how can they charge me if I ruin their car They will prevent you from departing,…

>"Hey, this isn't the right place. Take me where you said you would please." The app still charges you. You need a way to get a refund from Lyft , not from the driver. >"Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there." The app still charges you. You need a way to get a refund from Lyft , or alternatively, to refute the lo…

    > Is your issue with Lyft's business model, or my 
    > comments about encryption?
Both, as it goes :)

I think you're using the word need in a much more narrow context than I am. Without Lyft/Uber/whoever convincing their customers that they're needed, there is no need for the data to be recorded in the first place.

And most of the time, you'd still get to Gran's when you said you would.

Re: Former employees say Lyft staffers spied on passengers

#44
post #2

Someone I know was just commenting that from convos w/ people in other companies, it seems many startups have benefitted from not being under the limelight, and thus had the chance to quietly clean up their own messes while Uber was taking all the heat from the media.

I always suspected that uber flames were fanned by its many competitors.

Re: Former employees say Lyft staffers spied on passengers

#45

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

https://danluu.com/wat/ apparently this is normal: Facebook famously let all employees access everyone’s profile for a long time, and you can even find HN comments indicating that some recruiters would explicitly mention that as a perk of working for Facebook. And I can think of more than one well-regarded unicorn where everyone still has access to basically everything, even after their first or second bad security breach. It’s hard to get the political capital to restrict people’s access to what they believe they need, or are entitled, to know. A lot of trendy startups have core values like “trust” and “transparency” which make it difficult to argue against universal access.

Re: Former employees say Lyft staffers spied on passengers

#46

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

> Basically, I think its reasonable to both allow many people access and expect them to not abuse it.

I couldn't disagree more. Eventually, you're going to hire an idiot (and/or budding rapist). When you have PII of this nature, if you're going to allow lots of people access, you need individual access controls, logging, and most importantly, auditing of the aforementioned data. And auditing may not be enough; you probably need individual inspection and approval to eg look up user info not tied to a ticket you're processing.

Particularly after seeing the Uber god view scandal, there's just no excuse not to have this basic stuff in place.

I worked for a much much smaller startup handling data that was significantly harder to tie to a actual person and we did the above.

Re: Former employees say Lyft staffers spied on passengers

#47

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

In hospitals in the U.S. the way it works in some is nurses can view a lot of the patients charts (including VIP). And then someone is supposed to audit who viewed those VIP patients (celebrity or what not) but every hospital is different and it's a mess.

Re: Former employees say Lyft staffers spied on passengers

#48

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

In hospitals in the U.S. the way it works in some is nurses can view a lot of the patients charts (including VIP). And then someone is supposed to audit who viewed those VIP patients (celebrity or what not) but every hospital is different and it's a mess.

Here in Sweden you can view any patients info, and there is supposed to be audits to check that a doctor only ever checked relevant patient journals.

Always a few cases now and then of people getting caught checking friends, family and foes.

Pretty sure that auditing is completely separate from the caregiver.

Re: Former employees say Lyft staffers spied on passengers

#49
post #2

Someone I know was just commenting that from convos w/ people in other companies, it seems many startups have benefitted from not being under the limelight, and thus had the chance to quietly clean up their own messes while Uber was taking all the heat from the media.

I always suspected that uber flames were fanned by its many competitors.

That may be, but the fires were caused by Uber.

Re: Former employees say Lyft staffers spied on passengers

#50
post #45

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

https://danluu.com/wat/ apparently this is normal: Facebook famously let all employees access everyone’s profile for a long time, and you can even find HN comments indicating that some recruiters would explicitly mention that as a perk of working for Facebook. And I can think of more than one well-regarded unicorn where everyone still has access to basically everything, even after their first or second bad security b…

It doesn't need to be normal. There's no reason companies couldn't build a system that required approval from your manager before being able to access customer data. Any time a manager granted access, that could be audited by some second tier.
Post reply on HN