8 ms·
When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would fo
by mpolichette 9y ago
When I did an internship at a national lab, a lot of the hard rules about security relied on the fact that you had gone though their hiring process and would follow the rules.
There were different access levels, for sure, but only like 2 or 3. You might have "had access" but you shouldn't be anywhere you didn't have a good reason for being.
Lyft should be checking on this, running audits and whatnot, but they also should be setting good policy and culture to not abuse access.
Basically, I think its reasonable to both allow many people access and expect them to not abuse it.
- toomuchtodo 9y agoI’m at a financial services firm, and we have an entire internal risk department to ensure employees aren’t exceeding their authority. Surfing the wrong websites? Badging in and out at abnormal hours? Accessing internal apps in ways you shouldn’t? Access immediately flagged for human intervention and you’re locked out. Our data scientist team improves on the heuristics constantly. At some point, organizations with data have to learn how to manage IAM [1] properly. [1] https://en.wikipedia.org/wiki/Identity_management https://en.wikipedia.org/wiki/Identity_management
- desireco42 9y agoThat sounds like fantastic place to work :), how come you are not locked out for posting on HN? (I am assuming you are doing this during work hours)
- LeifCarrotson 9y agoProbably is on the data science team...
- deleted 9y ago[deleted]
- toomuchtodo 9y agoI’m on our cloud security team; our leadership chain gives us wide latitude (Hacker News A-OK) since our entire job is to be subject matter experts. Literally “Know All The Things” was how my job req was described to me.
- heartbreak 9y agoThe FFIEC considers your heuristic system “Innovative” according to the Cybersecurity risk assessment methodology. Certainly not typical for a financial institution. Pretty cool stuff though! https://www.ffiec.gov/pdf/cybersecurity/FFIEC_CAT_May_2017.pdf https://www.ffiec.gov/pdf/cybersecurity/FFIEC_CAT_May_2017.p... (Page 39)
- deleted 9y ago[deleted]
- outworlder 9y ago"Accessing internal apps in ways you shouldn’t?" At a high level, how do they do that? I can only think of a bunch of rules, and that will have to be tweaked endlessly to deal with edge cases.
- deleted 9y ago[deleted]
- jstarfish 9y ago> Basically, I think its reasonable to both allow many people access and expect them to not abuse it. Indeed. The FCRA accounts for bored clerks looking up random peoples' credit history. Just because you have access to something doesn't mean you're allowed to touch it without a valid business reason. I'm no fan of regulation but the wild west of PII is long past needing to be tamed. Companies need to be held responsible for their intelligence and how it gets used.
- lobo_tuerto 9y ago"Just because you have access to something doesn't mean you're allowed to touch it without a valid business reason." Then you should not have access to it? People will touch them if they can. That's why Access Control rules exist.
- btown 9y agoToo much reliance on programmatic access controls causes people to think “if it’s allowed by the controls, it’s allowed by common sense” which is rarely the case.
- ams6110 9y agoOn the flipside, systems that are too cumbersome to use because of access controls lead people to do things like maintain shadow systems in Excel spreadsheets just to get their work done. Of course with no security at all.
- rtpg 9y agoThere's a bit of pragmatism involved in the level of control. If you add too much friction to the process of accessing information, then it can actually impede on actually handling user support. For example, having access to someone's ride history when trying to resolve a dispute seems relatively normal. Of course in Lyfts case it seems pretty clear that there can be more programatic locks. And auditable logs are able very good idea in general. But programatic locks are tricky. How do you transform and e-mail from a user confirming permission to history into an unlock code?
- spiznnx 9y agoIt should be easy to audit and enforce. Just have to scare people a bit into respecting the system.
- x0x0 9y ago> Basically, I think its reasonable to both allow many people access and expect them to not abuse it. I couldn't disagree more. Eventually, you're going to hire an idiot (and/or budding rapist). When you have PII of this nature, if you're going to allow lots of people access, you need individual access controls, logging, and most importantly, auditing of the aforementioned data. And auditing may not be enough; you probably need individual inspection and approval to eg look up user info not tied to a ticket you're processing. Particularly after seeing the Uber god view scandal, there's just no excuse not to have this basic stuff in place. I worked for a much much smaller startup handling data that was significantly harder to tie to a actual person and we did the above.
- walshemj 9y agoI remember a briefing when I worked for BT in the UK some one looked up for a mate his exes new address - who then got murdered. There was also the case involving hit men who found the address of a targets mom and dad who where also killed by bribing some one. BT took security v seriously and you had better hope if you did something bad that the cops or the even the secret service (MI5) got to you before the internal security team did.
- chipperyman573 9y ago>BT took security v seriously and you had better hope if you did something bad that the cops or the even the secret service (MI5) got to you before the internal security team did. I would rather be "dealt with" by BT than with the cops or secret service. BT can fire you, the cops and SS can take away your rights (with due process)
- walshemj 9y agoAs a former PTT IB or SD was descended from the unit in the GPO that dealt with stealing for the post so had some odd quasi legal standing - its also where the secret squirrels worked. They have a bad reputation as in the bad old days some of the confessions involved falling down stairs, which I was hinting at :-)
- milofeynman 9y agoIn hospitals in the U.S. the way it works in some is nurses can view a lot of the patients charts (including VIP). And then someone is supposed to audit who viewed those VIP patients (celebrity or what not) but every hospital is different and it's a mess.
- tapland 9y agoHere in Sweden you can view any patients info, and there is supposed to be audits to check that a doctor only ever checked relevant patient journals. Always a few cases now and then of people getting caught checking friends, family and foes. Pretty sure that auditing is completely separate from the caregiver.
- zkomp 9y agoIn Stockholm, there is one journal system everyone is mandated to use, written in APL (was called Take Care but could have changed name), and completely without access control. I believe each institution get printed access logs sent to them, which is never looked at.
- pookeh 9y agoHere in Canada if you have access to the central medical records you can look up anyone but (a) if you are not a doc and are not assigned to the case or (b) you are looking up yourself or a family member, you immediately get a call and get fired on the spot. (Source: Wife works at the hospital and has seen some people get fired shortly after unauhorized access.)
- ddinh 9y agoJust curious - why is looking up yourself an offense?
- opportune 9y agoYou don't really own your medical record, also doctors add notes to your medical record that you may not like. For example your medical record may say that you don't follow up with medication, abuse drugs, have psychiatric/personality problems, etc. which patients could be sensitive about.
- jamestimmins 9y agoThis was how it worked when I worked in admissions during college. You had access to every applicants' information, grades, essays, etc., as well as counselor feedback. But you were told that if you looked up yourself, someone you knew, or any celebrities, then you could be fired. I don't know if there were automated checks for that kind of thing, but everyone knew there was a line you didn't cross.
- jsmthrowaway 9y agoWhereas folks I worked with at a support vendor for AT&T HomeZone, when that was a thing, regularly looked up celebrities’ private phone numbers in the unified customer systems with no repercussion, despite the same onboarding spiel. HomeZone was unique in that support reps by necessity had access to AT&T, Dish, and Yahoo! (email) CRM, which covers a very broad range of people and activities; I didn’t do the looking, but I overheard a sampling of notables and legislators who subscribed to the “500s” (Dish lingo for porn at the time, don’t know if they’ve moved the channels since). Yahoo! was the only one that limited access reasonably. It always struck me as odd that auditing didn’t pick up that query behavior. For your main job, PeopleSoft would take care of everything and limit you to who you needed to see, but there were a plethora of other systems and places to look. This type of thing certainly isn’t limited to Lyft.
- dkarl 9y agoAt Lyft people did think there were automated checks, did know there was a line that shouldn't be crossed, and yet there was rampant abuse. Don't you suspect that many of the students in your position abused their access? I think companies should be responsible for implementing effective security, whether that means preventing improper access or at least detecting it and punishing it after the fact, not just establishing a "culture." The most dangerous people, the ones who commit violent crimes, aren't limited by culture anyway, because they despise norms and have very different perceptions of risk compared to most people. In your case, your fellow student workers might simply have not felt safe sharing their crimes with you. "Naughty" behavior can be taboo yet widespread.
- jamestimmins 9y ago
- dpweb 9y agoBetter to not expect anything from anyone, and you wont be disappointed. What you do is simply restrict data to employees on a need to know basis. Not difficult to do.