Live data from Hacker News

Former employees say Lyft staffers spied on passengers

techcrunch.com

91–100 of 253 posts

Re: Former employees say Lyft staffers spied on passengers

#91
post #36

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

What's the need for anything? Your argument seems to be predicated on a very specific definition of what need is which is somewhat at odds with most of the rest of the world.

It seems to me "need" is very specific almost by definition. One needs access to only that which is fundamentally required to perform work. That need in most cases is actually quite constrained. Often it is far smaller in scope that some might like.

Re: Former employees say Lyft staffers spied on passengers

#92

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

Have you tried to debug the same two problems when you do not have access to the infrastructure, versus when you do have infrastructure access? It's a radically different experience.

In addition, even if no one needs access, a bad actor who writes the code can always put a backdoor in place and read whatever they want.

Re: Former employees say Lyft staffers spied on passengers

#93
post #75

Earlier quoted context omitted.

You don't really own your medical record, also doctors add notes to your medical record that you may not like. For example your medical record may say that you don't follow up with medication, abuse drugs, have psychiatric/personality problems, etc. which patients could be sensitive about.

That's not true. In the US at least as an adult you have a legal right to see everything in your medical record.

Almost, but not quite. There are exceptions, such as psychotherapy notes. (Cite: https://www.hhs.gov/hipaa/for-professionals/privacy/laws-reg... section “Access”.)

Re: Former employees say Lyft staffers spied on passengers

#94

Earlier quoted context omitted.

I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with da…

The FFIEC considers your heuristic system “Innovative” according to the Cybersecurity risk assessment methodology. Certainly not typical for a financial institution. Pretty cool stuff though! https://www.ffiec.gov/pdf/cybersecurity/FFIEC_CAT_May_2017.p... (Page 39)

[deleted]

Re: Former employees say Lyft staffers spied on passengers

#95
post #45

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

https://danluu.com/wat/ apparently this is normal: Facebook famously let all employees access everyone’s profile for a long time, and you can even find HN comments indicating that some recruiters would explicitly mention that as a perk of working for Facebook. And I can think of more than one well-regarded unicorn where everyone still has access to basically everything, even after their first or second bad security b…

What Unicorns would those be?

Re: Former employees say Lyft staffers spied on passengers

#96

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

This was how it worked when I worked in admissions during college. You had access to every applicants' information, grades, essays, etc., as well as counselor feedback. But you were told that if you looked up yourself, someone you knew, or any celebrities, then you could be fired. I don't know if there were automated checks for that kind of thing, but everyone knew there was a line you didn't cross.

At Lyft people did think there were automated checks, did know there was a line that shouldn't be crossed, and yet there was rampant abuse. Don't you suspect that many of the students in your position abused their access?

I think companies should be responsible for implementing effective security, whether that means preventing improper access or at least detecting it and punishing it after the fact, not just establishing a "culture." The most dangerous people, the ones who commit violent crimes, aren't limited by culture anyway, because they despise norms and have very different perceptions of risk compared to most people.

In your case, your fellow student workers might simply have not felt safe sharing their crimes with you. "Naughty" behavior can be taboo yet widespread.

Re: Former employees say Lyft staffers spied on passengers

#97
post #77

I thought 'staffer' was only used when talking about people working in government or for a political party. Aren't 'staff' or 'employees' just as good for the headline?

> I thought 'staffer' was only used when talking about people working in government or for a political party. Nope. > Aren't 'staff' or 'employees' just as good for the headline? No. Staff has a different connotation; as a mass noun, it implies things that are true generally* of the staff. “Employees” would be about as good as “staffers”; the latter is shorter, though, which often is preferable in headlines.

Employees is already used in the headline, so the editor would have been looking for a different word to use anyway.

Re: Former employees say Lyft staffers spied on passengers

#98
post #92

Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…

Have you tried to debug the same two problems when you do not have access to the infrastructure, versus when you do have infrastructure access? It's a radically different experience. In addition, even if no one needs access, a bad actor who writes the code can always put a backdoor in place and read whatever they want.

The best approach is to make it the exception not the rule. This ultimately protects everyone and provides a nice paper trail in the event something does happen and needs to be audited. You can partially mitigate the bad actor problem by putting safe guards in place to make sure all changes have to be peer reviewed before shipping.

Re: Former employees say Lyft staffers spied on passengers

#99

I worked there. I was an engineer and definitely needed access to these data. Fraud and abuse is constantly evolving and touches every part of the business. Everything was audited and I never saw or heard of a single abuse of access. Privacy was talked about seriously at onboarding and other trainings. I have no doubt if somebody was caught abusing this they’d be fired.

The article is indicating that what you are saying is at least not universally true in Lyft

Re: Former employees say Lyft staffers spied on passengers

#100
post #68
post #58

Earlier quoted context omitted.

Just curious - why is looking up yourself an offense?

Not infrequently there are notes in patients charts that only care providers can see. This practice is becoming frowned upon in some circles however, in lieu of more transparency. I imagine it being really useful for certain scenarios (e.g. mental illness or documentation a sensitive domestic relationship, where you wouldn't want a potentially abuse family member to see comments about their behavior in a relative's c…

[deleted]
Post reply on HN