Live data from Hacker News

Former employees say Lyft staffers spied on passengers

techcrunch.com

81–90 of 253 posts

Re: Former employees say Lyft staffers spied on passengers

#81

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

This was how it worked when I worked in admissions during college. You had access to every applicants' information, grades, essays, etc., as well as counselor feedback. But you were told that if you looked up yourself, someone you knew, or any celebrities, then you could be fired. I don't know if there were automated checks for that kind of thing, but everyone knew there was a line you didn't cross.

Whereas folks I worked with at a support vendor for AT&T HomeZone, when that was a thing, regularly looked up celebrities’ private phone numbers in the unified customer systems with no repercussion, despite the same onboarding spiel. HomeZone was unique in that support reps by necessity had access to AT&T, Dish, and Yahoo! (email) CRM, which covers a very broad range of people and activities; I didn’t do the looking, but I overheard a sampling of notables and legislators who subscribed to the “500s” (Dish lingo for porn at the time, don’t know if they’ve moved the channels since).

Yahoo! was the only one that limited access reasonably. It always struck me as odd that auditing didn’t pick up that query behavior. For your main job, PeopleSoft would take care of everything and limit you to who you needed to see, but there were a plethora of other systems and places to look.

This type of thing certainly isn’t limited to Lyft.

Re: Former employees say Lyft staffers spied on passengers

#82
post #77

I thought 'staffer' was only used when talking about people working in government or for a political party. Aren't 'staff' or 'employees' just as good for the headline?

> I thought 'staffer' was only used when talking about people working in government or for a political party.

Nope.

> Aren't 'staff' or 'employees' just as good for the headline?

No. Staff has a different connotation; as a mass noun, it implies things that are true generally* of the staff. “Employees” would be about as good as “staffers”; the latter is shorter, though, which often is preferable in headlines.

Re: Former employees say Lyft staffers spied on passengers

#83

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

These laws already exist as part of Sarbanes-Oxley but aren't as strict as what you're proposing. Certain public companies are required to implement safeguards that prevent most employees from having access to customer PII(personal identifiable information). Non-public companies don't have to comply with SOX regulations but maybe some of them should be expanded to include large private companies.

Re: Former employees say Lyft staffers spied on passengers

#84

Earlier quoted context omitted.

> if my driver just drops me off at a different place than where I asked... "Hey, this isn't the right place. Take me where you said you would please." > ...or doesn't pick me up. "Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there." > otherwise how can they charge me if I ruin their car They will prevent you from departing,…

>"Hey, this isn't the right place. Take me where you said you would please." The app still charges you. You need a way to get a refund from Lyft , not from the driver. >"Hey gran, I'm going to be late for lunch, the darn taxi driver hasn't turned up. I'm calling another firm - guess I'll see you when I get there." The app still charges you. You need a way to get a refund from Lyft , or alternatively, to refute the lo…

I don’t completely disagree but there are some ways to handle at least parts of what you’re talking about. For example, either persistent or ephemeral pseudonyms (yet still uniquely identifiable, at least for a time) and threshold decryption if at least 2 out of the 3 parties agree to some kind of privilege escalation (most likely would be either lyft and rider or lyft and driver, but rider-driver is interesting).

Re: Former employees say Lyft staffers spied on passengers

#85

The screenshots from the leaker mention that they are using "redshift", which is the name of Amazon's RDB product. Which means this is about people who have access to the database. This is unsurprising that they could access customer data given access to their database. I'm not sure how you prevent this without preventing access to the db (and there are legitimate reasons people within the company would have access -…

You can't prevent access but you can log all access and require a written reason for access. That, followed up by routine audits of access logs will reduce and discourage abuse as described in the article.

Re: Former employees say Lyft staffers spied on passengers

#86

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with da…

The FFIEC considers your heuristic system “Innovative” according to the Cybersecurity risk assessment methodology. Certainly not typical for a financial institution. Pretty cool stuff though!

https://www.ffiec.gov/pdf/cybersecurity/FFIEC_CAT_May_2017.p... (Page 39)

Re: Former employees say Lyft staffers spied on passengers

#87

The screenshots from the leaker mention that they are using "redshift", which is the name of Amazon's RDB product. Which means this is about people who have access to the database. This is unsurprising that they could access customer data given access to their database. I'm not sure how you prevent this without preventing access to the db (and there are legitimate reasons people within the company would have access -…

Eh, I think the only thing that works is you kill your velocity and institute a bunch of processes, and bureaucracy or put up light gates and hire people that you trust to do the right thing. It sounds like they have some gating, but perhaps they need better auditing, and logging?

Anyone who can access that database can _probably_ deploy code too. If you can deploy code, you can sneak in whatever you want.

Re: Former employees say Lyft staffers spied on passengers

#88
post #25

Earlier quoted context omitted.

What do you do when you pay with 20$ for something, but get change for 10$? Why are "argue with them", "accept the loss and move on", "karate chop" and infinite other things not among the options? > You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver. How did taxi drivers handle that for the last nearing 100 years? People before us m…

> How did taxi drivers handle that for the last nearing 100 years? They used specially-built cars with plexiglass barriers and uncomfortable thick vinyl covered seats that could be easily replaced.

I rode in plenty taxis and never in ones that had either of that. The drivers seemed pretty relaxed about the whole thing, as was I.

Re: Former employees say Lyft staffers spied on passengers

#89
post #36

Earlier quoted context omitted.

What's the need for anything? Your argument seems to be predicated on a very specific definition of what need is which is somewhat at odds with most of the rest of the world.

Can you actually refute the parent comment's argument? Because it seems more than reasonable to me. Analytics and Engineering definitely don't need this level of data access for any sort of day-to-day work. I work on analytics tools, and at best, anonymized and generalized data is needed, but never specific customer data. We specifically strip out any PII on data that might reach developers and need to request permis…

It is probably possible to design systems to avoid access, but they will get more complex. Engineering has to debug bugs. For example, suppose there is bug where the rate calculations aren't working for certain types of routes. The engineers will want to look up those routes to understand what is causing it. If you are designing an algorithm to detect to fraud, you are going to want to look at cases of fraud to understand how to design the algorithm. Further, if you want to do usability testing you are going to need to test with. You might want to check the different types of names used in the system to make sure they display properly. You may also want to sample the list of customers to user-test with live data or survey customers.

Re: Former employees say Lyft staffers spied on passengers

#90

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

[deleted]
Post reply on HN