Former employees say Lyft staffers spied on passengers
101–110 of 253 posts
Re: Former employees say Lyft staffers spied on passengers
#102What circumstance would be needed to have a view where an employee can find riders by name and look at their whole history? If there is a complaint it should allow the customer service agent to see the ride and perhaps some history (ratings make sense, but including full locations/times seems unwise), but I can't think of a reason why this would ever need to be a process started by a Lyft agent and not the customer o…
I used to be in the habit of taking my cat to the vet in a regular taxi, with a local company. I always got the same guy and the same car as they always 'knew' where I was going. The guy I got liked cats, didn't mind waiting around and made sure everything was looked after. Others were allergic to cats or only doing airport trips, so I had no problem with them looking at my history and doing their best for me.
Re: Former employees say Lyft staffers spied on passengers
#103Someone I know was just commenting that from convos w/ people in other companies, it seems many startups have benefitted from not being under the limelight, and thus had the chance to quietly clean up their own messes while Uber was taking all the heat from the media.
I always suspected that uber flames were fanned by its many competitors.
Re: Former employees say Lyft staffers spied on passengers
#104Re: Former employees say Lyft staffers spied on passengers
#105Re: Former employees say Lyft staffers spied on passengers
#106When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…
I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with da…
At a high level, how do they do that? I can only think of a bunch of rules, and that will have to be tweaked endlessly to deal with edge cases.
Re: Former employees say Lyft staffers spied on passengers
#107The screenshots from the leaker mention that they are using "redshift", which is the name of Amazon's RDB product. Which means this is about people who have access to the database. This is unsurprising that they could access customer data given access to their database. I'm not sure how you prevent this without preventing access to the db (and there are legitimate reasons people within the company would have access -…
See the docs -> https://docs.aws.amazon.com/redshift/latest/dg/r_GRANT.html
Perhaps some people have legitimate reasons to access some sensitive info, perhaps not. But not _everyone_ needs that access anyways.
Re: Former employees say Lyft staffers spied on passengers
#108Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information See, that's a complete lie and that's the attitude that needs to sop. No-one needed access. Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason.…
https://danluu.com/wat/ apparently this is normal: Facebook famously let all employees access everyone’s profile for a long time, and you can even find HN comments indicating that some recruiters would explicitly mention that as a perk of working for Facebook. And I can think of more than one well-regarded unicorn where everyone still has access to basically everything, even after their first or second bad security b…
Re: Former employees say Lyft staffers spied on passengers
#109When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…
> Basically, I think its reasonable to both allow many people access and expect them to not abuse it. Indeed. The FCRA accounts for bored clerks looking up random peoples' credit history. Just because you have access to something doesn't mean you're allowed to touch it without a valid business reason. I'm no fan of regulation but the wild west of PII is long past needing to be tamed. Companies need to be held respons…
Then you should not have access to it? People will touch them if they can. That's why Access Control rules exist.
Re: Former employees say Lyft staffers spied on passengers
#110Earlier quoted context omitted.
> How did taxi drivers handle that for the last nearing 100 years? They used specially-built cars with plexiglass barriers and uncomfortable thick vinyl covered seats that could be easily replaced.
I rode in plenty taxis and never in ones that had either of that. The drivers seemed pretty relaxed about the whole thing, as was I.