Lyft should be checking on this, running audits and whatnot, but they also should be setting good policy and culture to not abuse access.
Basically, I think its reasonable to both allow many people access and expect them to not abuse it.
Lyft should be checking on this, running audits and whatnot, but they also should be setting good policy and culture to not abuse access.
Basically, I think its reasonable to both allow many people access and expect them to not abuse it.
Indeed. The FCRA accounts for bored clerks looking up random peoples' credit history.
Just because you have access to something doesn't mean you're allowed to touch it without a valid business reason.
I'm no fan of regulation but the wild west of PII is long past needing to be tamed. Companies need to be held responsible for their intelligence and how it gets used.
Then you should not have access to it? People will touch them if they can. That's why Access Control rules exist.
If you add too much friction to the process of accessing information, then it can actually impede on actually handling user support. For example, having access to someone's ride history when trying to resolve a dispute seems relatively normal.
Of course in Lyfts case it seems pretty clear that there can be more programatic locks. And auditable logs are able very good idea in general.
But programatic locks are tricky. How do you transform and e-mail from a user confirming permission to history into an unlock code?
That info should be unlocked the millisecond I am connected with a rep . It's not a moonshot
My feeling is that stuff is doable, but hard-ish. For example, for this case now you're writing something to interface with the phones? How do you know the phone number is for a certain client?
Though I definitely see someone writing a thing where your ticketing/support system grants partial data access, you end up either making the support system pull in information from the DB... or your DB access controls being controlled through the support system.
the latter one can potentially introduce security issues. The former one's easier but you can easily run into the "oh, this information's not gettable through the ticketing system".
Access controls are not a substitute for maturity.
I don't mean that everything should be super-locked down to the point where it's inaccessible, just tweak it enough to not be misused.
The idea of an audit trail is good, since you can go back in history and make any misbehaving parties accountable. Or design a system where the client authorize a rep to look into her records ---just like banks do when you ask for your balance.
Isn't the real concern bad actors? e.g., LOVEINT
But maturity is not a substitute for access controls either.
In any organization of some size, no matter how much you hire for "maturity", eventually people will slip past who have all kinds of reasons they'll be able to justify to themselves for deciding it's too tempting to look at things they shouldn't.
Not that I'm against new regs, I'm for it.
I don't know if there were automated checks for that kind of thing, but everyone knew there was a line you didn't cross.
Yahoo! was the only one that limited access reasonably. It always struck me as odd that auditing didn’t pick up that query behavior. For your main job, PeopleSoft would take care of everything and limit you to who you needed to see, but there were a plethora of other systems and places to look.
This type of thing certainly isn’t limited to Lyft.
I think companies should be responsible for implementing effective security, whether that means preventing improper access or at least detecting it and punishing it after the fact, not just establishing a "culture." The most dangerous people, the ones who commit violent crimes, aren't limited by culture anyway, because they despise norms and have very different perceptions of risk compared to most people.
In your case, your fellow student workers might simply have not felt safe sharing their crimes with you. "Naughty" behavior can be taboo yet widespread.
If Lyft had fired a few rulebreakers early on, everyone else would know they were serious.
That's what the EU data protection law requires! And there are high fines, and new abilities coming into force in May!
Always a few cases now and then of people getting caught checking friends, family and foes.
Pretty sure that auditing is completely separate from the caregiver.
I believe each institution get printed access logs sent to them, which is never looked at.
(Source: Wife works at the hospital and has seen some people get fired shortly after unauhorized access.)
Better to keep the cat and the bacon separate, the temptation to peek is large and if there is one thing I know about people then it is that curiosity is a pretty common affliction.
And that is assuming that those accesses are on purpose, people can make honest mistakes as well and they will also look like unauthorized access.
Better to avoid that situation and implement auditing while making sure people know the rules are enforced.
Of course, both of them are prohibited (without a valid business reason), but the latter is easier to detect in an automated fashion.
At some point, organizations with data have to learn how to manage IAM [1] properly.
https://www.ffiec.gov/pdf/cybersecurity/FFIEC_CAT_May_2017.p... (Page 39)
At a high level, how do they do that? I can only think of a bunch of rules, and that will have to be tweaked endlessly to deal with edge cases.
I couldn't disagree more. Eventually, you're going to hire an idiot (and/or budding rapist). When you have PII of this nature, if you're going to allow lots of people access, you need individual access controls, logging, and most importantly, auditing of the aforementioned data. And auditing may not be enough; you probably need individual inspection and approval to eg look up user info not tied to a ticket you're processing.
Particularly after seeing the Uber god view scandal, there's just no excuse not to have this basic stuff in place.
I worked for a much much smaller startup handling data that was significantly harder to tie to a actual person and we did the above.
There was also the case involving hit men who found the address of a targets mom and dad who where also killed by bribing some one.
BT took security v seriously and you had better hope if you did something bad that the cops or the even the secret service (MI5) got to you before the internal security team did.
I would rather be "dealt with" by BT than with the cops or secret service. BT can fire you, the cops and SS can take away your rights (with due process)
They have a bad reputation as in the bad old days some of the confessions involved falling down stairs, which I was hinting at :-)
What you do is simply restrict data to employees on a need to know basis. Not difficult to do.