4 ms·
Telcos have this level of monitoring of accounts because employees routinely would abuse this access to find details of exs, family members, friends and celebri
by kitteh 6y ago
Telcos have this level of monitoring of accounts because employees routinely would abuse this access to find details of exs, family members, friends and celebrities (billing info, call detail records, etc.). The problem was there was no proactive monitoring - it was all reaction based upon complaints that would kick off the investigation. I asked why this wasn't automatic to detect clear abuse and the answer was "do you know how many people we'd have to fire if we went looking for abuse?".
- Red_Leaves_Flyy 6y agoIf they're abusing their position they don't deserve to keep their job. The companies complicity makes them party to whatever these staff do. Whether a lawyer can prove that or not depends on the depth of the aggrieveds bank account.
- mc32 6y agoThe same problem existed in patient data prior to HIPAA. It still happens, but the unauthorized disclosures have gone down due to automated trips. It used to be your check in clerk could run any reports on whomever they wanted without giving it a second thought.
- ticmasta 6y agoSo when I worked for the cable company straight out of uni and we would look up famous local people to see what packages they subscribed to, we should have all been fired? I guess technically, but that's pretty draconian. Are you also no mercy, hard on crime, 1-strike and you're out person, or more progressive in that area?
- neolog 6y agoWould you have done it if you knew you would definitely get caught and be fired immediately?
- dboreham 6y ago> we should have all been fired? Yes.
- CyberDildonics 6y agoYou should not have been able to do it in the first place.
- Red_Leaves_Flyy 6y agoYou answered your own question. Seems you're having trouble taking responsibility for the fact that you acted unprofessionally by lashing out with presumptive attacks on my beliefs, which are incorrect. The culture of that workplace is a mitigating factor for the lower ranked staff, conversely it is a compounding factor for the senior staff that failed to put an end to it and discipline those involved. Should you have been fired? Depends on how much you abused your privilege and what you did with that information. Your comparison to 1 strike laws and greater crime is pretty rich given the information you improperly accessed could be used to blackmail others, or whatever. It's important to treat such information with the utmost respect. Your cavalier attitude and inability to accept responsibility in this regard may be very common within the tech industry, but such attitudes are also why there is a growing movement to; take data out of the hands of companies, and to harshly punish companies who fail to protect the data on one hand while vacuuming up as much as possible with the other.
- im3w1l 6y agoThis kind of thing has to involve cultural change where people internalize on a deep level that looking celebs up is a big no-no. You have to judge people by contemporary standards, and for this reason I think you do not deserve as much punishment as future offenders.
- kjs3 6y agoI'm honestly somewhat mystified at the lack of personal ethics where you could justify in your own mind that you shouldn't be fired for this sort of breach of trust. But I shouldn't be I suppose...I've seen all sorts of appalling behavior excused with 'gee, it's not like I killed anyone...'.
- mabbo 6y ago> "do you know how many people we'd have to fire if we went looking for abuse?" I think they make the mistake of presuming this has to go up to 11 on day 1. Tell the employees you're going to be proactively auditing. Choose a threshold. Interview and potentially fire those employees going over the threshold. Do this until you're done firing people, then increase the threshold and repeat. You will have to fire people, or threaten to, but employees will get the message that the PII-party is over.
- kitteh 6y agoThe challenge was that depending on the role, the union was involved. When that came into the picture there was a long, dragged out grievance process where someone would have to violate the policy x amount of times in y months before they'd be terminated. It was not unusual from what I've seen for folks to abuse this for years. To be honest tho - this is the contract that both the company and union agreed to, so bad on the company for being okay and not making this a more serious infraction. I've talked to some of the union stewards about this and they basically said they wanted this data locked down harder. They said it's too easy to access and super temping and wished the company would put more protection around it. Go figure.
- 3pt14159 6y agoI know for a fact that The Canadian Revenue Agency has this type of system in place and it isn't reactive to a complaint. It's proactive. If you try to pull up, say, Wayne Gretzky's tax information the system is able to detect whether or not you have a likely need for the information. If not, you're temporarily denied access until your access is evaluated by humans that are capable of asking why you need access. "For funsies" is not an acceptable response.
- edoceo 6y agoWow, even their revenuers skate to where the puck is going.
- Giornito 6y agoIt has mostly been reactionary because the cost of being proactive and that most of the active work would likely be associated with national security, which is often outside the public eyes.