Live data from Hacker News

Former employees say Lyft staffers spied on passengers

techcrunch.com

1–10 of 253 posts

Re: Former employees say Lyft staffers spied on passengers

#2
Someone I know was just commenting that from convos w/ people in other companies, it seems many startups have benefitted from not being under the limelight, and thus had the chance to quietly clean up their own messes while Uber was taking all the heat from the media.

Re: Former employees say Lyft staffers spied on passengers

#4
Whether it’s Uber or the NSA stories of staff spying on people for a variety of reasons... it always comes down to people who seem to have access to things that they probably shouldnt have gotten access to in the first place. Users should be protected by having their data encrypted and anonymized so no other human being (staffers, governments or hackers) can connect an ID to the data. This way they can still access the data and use it for what ever work related purpose, with less risk of these things happening

Re: Former employees say Lyft staffers spied on passengers

#5
When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being.

Lyft should be checking on this, running audits and whatnot, but they also should be setting good policy and culture to not abuse access.

Basically, I think its reasonable to both allow many people access and expect them to not abuse it.

Re: Former employees say Lyft staffers spied on passengers

#6

Whether it’s Uber or the NSA stories of staff spying on people for a variety of reasons... it always comes down to people who seem to have access to things that they probably shouldnt have gotten access to in the first place. Users should be protected by having their data encrypted and anonymized so no other human being (staffers, governments or hackers) can connect an ID to the data. This way they can still access t…

(I work at Google, but these views are my own):

This works until you need some kind of ombudsperson. At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up.

You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car. You need to know they were my driver.

There absolutely should be data privacy guarantees that are as strong as possible. But "encrypt and anonymize everything" doesn't work. (edit: and note, I think this is an unfortunate truth, but still a truth).

Re: Former employees say Lyft staffers spied on passengers

#7

When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules. There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being. Lyft should be checking on this, running audits and whatnot, but they also sh…

I’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly.

At some point, organizations with data have to learn how to manage IAM [1] properly.

[1] https://en.wikipedia.org/wiki/Identity_management

Re: Former employees say Lyft staffers spied on passengers

#8
What circumstance would be needed to have a view where an employee can find riders by name and look at their whole history? If there is a complaint it should allow the customer service agent to see the ride and perhaps some history (ratings make sense, but including full locations/times seems unwise), but I can't think of a reason why this would ever need to be a process started by a Lyft agent and not the customer or driver.

Re: Former employees say Lyft staffers spied on passengers

#10
Lyft tells TechCrunch that staffers in several departments that might need access to this data for their job have the ability to look up this information

See, that's a complete lie and that's the attitude that needs to sop.

No-one needed access.

Analytics definitely didn't. Engineers never did. Customer services should have to request permission from the customer before accessing sensitive data, with a valid reason. Insurance definitely did not. And "trust and safety", just like customer service, should have had to get customer permission first.

What's the need?

These are the laws that need to come into place, if your company is bigger than X, safeguards on personal data must be in place to stop anyone accessing a customer's personal data without explicit permission from the customer/senior (legally culpable) manager or as needed to fulfil an order.

Post reply on HN